- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-30-2017 09:16 PM
Hi Team,
How many rules is below table based on?
ISE TACACS+ Performance
Platform performance specs are for a dedicated PSN.
PAN and MNT nodes are deployed as separate node(s).
Scenario | ||||
---|---|---|---|---|
ISE Version | ISE 2.0 | ISE 2.0 | ISE 2.1 | ISE 2.1 |
TACACS+ Function: PAP | 1,400 / second | 2,800 / second | 3,236 / second | 4,884 / second |
TACACS+ Function: CHAP | 1,500 / second | 2,900 / second | 2,413 / second | 4,961 / second |
TACACS+ Function: Enable | 700 / second | 1,200 / second | 1631/second | 1,984 / second |
TACACS+ Function: Session AuthZ | 900 / second | 1,700 / second | 2,191 / second | 3,453 / second |
TACACS+ Function: Command AuthZ | 900 / second | 1,700 / second | 2,359 / second | 3,467 / second |
TACACS+ Function: Accounting | 2,900 / second | 4,900 / second | 3,209 / second | 9,128 / second |
Thanks
DL
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-31-2017 11:16 AM
Refer here for policy table limits: ISE Performance & Scale
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-31-2017 10:14 AM
Would require some digging to learn from QA the size of specific rule set used in testing, but I would ask if there is a specific concern over the size of rule set you are using.
Craig
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-31-2017 10:27 AM
Customer cannot provide policy number at this time, but since they have more than 60K network device, and need to use different condition for different type of network device or location. So policy number will be larger as they said.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-31-2017 11:16 AM
Refer here for policy table limits: ISE Performance & Scale
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-31-2017 11:29 PM
Hi Craig,
Customer don't have oversize policies, just need to know the performance number we list based on how many rules. 1 rule or 100 rules? Did you mean the performance number I list in first post is based on max policy number?
Thanks
DL

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-01-2017 01:59 PM
Hi DL,
The link below is the same as the one Craig copy/pasted. If you look at the first table, you will see the limits of authentication/ authorization rules per deployment
https://communities.cisco.com/docs/DOC-68347
-Krishnan
