02-21-2023 03:58 AM
Hi All,
I need help to verify an ISE setup. we currently have an HQ and two branch sites, the HQ currently have DNA and ISE integrated for SD-Access. At HQ we have two admin nodes and two PSNs and are currently used for used for user authentication using dot1x. We have purchased to PSN nodes to be located and used by our two branch offices and are suppose to join the admin nodes at our HQ. What i need to verify is that we will not have SD-Access implemented on the branch sites network so the PSN will directly be communicating to the network devices at the branch offices. we are currently only implementing dot1x at branch sites but we plan to do posturing as well in both HQ and branch offices.
I need to confirm if this setup would work and if it will require special configuration or not.
Thanks
Solved! Go to Solution.
02-21-2023 08:42 AM
02-21-2023 05:37 AM
ISE can be deploy any where in the distributed environment :
make sure check this requirement :
Maximum network latency between primary PAN and any other Cisco ISE node including the secondary PAN, MnT, and PSNs |
300 milliseconds |
check some bandwidth calculator :
02-21-2023 08:12 AM
thanks but i was actually trying to understand if ISE would be able to handle Cisco SD-Access and DNA managed network while still be to work with standalone and legacy network devices.
02-21-2023 08:42 AM
Yes
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide