05-11-2017 02:00 AM
Hello,
I have a question about PSN scaling.
At the moment CU is running ACS 5.8 and running MAB for about 350.000 Clients. The radius authentication requests are handled by 2 ACS-Servers without any performance issues. Clients are mix of PC's, printers and Cisco IP-Phones (about 160K).
Idle-Timer is 1200s and Reauth-Timer is 600s.
Now we are planing to migrate to ISE and I saw in the data sheets and sizing slides that a dedicated PSN (only Radius MAB) can handle max. 40K concurrent sessions. Is this number a "hard cut" or is it only a tested number and will only be supported in case of any issues ?.
CU is complaining about to have now about 10 PSN's + additional 10 PSN's for redundancy + PAN (prim + sec) + MnT (prim + sec).
PS: Still discussing to add load balancers into the ISE design to be more flexible and have the possibility to add profiling .. in the future without to "optimize" switch configurations ( talking about 12.000 Access-Switches)
Thanks in advance
-Dieter Grassler (dgrassle@cisco.com)
Solved! Go to Solution.
05-11-2017 07:29 AM
It’s a guideline, going over this you won’t be provided support and the services may degrade. Its not recommended or supported.
05-11-2017 06:54 AM
dgrassle-
There is a great sizing sheet here:
The ISE 2.2 install guide, for large deployments (either VM or appliance) support well over your client requirements. It will just depend on your deployment model and device sizing
Dedicated (PAN, MnT, PXG, and PSN Nodes) | 3495 as PAN and MnT | 40 | 250,000 | 100,000 | N/A | 25,000 |
3595 as PAN and MnT | 50 | 500,000 | 300,000 | N/A | 50,000 |
HTH-
Vince
05-11-2017 07:01 AM
Hi Vince,
thx.
I know all this slides and guides, but key question is: are the 40K max. concurrent sessions a hard limit or more a "main guideline" ?
05-11-2017 07:29 AM
It’s a guideline, going over this you won’t be provided support and the services may degrade. Its not recommended or supported.
05-11-2017 07:48 AM
Thx. for hint about support.
Will go ahead with the load balancer design.
-Dieter
05-11-2017 08:21 AM
right otherwise you would have to manually load balance by watching and making certain PSNs primary and secondary depending on the NADs, then juggling them around if become an issue. Load balancer can easily add in another PSN is you go over
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide