<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic There is no such config for in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/2988349#M37388</link>
    <description>&lt;P&gt;There is no such config for this feature.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Policy Service nodes in a distributed deployment do not share their Machine Access Restriction (MAR) cache with each other. If you have enabled the MAR feature in Cisco ISE and the client machine is authenticated by a Policy Service node that fails, then another Policy Service node in the deployment handles the user authentication. However, the user authentication fails because the second Policy Service node does not have the host authentication information in its MAR cache.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010.html#concept_6D26AEAD132A45DB91C51ED0B8890746&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Gagan&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;rate if it helps!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2016 15:00:33 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2016-12-06T15:00:33Z</dc:date>
    <item>
      <title>Cisco ISE 2.1 MAR Feature</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/2988348#M37386</link>
      <description>&lt;P&gt;All,&lt;/P&gt;
&lt;H4 class="topictitle4"&gt;Machine Access Restriction (MAR) Cache Persistency&lt;/H4&gt;
&lt;SECTION&gt;
&lt;P&gt;Cisco ISE stores the MAR cache content, calling-station-ID list, and the corresponding time stamps to a file on its local disk when you manually stop the Cisco ISE application services. Cisco ISE does not store the MAR cache entries of an instance when there is an accidental restart of its application services.&lt;/P&gt;
&lt;P&gt;Cisco ISE reads the MAR cache entries from the file on its local disk based on the cache entry time to live when the Cisco ISE application services get restarted. When the application services of a Cisco ISE instance come up after a restart, Cisco ISE compares the current time of that instance with the MAR cache entry time. If the difference between the current time and the MAR entry time is greater than the MAR cache entry time to live, then Cisco ISE does not retrieve that entry from disk. Otherwise, Cisco ISE retrieves that MAR cache entry and updates its MAR cache entry time to live.&lt;/P&gt;
&lt;H4 class="topictitle4"&gt;&lt;FONT size="3"&gt;Does anyone have any config for this feature and brief explanations of operation, &amp;nbsp;TTL's etc.&lt;/FONT&gt;&lt;/H4&gt;
&lt;/SECTION&gt;
&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/2988348#M37386</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2019-03-11T07:16:16Z</dc:date>
    </item>
    <item>
      <title>There is no such config for</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/2988349#M37388</link>
      <description>&lt;P&gt;There is no such config for this feature.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Policy Service nodes in a distributed deployment do not share their Machine Access Restriction (MAR) cache with each other. If you have enabled the MAR feature in Cisco ISE and the client machine is authenticated by a Policy Service node that fails, then another Policy Service node in the deployment handles the user authentication. However, the user authentication fails because the second Policy Service node does not have the host authentication information in its MAR cache.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010.html#concept_6D26AEAD132A45DB91C51ED0B8890746&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Gagan&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;rate if it helps!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 15:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/2988349#M37388</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-12-06T15:00:33Z</dc:date>
    </item>
    <item>
      <title>Gagan is correct. The MAR</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/2988350#M37391</link>
      <description>&lt;P&gt;Gagan is correct. The MAR cache share/sync between nodes is currently only available for Cisco ACS. On ISE this feature is still not available. The latest MAR enhancement with version 2.1 is the Persistent MAR Cache where the MAR data is stored on the local disk of each ISE server:&lt;/P&gt;
&lt;PRE class="p_H_Head2 prettyprint"&gt;&lt;SPAN style="font-size: 14pt;"&gt;&lt;STRONG&gt;Persistent Machine Access Restriction (MAR) Cache&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;Cisco ISE stores the MAR cache content, calling-station-ID list, and the corresponding time stamps to a file on its local disk when you manually stop the Cisco ISE application services. Cisco ISE does not store the MAR cache entries of an instance when there is an accidental restart of its application services.&lt;BR /&gt;Cisco ISE reads the MAR cache entries from the file on its local disk based on the cache entry time to live when the Cisco ISE application services get restarted. When the run-time services of an Cisco ISE instance come up after a restart, Cisco ISE compares the current time of that instance with the MAR cache entry time. If the difference between the current time and the MAR entry time is greater than the MAR cache entry time to live, then Cisco ISE does not retrieve that entry from disk. Otherwise, Cisco ISE retrieves that MAR cache entry and updates its MAR cache entry time to live.&lt;/PRE&gt;
&lt;P&gt;Also MAR comes with tons of limitations and as a result I always advice against it. A while back we had a good discussion here. Here is the link for it:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/discussion/12735486/machine-access-restrictions-mar"&gt;https://supportforums.cisco.com/discussion/12735486/machine-access-restrictions-mar&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 18:19:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/2988350#M37391</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-12-06T18:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Gagan is correct. The MAR</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/3783123#M37393</link>
      <description>&lt;P&gt;can we put all ISE in the same node group? so the MAR can be sync? but the ISE PSN is over WAN&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 17:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/3783123#M37393</guid>
      <dc:creator>Freemen</dc:creator>
      <dc:date>2019-01-18T17:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Gagan is correct. The MAR</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/3803613#M37396</link>
      <description>&lt;P&gt;Potentially yes but not recommended as it may contribute to delays in ISE auth processes.&lt;/P&gt;
&lt;P&gt;PS: Please start your own thread and reference an existing one instead of posting to a thread that dormant for months and already answered.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Feb 2019 16:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-mar-feature/m-p/3803613#M37396</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-17T16:47:36Z</dc:date>
    </item>
  </channel>
</rss>

