05-23-2018 01:35 PM
Customer wants to user the ISE CA for 4000 endpoints (WifiPersonalLaptops,tablets,smartphones).
It will be used for BYOD flow so that ISE can provision the device and provide certificate with EAP-TLS and supplicant configuration.
They do not want to use the corporate Microsoft CA.
Based on the below document, ISE supports up to 1.000.000 usercertificates.
https://communities.cisco.com/docs/DOC-68347
So I guess 4k-5k certificates will be ok for this certificate.
Is this correct ?
Any feedback for any issues from a similar customer deployment ?
Thanks,
Nikos
Solved! Go to Solution.
05-23-2018 01:39 PM
Yes, no concern? Why do you have one?
05-23-2018 01:39 PM
Yes, no concern? Why do you have one?
05-23-2018 10:36 PM
Many Thanks. Parter did not have experience on ISE internal CA. That's why they were asking.
05-23-2018 01:50 PM
Hi Nikos,
Also check out ISE 2.3 scenario based performance that describes how many certs issued per second and related performance. It is good to know this information when you provision certificate for the first time.
Thanks
Krishnan
05-23-2018 10:37 PM
Many Thanks for your help.
05-24-2018 04:13 AM
You said partner didn’t have experience on ISE internal ca, this is more robust than using external ca as it has less parts and complexities
05-24-2018 04:34 AM
This is great.
Jason, many thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide