cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2105
Views
10
Helpful
7
Replies

Difference between suppress & reject Cisco ISE?

Mottok
Level 1
Level 1

Hi, can anyone tell me exactly what the difference between suppress and reject is please? Because when you look at the info it says 'Suppress' is to supress from audit logs AND to reject, and to reject is to reject......eh??

 

Can't find much on interweb either.

 

Any help appreciated thanks.

 

ISE.JPG

1 Accepted Solution

Accepted Solutions

Suppress as per your config means if the client has failed authentication 2 times in 5 minutes, then don't report failure in logs everytime the client failed after first 2 times, only report it every 15 minutes once.

Reject as per your config means after total 5 failures, don't process client request for authentication for 60 minutes.

 

-hope this helps-

View solution in original post

7 Replies 7

Mottok
Level 1
Level 1
Hi - anyone able to answer the above? Thanks.

Ok thanks, so it basically looks like the suppress keeps it out of logs and reject actually stops/rejects authentication. Just the supress part which is badly worded in the "i" info section.

Yeah Suppress will reduce the repeated logs & reject will stop the failed authentication of endpoint for mentioned time period.

 

Thanks,

Aravind

-Aravind

yeh it's just that last sentence about the suppression that was confusing me, it looks as if this could reject too. Thanks all.

 

Supress.JPG

Suppress as per your config means if the client has failed authentication 2 times in 5 minutes, then don't report failure in logs everytime the client failed after first 2 times, only report it every 15 minutes once.

Reject as per your config means after total 5 failures, don't process client request for authentication for 60 minutes.

 

-hope this helps-

Was looking for a nice simple answer and that's it thanks!
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card