<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the default 802.1X session timeout on a Cisco Switch? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3841605#M24842</link>
    <description>&lt;P&gt;I had a look and &lt;FONT face="courier new,courier"&gt;show authentication session&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;show access-session&lt;/FONT&gt; are the same command. There is no mention of the session timer in that output - this is weird - I would expect that one should be able to view this per session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;This is the closest I can find to an authentication timer display command&lt;/FONT&gt;&lt;/P&gt;
&lt;PRE&gt;#&lt;STRONG&gt;show authentication brief&lt;/STRONG&gt;
Interface  MAC Address     AuthC           AuthZ                   Fg  Uptime
-----------------------------------------------------------------------------
Tw2/0/23   b0aa.771c.1ced  m:CF d:NR      AZ: SA-                 X    1030749s
Tw2/0/35   0004.7d35.f248  m:OK           AZ: SA-V:               X    1030753s&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was tracking one MAB authentication in ISE and I can see that the Accounting Session ID has not changed in many days.&amp;nbsp; This means that no re-authentication has taken place.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also have this enabled globally&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;aaa accounting update newinfo periodic 2880&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know what the DHCP lease time is on that VLAN (I will have to ask the customer) but ISE is processing an Interim-Accounting request every 10 minutes - which leads me to believe that the DHCP renewal is triggering an Interim-Update (due to the "newinfo" argument in the aaa command above).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The port profile Interface contains this config&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt; authentication periodic&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;authentication timer reauthenticate server&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Since&lt;STRONG&gt; I don't return a Session-Timeout to the switch (Server Timeout=0), and since I told the switch to use&amp;nbsp;&lt;FONT face="courier new,courier"&gt;authentication timer reauthenticate server,&lt;/FONT&gt;&amp;nbsp;&lt;/STRONG&gt;the switch has effectively deactivated the Session-Timeout - which is actually the behaviour I was hoping for - I think the command below validates that:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;show dot1x interface twoGigabitEthernet 2/0/35 switch  active R0&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Dot1x Info for TwoGigabitEthernet2/0/35&lt;BR /&gt;--------------------------------------------&lt;BR /&gt;PAE = AUTHENTICATOR&lt;BR /&gt;QuietPeriod = 60&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;ServerTimeout = 0&lt;/FONT&gt;&lt;BR /&gt;SuppTimeout = 30&lt;BR /&gt;ReAuthMax = 3&lt;BR /&gt;MaxReq = 2&lt;BR /&gt;TxPeriod = 7&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2019 11:03:56 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2019-04-19T11:03:56Z</dc:date>
    <item>
      <title>What is the default 802.1X session timeout on a Cisco Switch?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3840705#M24829</link>
      <description>&lt;P&gt;Hello 802.1X (switch) experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I deal mostly with WLC deployments and Session-Timeout is configured globally on the WLAN profile and applies to all authenticated sessions (unless over-ridden by AAA Override).&amp;nbsp; &amp;nbsp;Is there a similar concept on Cisco switches when doing 802.1X?&amp;nbsp; Or does the session stay up as long as the physical layer stays up (e.g. a printer remains plugged into the switch port and the switch keeps the session alive) ?&amp;nbsp; I am not sending Session-Timeout or Idle-Timeout to any wired 802.1X authentications.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am seeing a lot of session events in the ISE Live Logs.&amp;nbsp; Wondering whether those are re-authentications&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should one only generally return a AAA Session-Timeout to devices that might be connected to Wired Phones (e.g. non-Cisco IP Phones, since they don't alert the Cisco Switch when the laptop/PC disconnects from the phone - so session will stay up forever?)&amp;nbsp; With a Cisco phone I believe this is proxy-signalled via CDP to the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3840705#M24829</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-02-21T19:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: What is the default 802.1X session timeout on a Cisco Switch?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3840855#M24833</link>
