02-21-2019 07:49 AM - edited 03-08-2019 07:13 PM
Hi Team,
I have query regarding ISE HW 3595/ OS 2.3 concurrent connections limit into distributed deployment, there are 8 nodes- 2 PAN+MnT (1 node – Primary PAN & Standby MnT, 1 node – Standby PAN and primary MnT) and rest are dedicated PSN nodes.
I went through the below document regarding ISE scalability and performance:
https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148
Solved! Go to Solution.
02-21-2019 08:02 AM
02-21-2019 08:02 AM
02-21-2019 08:23 AM
Hi Damien, thanks for quick reply.
my 1st query is clear now and same i was hoping to have.
for second query, CU has TACACS packets(Device admin) only, so connection count will be per user/per device based?
There is one option-""Enable Single Connect Mode" Documented- Check to use a single TCP connection for all TACACS+ communication with the network device.
Choose one of the following:
Legacy Cisco Devices
Or, TACACS+ Draft Compliance Single Connect Support. If you disable Single Connect Mode, ISE uses a new TCP connection for every TACACS+ request."To use the above option, can help in scaling into 20k PSN limit per CU's scenario.
02-21-2019 08:51 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide