<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Reauthentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication/m-p/3458112#M519112</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Recommended reauth / session timeout value is 2 hours.&amp;nbsp; To Jason's point, you typically do not need to reauth very often.&amp;nbsp; Idle timeouts are typically used to detect cases where user no longer present, especially if clients not directly connecting to switchport.&amp;nbsp; If directly connected, then typically no reason to reauth until disconnect and reconnect, and this happens automatically.&amp;nbsp; You may want to compromise and set reauth to 1/day with RADIUS Accounting updates being sent every 2-3 days to keep session status updated in ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Dec 2017 16:58:13 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-12-14T16:58:13Z</dc:date>
    <item>
      <title>ISE Reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication/m-p/3458110#M519107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is there a way to randomise the time for the reauthentication for ISE clients? When we select "Reauthentication" in the authorization profile it asks me an exact time in seconds to do the reauthentication. If possible, I would like to enter a range of time with min and max values, and ISE can select a random time from that range for each client.&lt;/P&gt;&lt;P&gt;My aim is to distribute the load on ISE to a wide range of time. Currently, in the morning all of the clients are logging in approximately in half an hour then after the reauthentication time same thing goes on again in half an hour. It would be great to widen this time to an hour or a couple of hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Dec 2017 15:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication/m-p/3458110#M519107</guid>
      <dc:creator>Ufuk Gudulluoglu</dc:creator>
      <dc:date>2017-12-14T15:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication/m-p/3458111#M519110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #000000; font-family: -webkit-standard;"&gt;There is no feature and don't really see the need.&amp;nbsp; &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard;"&gt;From our SME &lt;A href="https://community.cisco.com//u1/38995"&gt;hslai&lt;/A&gt; Human nature is a great random factor. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard;"&gt;In case it’s robotic logins, setting this re-auth timers randomly in ISE authorization profiles can only help reauth.&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard;"&gt;Anyhow, reauth every 1/2 hour is too often. I believe our recommendation is every 3 or 4 days.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Dec 2017 16:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication/m-p/3458111#M519110</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-14T16:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication/m-p/3458112#M519112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Recommended reauth / session timeout value is 2 hours.&amp;nbsp; To Jason's point, you typically do not need to reauth very often.&amp;nbsp; Idle timeouts are typically used to detect cases where user no longer present, especially if clients not directly connecting to switchport.&amp;nbsp; If directly connected, then typically no reason to reauth until disconnect and reconnect, and this happens automatically.&amp;nbsp; You may want to compromise and set reauth to 1/day with RADIUS Accounting updates being sent every 2-3 days to keep session status updated in ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Dec 2017 16:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication/m-p/3458112#M519112</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-12-14T16:58:13Z</dc:date>
    </item>
  </channel>
</rss>

