<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP External Identity Source - Primary/Secondary in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ldap-external-identity-source-primary-secondary/m-p/3515517#M537056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mainly during failover. In case that the auth requests fail over to the secondary LDAP and the connections are active, I would expect ISE continuing with the secondary LDAP until the connections are closed or failed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Nov 2016 17:24:41 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2016-11-08T17:24:41Z</dc:date>
    <item>
      <title>LDAP External Identity Source - Primary/Secondary</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-external-identity-source-primary-secondary/m-p/3515516#M537055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would like clarification on this from the Admin Guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01101.html#ID917" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01101.html#ID917"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.1 - Manage Users and External Identity Sources [Cisco Ide…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cisco ISE always uses the primary LDAP server to obtain groups and attributes for use in authorization policies from the Admin portal, so the primary LDAP server must be accessible when you configure these items. Cisco ISE uses the secondary LDAP server only for authentications and authorizations at run time, according to the failover configuration.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you explain the last sentence? Does this imply that the secondary server is used when the primary is up and running or just during a failover event and the primary is no longer available?&amp;nbsp; Trying to determine authentication degradation if the secondary LDAP server was to fail or there was a misconfiguration on the secondary server.&amp;nbsp; If the primary was still up, would there be any interruption of authentications.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2016 13:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-external-identity-source-primary-secondary/m-p/3515516#M537055</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-11-08T13:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP External Identity Source - Primary/Secondary</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-external-identity-source-primary-secondary/m-p/3515517#M537056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mainly during failover. In case that the auth requests fail over to the secondary LDAP and the connections are active, I would expect ISE continuing with the secondary LDAP until the connections are closed or failed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2016 17:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-external-identity-source-primary-secondary/m-p/3515517#M537056</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-11-08T17:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP External Identity Source - Primary/Secondary</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-external-identity-source-primary-secondary/m-p/3515518#M537057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Nov 2016 04:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-external-identity-source-primary-secondary/m-p/3515518#M537057</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-11-10T04:55:03Z</dc:date>
    </item>
  </channel>
</rss>

