Introduction
Welcome to the Cisco ISE Deployment Guide. This guide is designed to walk you through a professional, high-security deployment of Cisco Identity Services Engine (ISE).
Deployment Overview
This guide follows a specific, real-world deployment model intended for high availability and redundancy.
- Hardware Model: Cisco 3715 Appliances (2 units).
- Persona Configuration: To maximize efficiency and provide redundancy, both appliances are configured with the following personas:
- Administration (Admin): For managing the ISE deployment.
- Monitoring (MNT): For logging, reporting, and analytics.
- Policy Service Node (PSN): For handling RADIUS/TACACS+ requests and posture evaluation.
- Deployment Strategy: By running all personas on both nodes, we ensure that if one appliance fails, the other can continue to handle both management and network access tasks.
Hardware & Resource Requirements
Before beginning the installation, ensure your Cisco 3715 appliances meet the following minimum requirements for this deployment:
| Resource |
Requirement |
| CPU |
Minimum recommended cores for full persona load |
| Memory |
Sufficient RAM to support Admin, MNT, and PSN personas simultaneously |
| Storage |
High-performance SSD/HDD for logging and database operations |
| Network |
Multiple physical interfaces for Management, Data, and redundant paths |
Note: For a production environment, always consult the official Cisco ISE Hardware Compatibility List (HCL) for specific resource requirements based on your expected endpoint count.
Prerequisites
Successful deployment depends on having the following infrastructure components ready and correctly configured:
1. Network Connectivity
- Management Network: Dedicated connectivity for the Admin and MNT personas.
- Data Network: Connectivity for the PSN persona to communicate with network devices (Switches, WLCs, etc.).
- Routing: Proper routing between all ISE nodes and the network access devices.
2. Network Services
- DNS (Domain Name System): Both ISE nodes must be able to resolve each other's FQDNs (Fully Qualified Domain Names) and external resources.
- NTP (Network Time Protocol): Time synchronization is critical. All ISE nodes and all network access devices must be synchronized to the same NTP source to ensure certificate validation and log accuracy.
3. Security & Compliance
- FIPS Readiness: This deployment will be enabled for FIPS (Federal Information Processing Standards) compliance. This requires specific configuration of RADIUS protocols and certificate management.
- Access Control: Ensure that firewall rules allow necessary traffic between ISE nodes (e.g., database replication, monitoring traffic) and between ISE and network devices (RADIUS/TACACS+).