cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1516
Views
0
Helpful
11
Replies

PAN/Mnt/PXGrid and PSN virtual deployment

ibrahimbadr4669
Level 1
Level 1

Dears,

I have two nodes  (PAN/Mnt/PXGrid and PSN ), I have to choose which one will be on appliance 3615 and which one will be on virtual deployment?

1- PSN virtual and PAN/Mnt/PXGrid on the appliance  

2- PSN on appliance and PAN/Mnt/PXGrid virtual 

Thanks and BR;

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

@ibrahimbadr4669 If your access to both virtual and hardware appliances are the same and the both types have the same performance characteristics, then it does not matter how you assign the personas. You may always swap the personas around later.

View solution in original post

11 Replies 11

balaji.bandi
Hall of Fame
Hall of Fame

i go with the below :

2- PSN on appliance and PAN/Mnt/PXGrid virtual

also make sure you choose right VM compute resources.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

ibrahimbadr4669
Level 1
Level 1

Thanks alot Balaji for your kind support, is there cisco document discuss this subject

some of the things not documented always it was experience we suggest.

to be honest if you do not do compute properly on Virtual environment ISE struggle lot - compare to appliance which was tuned for ISE to run as expected.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

ibrahimbadr4669_0-1693462304743.png

 

ibrahimbadr4669
Level 1
Level 1

if we use virtual for PSN, if the it's fail. I Think it's easier to recover it . Is the virtual has performance issue so HW is preferred as PSN do the main function of ISE. Is that Right ?

Virtual should be more flexible and, with properly reservation, have similar performance characteristics to that of HW. You might want to opt for HW due to coordination complexity with virtual infrastructure teams, and due to security.

hslai
Cisco Employee
Cisco Employee

@ibrahimbadr4669 If you have two ISE nodes, it's better to have both to run everything for redundancy. Virtual appliances could perform better or poorer than hardware appliances depending on the underlying hardware and resource allocations.

@hslai thanks for your reply, we will do the medium deployment and the redundancy is considered, however due to the appliance numbers limitation we have , we will mix virtual and appliance.  So my question if I have to choose between PSN and PAN/Mnt/PXGrid which one should be virtual ? And if there is any document that discuss the pros and cons , it will be wonderful 

hslai
Cisco Employee
Cisco Employee

@ibrahimbadr4669 If your access to both virtual and hardware appliances are the same and the both types have the same performance characteristics, then it does not matter how you assign the personas. You may always swap the personas around later.

ibrahimbadr4669
Level 1
Level 1

thanks you  all  a lot for  your kind information and support