<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAB No Session Timeout behind a NON-Cisco IP-Phone in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211068#M126490</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i´ve found a solution with IOS 12.2(55SE).&lt;/P&gt;&lt;P&gt;A combination of mac-move permit and authentication violation replace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAC-MOVE.&lt;/P&gt;&lt;P&gt;If the PC behind the Phone will be disconnected the session remains for ever. If i plug the PC into another Port on the same switch a new session will be established and the old session will be cleared.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHENTICATION VIOLATION REPLACE&lt;/P&gt;&lt;P&gt;If the PC behind the Phone will be disconnected the session remains for ever. If a new Device will be connected behind the Phone a security violation occurs but the session will be replaced by the new Device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No inactivity timer is needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Horst&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Jun 2013 08:55:37 GMT</pubDate>
    <dc:creator>hdussa</dc:creator>
    <dc:date>2013-06-25T08:55:37Z</dc:date>
    <item>
      <title>MAB No Session Timeout behind a NON-Cisco IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211065#M126349</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I´ve a Alctel IP-Phone authenticated via 802.1. A PC ist connected at the Phone using MAB. When the PC will be disconnected the session remains for ever. The session can be cleared with the inactivity timer. The PROBLEM is....when the PC is still connected (during Lunch time) the session will e cleared.&lt;/P&gt;&lt;P&gt;Is there a possibility to clear the session only when disconnecting the PC. Device tracking does not help. I´ve configured Session timeout in combination with Termination action = Default on ACS5.4. Nothing happened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport voice vlan 24&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;/P&gt;&lt;P&gt;authentication host-mode multi-domain&lt;/P&gt;&lt;P&gt;authentication order dot1x mab&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;authentication timer inactivity server&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;dot1x timeout tx-period 1&lt;/P&gt;&lt;P&gt;dot1x max-reauth-req 1&lt;/P&gt;&lt;P&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx Horst&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211065#M126349</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2019-03-11T03:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: MAB No Session Timeout behind a NON-Cisco IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211066#M126386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting.... Do you know why the PC is getting disconnected over lunch? Is it being turned off / standby / hibernated / idle for too long?&lt;BR /&gt;&lt;BR /&gt;Also, if you're doing MAB, it shouldn't really matter too much if it does get disconnected because as soon as the PC starts to transmit frames again, the switch should do another MAC Auth and you're in business again. Is this secondary authentication not happening?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 08:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211066#M126386</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-06-14T08:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: MAB No Session Timeout behind a NON-Cisco IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211067#M126429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what you say it´s right. But what happens with Outlook-Connection or other applications which needs connectivity? If the PC send no "keepalive". I think a user will not be happy to restart the applications. As soon as the Pc send a packet reauthentication starts succesful. The coolest thing would be if the inactivity timer, in combination with ip device tracking, would restart. RadiusAttribute 27 and 29 configured on ACS has got no effect. With "debug radius" i can see it. But show dot1x all on the interface doses not show anything. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CEST: RADIUS:&amp;nbsp; Session-Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [27]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 77&lt;/P&gt;&lt;P&gt;CEST: RADIUS:&amp;nbsp; Termination-Action&amp;nbsp; [29]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch#sh dot1x interface fa0/1&lt;/P&gt;&lt;P&gt;Dot1x Info for FastEthernet0/1&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;PAE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = AUTHENTICATOR&lt;/P&gt;&lt;P&gt;PortControl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = AUTO&lt;/P&gt;&lt;P&gt;ControlDirection&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = In&lt;/P&gt;&lt;P&gt;HostMode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = MULTI_DOMAIN&lt;/P&gt;&lt;P&gt;QuietPeriod&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 60&lt;/P&gt;&lt;P&gt;ServerTimeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 0&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;----- NO ENTRY &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 08:56:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211067#M126429</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2013-06-14T08:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: MAB No Session Timeout behind a NON-Cisco IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211068#M126490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i´ve found a solution with IOS 12.2(55SE).&lt;/P&gt;&lt;P&gt;A combination of mac-move permit and authentication violation replace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAC-MOVE.&lt;/P&gt;&lt;P&gt;If the PC behind the Phone will be disconnected the session remains for ever. If i plug the PC into another Port on the same switch a new session will be established and the old session will be cleared.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHENTICATION VIOLATION REPLACE&lt;/P&gt;&lt;P&gt;If the PC behind the Phone will be disconnected the session remains for ever. If a new Device will be connected behind the Phone a security violation occurs but the session will be replaced by the new Device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No inactivity timer is needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Horst&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 08:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211068#M126490</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2013-06-25T08:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: MAB No Session Timeout behind a NON-Cisco IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211069#M126544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mac-move is enabled by default. Unfortunately, authentication violation replace is not an option in my network.&lt;BR /&gt;&lt;BR /&gt;Thank you for the response.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 01:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-no-session-timeout-behind-a-non-cisco-ip-phone/m-p/2211069#M126544</guid>
      <dc:creator>dynamitec1</dc:creator>
      <dc:date>2013-06-27T01:40:55Z</dc:date>
    </item>
  </channel>
</rss>

