<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recommended latency between user and ISE nodes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3809741#M484826</link>
    <description>Hi,&lt;BR /&gt;Starting in ISE 2.1 up to 300ms between any 2 ISE nodes. Check out Cisco Live presentation BRKSEC-3432, it has a section on latency. &lt;BR /&gt;&lt;BR /&gt;HTH</description>
    <pubDate>Tue, 26 Feb 2019 09:45:32 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2019-02-26T09:45:32Z</dc:date>
    <item>
      <title>Recommended latency between user and ISE nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3809655#M484825</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any documentation regarding recommended latency between users and ISE nodes ?&lt;/P&gt;
&lt;P&gt;I have customer with users across 100+ sites, and latency between sites and ISE in HQ is around 200ms.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Omar&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 03:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3809655#M484825</guid>
      <dc:creator>ommaayah</dc:creator>
      <dc:date>2019-03-09T03:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended latency between user and ISE nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3809741#M484826</link>
      <description>Hi,&lt;BR /&gt;Starting in ISE 2.1 up to 300ms between any 2 ISE nodes. Check out Cisco Live presentation BRKSEC-3432, it has a section on latency. &lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 26 Feb 2019 09:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3809741#M484826</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-02-26T09:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended latency between user and ISE nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3810240#M484827</link>
      <description>&lt;P&gt;There are two pieces here, but what you are asking is not exactly an ISE thing but a general radius concept. ISE has a very high timeout interval, 120 seconds.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Latency between ISE nodes and the PAN, less than 200 ms or 300 ms depending on the version you are running.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And then the second which is the latency of radius authentication (user/endpoint/NAD).&amp;nbsp; What you have to pay attention to here is the latency between the NAD (Switch/WLC), ISE, and the ID store. Usually referred to as the radius timeout interval, it's usually set at something like 5 seconds by default.&amp;nbsp; I have seen issues where an aggressive 1000ms radius timeout is set on a WLC and it causes problems when ISE or AD cannot process the request quick enough.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The radius timeout interval is usually configurable on all devices, but there is always a default.&amp;nbsp; The time has to include everything in the authentication path, RTT of ISE and NAD, time it takes ISE to authenticate the device, time it takes AD to respond.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you can stay under 5 seconds then you are unlikely to have issues with default timers.&amp;nbsp; I would check the WLC's though.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 18:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3810240#M484827</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-26T18:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended latency between user and ISE nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3812400#M484828</link>
      <description>Thanks for the response, i have read in the guides that ISE 2.1 onwards support latency between ISE nodes up to 300 ms, but my question was related to NAD to ISE which you answered clearly.&lt;BR /&gt;Thanks a lot.</description>
      <pubDate>Fri, 01 Mar 2019 10:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/recommended-latency-between-user-and-ise-nodes/m-p/3812400#M484828</guid>
      <dc:creator>ommaayah</dc:creator>
      <dc:date>2019-03-01T10:15:41Z</dc:date>
    </item>
  </channel>
</rss>

