Cisco ISE on Azure Cloud
Cisco ISE is available on Azure Cloud Services. To configure and install Cisco ISE on Azure Cloud, you must be familiar with Azure Cloud features and solutions. Some Azure Cloud concepts that you should be familiar with before you begin are:
-
Subscriptions and Resource Groups
-
Azure Virtual Machines: See Instances, Images, SSH Keys, Tags, VM Resizing.
You can deploy Cisco ISE on Microsoft Azure using an Azure Application or an Azure Virtual Machine. There are no differences in cost or Cisco ISE features when you deploy Cisco ISE using an Azure Application or an Azure Virtual Machine. We recommend using the Azure Application for the following advantages it offers in comparison to the Azure Virtual Machine:
-
Azure Application allows you to easily configure Cisco ISE-specific choices directly through its UI instead of a user-data field as in the case of Azure Virtual Machine configuration.
-
At the initial configuration of an Azure Application, you can choose an OS disk volume ranging between 300 and 2400 GB. However, during the initial configuration of an Azure Virtual Machine, you can change the OS disk volume to a fixed set of values provided by Azure portal in their drop-down menu. You must carry out more steps after Cisco ISE installation and launch to reconfigure the virtual machine.
-
You can directly choose from the specific Azure VM sizes that Cisco ISE supports.
-
You can configure a static private IP address at the initial configuration.
You can use the Azure Virtual Machine when:
-
You do not use the Azure portal UI to deploy Cisco ISE.
-
If you need to use one of the additional settings that are available in the Azure Virtual Machine configuration workflow.
The following task flows guide you through deploying Cisco ISE on Microsoft Azure using an Azure Application or an Azure Virtual Machine.
Cisco ISE can be installed by using one of the following Azure VM sizes.
Azure VM Sizes |
vCPU |
RAM (in GB) |
---|---|---|
Standard_D4s_v4 (This instance supports the Cisco ISE evaluation use case. 100 concurrent active endpoints are supported.) |
4 |
16 |
Standard_D8s_v4 |
8 |
32 |
Standard_F16s_v2 |
16 |
32 |
Standard_F32s_v2 |
32 |
64 |
Standard_D16s_v4 |
16 |
64 |
Standard_D32s_v4 |
32 |
128 |
Standard_D64s_v4 |
64 |
256 |
The Fsv2-series Azure VM sizes are compute-optimized and are best suited for use as PSNs for compute-intensive tasks and applications..
The Dsv4-series are general purpose Azure VM sizes that are best suited for use as PAN or MnT nodes or both and are intended for data processing tasks and database operations.
If you use a general purpose instance as a PSN, the performance numbers are lower than the performance of a compute-optimized instance as a PSN.
The Standard_D8s_v4 VM size must be used as an extra small PSN only.
For information on the scale and performance data for Azure VM sizes, see the Performance and Scalability Guide for Cisco Identity Services Engine.
Note |
Do not clone an existing Azure Cloud image to create a Cisco ISE instance. |
In addition to the procedures explained above, you can also use the following Cisco developed solution to install and automatically create multi-node Cisco ISE deployments on Azure: