12-7
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 12 Administering External User Databases
Unknown User Processing
most reliable method of supporting multiple instances of a username across
domains is to require users to supply their domain memberships as part of the
authentication request.
Performance of Unknown User Authentication
Processing authentication requests for unknown users requires slightly more time
than processing authentication requests for known users. This small delay may
require additional configuration on the AAA clients through which unknown
users may attempt to access your network.
Added Latency
Adding external databases against which to process unknown users can
significantly increase the time needed for each individual authentication. At best,
the time needed for each authentication is the time taken by the external database
to authenticate, plus some latency for Cisco Secure ACS processing. In some
circumstances (for example, when using a Windows NT/2000 user database), the
extra latency introduced by an external database can be as much as tens of
seconds. If you have configured multiple databases, this number is multiplied by
the time taken for each one to complete.
You can account for added latency by setting the order of databases. If you are
using an authentication protocol that is particularly time sensitive, such as PEAP,
we recommend configuring unknown user processing to attempt authentication
first with the database most likely to contain unknown users using the
time-sensitive protocol. For more information, see
Database Search Order,
page 12-9
.
Authentication Timeout Value on AAA clients
Be sure to increase the AAA client timeout to accommodate the longer
authentication time required for Cisco Secure ACS to pass the authentication
request to the external databases. If the AAA client timeout value is not set high
enough to account for the delay required by unknown user authentication, the
AAA client times out the request and every unknown user authentication fails.