cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

Cisco ISE 1.1.2 and Certfication Revocation List (CRL) checking

david.tran
Level 4
Level 4

All,

I have 4 ISE appliances version 1.1.2  running in my networ called nodeA, nodeB, nodeC and nodeD. 

- NodeA is Primary Admin and Secondary Monitoring,

- NodeB is Secondary Admin and Primary Monitoring,

- NodeC is Policy node,

- NodeD is Policy node,

The ISE environment is tightly integrated with the company Microsoft Active Directory Windows 2008R2.  We import the company issue cert into the ISE for PEAP and CRL checking

Question:  How often does the ISE perform CRL checking with the Certiticate Authority (CA) Server? 

I also have an ACS environment that also tightly integrated with Microsoft AD.   How often does the ACS peform CRL checking with the Certificate Authority (CA) Server?

What will happen to the ISE and ACS environment if the CA Server becomes un-available?

I can't seem to find this question in either ISE or ACS documentation anywhere. 

Thank you.

Who Me Too'd this topic