cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1568
Views
5
Helpful
1
Replies

ISE Hybrid deployment

sergey.dibrov
Level 1
Level 1

Hello

What is the point of ISE hybrid deployment if max Active Sessions per Deployment the same as standalone and limited by performance of PAN+Mnt Node?
What is the point to have separate PSN from scaling point of view?

 

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni

As you pointed out, the max number of active sessions does not change between a standalone and hybrid deployment. But there are still reasons this is still a deployment methodology companies consider. 

 

  1. A customer may want dedicated guest PSNs they can place in an access restricted location. 
  2. There may be a specific ask to have authentication services local to a region. 
  3. A customer wants to run load balancers and place two PSNs behind each VIP so easier patching and upgrading without NAD impact.
  4. Less likely, the transactions per second or integration load dictates additional PSNs. 

View solution in original post

1 Reply 1

Damien Miller
VIP Alumni
VIP Alumni

As you pointed out, the max number of active sessions does not change between a standalone and hybrid deployment. But there are still reasons this is still a deployment methodology companies consider. 

 

  1. A customer may want dedicated guest PSNs they can place in an access restricted location. 
  2. There may be a specific ask to have authentication services local to a region. 
  3. A customer wants to run load balancers and place two PSNs behind each VIP so easier patching and upgrading without NAD impact.
  4. Less likely, the transactions per second or integration load dictates additional PSNs.