12-20-2019 09:58 PM
I have a Customer, planning to purchase Cisco ISE.
There 500 users distributed across 9 locations(8 in India and 1-US). In US there are only 50 Users. Around 100 Users are mobile workers who frequently travel across this locations. They need Complete NAC solution with dotlx, Profiling and posturing. They have Mixed End points(Windows, Mac and Linux). AD is hosted in Central Location India.
All the branches are connected via P2P link and they also have WAN redundancy.
My Question is:
1. whether i need to Choose Centralized deployment with HA? (Both ISE appliance in India)
2. Or I need to Suggest Separate ISE instances in India and US as latency can be a factor to be considered?
Solved! Go to Solution.
12-21-2019 09:43 AM
12-20-2019 10:14 PM
12-21-2019 02:37 AM
Hi Damien,
Thanks for all the information.
Just in case, what is your opinion on proposing Split deployment? One ISE is US and one in India?
Customer is just worried because there were some outcomes of Internet B.W outage.
12-21-2019 09:43 AM
12-21-2019 10:17 PM
Thanks Damien for all the information shared. It was of great help
Thanks Jason for sharing the live session link. I have gone through it and got a better picture interms of deployment
12-21-2019 06:58 AM
@Damien Miller wrote:
Due to the layout of users and sites I would lean towards two 3615 appliances in India. Opting to not deploy US based nodes. It largely would depend on the WAN connection reliability and latency.
The latency between India and the USA is more of an issue for ISE deployment node to node communication between themselves, rather than endpoint authentication latency. We want to keep node to node latency under 300 ms, and that's pretty close to what I have seen going between the two countries.
Endpoint authentication is less susceptible to latency, and we can plan for it with the radius timers. Typical timers are set between 5 - 10 seconds, often not needing anywhere near that much time for responses.
Also look at http://cs.co/ise-training and watch BRKSEC-3432, there are slides explaining different models
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide