Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cache Clearpass with LDAP query

This thread has been viewed 17 times
  • 1.  Cache Clearpass with LDAP query

    Posted Sep 05, 2016 07:33 PM

    Hello,

     

    We have a Controller with ClearPass and we use the protocol 802.1x for authentication issue with LDAP you may not make the ClearPass frequently queries the LDAP and cache is generated for a certain time, there is that option?

     

    Thanks for your help.

     

    Regards.

     

    HC 



  • 2.  RE: Cache Clearpass with LDAP query

    EMPLOYEE
    Posted Sep 05, 2016 07:58 PM

    It does not look up LDAP for AD group membership for X seconds.

     

    It is located in configuration> Authentication> Sources.  Click on your Authentication Source and then General to see the Cache timeout:

     

     

    source.png

     

    In the lower right hand corner of that same screen is a clear cache button:

     

    clearcache.png



  • 3.  RE: Cache Clearpass with LDAP query
    Best Answer

    EMPLOYEE
    Posted Sep 05, 2016 08:03 PM

    The reason for that cache is that some LDAP servers cannot keep up with tons of authentications a second, so doing a lookup for a group membership constantly can slow down regular authentications.  When it does an authentication, it will cache the group memberships for X seconds, which prevents another group lookup.  It will check the authenticaton for the password, every time, however.  If you are doing testing and changing AD group memberships, you can click on clear cache to test if the user is getting the correct LDAP group membership.



  • 4.  RE: Cache Clearpass with LDAP query

    Posted Sep 06, 2016 09:57 AM

    Thanks for your help 

     

    One Question? The maximum cache how long is it? right now I have it set for 10 hours 36000 seconds which is maximum time that could define ?

     

    Regards