Cisco ISE hardware and virtual appliance requirements
Cisco ISE can be installed on Cisco Secure Network Server (SNS) hardware or virtual appliances. The virtual machine should have the same system resources as the Cisco SNS hardware appliances to achieve similar performance and scalability as the Cisco ISE hardware appliance. This section lists the hardware, software, and virtual machine requirements for installing Cisco ISE.
![]() Note |
Harden your virtual environment and ensure that all security updates are current. Cisco is not liable for any security issues found in hypervisors. |
![]() Caution |
Cisco ISE does not support VM snapshots to back up data on any virtual environment. Enabling the Snapshot feature on the VM might corrupt the configuration. If this happens, you may need to reimage the VM. |
Cisco SNS hardware appliances
For Cisco SNS 3600 series appliances, see Cisco SNS-3600 Series Appliance Hardware Installation Guide.
For Cisco SNS 3700 series appliances, see Cisco SNS-3700 Series Appliance Hardware Installation Guide.
For Cisco SNS 3800 series appliances, see Cisco SNS-3800 Series Appliance Hardware Installation Guide.
For information about the supported hardware platforms for your version of Cisco ISE, see the Release Notes for Cisco Identity Services Engine.
Support for Cisco SNS 3800 series appliance
The Cisco SNS 3800 series appliances are based on the Cisco Unified Computing System (Cisco UCS) C225 M8 Rack Server and are configured specifically to support Cisco ISE. Cisco SNS 3800 series appliances are designed to deliver high performance and efficiency for a wide range of workloads.
The Cisco SNS 3800 series appliances are available in these models:
-
Cisco SNS 3815 (SNS-3815-K9)
-
Cisco SNS 3855 (SNS-3855-K9)
-
Cisco SNS 3895 (SNS-3895-K9)
Cisco SNS 3815 appliance is ideal for small deployments. Cisco SNS 3855 and Cisco SNS 3895 appliances have several redundant components such as hard disks and power supplies and are suitable for larger deployments that require highly reliable system configurations. Cisco SNS 3895 is recommended for PAN and MnT personas.
![]() Note |
|
This table describes the hardware specifications of Cisco SNS 3800 series appliances.
|
Cisco SNS 3800 series appliance |
RAM |
CPU cores |
Number of hard disks |
Total hard disk capacity |
RAID |
|---|---|---|---|---|---|
|
Cisco SNS-3815-K9 |
64 GB |
16 cores, 32 threads |
NVME-1 |
960 GB |
NA |
|
64 GB |
16 cores, 32 threads |
SED-1 |
960 GB |
RAID-0 |
|
|
64 GB |
16 cores, 32 threads |
SED-FIPS-1 |
1.6 TB |
RAID-0 |
|
|
Cisco SNS-3855-K9 |
128 GB |
24 cores, 48 threads |
NVME-1 |
960 GB |
NA |
|
128 GB |
24 cores, 48 threads |
NVME-4 |
1.9 TB |
RAID-10 |
|
|
128 GB |
24 cores, 48 threads |
SED-1 |
960 GB |
RAID-0 |
|
|
128 GB |
24 cores, 48 threads |
SED-4 |
1.9 TB |
RAID-10 | |
|
128 GB |
24 cores, 48 threads |
SED-FIPS-1 |
1.6 TB |
RAID-0 |
|
|
128 GB |
24 cores, 48 threads |
SED-FIPS-4 |
3.2 TB |
RAID-10 |
|
|
Cisco SNS-3895-K9 |
256 GB |
24 cores, 48 threads |
NVME-8 |
3.8 TB |
RAID-10 |
|
256 GB |
24 cores, 48 threads |
SED-8 |
3.8 TB |
RAID-10 |
|
|
256 GB |
24 cores, 48 threads |
SED-FIPS-8 |
6.4 TB |
RAID-10 |
For more information, see the Cisco SNS 3800 Series Appliance Hardware Installation Guide.
VMware virtual machine requirements
You can use the VMware migration feature to migrate VM instances (running any persona) between hosts. Cisco ISE supports both hot and cold migration.
-
Hot migration is also called live migration or vMotion. You do not need to shut down or power off Cisco ISE during hot migration. You can migrate the Cisco ISE VM without any interruption in its availability.
-
Cisco ISE must be shutdown and powered off for cold migration. Cisco ISE does not allow to stop or pause the database operations during cold migration. Hence, ensure that Cisco ISE is not running and active during the cold migration.

