Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Authentication Source Cache Timeout

This thread has been viewed 23 times
  • 1.  CPPM Authentication Source Cache Timeout

    Posted Sep 08, 2014 01:25 PM

    Hi:

    I've had several problems lately that were solved by clearing the cache for the AD authentication source.

    Currently the Cache Timeout (Configuration -- Authentication -- Sources -- Our AD - General Tab) is set to 36000 seconds, or 10 hours.

     

    I would like to make this much shorter - something like 15 minutes.

     

    Are there any side effects I should be aware of, before I do this?

     

    Thanks,

    Tony



  • 2.  RE: CPPM Authentication Source Cache Timeout
    Best Answer

    EMPLOYEE
    Posted Sep 08, 2014 01:27 PM

    Side effects are more authorization requests to AD. I have a large university set to 1 hour with no issues.



  • 3.  RE: CPPM Authentication Source Cache Timeout

    Posted Sep 08, 2014 01:40 PM

    I will begin the shortening process! :-)

    Thank you.



  • 4.  RE: CPPM Authentication Source Cache Timeout

    Posted Dec 31, 2014 04:01 AM

    Hi Tony1234,

     

    How do you do for to clear the cache of AD auth in CPPM ?

     

    regards

     

    Yann



  • 5.  RE: CPPM Authentication Source Cache Timeout
    Best Answer

    Posted Dec 31, 2014 04:07 AM

    Sorry, i hadn't opened my eyes, is it on the auth Source.Capture23.JPG



  • 6.  RE: CPPM Authentication Source Cache Timeout

    Posted Feb 14, 2016 06:34 AM

    Does anyone see a problem with setting the Cache Timeout to 0 - 300s?

     

    What we are trying to achieve is only allowing users connect to wifi if they badge in using their campus ID card. We want to utilize CPPM and its functionality to search AD/LDAP attributes. So we would want to achieve the following:

    • When student arrives on campus, they will badge in with their ID.
    • The ID software will then update an attribute in ActiveDirectory/LDAP, "pager" and will change it to say 1, so that we know that this user has tapped into the system and is on campus.
    • CPPM Rules: 
      • If user is a "student" AND "pager = 1" then user can connect. (User is a student and has badged in)
      • If user is a "student" AND "pager is not 1" then user can't connect. (User is a student but has not badged in, no wifi)
    • I've tested a trial run in our Test environment, with CPPM, I have two authentication sources from Active Directory.
      • Authentication Source: AD Server 1, with cache timeout set to it's default 36000s. This will be for main authentication
      • Authentication Source: AD Server 2, which is looking for a change in the "pager" attribute., with cache timeout set to 0-300s

    I know I can do all of this using one authentication source with a very low Cache Timout, but I'm just not sure if the load will be too great? We would hypothetically have 1500 users authenticating at peak hours or beginning of the day.

     

    Any recommended settings would be appreciated? My main worry is if CPPM could handle that load?

     

    Thanks



  • 7.  RE: CPPM Authentication Source Cache Timeout

    Posted Feb 22, 2016 01:45 PM

    i would start a new thread, as this is different question.

     

    [EDIT] you did exactly that already :) ignore my post.

     

    personally i don't really see the difference between the clearpass having to do the lookup internally or against an external source. to an external source will take more time but i don't see the load go up that much because of that.



  • 8.  RE: CPPM Authentication Source Cache Timeout

    Posted Sep 05, 2016 07:57 PM

    Hello,

     

    The 36000 is the time maximum range? or whats is the range maximum the time? because the default is 10 hours or 36000 , We can put the 24 hours? or 12 hours? 

     

    Thanks.

     

    Regards