Security

 View Only

Onguard Agent and Policy Cache timeout

This thread has been viewed 3 times
  • 1.  Onguard Agent and Policy Cache timeout

    Posted Feb 27, 2019 05:52 AM

    We are facing an issue with ClearPass Ongaurd. We set the policy cache time out in the cluster wide parameters to 8 hours, which works as expected. However, if we clear the policy cache for a specific endpoint, we assume the agent will run again and collect health status for the user specially that keep-alive in the agent settings is enabled for every 60 second, but this is not happening.

     

    We also, tried to disconnect/terminate/bounce the user port, and seems that agent sometime run and sometimes it does not and the only way to get it working, is to hit the retry button on the agent.

     

    Our main goal is that the user gets connected, and we should not interrupt the service as long as he is healthy. If we keep the policy cache timeout set to the default value, that is 5 min, the onguard agent keeps disconnecting the user after every health check.

     

    We are running ClearPass 6.7.6 version.