04-19-2017 02:12 AM
Hi All
I have a query related to ISE deployment for 10 K users.
We have a set of dedicated ISE appliances ( 3595) for PAN/MNT personas.
We are planning to have active PAN/ secondary MNT personas in distributed model and other appliance as Secondary PAN/ active MNT personas.
This is a known design and often it is observed both sets are in same data centre. However I have a query can we have one set in Data Center 1 and other in Data Centre 2. Data Center 1 and Data Centre are connected with 1 gig link as primary and 20 MBPS MPLS link.
PSN will connect to these PAN/MNT personas for both wired and wireless network.
I have attached the propose topolgy , can any one share their views is this a correct way of deployment?
Cheers
Yasir
Solved! Go to Solution.
04-19-2017 10:19 AM
Certainly, you can split the nodes across DCs, but I would also recommend collocating the Primary for both Admin and MnT in one DC and Secondary at the other (i.e. not split Primary/Secondary). The diagram looks like it was based on one I created a while back, but current diagram (from BRKSEC-3699) reflects my recommendation.
Craig
04-19-2017 10:19 AM
Certainly, you can split the nodes across DCs, but I would also recommend collocating the Primary for both Admin and MnT in one DC and Secondary at the other (i.e. not split Primary/Secondary). The diagram looks like it was based on one I created a while back, but current diagram (from BRKSEC-3699) reflects my recommendation.
Craig
04-19-2017 10:21 AM
Yasir,
Your design proposal is a supported configuration. Just be sure to observe latency requirements. We have tons of resources you can use here in the community you can reference.
Regards,
-Tim
04-19-2017 09:53 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide