cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1294
Views
0
Helpful
2
Replies

Expanding ISE 3.0 Deployment

Currently, I'm managing a small ISE deployment. There is x1 PAN running M&T and Policy Services personas. The other two PSN's are deployed at two other sites. We're planning on adding five additional PSN nodes to the deployment.

After adding the new PSN's to the deployment, I would have a total of x7 PSN's and x1 PAN. Since the Cisco deployment guidelines state that you can have up to x6 PSN's for a medium-sized deployment and still be able to maintain an environment where the PAN has the M&T and Policy roles in one node if I have the 7th PSN node, would I then be required to move to a large deployment by breaking out the Administration, Policy, and M&T roles into separate nodes?

And how exactly is the enforcement of the medium and large deployments done? I saw that the ISE deployment documentation says that you cannot enable the policy service persona with a node running the Administration persona. But I already have the Admin persona deployed. Will the policy service role become disabled if I attempt to add too many PSN's to the existing deployment?

 

CharlesGaskin8417_0-1645125326464.png

 

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni

This is not enforced in any way, ISE will allow you to join all those PSNs and more. The issue is that it's not tested so your mileage may vary. It could work fine, or you could run in to issues, but if you need TAC support for an issue it's very likely they will point to that as being an unknown. 

tldr: It will work but not recommended. 

View solution in original post

2 Replies 2

Damien Miller
VIP Alumni
VIP Alumni

This is not enforced in any way, ISE will allow you to join all those PSNs and more. The issue is that it's not tested so your mileage may vary. It could work fine, or you could run in to issues, but if you need TAC support for an issue it's very likely they will point to that as being an unknown. 

tldr: It will work but not recommended. 

Thank you, Damien. I just needed to verify that with someone.