<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between how ACS and ISE queries AD/LDAP groups for TACACS+ in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/difference-between-how-acs-and-ise-queries-ad-ldap-groups-for/m-p/3766324#M486890</link>
    <description>&lt;P&gt;ISE 2.3 has a cache for internal users. If you need similar for AD/LDAP, please discuss your requirements with our PM team.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Dec 2018 01:36:46 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-12-19T01:36:46Z</dc:date>
    <item>
      <title>Difference between how ACS and ISE queries AD/LDAP groups for TACACS+</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-how-acs-and-ise-queries-ad-ldap-groups-for/m-p/3766290#M486880</link>
      <description>&lt;P style="margin: 0in; font-family: Calibri; font-size: 12.0pt; color: #58585b;"&gt;We have a TACACS environment on ISE where authentication is done via SecurID and authorization via LDAP.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 12.0pt; color: #58585b;"&gt;ACS allows for both SecureID and Ldap to be referred to in the Identity Source Sequence.&amp;nbsp;Hence the LDAP group for users are fetched during authentication phase and are referred in authorization rules for all subsequent command authorization. The idea is that ACS only reaches out to LDAP only once during authentication phase.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 12.0pt; color: #58585b;"&gt;I believe this behaviour has changed in ISE and ISE reaches out to&amp;nbsp;LDAP for each command being fired&amp;nbsp;every time an authorization rule is hit.&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 12.0pt; color: #58585b;"&gt;Is there any way to prevent for ISE to not query the LDAP&amp;nbsp; everytime a command is fired with some caching mechanism fired ? We are concerned about the amount of extra load LDAP would have once we move into ISE.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 23:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-how-acs-and-ise-queries-ad-ldap-groups-for/m-p/3766290#M486880</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-12-18T23:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between how ACS and ISE queries AD/LDAP groups for TACACS+</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-how-acs-and-ise-queries-ad-ldap-groups-for/m-p/3766324#M486890</link>
      <description>&lt;P&gt;ISE 2.3 has a cache for internal users. If you need similar for AD/LDAP, please discuss your requirements with our PM team.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 01:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-how-acs-and-ise-queries-ad-ldap-groups-for/m-p/3766324#M486890</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-19T01:36:46Z</dc:date>
    </item>
  </channel>
</rss>

