05-23-2017 05:18 AM
Hi,
I have a customer which had experienced ISE high load and big impacts after building power outage.
When they restored power, every switch comes up in a synchronized timeframe and load on ISE was critical. Also at each reauthentication the same happened.
Do we have any workaround for that? Like we have for critical « authentication critical recovery delay ».
Something that can throttle interface bring up at switch boot up?
Regards,
Solved! Go to Solution.
05-24-2017 08:09 PM
We perform scale testing to validate that all endpoints can be reauthenticated within a few minutes, but certainly is one of the use cases to consider buffer capacity under such extreme cases. By setting reauth timers via server, it would be possible to return reauth timers that are dispersed by minutes or tens of minutes to reduce a periodic wave that resonates at the same interval.
Craig
05-23-2017 03:36 PM
Hi Jeremy,
Please take a look at the ISE best practices suggestions made in the CIsco Live sessions.
There are several things you can do in an enterprise infrastructure. In ISE you can reduce duplicate authentication requests by ignoring it totally, there are best practices around reauth, idle timer etc.
Designing ISE for Scale & High Availability (2017 Berlin)
Thanks
Krishnan
05-24-2017 08:09 PM
We perform scale testing to validate that all endpoints can be reauthenticated within a few minutes, but certainly is one of the use cases to consider buffer capacity under such extreme cases. By setting reauth timers via server, it would be possible to return reauth timers that are dispersed by minutes or tens of minutes to reduce a periodic wave that resonates at the same interval.
Craig
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide