10-27-2017 05:47 AM - edited 02-21-2020 10:37 AM
New Identity Services Engine Deployment
Is it possible to mix and match servers?
Example
3495 admin node
3595 policy node
10-27-2017 06:12 AM
10-27-2017 06:29 AM
10-27-2017 06:59 AM
10-27-2017 07:56 AM
Rahul is correct but also note that using both PSNs requires some sort of RADIUS load balancing.
Cisco wireless delivered via WLC usually doesn't do this on its own and you would need some sort of Application Delivery controller / load balancer in front of your PSNs (i.e. F5 Big-IP, Citrix Netscaler or such).
Cisco wired has some crude round robin load balancing but still a real ADC is recommended.
You also need to consider failure scenarios. If you require 2 PSNs for your deployment day to day it's recommended to add a 3rd for availability.
10-27-2017 07:55 AM - edited 10-27-2017 08:06 AM
Based on recent findings and issues in our LARGE distributed environment, you should do the following:
1.-All the PAN and MNT Nodes MUST be the same type of device, in our case 3595's to handle the significant amount of data our Wireless network generates. We realized that 3495 as MNT's is NOT good enough for a large deployment (60k+ endusers/concurrent sessions).
2.-Use 3495 preferably as PSN only.
3.-DO NOT, combine 2 personas on the same node 3495/3595 because the performance goes significantly down. (it does not apply to your case).
4.-USE Load balancing to efficiently distribute the load between the PSN's.
The most important piece is the version that you would like to run. I would strongly suggest to use 2.3 version.
BTW, from your post above if you are using 3595 as PSN's then you have 40K sessions x node so that would cover you without needing another PSN. WHY the Load Balancing mechanism is important??.
1.-Round Robin DNS does not work properly when using CWA or WebAuth on the WLC.
2.-Failover mechanism is straightforward when using for example F5 (our case).
If you use 3495 as PSN's, then you would need another PSN to be covered in case of failure
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide