<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE authentication latency. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465656#M530244</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't seen AD latency myself, but there are some bugs from upgrades causing latency. I did not see anything specific to 2.1 patch 2 though. I would open a TAC to see if there is a bug I'm not aware of. If you have a test system, or can spin up a test VM, see if you can recreate the issue, then update it to 2.2 and see if it disappears. This would at least give you an idea if you can upgrade to 2.2 to alleviate the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 May 2017 14:24:41 GMT</pubDate>
    <dc:creator>Dustin Anderson</dc:creator>
    <dc:date>2017-05-10T14:24:41Z</dc:date>
    <item>
      <title>ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465648#M530218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I have a TAC case open since Feb 21st on this, but have the rep that never responds, so want to see if anyone here has had this same issue and can give me some direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, we are running on 2.1 unpatched. all works fine and we see standard 10-20ms auth latency. The problem started when we applied update 3. The average auth latency went to ~5000ms with some as high as 16000ms.This was causing items to give up connecting due to the delay.&lt;/P&gt;&lt;P&gt;This is when I opened the TAC case. We did not hear anything for a week and ended up rolling back since Cisco didn't respond.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We ended up spinning up a test ISE and was able to reproduce the issue. I also tried to upgrade to 2.2 to see if it was patch specific and problem still persists. We need to move to ISE 2.2 for Passive ID for server 2016 since they are not updating the CDA's for 2016 and forcing us to move it to ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, anyone run into this in your deployments? The latency wouldn't affect us as much if it din't cause disruption and disconnects to the clients.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Apr 2017 15:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465648#M530218</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-04-11T15:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465649#M530223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the TAC Case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggest you request a requeue and escalation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Apr 2017 15:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465649#M530223</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-11T15:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465650#M530226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;OL class="breadcrumb" style="list-style: none; background: 0 0 #ffffff; color: #000000; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; padding-left: 0 !important;"&gt;&lt;LI&gt;&lt;SPAN class="ng-binding"&gt;681837813&lt;/SPAN&gt; &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did, escalated to a lvl 2, but the new tech resigned it back to the old tech.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Apr 2017 15:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465650#M530226</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-04-11T15:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465651#M530232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks, please ask for requeue I will see how i can help from my side&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Apr 2017 15:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465651#M530232</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-11T15:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465652#M530238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I escalated myself, someone is going to reach out&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Apr 2017 19:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465652#M530238</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-11T19:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465653#M530241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you get any response on this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same issue. Running a deployment at 2.1p1 working just fine but after I have applied patch 2 and 3 I get latencies well over 10 seconds without any issues on the AD backend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've planned to do an upgrade to 2.2 tomorrow but perhaps I have to schedule for a downgrade instead.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 06:41:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465653#M530241</guid>
      <dc:creator>Joakim Backlund</dc:creator>
      <dc:date>2017-05-10T06:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465654#M530242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a ticket open with MobileIron. It doesn't show, but we have the latency in 2.1 also. In 2.1, seems to be 10-12 seconds. Patched or 2.2 went to 14-18 seconds, and it reports it now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't notice the latency in 2.1 until I did a TCPdump and we use Omnipeek that flagged the latency, so was easier to find. And, I think until the latency got over 14 seconds, phones just waited. Now, it will drop the attempt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, I'll post what MobileIron comes back with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you seeing the latency with a MDM, or another authc step?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 12:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465654#M530242</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-05-10T12:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465655#M530243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't use any MDM instead we see it with AD as auth backend. Still investigating if the problem is within ISE or actually an AD issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 13:30:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465655#M530243</guid>
      <dc:creator>Joakim Backlund</dc:creator>
      <dc:date>2017-05-10T13:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465656#M530244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't seen AD latency myself, but there are some bugs from upgrades causing latency. I did not see anything specific to 2.1 patch 2 though. I would open a TAC to see if there is a bug I'm not aware of. If you have a test system, or can spin up a test VM, see if you can recreate the issue, then update it to 2.2 and see if it disappears. This would at least give you an idea if you can upgrade to 2.2 to alleviate the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 14:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465656#M530244</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-05-10T14:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465657#M530245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you had some conclusions ? I'm having high step latency issue too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2017 01:43:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465657#M530245</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2017-06-02T01:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465658#M530246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Solution for my problem I had was to either downgrade to 2.1 patch 1 or upgrade to 2.2. TAC didn't have anything to come with except cosmetic bugs related to high latency. We could spot any real latencies related to AD authentication apart from the statistics in ISE but we had very high numbers on radius timeouts on the NADs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We experienced many radius timeouts at 2.1 patch 2&amp;amp;3. I tested to revert back to 2.1 patch 1 and that solved it. If I remember correctly I upgraded directly to patch 3, not installing the explicit patch 2 and everything was working fine. As I had to go to 2.2 I also tested to upgrade a malfunctioning 2.1 patch 1,2&amp;amp;3 installation to 2.2 and that also worked out fine. Before I did the upgrade for the whole deployment I upgrade the test environment to 2.2 patch 1 and that worked fine as well with very few radius timeouts. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, in short, the solution for me was to upgrade the whole deployment to 2.2 patch 1 as it resolved our problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2017 07:56:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465658#M530246</guid>
      <dc:creator>Joakim Backlund</dc:creator>
      <dc:date>2017-06-02T07:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465659#M530247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for sharing the info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2017 20:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465659#M530247</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2017-06-02T20:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465660#M530248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My issue is still pending, but Mobil Iron admitted to a bug in the 9.3 code. When ISE requests the status of a device, it sends it's whole database....every time...for every check. This is corrected in 9.4 and waiting on the admin to update it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2017 20:45:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465660#M530248</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-06-02T20:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE authentication latency.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465661#M530249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. Good to hear that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2017 20:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-latency/m-p/3465661#M530249</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2017-06-02T20:49:19Z</dc:date>
    </item>
  </channel>
</rss>

