Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Delay Syncronize User AD to Clearpass

This thread has been viewed 1 times
  • 1.  Delay Syncronize User AD to Clearpass

    Posted Oct 14, 2016 01:58 AM

    Hi All,

     

    Kindly need your advise,

     

    I already integrated Clearpass and AD. and i have 2 group. Group A and Group B.

    User Group A are User1 and  User2

    User Group B are User100 and User200

     

    Group A will get Role A => VLAN A

    Group B will get Role B => VLAN B

    and the configuration already running well.

    But , when i move user1 from group A to Group B, why the user1 still have Role A and VLAN A. I already remove on Group A and move to Group B.

     

    Can i make that change real time or quickly ?

     

    Kindly need your advise

     



  • 2.  RE: Delay Syncronize User AD to Clearpass
    Best Answer

    EMPLOYEE
    Posted Oct 14, 2016 05:10 AM

    You need to change to cache timeout for your AD servers.  In my lab example below I have this to zero.

     

    Snip20161014_2.png



  • 3.  RE: Delay Syncronize User AD to Clearpass

    EMPLOYEE
    Posted Oct 14, 2016 05:30 AM
    Just be cautious setting it to 0 in a large production environment.


  • 4.  RE: Delay Syncronize User AD to Clearpass

    Posted Oct 17, 2016 03:37 AM

    Whats the effect , if i change to 0 ? any issue?



  • 5.  RE: Delay Syncronize User AD to Clearpass
    Best Answer

    EMPLOYEE
    Posted Oct 17, 2016 03:40 AM

    If you set that to 0 CPPM will look up a group membership on every authentication using LDAP.  While a radius server can handle so many queries/second, typically handle as many.  The end result could be many delayed authentications, as a result.



  • 6.  RE: Delay Syncronize User AD to Clearpass

    Posted Oct 17, 2016 03:47 AM

    Ok, Thanks a lot for your support