<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE-AD Integration timeout value in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-timeout-value/m-p/3694196#M495027</link>
    <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My customer is now planning to replace a 3&lt;SUP&gt;rd&lt;/SUP&gt; party RADIUS server to Cisco ISE. But they are much worried about AD timeout issue because they are running huge Windows domain network so that they have experienced Name resolution timeout with current radius server. (they tuned the timer)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you provide detailed information about&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Default ISE Timeout value for Windows Domain Authentication&lt;/LI&gt;
&lt;LI&gt;Can we tune a timer wit AD connection with “Advanced Tuning” under External Identity Sources? (it seems restricted for TAC use).&lt;/LI&gt;
&lt;LI&gt;How does DNS A-record cache work in ISE with AD integration?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Any comment would be highly appreciated.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Aug 2018 04:01:34 GMT</pubDate>
    <dc:creator>sikeda</dc:creator>
    <dc:date>2018-08-24T04:01:34Z</dc:date>
    <item>
      <title>ISE-AD Integration timeout value</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-timeout-value/m-p/3694196#M495027</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My customer is now planning to replace a 3&lt;SUP&gt;rd&lt;/SUP&gt; party RADIUS server to Cisco ISE. But they are much worried about AD timeout issue because they are running huge Windows domain network so that they have experienced Name resolution timeout with current radius server. (they tuned the timer)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you provide detailed information about&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Default ISE Timeout value for Windows Domain Authentication&lt;/LI&gt;
&lt;LI&gt;Can we tune a timer wit AD connection with “Advanced Tuning” under External Identity Sources? (it seems restricted for TAC use).&lt;/LI&gt;
&lt;LI&gt;How does DNS A-record cache work in ISE with AD integration?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Any comment would be highly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 04:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-timeout-value/m-p/3694196#M495027</guid>
      <dc:creator>sikeda</dc:creator>
      <dc:date>2018-08-24T04:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-AD Integration timeout value</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-timeout-value/m-p/3694402#M495028</link>
      <description>&lt;P&gt;Interesting question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe I'm being dumb, but what does the size of AD have to do with slow DNS responses?&amp;nbsp; It feels like they want to manipulate ISE when really they should be fixing their DNS, but I suppose they have their reasons.&amp;nbsp; Or do you mean that user lookups are also slow?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How many DCs do they have and how often do they change address / hostname?&amp;nbsp; If DNS is slow you could always define the DC hostname / IP address associations manually and cut extrnal DNS out of the loop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;ip host &lt;/SPAN&gt;[&lt;VAR&gt;ipv4-address&lt;/VAR&gt; | &lt;VAR&gt;ipv6-address&lt;/VAR&gt;] [&lt;VAR&gt;host-alias&lt;/VAR&gt; | &lt;VAR&gt;FQDN-string&lt;/VAR&gt;] &lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ph synph"&gt;Feels a bit of a naff way to do it though.&amp;nbsp; Hopefully somebody has a better idea...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 11:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-timeout-value/m-p/3694402#M495028</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2018-08-24T11:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-AD Integration timeout value</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-integration-timeout-value/m-p/3695922#M495029</link>
      <description>Hi Richard,&lt;BR /&gt;Thank you for your suggestion! My customer agreed to try the "ip host" command to avoid the AD timeout in their test environment. Much appreciate for your help!</description>
      <pubDate>Tue, 28 Aug 2018 04:44:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-integration-timeout-value/m-p/3695922#M495029</guid>
      <dc:creator>sikeda</dc:creator>
      <dc:date>2018-08-28T04:44:26Z</dc:date>
    </item>
  </channel>
</rss>