      <description>Default is 1hours&lt;BR /&gt;&lt;BR /&gt;Rack1(config-if)#authentication timer ?&lt;BR /&gt;  inactivity      Interval in seconds after which if there is no activity&lt;BR /&gt;from the client then it will be unauthorized (default OFF)&lt;BR /&gt;*  reauthenticate  Time in seconds after which an automatic&lt;BR /&gt;re-authentication should be initiated (default 1 hour)*&lt;BR /&gt;  restart         Interval in seconds after which an attempt should be made&lt;BR /&gt;to authenticate an unauthorized port (default 60 sec)&lt;BR /&gt;  unauthorized    Time in seconds after which an unauthorized session will&lt;BR /&gt;get deleted&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Apr 2019 06:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3840855#M24833</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-04-18T06:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: What is the default 802.1X session timeout on a Cisco Switch?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3841410#M24837</link>
      <description>&lt;P&gt;Thanks! Is there a show command that shows the remaining session time? I didn’t see this in the show access-session command&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 23:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3841410#M24837</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-04-18T23:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: What is the default 802.1X session timeout on a Cisco Switch?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3841411#M24840</link>
      <description>I think you will see it in sh auth sess interface x/x detail&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Apr 2019 23:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3841411#M24840</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-04-18T23:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: What is the default 802.1X session timeout on a Cisco Switch?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3841605#M24842</link>
      <description>&lt;P&gt;I had a look and &lt;FONT face="courier new,courier"&gt;show authentication session&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;show access-session&lt;/FONT&gt; are the same command. There is no mention of the session timer in that output - this is weird - I would expect that one should be able to view this per session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;This is the closest I can find to an authentication timer display command&lt;/FONT&gt;&lt;/P&gt;
&lt;PRE&gt;#&lt;STRONG&gt;show authentication brief&lt;/STRONG&gt;
Interface  MAC Address     AuthC           AuthZ                   Fg  Uptime
-----------------------------------------------------------------------------
Tw2/0/23   b0aa.771c.1ced  m:CF d:NR      AZ: SA-                 X    1030749s
Tw2/0/35   0004.7d35.f248  m:OK           AZ: SA-V:               X    1030753s&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was tracking one MAB authentication in ISE and I can see that the Accounting Session ID has not changed in many days.&amp;nbsp; This means that no re-authentication has taken place.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also have this enabled globally&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;aaa accounting update newinfo periodic 2880&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know what the DHCP lease time is on that VLAN (I will have to ask the customer) but ISE is processing an Interim-Accounting request every 10 minutes - which leads me to believe that the DHCP renewal is triggering an Interim-Update (due to the "newinfo" argument in the aaa command above).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The port profile Interface contains this config&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt; authentication periodic&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;authentication timer reauthenticate server&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Since&lt;STRONG&gt; I don't return a Session-Timeout to the switch (Server Timeout=0), and since I told the switch to use&amp;nbsp;&lt;FONT face="courier new,courier"&gt;authentication timer reauthenticate server,&lt;/FONT&gt;&amp;nbsp;&lt;/STRONG&gt;the switch has effectively deactivated the Session-Timeout - which is actually the behaviour I was hoping for - I think the command below validates that:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;show dot1x interface twoGigabitEthernet 2/0/35 switch  active R0&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Dot1x Info for TwoGigabitEthernet2/0/35&lt;BR /&gt;--------------------------------------------&lt;BR /&gt;PAE = AUTHENTICATOR&lt;BR /&gt;QuietPeriod = 60&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;ServerTimeout = 0&lt;/FONT&gt;&lt;BR /&gt;SuppTimeout = 30&lt;BR /&gt;ReAuthMax = 3&lt;BR /&gt;MaxReq = 2&lt;BR /&gt;TxPeriod = 7&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 11:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-default-802-1x-session-timeout-on-a-cisco-switch/m-p/3841605#M24842</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-04-19T11:03:56Z</dc:date>
    </item>
  </channel>
</rss>

