cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1446
Views
5
Helpful
2
Replies

Multiple DNA Centers with a distributed ISE or not

rusbaker
Level 1
Level 1

All,

 

I'm looking at a deployment of SD-Access in three countries so will need 2 to 3 DNA Centres due to the distances involved, is it possible to have them all talking to a distributed ISE solution for consistency on polices etc.. or will I have to look at regional ISE deployments instead? 

 

 

Thanks Russ 

1 Accepted Solution

Accepted Solutions

Dan Rowe
Cisco Employee
Cisco Employee
We aim to have multi-DNAC to single ISE capability in release codenamed Wolverine which will be DNAC version 1.5. Once available, we expect to be able to support up to 4 separate DNA clusters by 1 ISE server. Please reach out to your account team if you would like to get involved in the canary / EFT program for DNAC version 1.5.

View solution in original post

2 Replies 2

Mike.Cifelli
VIP Alumni
VIP Alumni
You should definitely get with your reps so that they can assist you with the design. A few things you will want to consider/know based on my experiences:
-For a DNAC cluster you must run 3 nodes
-The latency RTT (round-trip-time) between Cisco DNA Center and the network devices it manages must be taken into consideration. The optimal RTT should be less than 100 milliseconds to achieve optimal performance. Latency RTT of up to 200ms is support.
-As far as an ISE solution, this will definitely depend on what you plan to accomplish from a feature perspective & how many NADs/endpoints you will manage across your locations. For ISE info, this link is usually updated and should answer many concerns: https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148#toc-hId-1185499862
-You will probably want to have your ISE PANs near the DNAC cluster, with however many PSNs you require to support your numbers at the remote locations.
-Since it sounds like you will span across WANs you are going to need to determine how you intend on extending your SDA. Options include: IP transit (heavy on manual bgp peering config etc); VXLAN extension (based on what I know not recommended unless you own the dedicated links); SD-WAN (which has several components itself; benefit is you can use a variety of transport means)
-If needing to split management, you would consider multiple fabrics, instead of one fabric with multiple sites.

Dan Rowe
Cisco Employee
Cisco Employee
We aim to have multi-DNAC to single ISE capability in release codenamed Wolverine which will be DNAC version 1.5. Once available, we expect to be able to support up to 4 separate DNA clusters by 1 ISE server. Please reach out to your account team if you would like to get involved in the canary / EFT program for DNAC version 1.5.