<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5411 EAP session timeout with ACS in the WAN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829850#M227199</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know anything about your environment, but we have a problem at our headoffice with 5411 EAP Session Timeout. We suspect that it's because we have two VLAN, one for clients and one for servers. The DHCP-server is in the server VLAN and we use "ip helper" on the client VLAN to relay dhcp-requests between VLANs. We found two articles on this indicating that this might be a problem;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://support.microsoft.com/kb/2459530" rel="nofollow"&gt;http://support.microsoft.com/kb/2459530&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://support.microsoft.com/kb/938449" rel="nofollow"&gt;http://support.microsoft.com/kb/938449&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The symptoms is that the client hangs on the "Welcome"-screen for a long time, or the clients are being assigned the guest vlan. On the ACS we see "5411 EAP Session timeout..".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're gonna test it out by placing a dhcp-server in our client VLAN and remove the "ip helper" command for that VLAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 May 2012 10:17:44 GMT</pubDate>
    <dc:creator>bvj197222</dc:creator>
    <dc:date>2012-05-22T10:17:44Z</dc:date>
    <item>
      <title>5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829849#M227162</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're having trouble trying to deploy 802.1x authentication on a brand new site.&lt;/P&gt;&lt;P&gt;Our primary and secondary ACS are located in Paris and the new site located in Toulouse, France.&lt;/P&gt;&lt;P&gt;Both sites are connected through the WAN.&lt;/P&gt;&lt;P&gt;Everytime a computer/user connects to this new site in Toulouse, ACS 5.2 sends a "5411 EAP session timeout" error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any pieces of advice greatly appreciated,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829849#M227162</guid>
      <dc:creator>Laurent BOURHIS</dc:creator>
      <dc:date>2019-03-11T01:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829850#M227199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know anything about your environment, but we have a problem at our headoffice with 5411 EAP Session Timeout. We suspect that it's because we have two VLAN, one for clients and one for servers. The DHCP-server is in the server VLAN and we use "ip helper" on the client VLAN to relay dhcp-requests between VLANs. We found two articles on this indicating that this might be a problem;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://support.microsoft.com/kb/2459530" rel="nofollow"&gt;http://support.microsoft.com/kb/2459530&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://support.microsoft.com/kb/938449" rel="nofollow"&gt;http://support.microsoft.com/kb/938449&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The symptoms is that the client hangs on the "Welcome"-screen for a long time, or the clients are being assigned the guest vlan. On the ACS we see "5411 EAP Session timeout..".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're gonna test it out by placing a dhcp-server in our client VLAN and remove the "ip helper" command for that VLAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 10:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829850#M227199</guid>
      <dc:creator>bvj197222</dc:creator>
      <dc:date>2012-05-22T10:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829851#M227226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi and thanks for your input &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt; !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently testing the hotfix mentionned in the first article.&lt;/P&gt;&lt;P&gt;I'll let you know after intensive testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 14:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829851#M227226</guid>
      <dc:creator>Laurent BOURHIS</dc:creator>
      <dc:date>2012-05-22T14:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829852#M227251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking forward to see if the patch helps. We're also testing out the patch mentioned in KB2459530, and have installed it on two computers. The problem with 5411 EAP... comes and goes in our organisation. It's not persistent on one computer. So we have to test this patch for some time to see if it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 06:23:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829852#M227251</guid>
      <dc:creator>bvj197222</dc:creator>
      <dc:date>2012-05-23T06:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829853#M227279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Be sure I'll let you know ASAP.&lt;/P&gt;&lt;P&gt;Just for my information, do you have the GPO "Always Wait for Network" disabled ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 07:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829853#M227279</guid>
      <dc:creator>Laurent BOURHIS</dc:creator>
      <dc:date>2012-05-23T07:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829854#M227294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes, we have disabled that GPO because it causes a 10-20 sec (sometimes longer) delay for the user..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 07:46:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829854#M227294</guid>
      <dc:creator>bvj197222</dc:creator>
      <dc:date>2012-05-23T07:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829855#M227303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Laurent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any news? We have checked out the patch in our environment and it did not work. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 08:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829855#M227303</guid>
      <dc:creator>bvj197222</dc:creator>
      <dc:date>2012-07-05T08:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829856#M227315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are still struggling even after applying the MS patch. After a bit of research, we found that the issue is related to the PC being connected behind an IP phone. I also found a document related to our problem : &lt;A href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/config_guide_c17-605524.html#wp9000357"&gt;http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/config_guide_c17-605524.html#wp9000357&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I do not know your configuration, but I have one question : is your ACS pointing to Active Directory for authentication ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 11:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829856#M227315</guid>
      <dc:creator>Laurent BOURHIS</dc:creator>
      <dc:date>2012-07-05T11:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829857#M227322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes, it is pointing to Active Directory for authentication. It works fine for our branch offices, which have the client and server (for dhcp) on the same vlan. The ACS is on a separate vlan, protected by firewall, at head office. Our problem is clients at the head office, which are on a different VLAN than the server providing DHCP. There is also a firewall between those to VLANs. Our problem occurs randomly every now and then, on various computers. We are considering placing the dhcp-server on the same VLAN as the clients to verify if that is the problem. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 13:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829857#M227322</guid>
      <dc:creator>bvj197222</dc:creator>
      <dc:date>2012-07-10T13:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: 5411 EAP session timeout with ACS in the WAN</title>
      <link>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829858#M227329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There arent any policiing policies that might be dropping this traffic when other traffic is priortized? I dont think moving the dhcp server on the same vlan will affect anything since dhcp traffic isnt forwarded until eap success is handed to the client. The default timer for the eap session if using peap is around 120 seconds. Also are you experiencing this on mac osx clients by any chance or is this affecting windows machines?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 06:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5411-eap-session-timeout-with-acs-in-the-wan/m-p/1829858#M227329</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-11T06:03:53Z</dc:date>
    </item>
  </channel>
</rss>

