<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks for your reply, Sandy; in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485470#M90547</link>
    <description>&lt;P&gt;Thanks for your reply, Sandy; unfortunately, it doesn't answer any of my questions.&lt;/P&gt;</description>
    <pubDate>Wed, 14 May 2014 12:42:37 GMT</pubDate>
    <dc:creator>tgrundbacher</dc:creator>
    <dc:date>2014-05-14T12:42:37Z</dc:date>
    <item>
      <title>ISE MAR cache</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485468#M90545</link>
      <description>&lt;P&gt;Does anybody know what's going to happen if one changes the MAR cache timeout/aging setting found under Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory &amp;gt; Advanced Settings? Are the current cache entries going to get cleared or are they going to stay? Is there a way to actually see these entries somewhere (per PSN), and can one selectively delete them?&lt;/P&gt;&lt;P&gt;Depending on the answer to these questions, I have to make the aging timeout change during a maintenance window on the customer's infrastructure. Using ISE 1.2, patch 6.&lt;/P&gt;&lt;P&gt;Oh, and another question: Are there any drawbacks (e.g. cache size or security issues, other constraints) that would suggest to not increase the default aging timeout to a value of a full week or even more?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Toni&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485468#M90545</guid>
      <dc:creator>tgrundbacher</dc:creator>
      <dc:date>2019-03-11T04:43:11Z</dc:date>
    </item>
    <item>
      <title>Hi Toni,Machine Access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485469#M90546</link>
      <description>&lt;P&gt;Hi Toni,&lt;/P&gt;&lt;H2 class="p_H_Head1" style="font-size: 14px; color: rgb(51, 102, 102); font-weight: bold; font-family: Arial, Helvetica, sans-serif; margin: 14px 0em 7px -0.1in; line-height: normal;"&gt;Machine Access Restriction for Active Directory User Authorization&lt;/H2&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1205206"&gt;&lt;/A&gt;Cisco ISE contains a Machine Access Restriction (MAR) component that provides an additional means of controlling authorization for Microsoft Active Directory-authentication users. This form of authorization is based on the machine authentication of the computer used to access the Cisco ISE network. For every successful machine authentication, Cisco ISE caches the value that was received in the RADIUS Calling-Station-ID attribute (attribute 31) as evidence of a successful machine authentication.&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1205207"&gt;&lt;/A&gt;Cisco ISE retains each Calling-Station-ID attribute value in cache until the number of hours that was configured in the “Time to Live” parameter in the Active Directory Settings page expires. Once the parameter has expired, Cisco ISE deletes it from its cache.&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1205208"&gt;&lt;/A&gt;When a user authenticates from an end-user client, Cisco ISE searches the cache for a Calling-Station-ID value from successful machine authentications for the Calling-Station-ID value that was received in the user authentication request. If Cisco ISE finds a matching user-authentication Calling-Station-ID value in the cache, this affects how Cisco ISE assigns permissions for the user that requests authentication in the following ways:&lt;/P&gt;&lt;UL style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal;"&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&lt;A name="pgfId-1205209"&gt;&lt;/A&gt;If the Calling-Station-ID value matches one found in the Cisco ISE cache, then the authorization profile for a successful authorization is assigned.&lt;/LI&gt;&lt;LI class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&lt;A name="pgfId-1205210"&gt;&lt;/A&gt;If the Calling-Station-ID value is not found to match one in the Cisco ISE cache, then the authorization profile for a successful user authentication without machine authentication is assigned.&lt;/LI&gt;&lt;/UL&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_authz_polprfls.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_authz_polprfls.html&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;HTH&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="font-size: 12px; margin: 0px 0em 7px -28px; text-align: left; list-style-type: disc; padding-left: 12px;"&gt;Sandy&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 12:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485469#M90546</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-05-14T12:32:16Z</dc:date>
    </item>
    <item>
      <title>Thanks for your reply, Sandy;</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485470#M90547</link>
      <description>&lt;P&gt;Thanks for your reply, Sandy; unfortunately, it doesn't answer any of my questions.&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 12:42:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485470#M90547</guid>
      <dc:creator>tgrundbacher</dc:creator>
      <dc:date>2014-05-14T12:42:37Z</dc:date>
    </item>
    <item>
      <title>Hi , If i understand your</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485471#M90549</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;If i understand your request , your questionnaire is about MAR cache time out during your maintenance window right ?? or You &amp;nbsp;look for some other things&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 14px;"&gt;MAR cache timeout/aging setting found under&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Sandy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 12:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485471#M90549</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-05-14T12:51:18Z</dc:date>
    </item>
    <item>
      <title>Are the current cache entries</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485472#M90551</link>
      <description>&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 14px;"&gt;Are the current cache entries going to get cleared or are they going to stay?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 14px;"&gt;Is there a way to actually see these entries somewhere (per PSN), and can one selectively delete them?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 14px;"&gt;Are there any drawbacks (e.g. cache size or security issues, other constraints) that would suggest to not increase the default aging timeout to a value of a full week or even more?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 14 May 2014 12:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485472#M90551</guid>
      <dc:creator>tgrundbacher</dc:creator>
      <dc:date>2014-05-14T12:59:13Z</dc:date>
    </item>
    <item>
      <title> Hi Are the current cache</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485473#M90553</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;UL style="margin-top: 15px; margin-bottom: 0px; color: rgb(119, 119, 119); font-size: 14px;"&gt;&lt;LI style="margin: 5px 0px;"&gt;Are the current cache entries going to get cleared or are they going to stay? :&amp;nbsp;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: rgb(247, 247, 247);"&gt;Cisco ISE retains each Calling-Station-ID attribute value in cache until the number of hours that was configured in the “Time to Live” parameter in the Active Directory Settings page expires&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="margin: 5px 0px;"&gt;Is there a way to actually see these entries somewhere (per PSN), and can one selectively delete them? &amp;nbsp;yes you can see in logs&lt;/LI&gt;&lt;LI style="margin: 5px 0px;"&gt;&lt;TABLE border="1" bordercolor="#808080" cellpadding="3" cellspacing="0" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;CacheTracker&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1609913"&gt;&lt;/A&gt;&lt;EM class="cEmphasis" style="text-indent: 0em; background-color: transparent;"&gt;ise-tracking.log&lt;/EM&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin: 5px 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 5px 0px;"&gt;See under&amp;nbsp;Downloading Debug Logs&lt;/P&gt;&lt;P style="margin: 5px 0px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_mnt.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_mnt.html&lt;/A&gt;&lt;/P&gt;&lt;UL style="margin-top: 15px; margin-bottom: 0px; color: rgb(119, 119, 119); font-size: 14px;"&gt;&lt;LI style="margin: 5px 0px;"&gt;Are there any drawbacks (e.g. cache size or security issues, other constraints) that would suggest to not increase the default aging timeout to a value of a full week or even more? For Pro &amp;amp; Cons &amp;nbsp;go through below document&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin: 5px 0px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin: 5px 0px;"&gt;HTH&lt;/P&gt;&lt;P style="margin: 5px 0px;"&gt;Sandy&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 14:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485473#M90553</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-05-14T14:45:16Z</dc:date>
    </item>
    <item>
      <title>Thanks for your input, Sandy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485474#M90554</link>
      <description>&lt;P&gt;Thanks for your input, Sandy.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The Cisco documentation still doesn't state what happens to the entries in the cache when you MODIFY the MAR aging timeout during operation. I'm well aware what happens if you LEAVE the timer as it is. Up to this point we can only speculate that the entries will stay, but I have to be sure before I go ahead.&lt;/LI&gt;&lt;LI&gt;It's good to know that there is a log for the cache tracker, thanks.&lt;/LI&gt;&lt;LI&gt;Reading the last link won't let me think that increasing the MAR cache aging timer will degrade performance, security or functionality in any way, so...I guess I can only find out if that's true if I try it out.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 14 May 2014 15:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mar-cache/m-p/2485474#M90554</guid>
      <dc:creator>tgrundbacher</dc:creator>
      <dc:date>2014-05-14T15:06:42Z</dc:date>
    </item>
  </channel>
</rss>

