07-16-2018 01:57 AM
Hello ,
I have read the below document on how an external RADIUS server can be configured as an authentication server on Identity Services Engine (ISE) where ISE acts a proxy and as an authorization server as well.
The default dead time for external RADIUS Servers in ISE is 5 minutes. This value is hardcoded and cannot be modified as of this version.
Can I suppose that if I set the server timeout and connection attempt can I modify definitively the dead time of external radius?
Solved! Go to Solution.
07-16-2018 04:36 AM
Not exactly. The options for the server timeout and the number of connection attempts are for every request and influence when will ISE mark a server as dead. Once marked dead, ISE will skip the dead server for 5 minutes and not send any requests to it.
07-16-2018 04:36 AM
Not exactly. The options for the server timeout and the number of connection attempts are for every request and influence when will ISE mark a server as dead. Once marked dead, ISE will skip the dead server for 5 minutes and not send any requests to it.
11-23-2018 02:52 AM
Is the RADIUS server marked dead for the whole deployment or is this on a per node basis?
Some further questions:
What happens if all servers are dead in the sequence? Will ISE try to contact a server anyways, as the newer switches do as well or will there be just no authentication attempts at all during those five minutes?
Also does ISE switch to the second Server in the sequence after the first timeout as seen on some switches or does it only attempt the next server after all retries failed?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide