02-17-2022 11:15 AM
Currently, I'm managing a small ISE deployment. There is x1 PAN running M&T and Policy Services personas. The other two PSN's are deployed at two other sites. We're planning on adding five additional PSN nodes to the deployment.
After adding the new PSN's to the deployment, I would have a total of x7 PSN's and x1 PAN. Since the Cisco deployment guidelines state that you can have up to x6 PSN's for a medium-sized deployment and still be able to maintain an environment where the PAN has the M&T and Policy roles in one node if I have the 7th PSN node, would I then be required to move to a large deployment by breaking out the Administration, Policy, and M&T roles into separate nodes?
And how exactly is the enforcement of the medium and large deployments done? I saw that the ISE deployment documentation says that you cannot enable the policy service persona with a node running the Administration persona. But I already have the Admin persona deployed. Will the policy service role become disabled if I attempt to add too many PSN's to the existing deployment?
Solved! Go to Solution.
02-17-2022 08:02 PM
This is not enforced in any way, ISE will allow you to join all those PSNs and more. The issue is that it's not tested so your mileage may vary. It could work fine, or you could run in to issues, but if you need TAC support for an issue it's very likely they will point to that as being an unknown.
tldr: It will work but not recommended.
02-17-2022 08:02 PM
This is not enforced in any way, ISE will allow you to join all those PSNs and more. The issue is that it's not tested so your mileage may vary. It could work fine, or you could run in to issues, but if you need TAC support for an issue it's very likely they will point to that as being an unknown.
tldr: It will work but not recommended.
02-17-2022 08:42 PM
Thank you, Damien. I just needed to verify that with someone.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide