Network Management

 View Only
last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

clearpass Active Directory Cache Timeout

This thread has been viewed 16 times
  • 1.  clearpass Active Directory Cache Timeout

    Posted Mar 14, 2021 08:34 PM
    hi all
        I am not sure how the Active Directory Cache Timeout is calculated? When a user is successfully authenticated for the first time, will it be cached for 10 hours without going to AD for authentication?

    ------------------------------
    leo ma
    ------------------------------


  • 2.  RE: clearpass Active Directory Cache Timeout
    Best Answer

    EMPLOYEE
    Posted Mar 15, 2021 03:48 AM
    It is more like an authorization timeout. If a client reconnects within the configures cache timeout, the cached attributes like group membership are used instead of them being pulled from the AD each and every time.

    Authentication will happen on the ClearPass (EAP-TLS) or through the Active Directory domain join (MS-CHAPv2; deprecated!)

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 3.  RE: clearpass Active Directory Cache Timeout

    Posted Mar 23, 2021 04:27 AM
    hi Robers
      Thank you for your reply, I consulted tac, the account password authentication will go to AD every time, but the attribute information of the account is cached. The machine verification will be cached for 24 hours.
      Sorry my english is not very good,


    ------------------------------
    leo ma
    ------------------------------