cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Announcements
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

321
Views
4
Helpful
1
Replies
Highlighted
Beginner

Cisco ISE Distributed Deployment Node Communication

Hi All,

I want to ask some questions,

Currently I plan to implement Cisco ISE in Dispersed Network Deployment on 5 different countries.

The main campus will have 1 Admin Node, 1 Monitoring Node, and 2 PSN. Four other country will have 1 PSN.

My questions are:

  • Apart from when the nodes join, when will the PSN and Admin Node communicate each other?
  • When will PSN and Monitoring Node communicate each other?
  • When will Admin Node and Monitoring Node communicate each other?
  • What will it based on? Trigger by certain event such as user connection/disconnection, configuration change or will it be trigger on regular basis, ex: per 5 minutes.
  • Any reference about the size of information exchange between these nodes?

Thanks for any advice in advanced.

Regards,

Kevin

Everyone's tags (3)
1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Cisco Employee

Re: Cisco ISE Distributed Deployment Node Communication

Kevin,

There are several instances in which each node will talk to each other but here are some cases at a high level:

  • PSN -> Admin:
    • Node joins deployment
    • Policy created / modified on Admin
    • Guest accounts created
    • Device profile
  • PSN -> MnT
    • Client connect / disconnect
    • PSN health data
    • Audit information
    • Logging information
    • Much more...
  • Admin -> MnT
    • Session directory access (live log)
    • Deployment health status
    • All reporting operations
    • Backup operations
    • Much more...

Once the nodes are in sync, the size of information transferred in not enormous.  What you need to be more concerned with is latency between nodes.  Depending on the version, that could be as much as 300ms.  Please see the content we have available in the community for more information about distributed deployments.

Regards,

-Tim

View solution in original post

1 REPLY 1
Highlighted
Cisco Employee

Re: Cisco ISE Distributed Deployment Node Communication

Kevin,

There are several instances in which each node will talk to each other but here are some cases at a high level:

  • PSN -> Admin:
    • Node joins deployment
    • Policy created / modified on Admin
    • Guest accounts created
    • Device profile
  • PSN -> MnT
    • Client connect / disconnect
    • PSN health data
    • Audit information
    • Logging information
    • Much more...
  • Admin -> MnT
    • Session directory access (live log)
    • Deployment health status
    • All reporting operations
    • Backup operations
    • Much more...

Once the nodes are in sync, the size of information transferred in not enormous.  What you need to be more concerned with is latency between nodes.  Depending on the version, that could be as much as 300ms.  Please see the content we have available in the community for more information about distributed deployments.

Regards,

-Tim

View solution in original post