04-05-2022 03:36 AM
Hello everybody!
I would like to know how long it takes the ISE to synchronize with the AD after a change has been made on the AD.
Is there a default parameter set on the ISE that forces it to synchronize with the AD?
Is it possible to change it?
Thanks in advance for the reply!
Solved! Go to Solution.
04-05-2022 10:00 AM
ISE does not synchronize or cache the Active Directory database. This is more of a function of AD replication than anything else and it's a deep topic with many intricacies. Depending on what the change in AD is, and how the domain is set up, some changes can be replicated within 15 seconds, while some things could be more than an hour. Intrasite (same site) replication happens within a minute regardless of how many domain controllers there are in the site, while intersite (site to site) replication by default happens on a 180 minute interval.
Each ISE node asks it's "peered" AD domain controller for authentication and attributes when an authentication comes in. Which group of DCs the PSN hits is mostly determined by the AD sites and Services configuration within AD.
04-05-2022 03:58 AM
as per i know ISE keeping checking the LDAP connection every 10Seconds get updates. (this can be changerd depends on requirement)
04-05-2022 10:00 AM
ISE does not synchronize or cache the Active Directory database. This is more of a function of AD replication than anything else and it's a deep topic with many intricacies. Depending on what the change in AD is, and how the domain is set up, some changes can be replicated within 15 seconds, while some things could be more than an hour. Intrasite (same site) replication happens within a minute regardless of how many domain controllers there are in the site, while intersite (site to site) replication by default happens on a 180 minute interval.
Each ISE node asks it's "peered" AD domain controller for authentication and attributes when an authentication comes in. Which group of DCs the PSN hits is mostly determined by the AD sites and Services configuration within AD.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide