last person joined: 12 hours ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass - AD Sites and Services

Jump to Best Answer
  • 1.  ClearPass - AD Sites and Services

    Posted Mar 05, 2013 11:50 AM

    We have several CPPMs in a cluster, with one CPPM server at each campus we have.  In order to make sure that authentications at each location stay local, I setup services for each location with authentication sources that are local to each.  I'm working with a contractor that has deployed Cisco ISE, and he asked why I setup CPPM with services for each location.  I mentioned that I wanted to be sure that authentications happened locally, rather than going across our WAN network.  He mentioned that ISE works with MS Sites and Services to determine which AD servers belong to a subnet, so that each independant ISE server can select the closest AD server for authentication.  That way you don't have to create multiple services which local authentication sources like I did.  Is this supported in CPPM?

  • 2.  RE: ClearPass - AD Sites and Services
    Best Answer

    Posted Apr 21, 2013 11:20 PM

    I was told by an ClearPass engineer that the CP server will be served the DNS record for the closest domain controllers if AD Sites and Services is setup with site subnets.