cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
867
Views
2
Helpful
2
Replies

Average ISE AAA+Posture bandwidth consumption per user

bawagne
Cisco Employee
Cisco Employee

Dear ISE expert

I have a customer that can not go for distrubetd deployment because of latency issue.

He has some remote sites that can have up to 1000 users and is worried about having

all the users connecting within a short time and affecting bandwidth usage.

Please can you help identify the average bandwidth consumption for ISE AAA with posture and the average time it takes.

Many Tahnks

Babacar

2 Replies 2

Craig Hyps
Level 10
Level 10

I have posted BW/Latency guidance here: ISE Latency and Bandwidth Calculators

but specifically call out that the calculator does not cover bandwidth required for RADIUS or other services like Profiling and Posture since they are so variable depending on your config.

For example, each RADIUS transaction will be depend on EAP type, protocol selection, key sizes, and timers.  Profiling will depend on probes enabled, and posture will depend on the checks performed, and more specifically the remediations configured.  For example, it may be trivial to update a registry setting, but much more bandwidth to fetch AV signatures, and even more to download a Windows service pack, especially if no local remediation server or WAN caching not employed.

My general recommendation in these cases is to take what you believe to be a typical set of clients and then measure the load for that control set.  You can then extrapolate against the larger community.

Often the bandwidth for RADIUS is not that high, but be sure to implement best practices for timers as called out in BRKSEC-3699 (find reference version of presentation @ ciscolive.com).  By setting reasonable timers for interim accounting, reauth, etc, you will limit the noise.  The session also calls out the need to set reasonable values for DHCP leases as there is an impact to profiling.  Related to Posture, consider the type of assessments and remediation needed and where the remediation servers are located.

Craig

Many Thanks Craig.

BR

Babacar