Note
You must use the application stop command before using the halt command or powering off the VM to prevent database corruption issues.
The 300 GB OVA templates are sufficient for Cisco ISE nodes that serve as dedicated Policy Service or pxGrid nodes.
The 600 GB and 1.2 TB OVA templates are recommended to meet the minimum requirements for nodes that run the Administration or Monitoring persona.
If you need to customize the disk size, CPU, or memory allocation, you can manually deploy Cisco ISE using the standard .iso image. However, it is important that you ensure the minimum requirements and resource reservations specified in this document are met. The OVA templates simplify ISE virtual appliance deployment by automatically applying the minimum resources required for each platform.
|
OVA template type |
Number of CPUs |
CPU reservation (in GHz) |
Memory (in GB) |
Memory reservation (in GB) |
|---|---|---|---|---|
|
Evaluation |
4 |
No reservation. |
16 |
No reservation. |
|
Extra Small |
8 |
8 |
32 |
32 |
|
Small (SNS 3615) |
16 |
16 |
32 |
32 |
|
Medium (SNS 3655) |
24 |
24 |
96 |
96 |
|
Large (SNS 3695) |
24 |
24 |
256 |
256 |
|
Small (SNS 3715) |
24 |
24 |
32 |
32 |
|
Medium (SNS 3755) |
40 |
40 |
96 |
96 |
|
Large (SNS 3795) |
40 |
40 |
256 |
256 |
|
Small (SNS 3815) |
32 |
32 |
64 |
64 |
|
Medium (SNS 3855) |
48 |
48 |
128 |
128 |
|
Large (SNS 3895) |
48 |
48 |
256 |
256 |
![]() Note |
You can enable only the PSN persona on Extra Small VM. PAN and MnT personas are not supported for this node. |
Reserve CPU and memory resources to match the required allocation. Not reserving enough resources can significantly affect ISE performance and stability.
This table lists the VMware virtual machine requirements.
|
Requirement type |
Specifications |
||||||
|---|---|---|---|---|---|---|---|
|
CPU |
|
||||||
|
Memory |
|
||||||
|
Hard disks |
|
||||||
|
Storage and file system |
The storage system for the Cisco ISE virtual appliance requires a minimum write performance of 50 MB per second and a read performance of 300 MB per second. Deploy a storage system that meets these performance criteria and is supported by VMware server. You can use the show tech-support command to view the read and write performance metrics. We recommend the VMFS file system because it is most extensively tested, but other file systems, transports, and media can also be deployed provided they meet the above requirements. |
||||||
|
Disk controller |
Paravirtual or LSI Logic Parallel For best performance and redundancy, a caching RAID controller is recommended. Additionally, battery-backed controller cache can significantly improve write operations.
|
||||||
|
NIC |
1 NIC interface required (two or more NICs are recommended; six NICs are supported). Cisco ISE supports E1000E and VMXNET3 adapters.
|
||||||
|
VMware virtual hardware version/Hypervisor |
|
Linux KVM requirements
|
Requirement type |
Minimum requirements |
||||||
|---|---|---|---|---|---|---|---|
|
CPU |
|
||||||
|
Memory |
|
||||||
|
Hard disks |
|
||||||
|
KVM Disk Device |
Disk bus - virtio, cache mode - none, I/O mode - native Use preallocated RAW storage format. |
||||||
|
NIC |
1 NIC interface required (two or more NIC interfaces are recommended; six NIC interfaces are supported). Cisco ISE supports VirtIO drivers. We recommend VirtIO drivers for better performance. |
||||||
|
Hypervisor |
KVM on QEMU 2.12.0-99 or above |
Microsoft Hyper-V requirements
|
Requirement type |
Minimum requirements |
||||||
|---|---|---|---|---|---|---|---|
|
CPU |
|
||||||
|
Memory |
|
||||||
|
Hard disks |
|
||||||
|
NIC |
1 NIC interface required (two or more NICs are recommended, and six NICs are supported). |
||||||
|
Hypervisor |
Hyper-V (Microsoft) |
![]() Note |
Cisco ISE supports Azure Stack HCI 23H2 and later versions. The virtual machine requirements and the installation procedure for the Cisco ISE VMs in the Azure Stack HCI are the same as that of Microsoft Hyper-V. |
Nutanix AHV requirements
Cisco ISE must be deployed on Nutanix AHV using the standard Cisco ISE .iso image. You cannot deploy Cisco ISE using OVA templates on Nutanix AHV.
