<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does PSN query AD for every RADIUS session? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086270#M560444</link>
    <description>&lt;P&gt;In general yes - that is the case. If you want to limit the connection rates to AD for EAP-PEAP, then you can enable a feature in ISE called Fast-Reconnect - this will cache the last Authentication status of that user for a specified number of minutes. The only trouble is, if that user's status changes in that time frame (e.g. account locked) then ISE will not take note of it. But it's still a useful feature.&lt;/P&gt;</description>
    <pubDate>Fri, 15 May 2020 00:09:02 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2020-05-15T00:09:02Z</dc:date>
    <item>
      <title>Does PSN query AD for every RADIUS session?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086025#M560430</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;From what I understand, when you integrate your AD to your ISE deployment, the PSN will be the one that make direct connection to the AD. My question here is: does PSN query AD for every new/unique RADIUS session?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Yedi&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 17:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086025#M560430</guid>
      <dc:creator>YediaelHutahaean</dc:creator>
      <dc:date>2020-05-14T17:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Does PSN query AD for every RADIUS session?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086038#M560433</link>
      <description>&lt;P&gt;Its depend what policy have been set it for ? Unless endpoint not logged into it doesn't query&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;were you using AD credential login for ISE servers ? or end users and NAD devices ?&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 18:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086038#M560433</guid>
      <dc:creator>Shivu b</dc:creator>
      <dc:date>2020-05-14T18:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Does PSN query AD for every RADIUS session?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086075#M560435</link>
      <description>If you use AD probe for profiling then yes. Also, if you use AD&lt;BR /&gt;authentication for endpoint dot1x, then yes.&lt;BR /&gt;&lt;BR /&gt;In both cases ISE will probe AD for every new connection.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Thu, 14 May 2020 19:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086075#M560435</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-05-14T19:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Does PSN query AD for every RADIUS session?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086270#M560444</link>
      <description>&lt;P&gt;In general yes - that is the case. If you want to limit the connection rates to AD for EAP-PEAP, then you can enable a feature in ISE called Fast-Reconnect - this will cache the last Authentication status of that user for a specified number of minutes. The only trouble is, if that user's status changes in that time frame (e.g. account locked) then ISE will not take note of it. But it's still a useful feature.&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 00:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4086270#M560444</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-05-15T00:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Does PSN query AD for every RADIUS session?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4087225#M560462</link>
      <description>&lt;P&gt;It depends on the configuration of your ISE Authentication Policy.&lt;/P&gt;
&lt;P&gt;In the example below - which is the ISE default with a rule for VPN added - you can see that MAB will only look to authenticate Internal Endpoints - and never to go AD. VPN, Dot1x and Default will attemtp to try each of the Identity Stores in the All_User_ID_Stores identity store sequence which, assuming you had configured one or more Active Directory stores, would include them. You may configure additional rules and conditions to control which IDentity Stores are used.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/74715iC3A55A33B84B9073/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You may create your own Identity Store Sequences (with or without AD) here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/74716i9E34E1A51B593E10/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2020 00:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4087225#M560462</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2020-05-17T00:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Does PSN query AD for every RADIUS session?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4104241#M561259</link>
      <description>Hi Thomas,&lt;BR /&gt;Thanks for your detailed and well-thought answers, it helps me a lot!!&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Yedi</description>
      <pubDate>Tue, 16 Jun 2020 16:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4104241#M561259</guid>
      <dc:creator>YediaelHutahaean</dc:creator>
      <dc:date>2020-06-16T16:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Does PSN query AD for every RADIUS session?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4104242#M561260</link>
      <description>Hi Arne,&lt;BR /&gt;Thanks for your confirmation, and especially for the information about "Fast-Reconnect", didn't know about it before this.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Yedi</description>
      <pubDate>Tue, 16 Jun 2020 16:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-psn-query-ad-for-every-radius-session/m-p/4104242#M561260</guid>
      <dc:creator>YediaelHutahaean</dc:creator>
      <dc:date>2020-06-16T16:29:38Z</dc:date>
    </item>
  </channel>
</rss>

