04-08-2025 05:58 AM - edited 04-08-2025 06:02 AM
Hi members,
@Greg Gibbs I need to migrate Cisco ISE to Azure. Can you advise if I should use VM or the application option to create ISE instance in Azure? which is better?
04-08-2025 09:21 AM
From my experience, the application is easier to deploy. However, why not go through the experience of standing up both so you have an understanding of how long it would take in case you need to standup another node. That is what I did, and at the end, it's an ISE application. The VM option is the same as if you stood up an VM in ESXi or Hyper-V you have to go through the setup. The application, you just fill out the information during the creation and you are pretty much done. Also if you are doing any type of automation, then it really depends on how you feel you want to automated the creation of the ISE in Azure. I don't know if one is better than the other.
04-08-2025 06:58 PM
Before making the solid decision to deploy ISE in Azure, be sure to review the issues discussed in the following posts. I would highly recommend deploying in AWS instead of Azure if possible to avoid these inherent issues with EAP-TLS caused by MS dropping out-of-sequence UDP packets.
https://community.cisco.com/t5/network-access-control/azure-packet-fragmentation/td-p/5205223
04-09-2025 08:32 AM
Thanks very much it really is very useful. It appears hiding out of order packets in IPSec is the way forward. Unfortunately we don't have an option to go to aws, we have a a big relationship with Microsoft and everything else in Azure.
So what do you reckon is the answer to my original question whether to use use ISE application or a VM?
04-09-2025 04:49 PM
There is no right answer for that question nor any functional difference in the end product. It would depend entirely on your comfort level, processes, and tools for deploying cloud resources in Azure.
The previous post from @Scott Fella reflects the same guidance.
04-09-2025 05:55 PM
I'm going to be setting up a few in Azure soon, but this time with Express Route.... should be fun, but hopefully I get it working.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide