<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Periodic in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-periodic/m-p/3994533#M455166</link>
    <description>&lt;P&gt;A couple of things come to mind.&amp;nbsp; First, from a security perspective, someone could use a hub or other device that keeps the link state of the port up and is able to plug a rogue device in after the good device authenticates.&amp;nbsp; Then the rogue device would have access seemingly for a long period of time without having to reauthenticate.&amp;nbsp; Reauthenticating at least every 12 hours may not stop this activity but would cause the rogue actor some headaches.&lt;/P&gt;&lt;P&gt;Second, for visibility, troubleshooting, and/or reporting, you may miss some devices if they haven't authenticated in the previous day or so.&amp;nbsp; ISE Live Logs only go back for 24 hours.&amp;nbsp; And some of the reporting gets slow if you try to go back more than 7 days.&amp;nbsp; I personally like to be able to filter on an IP, MAC address, or username/machine name to be able to see whether someone is online and what switch/port they are on.&amp;nbsp; You wouldn't be able to trust the Live Logs if you aren't sure if they authenticated recently or not.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2019 02:27:56 GMT</pubDate>
    <dc:creator>Colby LeMaire</dc:creator>
    <dc:date>2019-12-06T02:27:56Z</dc:date>
    <item>
      <title>Authentication Periodic</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-periodic/m-p/3994386#M455164</link>
      <description>&lt;P&gt;I had a couple of questions regarding authentication periodic.&lt;/P&gt;&lt;P&gt;If you do not have authentication periodic configured on a switch port, does that mean a device will only have to authenticate 1 time until the inactivity timer expires?&lt;/P&gt;&lt;P&gt;Would it be a bad practice to only authenticate devices 1 time?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 19:50:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-periodic/m-p/3994386#M455164</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2019-12-05T19:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Periodic</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-periodic/m-p/3994533#M455166</link>
      <description>&lt;P&gt;A couple of things come to mind.&amp;nbsp; First, from a security perspective, someone could use a hub or other device that keeps the link state of the port up and is able to plug a rogue device in after the good device authenticates.&amp;nbsp; Then the rogue device would have access seemingly for a long period of time without having to reauthenticate.&amp;nbsp; Reauthenticating at least every 12 hours may not stop this activity but would cause the rogue actor some headaches.&lt;/P&gt;&lt;P&gt;Second, for visibility, troubleshooting, and/or reporting, you may miss some devices if they haven't authenticated in the previous day or so.&amp;nbsp; ISE Live Logs only go back for 24 hours.&amp;nbsp; And some of the reporting gets slow if you try to go back more than 7 days.&amp;nbsp; I personally like to be able to filter on an IP, MAC address, or username/machine name to be able to see whether someone is online and what switch/port they are on.&amp;nbsp; You wouldn't be able to trust the Live Logs if you aren't sure if they authenticated recently or not.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 02:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-periodic/m-p/3994533#M455166</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-12-06T02:27:56Z</dc:date>
    </item>
  </channel>
</rss>

