01-02-2019 10:26 AM - edited 01-03-2019 05:50 AM
I have a large deployment with 10 PSNs spread between two datacenters. The two datacenters are in the same city with very high speed low latency links (sub 10 ms) running between them. Functionally they can be considered the same LAN.
Current I have the 5 PSNs in each datacenter configured into their own node group with MAR cache sync turned on. All RADIUS authentication is sent to DC 1 with DC 2 as backup. This means DC1's MAR cache will be accurate, but in the event of a failover to DC2 it won't have an accurate MAR cache meaning any rules using MAR cache attribute would fail.
I am debating putting all 10 PSNs into the same node group and want to know the thoughts about doing this:
Thanks.
Solved! Go to Solution.
01-04-2019 08:40 AM
On 1. With high speed and low latency, it's technically LAN speed so I would not expect any issue other than potentially physical disconnects.
On 2. With 10 in the same node group appears too much. I would suggest 2 in each group, as it could contribute to more time to authenticate an endpoint when ISE tries querying the other PSNs in the group if the cache not found locally.
01-03-2019 08:33 AM
01-03-2019 08:42 AM
01-03-2019 09:28 AM
01-04-2019 08:40 AM
On 1. With high speed and low latency, it's technically LAN speed so I would not expect any issue other than potentially physical disconnects.
On 2. With 10 in the same node group appears too much. I would suggest 2 in each group, as it could contribute to more time to authenticate an endpoint when ISE tries querying the other PSNs in the group if the cache not found locally.
01-04-2019 08:51 AM
01-04-2019 10:16 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide