11-23-2022 08:37 AM
Hello,
I would like to know if ISE is able to cache authentications when a user is authenticated with AD?
For example, a user connects to the network , then disconnects and reconnect few minutes later.
Does ISE use a cache or does it search each time in the AD?
Of course where is the setting?
Kind regards
Solved! Go to Solution.
12-12-2022 03:18 PM
ISE performs an authentication direct to AD (or any identity store) every single time because you may have just fired someone or changed their authorized groups, etc.
The cache setting that Balaji showed is for Machine Access Restrictions (MAR) cache which is for machine authentication requirements before a user logs in. This is totally separate scenario than a basic authentication.
11-23-2022 09:08 AM
for the Device authentication it will not cache.
for 802 1x machine acess it keep 5 hours default as per i know...you can change this in
11-23-2022 11:45 PM
Hi
So if I understand you well when ISE authenticate a user with AD it keeps it in cache for 5h? Not searching for this user in AD for 5h.
12-12-2022 03:18 PM
ISE performs an authentication direct to AD (or any identity store) every single time because you may have just fired someone or changed their authorized groups, etc.
The cache setting that Balaji showed is for Machine Access Restrictions (MAR) cache which is for machine authentication requirements before a user logs in. This is totally separate scenario than a basic authentication.
12-13-2022 04:29 AM - edited 12-13-2022 04:30 AM
By default no but you can enable PEAP session resume which will use the cached information in ISE to authenticate a user without performing the full auth against AD. However, I'm not sure if ISE still actively searches/applied authz conditions (like AD group) or if those are cached too.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide