<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE reauthentication best practices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704817#M507710</link>
    <description>Hey Paul,&lt;BR /&gt;&lt;BR /&gt;thank you very much for the post. I set the reauthentication at the ISE and it workes! Only one more question. Under Radius-Live Sessions I can see that it is "terminated" after I disconnected the PC. &lt;BR /&gt;(Connection: Switch &amp;lt;- Phone &amp;lt;- PC) &lt;BR /&gt;This was not working without the reauth because the telephone is not telling the ISE that the session to the PC is now disconnected. But in Radius-Live Logs I still see the session as "active". When is ISE killing the session in Live Logs? &lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Philipp&lt;BR /&gt;</description>
    <pubDate>Tue, 11 Sep 2018 13:28:22 GMT</pubDate>
    <dc:creator>pgerstenberger</dc:creator>
    <dc:date>2018-09-11T13:28:22Z</dc:date>
    <item>
      <title>Cisco ISE reauthentication best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704608#M507707</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we want to reauthenticate our Endpoints. Which way is recommended? Set reauthentication at the Cisco ISE Authorization Profile or at the switch port? And which timers are best practice? We use ISE version 2.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and best regards,&lt;/P&gt;
&lt;P&gt;Philipp&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 07:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704608#M507707</guid>
      <dc:creator>pgerstenberger</dc:creator>
      <dc:date>2018-09-11T07:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE reauthentication best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704715#M507708</link>
      <description>&lt;P&gt;Hey Philipp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I assume you're talking about wired NAS?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this document really handy to answer your question&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.pdf&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out pages 19 and 20.&amp;nbsp; The Termination-Action attributes are quite interesting too.&amp;nbsp; I think I might have to start using those myself &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 11:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704715#M507708</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-09-11T11:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE reauthentication best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704781#M507709</link>
      <description>&lt;P&gt;Use ISE to control the reauthentication timer by setting the following on the switchports:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;authentication periodic&lt;BR /&gt; authentication timer reauthenticate server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then set the reauthentication timer in ISE.&amp;nbsp; I set a reauthentication timer of 65,000 seconds on all my wired results.&amp;nbsp; Reauthentications ensures two things:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;I have an accurate picture what is on my network every day.&lt;/LI&gt;
&lt;LI&gt;If I change a policy, i.e. push a new DACL or SGT tag, I know the devices associated with that policy will get the change within a day.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 11 Sep 2018 12:48:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704781#M507709</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-11T12:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE reauthentication best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704817#M507710</link>
      <description>Hey Paul,&lt;BR /&gt;&lt;BR /&gt;thank you very much for the post. I set the reauthentication at the ISE and it workes! Only one more question. Under Radius-Live Sessions I can see that it is "terminated" after I disconnected the PC. &lt;BR /&gt;(Connection: Switch &amp;lt;- Phone &amp;lt;- PC) &lt;BR /&gt;This was not working without the reauth because the telephone is not telling the ISE that the session to the PC is now disconnected. But in Radius-Live Logs I still see the session as "active". When is ISE killing the session in Live Logs? &lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Philipp&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Sep 2018 13:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704817#M507710</guid>
      <dc:creator>pgerstenberger</dc:creator>
      <dc:date>2018-09-11T13:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE reauthentication best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704820#M507711</link>
      <description>What type of phones do you have and are the PC's behind the phones doing 802.1x?  If the PCs are doing 802.1x and the phones are doing EAP Proxy Logoff correctly the switch should be terminating the PC's session and communicating that to ISE.  If the phone doesn't support EAP proxy Logoff you can also set an inactivity timer as well in ISE if there is a concern about that session hanging out there.  I usually don't use the inactivity timer.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Sep 2018 13:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3704820#M507711</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-11T13:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE reauthentication best practices</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3705308#M507712</link>
      <description>&lt;P&gt;Hi Paul,&lt;BR /&gt;thanks for the detailed information. But I think that our phones do not support EAP Proxy Logoff.... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Yes, the PCs behind the phones doing 802.1x. So we have to look for the inactivity timer. &lt;BR /&gt;Again thank you very much for the support!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For those who are interested in setup 802.1x behind VOIP Phone refer to this cisco guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html&amp;nbsp;" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Philipp&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 06:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-best-practices/m-p/3705308#M507712</guid>
      <dc:creator>pgerstenberger</dc:creator>
      <dc:date>2018-09-12T06:04:02Z</dc:date>
    </item>
  </channel>
</rss>

