12-08-2016 08:10 AM
Team
My customer has a query about whether a 3595 is compatible with a 3495 in the same deployment. They would need to deploy a 3495 in one DC and a 3595 in a different DC for Guest access. Is that supported? Are there any specific guidelines that we need to follow to make it work? Understand that 3595 needs to run ISE 2.0.
Solved! Go to Solution.
12-08-2016 10:36 AM
There is no h/w requirement against using different h/w across DC. From the s/w side you need the same s/w on these h/w.
But you need to be aware of the performance difference and see if this is OK.
The performance and scale for this is very different that needs to be understood. Also ISE 2.0.1/2.1 supports 3595 not ISE 2.0.
https://communities.cisco.com/docs/DOC-68347
Its ok to mix different appliances and VMs in your deployment as long as they are sized appropriately depending on how many clients they will be serving from a specific node or for the whole deployment and the persona they be running.
12-08-2016 10:36 AM
There is no h/w requirement against using different h/w across DC. From the s/w side you need the same s/w on these h/w.
But you need to be aware of the performance difference and see if this is OK.
The performance and scale for this is very different that needs to be understood. Also ISE 2.0.1/2.1 supports 3595 not ISE 2.0.
https://communities.cisco.com/docs/DOC-68347
Its ok to mix different appliances and VMs in your deployment as long as they are sized appropriately depending on how many clients they will be serving from a specific node or for the whole deployment and the persona they be running.
02-19-2017 04:23 PM
Hi Jason,
I had a follow-up question on the mix of 3495/3595 that the sizing guide does not seem to address.
If the PAN/MNT nodes are 3495, but the PSNs are 3595, do we still get the max concurrent endpoints of 40K/PSN (with ISE 2.2), or does that require the PAN/MNT nodes to also be 3595?
Examples - Separate (4) PAN/MNT nodes on 3495, separate PSNs on 3595:
Max number of endpoints = 250K (limit of PAN/MNT hardware)
Max number of PSNs = 40 (limit of PAN hardware)
Max concurrent endpoints per PSN (all PSNs are 3595) = 40,000 (limit of PSN hardware?)
Can you please confirm if these are the limits for a mixed distributed deployment?
I would assume if the PSNs are also mixed 3495/3595, the supported limit would be 20,000 endpoints. Is that correct?
10-27-2017 07:27 AM
I would think that 20,000 would be the correct number. Did you ever get a response to this question?
Thanks,
Alex
10-27-2017 07:51 AM
You can mix and match
See table 1 - Cisco Identity Services Engine Installation Guide, Release 2.2 - Network Deployments in Cisco ISE [Cisco Identity Servi…
A deployment total amount of endpoints has to do with what your PAN/MNT is setup as.
With 3495 running as PAN/MNT we support up to 250k total active endpoints in a distributed deployment
Totally separate specification, You can run a PSN 3595 with a max of 40k endpoints in this same deployment.
The resources of the PAN/MNT nodes don't restrict the capacity of the PSNs themselves.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide