<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User authentication time in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4840666#M581918</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do I still need to select "Treat as if the user was not found and proceed to the next store in the sequence" after use the initial scope?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 May 2023 05:07:57 GMT</pubDate>
    <dc:creator>williamtan</dc:creator>
    <dc:date>2023-05-23T05:07:57Z</dc:date>
    <item>
      <title>User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4837543#M581786</link>
      <description>&lt;P&gt;Customer have one ISE and five AD domains which have zero trust between. I'm able to join the ISE to all five ADs and created the identity source sequence from top AD1 to bottom AD5.&lt;/P&gt;
&lt;P&gt;Any different of time taken to authenticate between user from AD1 and AD5? Is it in millisecond? Customer want to know how long it take and document it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 10:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4837543#M581786</guid>
      <dc:creator>williamtan</dc:creator>
      <dc:date>2023-05-17T10:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4837587#M581788</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/549292"&gt;@williamtan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;&amp;nbsp;1st&lt;/STRONG&gt; please take a look at &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; Identity Source Sequences &amp;gt;&lt;/STRONG&gt; select your &lt;U&gt;Sequence Name&lt;/U&gt; and make sure that at &lt;STRONG&gt;Advanced Search List Settings&lt;/STRONG&gt;, the&amp;nbsp;&lt;STRONG&gt;Treat as if the user was not found and proceed to the next store in the sequence&lt;/STRONG&gt;&amp;nbsp;is selected.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;2nd&lt;/STRONG&gt; at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Settings &amp;gt; Protocols &amp;gt; RADIUS &amp;gt;&lt;/STRONG&gt; check the value of &lt;STRONG&gt;Highlight steps longer than (millisenconds)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;3rd&lt;/STRONG&gt;&amp;nbsp;at &lt;STRONG&gt;Operations &amp;gt; Reports &amp;gt; Reports &amp;gt; Endpoint and Users &amp;gt; RADIUS Authentications &amp;gt;&lt;/STRONG&gt; click the &lt;STRONG&gt;Details&lt;/STRONG&gt; icon &amp;gt; at the new windows you are able to check the &lt;STRONG&gt;Steps&lt;/STRONG&gt; of the &lt;STRONG&gt;RADIUS Authentication&lt;/STRONG&gt;&amp;nbsp;and check the &lt;STRONG&gt;24325 Resolving Identity&lt;/STRONG&gt;, if this step takes longer than the value of &lt;STRONG&gt;Highlight steps longer than (millisenconds)&lt;/STRONG&gt;, then you have your answer in an exact number.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 11:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4837587#M581788</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-05-17T11:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4838031#M581808</link>
      <description>&lt;P&gt;Thank you &lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Advisor lia-component-message-view-widget-author-username"&gt;&lt;A id="link_15" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232" target="_self" aria-label="View Profile of Marcelo Morais"&gt;&lt;SPAN class=""&gt;Marcelo Morais&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt; for your fast reply.&lt;/P&gt;
&lt;P&gt;1. Yes, I have select this already.&lt;/P&gt;
&lt;P&gt;2. This one is default 1000 milliseconds.&lt;/P&gt;
&lt;P&gt;3. I didn't see a clock there so it should be less than 1000ms.&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 04:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4838031#M581808</guid>
      <dc:creator>williamtan</dc:creator>
      <dc:date>2023-05-18T04:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4838238#M581815</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/549292"&gt;@williamtan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;that's correct ... in your case less than &lt;STRONG&gt;1000 ms&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 11:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4838238#M581815</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-05-18T11:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4839024#M581834</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Advisor lia-component-message-view-widget-author-username"&gt;&lt;A id="link_23" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232" target="_self" aria-label="View Profile of Marcelo Morais"&gt;&lt;SPAN class=""&gt;Marcelo Morais&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;,&lt;/P&gt;
&lt;P&gt;I try to change the value of Highlight steps longer than to 500ms and it still not show the time. But customer want to know the exact time. Is it possible?&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 13:10:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4839024#M581834</guid>
      <dc:creator>williamtan</dc:creator>
      <dc:date>2023-05-19T13:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4839201#M581841</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/549292"&gt;@williamtan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;at &lt;STRONG&gt;Operations &amp;gt; Troubleshooting &amp;gt; Diagnostic Tools &amp;gt; General Tools &amp;gt; TCP Dump&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL class="lia-list-style-type-disc"&gt;
&lt;LI class="lia-align-justify"&gt;select the &lt;STRONG&gt;PSN&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;Promiscuous Mode = &lt;STRONG&gt;Off&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;Download and open the &lt;STRONG&gt;TCPDump.pcap&lt;/STRONG&gt; file via &lt;STRONG&gt;Wireshark&lt;/STRONG&gt; and filter by: &lt;STRONG&gt;tcp.port == 389&lt;/STRONG&gt;. (for example), you are able to check the &lt;STRONG&gt;Time&lt;/STRONG&gt; between packets exchange.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 18:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4839201#M581841</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-05-19T18:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4839916#M581893</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/549292"&gt;@williamtan&lt;/a&gt; For active directory, it's preferred to use scopes so the ISE will query all AD join points the same time.&lt;/P&gt;
&lt;P&gt;It's hard to judge the authentication time because it depends on both ISE and AD servers. AD servers could be busy and slower in responses.&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 01:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4839916#M581893</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-05-22T01:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4840666#M581918</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do I still need to select "Treat as if the user was not found and proceed to the next store in the sequence" after use the initial scope?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 05:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4840666#M581918</guid>
      <dc:creator>williamtan</dc:creator>
      <dc:date>2023-05-23T05:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4841022#M581928</link>
      <description>&lt;P&gt;We may use the Active Directory scope directly as the identity authentication source.&amp;nbsp;That setting is for an ISE identity source sequence so it would not be in effect unless we are using one when we combine the Active directory scope with other other sources.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 17:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4841022#M581928</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-05-23T17:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4841966#M581947</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;, let me investigate the "scope" configuration you are mentioning.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:45:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-time/m-p/4841966#M581947</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2023-05-24T14:45:31Z</dc:date>
    </item>
  </channel>
</rss>

