01-04-2019 08:34 AM
Our AD based USER-ID seems to keep loosing the IP/USER association.
We only have a few rules which work some of the time and then fail with a blank user.
What's the best solution to get it 100%???
Rob
01-04-2019 09:00 AM
is your user id timeout set to the default 45 mins.
just set it to either 4 hours or 8 hours (mins equiv)
I have mine set to 24 hours...
01-04-2019 09:00 AM
is your user id timeout set to the default 45 mins.
just set it to either 4 hours or 8 hours (mins equiv)
I have mine set to 24 hours...
01-04-2019 09:06 AM
Yes 45 mins.
Do new users logins on the same system get picked up ok with that setting of 24Hrs?
Cheers
Rob
01-04-2019 09:18 AM
Rob, not sure what you are asking. but yes..
although the timeout setting is global to all users, it is not a global timer...
so each user, as they authenticate with AD will start there own 24 hour timer for there own mapping.
i think existing mappings will only pick up the new timeout on next authentication.
24 hour is overkill, i only have it as we aslo use Network Access Control on our switches.
4 hours is good practice as usualyy stop for lunch, (lock laptop) 8 hours is a safer bet.
the other option is to use mapping against email server or similar. whatever has the most activity..
01-04-2019 09:26 AM
please note that if an old mapping exists from earlier and your scope runs out of IP addresses then a non AD user could obtain an address of an old mapping prior to it timing out, probably didn't explain that very well, post back if you neeed more info.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!