cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

662
Views
0
Helpful
2
Replies
dancall@cisco.com
Cisco Employee

ISE Node Replication to Azure

Hey Team, I have a customer that is interested in replicating an ISE node to Azure. Everything we are hearing from TAC indicates it is possible in theory, but we can't find any documentation or real world deployments. Does anyone have any customers doing this?

1 ACCEPTED SOLUTION

Accepted Solutions
Jason Kunst
Cisco Employee

FYI this is not officially supported, I am reaching out to our PM

General guidance is if it installs on any of the VM infrastructure supported by ISE then should work but heard there were issues running an ISE deployment (multiple VMs) in the cloud and that was being investigated.

Cisco Identity Services Engine Installation Guide, Release 2.2 - System Requirements [Cisco Identity Services Engine] -…

View solution in original post

2 REPLIES 2
Jason Kunst
Cisco Employee

FYI this is not officially supported, I am reaching out to our PM

General guidance is if it installs on any of the VM infrastructure supported by ISE then should work but heard there were issues running an ISE deployment (multiple VMs) in the cloud and that was being investigated.

Cisco Identity Services Engine Installation Guide, Release 2.2 - System Requirements [Cisco Identity Services Engine] -…

View solution in original post

Yeah I would think if the following are all true:

  1. DNS (forward and reverse) is setup correctly to resolve the hostname and IP of the Azure node.
  2. Network is setup to allow ISE synchronization and inter-node communication to the Azure node.
  3. Latency to Azure node is less than 300 ms.

If all those are true, then at the end of the day I have one IP talking to another IP and it should work.  Like Jason said, support may be another issue, but technically I can't see why it wouldn't work.

Content for Community-Ad