<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAR cache entry is purged on ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742620#M578914</link>
    <description>&lt;P&gt;Why do you need MAR at all?&amp;nbsp; Personally I think an upgrade from 2.4 to 3.1 would be a perfect time to migrate off of MAR.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Dec 2022 13:13:33 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2022-12-20T13:13:33Z</dc:date>
    <item>
      <title>MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4497087#M570814</link>
      <description>&lt;P&gt;ISE 3.0&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What’s happens to connected client if MAR cache entry is purged on ISE and they get a radius session timeout / reauth request while connected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our MAR cache setting is 18hours, if someone is logged in for 19hours, will they get disconnected and will the machine re-authenticate?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 11:29:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4497087#M570814</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2021-11-03T11:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4497507#M570837</link>
      <description>&lt;P&gt;If a reauth happens and the user is logged in, the native supplicant will not reauth the machine session if you're using EAP methods like EAP-TLS or PEAP. This is one of the many issues inherent in MAR and why using MAR should be avoided unless absolutely necessary. I've had many customers that used MAR only to quickly get rid of it due to increased calls to the helpdesk.&lt;/P&gt;
&lt;P&gt;See &lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html" target="_blank" rel="noopener"&gt;Machine Access Restriction Pros and Cons&lt;/A&gt; for other issues that MAR can cause.&lt;/P&gt;
&lt;P&gt;The only efficient way of tying a computer and user session together using the Windows native supplicant is by using &lt;A href="https://www.ise-support.com/2020/05/29/using-teap-for-eap-chaining/" target="_blank" rel="noopener"&gt;TEAP&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 21:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4497507#M570837</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-11-03T21:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742510#M578910</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;we are going to migrate our 2.4 deployment to a new 3.1 one. Unfortunately we have to rely on mar and mar cache distribution. I remember that in 2.4 there was an issue about mar cache distribution not actually enabled in spite of the configuration saved by GUI. It seems that the issue is present in iSE 3.1 as well. We have 4 PSN&amp;nbsp; and two PSN Groups , let's say group A and group B, both with mar cache distribution enabled. We performed some tests and everything seems to work in group A but not in group B. I tried to delete and recreate group B and assign back the node with not fortune. The most frustating thing with mar is the lack of documentation for trouble shooting and the lack of cache inspection. During 2.4 deployment setup I was able to find the right debug log to enable but I can't remember whchi was. Could you please give me some hint to trouble shot mar cache distribution issues working on ise logs?&lt;BR /&gt;Regards&lt;BR /&gt;M&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 10:31:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742510#M578910</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2022-12-20T10:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742620#M578914</link>
      <description>&lt;P&gt;Why do you need MAR at all?&amp;nbsp; Personally I think an upgrade from 2.4 to 3.1 would be a perfect time to migrate off of MAR.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 13:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742620#M578914</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-12-20T13:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742622#M578915</link>
      <description>&lt;P&gt;Unfortunately we can't.&lt;/P&gt;&lt;P&gt;We do not use anyconnect as supplicant and windows native supplicant seems not to support T-EAP on active directory joined machine....&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 13:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742622#M578915</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2022-12-20T13:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742626#M578916</link>
      <description>&lt;P&gt;TEAP certainly works on domain joined machines.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 13:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742626#M578916</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-12-20T13:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742636#M578917</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;I'll ask again&amp;nbsp; the guys in charge of GPOs administration since they showed me that TEAP is not listed between EAP methods one can configure by GPO, nor looking directly to a joined PC 802.1x configuration tab on NIC properties. I read some thing about exporting an xml profile from a not joined PC on witch TEAP has been configured and the import in the tool they use to build GPO but I am afraid there would be some issue with microsoft support.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;M&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 13:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742636#M578917</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2022-12-20T13:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742898#M578927</link>
      <description>&lt;P&gt;It is not a matter of support my Microsoft, it's more a matter that MS has not updated the GPO model in quite some time so TEAP is not an option directly in the GPO. TEAP is supported by the Windows native supplicant from Windows build 2004 and options for configuring the supplicant (including using XML or the RSAT tool) are discussed here:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 21:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4742898#M578927</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-12-20T21:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: MAR cache entry is purged on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4743098#M578933</link>
      <description>&lt;P&gt;Thanks Greb this is the post I read.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to introduce TEAP but using MSCHAPv2 as "inner" method do you thing is possible?&lt;/P&gt;&lt;P&gt;Since this new method will impact&amp;nbsp; more than 10k client and I have to convince the staff in charge of GPO management to add the new policy I estimate not less than 6 months during which we have to keep on leveraging on MAR.&lt;/P&gt;&lt;P&gt;Do you have some tips to DEBUG mar cache issues?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 08:22:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mar-cache-entry-is-purged-on-ise/m-p/4743098#M578933</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2022-12-21T08:22:49Z</dc:date>
    </item>
  </channel>
</rss>