This table specifies the recommended resource reservations for different types of deployment on Nutanix AHV:
| Type | Number of CPUs | CPU reservation (in GHz) | Memory (in GB) | Memory reservation (in GB) | Hard disks |
|
Evaluation |
4 |
No reservation |
16 |
No reservation |
300 GB |
|
Extra Small |
8 |
8 |
32 |
32 |
300 GB |
| Small | 16 | 16 | 32 | 32 | 600 GB |
| Medium | 24 | 24 | 96 | 96 | 1.2 TB |
| Large | 24 | 24 | 256 | 256 | 2.4 TB (4*600 GB) |
You must do these configuration on Nutanix AHV before you install Cisco ISE:
-
Create a VM on Nutanix AHV and keep the VM powered off.
-
If you are using AOS 6.8 or earlier versions, access the Nutanix CVM using ssh login and run these commands:
-
<acropolis> vm.serial_port_create <Cisco ISE VM Name> type=kServer index=0
-
<acropolis> vm.update <Cisco ISE VM Name> disable_branding=true
-
<acropolis> vm.update <Cisco ISE VM Name> disable_hyperv=true
If you are using AOS 7.0, access the Nutanix CVM using ssh login and run these commands:
-
<acropolis> vm.serial_port_create <Cisco ISE VM Name> type=kServer index=0
-
<acropolis> vm.update <Cisco ISE VM Name> disable_branding=true
-
-
Exit Acropolis CLI, power on the VM, and install Cisco ISE using the standard .iso image.
|
Requirement type |
Minimum requirements |
||
|---|---|---|---|
|
CPU |
Cisco ISE supports hyperthreading. We recommend that you enable hyperthreading, if it is available.
|
||
|
Memory |
|
||
|
Hard disks |
|
||
|
KVM disk device |
Disk bus - SCSI |
||
|
NIC |
1 GB NIC interface required (two or more NICs are recommended; six NICs are supported). Cisco ISE supports VirtIO drivers. We recommend VirtIO drivers for better performance. |
||
|
Hypervisor |
AOS - 6.8 and 7.0, Nutanix AHV - 10.0 |
Red Hat OpenShift requirements
You can deploy Cisco ISE release 3.4 patch 4 and later VMs on Red Hat OpenShift Virtualization platform. This enables you to manage both VM and container workloads on a single platform.
Review these requirements before you deploy a Cisco ISE VM on Red Hat OpenShift platform.
-
Cisco ISE must be deployed on OpenShift platform using the standard Cisco ISE ISO image. Deploying Cisco ISE using OVA templates is not supported.
-
Cisco ISE supports Red Hat OpenShift container platform 4.19 and later versions.
-
You must install the OpenShift Virtualization plug-in to deploy Cisco ISE.
-
You must install the OpenShift Container Network Interface (CNI) for network configuration.
Ensure you meet these prerequisites before installing Cisco ISE on OpenShift platform:
-
Create the storage infrastructure for Cisco ISE on OpenShift platform. Configure persistent volumes, storage classes, and persistent volume claims to meet CPU, memory, and other resource requirements for Cisco ISE VMs.
-
Create a bootable volume for the Cisco ISE ISO file. Choose Bootable Volume > Add Volume > ISO image and upload the Cisco ISE ISO file. Enter the required details in the Volume Mode, Access Mode, Volume Name, and Preferences fields and then click Save.
-
Configure a secondary-VLAN interface. Choose Networking > Network Attachment Definitions and create a secondary network.
Do not use the pod network for Cisco ISE configuration.
-
Create YAML files to configure a VM. In the YAML file, specify the VM settings such as CPU cores, disks, and boot order.
-
Choose Virtualization > Overview > Create Virtual Command Line Tools and use the oc and virtctrl OpenShift Command Line Interface utilities to create partitions based on Cisco ISE VM resource requirements.
You can also create a pod to upload the ISO file.
-
Ensure that the persistent volume claims and VM are on the same node.
Choose Virtual Machine > Create > YAML file to create a VM. You can monitor the installation progress from the Console > VNC page.
The installation process for Cisco ISE on OpenShift platform is the same as on other VM platforms. For information on how to install Cisco ISE using the ISO image, see Install Cisco ISE Using CIMC.
![]() Note |
You must use only this ISO file for Cisco ISE release 3.4 to support the Red Hat OpenShift platform: ise-3.4.0.608b.SPA.x86_64.iso |

Feedback