12-28-2019 07:31 AM
Hi,
As this great document states ISE Performance & Scale maximum number of endpoints on ISE 2.6 is 2,000,000. Does this number differ by the hardware models you select? I believe that it affects the supported number of active sessions but I'm wondering if it also affects the number of endpoints.
I assume that database replications within the deployment will happen when ISE PSNs or Primary PAN learn new MAC addresses or new updates about a MAC address. Thus, when you have 2,000,000 of endpoints in the deployment, all the nodes have the same 2,000,000 of data in terms of the number of MAC addresses.
I'm asking it because one of my customers will have much more than 2,000,000 of endpoints in their new deployment. (We are planning to have two or more ISE-CUBEs to store the 3millions of MAC addresses for MAB.) And we are looking at SNS-3615 for the PSNs. We are wondering if the hardware model is appropriate for this large amount of data. The following image is from one of my favorite presentations by Jason. This is quite informative but I'm a bit confused by this table.
https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-3432.pdf
Does it mean that a single hardware appliance can't store 2,000,000 mac addresses for authentication even if it is SNS-3695? The customer and I are discussing how we will be able to import the mac addresses into the ISE CUBE. We thought we would just need to import CSV files that list MAC addresses on the PAN, then the data would be replicated among all the other nodes in the deployment. But we are not sure.
And what happens if the number of MAC addresses exceeds 2,000,000? Data is deleted from the oldest ones?
Solved! Go to Solution.
12-28-2019 09:33 AM
12-28-2019 09:33 AM
01-05-2020 06:41 PM
Hi Demien,
Thank you very much for the informative comment.
>The 10k - 100k endpoints listed per appliance template/hardware model is for active endpoints and not known. The 2 million number is referring to active endpoints across all PSNs as well as stored MACs in the context visibility database.
We have not confirmed if more than 2 million endpoints will actively connect to the network. There will be some small regions for the early stages of the deployment. I think we can use virtual machines that have equivalent performance as SNS-3615 for some of the PSNs.
>Now, the stated maximum for "total known endpoints", or "Maximum number of Endpoints" as referred to in the performance and scale guides, states only 2 million stored in context visibility. I have had a deployment with 4.9 million known endpoints/MACs, and everything was still working.
This is quite important for this customer. Thanks for the information.
01-06-2020 08:43 AM
keep in mind officialy we only support 2 mil endpoints in the database. Please if you have further needs reach out to the product managers:
To contact our product team for future enhancement requests, externally for cisco customers/partners at http://cs.co/ise-feedback for cisco employees internally at http://cs.co/ise-pm
01-06-2020 05:21 PM
Hi Jason,
Happy new year!
I understand that the number is not supported and I have already posted a comment to ise-pm forum last night. And a CSS contacted one of the PMs about it. Thanks for the feedback!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide