cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1864
Views
5
Helpful
4
Replies

Does ISE use a cache for AD authentication?

REJR77
Level 1
Level 1

Hello,

I would like to know if ISE is able to cache authentications when a user is authenticated with AD?

For example, a user connects to the network , then disconnects and reconnect few minutes later.

Does ISE use a cache or does it search each time in the AD?

Of course where is the setting?

Kind regards

1 Accepted Solution

Accepted Solutions

thomas
Cisco Employee
Cisco Employee

ISE performs an authentication direct to AD (or any identity store) every single time because you may have just fired someone or changed their authorized groups, etc.

The cache setting that Balaji showed is for Machine Access Restrictions (MAR) cache which is for machine authentication requirements before a user logs in. This is totally separate scenario than a basic authentication.

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

for the Device authentication it will not cache.

for 802 1x machine acess it keep 5 hours default as per i know...you can change this in

balajibandi_0-1669223272896.png

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi

So if I understand you well when ISE authenticate a user with AD it keeps it in cache for 5h? Not searching for this user in AD for 5h.

 

thomas
Cisco Employee
Cisco Employee

ISE performs an authentication direct to AD (or any identity store) every single time because you may have just fired someone or changed their authorized groups, etc.

The cache setting that Balaji showed is for Machine Access Restrictions (MAR) cache which is for machine authentication requirements before a user logs in. This is totally separate scenario than a basic authentication.

By default no but you can enable PEAP session resume which will use the cached information in ISE to authenticate a user without performing the full auth against AD.  However, I'm not sure if ISE still actively searches/applied authz conditions (like AD group) or if those are cached too.