05-14-2020 10:40 AM
Hi Everyone,
I am curious about this scenario in distributed deployment: is it possible (technically or maybe legally - from TAC perspective maybe) to combine various Cisco ISE platforms in one distributed deployment?
The example is something like this:
Also, if you see the example above, in HQ and Branch 1 I use SNS-3655s as PAN+MnT nodes. Is it possible in this case to change it to smaller appliance like SNS-3615? I am still thinking it's possible since in this distributed deployment case, it doesn't handling any RADIUS session so we should need less resources. I could be wrong here, so please advise.
Thanks.
Best regards,
Yedi
Solved! Go to Solution.
05-14-2020 04:13 PM
Hi Yedi,
You can mix physical/virtual appliances as well as hardware models in the same deployment (you should use the same hardware model between PANs and MnTs, however) as long as you stick to the supported maximums and understand the scale limits as per the ISE Performance & Scale guide.
With the breakdown you provided below, you have a Hybrid model (PAN + MnT on the same node), but you are exceeding the support max 5 PSNs. To support the 6 PSNs you have, you need to move to a fully Dedicated model.
You are also exceeding the maximum supported endpoints for a Hybrid model (25,000 for 3655 as PAN+MnT)
You might also want to review the Cisco Live BRKSEC-3432 on sizing and scaling ISE.
05-14-2020 04:13 PM
Hi Yedi,
You can mix physical/virtual appliances as well as hardware models in the same deployment (you should use the same hardware model between PANs and MnTs, however) as long as you stick to the supported maximums and understand the scale limits as per the ISE Performance & Scale guide.
With the breakdown you provided below, you have a Hybrid model (PAN + MnT on the same node), but you are exceeding the support max 5 PSNs. To support the 6 PSNs you have, you need to move to a fully Dedicated model.
You are also exceeding the maximum supported endpoints for a Hybrid model (25,000 for 3655 as PAN+MnT)
You might also want to review the Cisco Live BRKSEC-3432 on sizing and scaling ISE.
06-16-2020 09:49 AM
09-12-2022 03:02 AM
Hello Greg,
Is there a specific reason why we cant MIX PSNs or MNTs ?
I cant find it documented anywhere,
Thanks
09-12-2022 06:59 AM
It is not a Cisco supported design: https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide