cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1783
Views
10
Helpful
3
Replies

Cisco ISE, AAA server group

Hi there,

 

We are deploying an ISE distributed Solution without using of a dedicated load balancer.

 

In relation to the definition of the AAA server group, I have 4 PSNs spread evenly across 2 datacentres that i want to use. Is it best practice to define all 4 of these PSNs within the AAA server group or to only use a subset?

 

Thanks in advance.

 

 

2 Accepted Solutions

Accepted Solutions

Anurag Sharma
Cisco Employee
Cisco Employee

Hi @bigbobmcquade  

It really depends on how you want it. Having said that, let's say that I have 4 DC sites, with each DC containing 50 switches.

I would put a PSN in each of those 4 sites and order them based on the proximity. Meaning, DC1 would have the local PSN listed on top in the aaa group. Then, the second farther one and then the next. etc. Similarly DC2 would have its own local PSN listed first, and then the other PSNs based on Geographical or response-time prioritised PSNs.

Again, if you have a Primary-site / DR-site site system, you may choose to design it differently.

Hope that helps!
Please 'RATE' and 'MARK ACCEPTED', if applicable.

View solution in original post

To add to @Anurag Sharma comments.  I like the PSN at each site sitting at the top of the list idea.  However, I definitely think it depends on your requirements.  If you choose to place all 4 in one group know that the priority is identified in a top-down approach.  Meaning if PSN1 is first in the group then your NADs will attempt to use it first.  HTH!

View solution in original post

3 Replies 3

Anurag Sharma
Cisco Employee
Cisco Employee

Hi @bigbobmcquade  

It really depends on how you want it. Having said that, let's say that I have 4 DC sites, with each DC containing 50 switches.

I would put a PSN in each of those 4 sites and order them based on the proximity. Meaning, DC1 would have the local PSN listed on top in the aaa group. Then, the second farther one and then the next. etc. Similarly DC2 would have its own local PSN listed first, and then the other PSNs based on Geographical or response-time prioritised PSNs.

Again, if you have a Primary-site / DR-site site system, you may choose to design it differently.

Hope that helps!
Please 'RATE' and 'MARK ACCEPTED', if applicable.

To add to @Anurag Sharma comments.  I like the PSN at each site sitting at the top of the list idea.  However, I definitely think it depends on your requirements.  If you choose to place all 4 in one group know that the priority is identified in a top-down approach.  Meaning if PSN1 is first in the group then your NADs will attempt to use it first.  HTH!

Thank you both for the advice, clear now on what we require. 

 

Appreciate it :)