Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass - Intune integration - performance questions

This thread has been viewed 23 times
  • 1.  Clearpass - Intune integration - performance questions

    Posted Mar 05, 2021 02:55 AM

    Hi, 
    we installed intune extension (V5) on clearpass test-cluster. Before moving to production, we have some questions about performanance.

    1) we have about 30.000 devices in Intune, not all are relevant to the scope we need this extension, but it's not possible to select fewer in AAD. But when the extension starts and will perform a full sync , how long will it take? Current test environment only has 11 devices and this takes 2 a 3 seconds to sync. We have a quite big & performant internet connection :) 

    On the 2nd (subscriber) we have the idea to perform a "syncupdateonly" every 5 a 10minutes, just to have recent info about compliant / non-compliant devices.

    2) However, also (real-time) http check is needed, any idea how many requests per second can be done? Clearpass is C3000 (4 servers of which 2 will have the extension installed)


    Thx4info!



    ------------------------------
    Danny Bosman (KBC Group BE)
    ------------------------------


  • 2.  RE: Clearpass - Intune integration - performance questions

    Posted Mar 05, 2021 01:30 PM
    Danny,

    My comments.... 30K devices should ingest in <3 hours comfortably.... but there could be limits as determined by end-2-end performance of your connectivity, not just limited or as a function of how big/fast your internet connection is to InTune

    I'd run the syncupdate on the PUB, if you run this on a SUB after it receives the data and writes to the local DB this write will be proxied to the PUB to complete the actual write 

    Is the appendix of the note on authZ perf, make a note of that, my recollection from when I initially built this {~5 years back} we we're capable of running circ 200 HTTPs calls / sec... you might need to tweak config for this but it really comes down to the API performance not as much CPPM constraints.

    HTH

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 3.  RE: Clearpass - Intune integration - performance questions

    Posted May 20, 2021 10:21 AM
    Danny,
    just as a confirmation, we process 25000 devices in +-2hours (every night full sync). Until now - everything works fine :)

    ------------------------------
    Danny Bosman
    KBC Group - Belgium
    ------------------------------