cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
897
Views
0
Helpful
0
Replies

ISE - PEAP retries, exclusion & reauthentication

Sir Chris
Level 1
Level 1

I cannot find anything in the ISE user manual that describes the behaviour when a client fails authentication after a number of failed authentications,. Lab trials are somewhat inconclusive!

Eg After 3 failed logins during a rolling 30 minute window I want client to be excluded for 30 mins before he can try again.

 

Policy > Policy Elements > Results shows:

Allow EAP-MS-CHAPv2: Retry Attempts—"Specifies how many times Cisco ISE requests user credentials before returning login failure". Valid values are 1 to 3.'

 

What governs the window, time recovery and where can I see an excluded client that has failed this way?

 

 

 

0 Replies 0