Security

Reply
Contributor II
Posts: 38
Registered: ‎12-01-2015

Delay Syncronize User AD to Clearpass

Hi All,

 

Kindly need your advise,

 

I already integrated Clearpass and AD. and i have 2 group. Group A and Group B.

User Group A are User1 and  User2

User Group B are User100 and User200

 

Group A will get Role A => VLAN A

Group B will get Role B => VLAN B

and the configuration already running well.

But , when i move user1 from group A to Group B, why the user1 still have Role A and VLAN A. I already remove on Group A and move to Group B.

 

Can i make that change real time or quickly ?

 

Kindly need your advise

 

Aruba
Posts: 1,285
Registered: ‎08-29-2007

Re: Delay Syncronize User AD to Clearpass

You need to change to cache timeout for your AD servers.  In my lab example below I have this to zero.

 

Snip20161014_2.png


If my post is helpful please give kudos, or mark as solved if it answers your post.

ACCP, ACMP, ACMX #294
mclarke@arubanetworks.com
Guru Elite
Posts: 8,203
Registered: ‎09-08-2010

Re: Delay Syncronize User AD to Clearpass

Just be cautious setting it to 0 in a large production environment.

Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Contributor II
Posts: 38
Registered: ‎12-01-2015

Re: Delay Syncronize User AD to Clearpass

[ Edited ]

Whats the effect , if i change to 0 ? any issue?

Guru Elite
Posts: 20,586
Registered: ‎03-29-2007

Re: Delay Syncronize User AD to Clearpass

If you set that to 0 CPPM will look up a group membership on every authentication using LDAP.  While a radius server can handle so many queries/second, typically handle as many.  The end result could be many delayed authentications, as a result.



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Contributor II
Posts: 38
Registered: ‎12-01-2015

Re: Delay Syncronize User AD to Clearpass

Ok, Thanks a lot for your support

Search Airheads
Showing results for 
Search instead for 
Did you mean: