<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: external RADIUS server on ISE, dead time in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/external-radius-server-on-ise-dead-time/m-p/3551515#M503719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not exactly. The options for the server timeout and the number of connection attempts are for every request and influence when will ISE mark a server as dead. Once marked dead, ISE will skip the dead server for 5 minutes and not send any requests to it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Jul 2018 11:36:50 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-07-16T11:36:50Z</dc:date>
    <item>
      <title>external RADIUS server on ISE, dead time</title>
      <link>https://community.cisco.com/t5/network-access-control/external-radius-server-on-ise-dead-time/m-p/3551514#M503718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read the below document on&amp;nbsp; how an external RADIUS server can be configured as an authentication server on Identity Services Engine (ISE) where ISE acts a proxy and as an authorization server as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html" title="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 12pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.5pt; font-family: CiscoSans, sans-serif; color: #58585b; background-color: white;"&gt;The default &lt;STRONG&gt;dead time &lt;/STRONG&gt;for external RADIUS Servers in ISE is &lt;STRONG&gt;5 minutes&lt;/STRONG&gt;. This value is hardcoded and cannot be modified as of this version.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 12pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN lang="EN-US" style="font-size: 11pt;"&gt;Can I suppose that if I set the &lt;STRONG&gt;server timeout&lt;/STRONG&gt; and &lt;STRONG&gt;connection attempt&lt;/STRONG&gt; can I modify definitively the dead time of external radius?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 08:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-radius-server-on-ise-dead-time/m-p/3551514#M503718</guid>
      <dc:creator>nmourtzi</dc:creator>
      <dc:date>2018-07-16T08:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: external RADIUS server on ISE, dead time</title>
      <link>https://community.cisco.com/t5/network-access-control/external-radius-server-on-ise-dead-time/m-p/3551515#M503719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not exactly. The options for the server timeout and the number of connection attempts are for every request and influence when will ISE mark a server as dead. Once marked dead, ISE will skip the dead server for 5 minutes and not send any requests to it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 11:36:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-radius-server-on-ise-dead-time/m-p/3551515#M503719</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-16T11:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: external RADIUS server on ISE, dead time</title>
      <link>https://community.cisco.com/t5/network-access-control/external-radius-server-on-ise-dead-time/m-p/3751855#M503720</link>
      <description>&lt;P&gt;Is the RADIUS server marked dead for the whole deployment or is this on a per node basis?&lt;/P&gt;
&lt;P&gt;Some further questions:&lt;/P&gt;
&lt;P&gt;What happens if all servers are dead in the sequence? Will ISE try to contact a server anyways, as the newer switches do as well or will there be just no authentication attempts at all during those five minutes?&lt;/P&gt;
&lt;P&gt;Also does ISE switch to the second Server in the sequence after the first timeout as seen on some switches or does it only attempt the next server after all retries failed?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 10:52:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-radius-server-on-ise-dead-time/m-p/3751855#M503720</guid>
      <dc:creator>Philipp Staiger</dc:creator>
      <dc:date>2018-11-23T10:52:24Z</dc:date>
    </item>
  </channel>
</rss>

