cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1607
Views
0
Helpful
5
Replies

ISE 2.2 PSN Scaling

dgrassle
Cisco Employee
Cisco Employee

Hello,

I have a question about PSN scaling.

At the moment CU is running ACS 5.8 and running MAB for about 350.000 Clients. The radius authentication requests are handled by 2 ACS-Servers without any performance issues. Clients are mix of PC's, printers and Cisco IP-Phones (about 160K).
Idle-Timer is 1200s and Reauth-Timer is 600s.
Now we are planing to migrate to ISE and I saw in the data sheets and sizing slides that  a dedicated PSN (only Radius MAB) can handle max. 40K concurrent sessions. Is this number a "hard cut" or is it only a tested number and will only be supported in case of any issues ?.

CU is complaining about to have now about 10 PSN's + additional 10 PSN's for redundancy + PAN (prim + sec) + MnT (prim + sec).

PS: Still discussing to add load balancers into the ISE design to be more flexible and have the possibility to add profiling ..  in the future without to "optimize" switch configurations ( talking about 12.000 Access-Switches)

Thanks in advance

-Dieter Grassler  (dgrassle@cisco.com)

1 Accepted Solution

Accepted Solutions

It’s a guideline, going over this you won’t be provided support and the services may degrade. Its not recommended or supported.

View solution in original post

5 Replies 5

vrostowsky
Level 5
Level 5

dgrassle-

There is a great sizing sheet here:

ISE Performance & Scale

The ISE 2.2 install guide, for large deployments (either VM or appliance)  support well over your client requirements.  It will just depend on your deployment model and device sizing

Cisco Identity Services Engine Installation Guide, Release 2.2 - Network Deployments in Cisco ISE [Cisco Identity Servi…

Dedicated (PAN, MnT, PXG, and PSN Nodes)

3495 as PAN and MnT

40

250,000

100,000

N/A

25,000

3595 as PAN and MnT

50

500,000

300,000

N/A

50,000

HTH-

Vince

Hi Vince,

thx.

I know all this slides and guides, but key question is: are the 40K max. concurrent sessions a hard limit or more a "main guideline" ?

It’s a guideline, going over this you won’t be provided support and the services may degrade. Its not recommended or supported.

Thx. for hint about support.

Will go ahead with the load balancer design.

-Dieter

right otherwise you would have to manually load balance by watching and making certain PSNs primary and secondary depending on the NADs, then juggling them around if become an issue. Load balancer can easily add in another PSN is you go over

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: