<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Inactivity Timeout in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603518#M524977</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 8.0pt; font-family: 'Arial',sans-serif; color: black;"&gt;Is &lt;STRONG&gt;authentication timer inactivity server &lt;/STRONG&gt;command used to download the below attribute ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8.0pt; font-family: 'Arial',sans-serif; color: black;"&gt;I tested this but wanted to confirm as well. &lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/107114_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;We have a scenario where non-dot1x endpoints connected behind IP Phones do not get their their sessions cleared when endpoints are disconnected. I am looking at the above option to clear the session after a certain time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 May 2017 14:46:51 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2017-05-10T14:46:51Z</dc:date>
    <item>
      <title>Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603518#M524977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 8.0pt; font-family: 'Arial',sans-serif; color: black;"&gt;Is &lt;STRONG&gt;authentication timer inactivity server &lt;/STRONG&gt;command used to download the below attribute ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8.0pt; font-family: 'Arial',sans-serif; color: black;"&gt;I tested this but wanted to confirm as well. &lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/107114_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;We have a scenario where non-dot1x endpoints connected behind IP Phones do not get their their sessions cleared when endpoints are disconnected. I am looking at the above option to clear the session after a certain time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 14:46:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603518#M524977</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-05-10T14:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603519#M524978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&amp;nbsp; This is a valid option.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 18:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603519#M524978</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-10T18:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603520#M524979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Utkarsh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That option should work, but you should be investigating why the phones are doing EAP proxy logoff correctly.&amp;nbsp; Most likely the phone has a setting to do proxy logoff, but is not currently configured to do it.&amp;nbsp; I have run into this many times with Avaya phones and worked with the customer to get the option enabled on the phones.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 14:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603520#M524979</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-11T14:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603521#M524980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP Proxy Logoff is working fine as expected for endpoints connected via dot1x behind the IP Phone.&lt;/P&gt;&lt;P&gt;The issue is with headless devices like printers if connected behind IP Phone or a machine authenticating via MAB.&lt;/P&gt;&lt;P&gt;In this case the session on switch is a MAB session.&lt;/P&gt;&lt;P&gt;I think the IP Phone will not send a Proxy EAPoL for a MAB session. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 14:20:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603521#M524980</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-05-11T14:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603522#M524981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh yes.  I missed the non-8021x part.  I am so used to running into this issue with EAP proxy logoff.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven’t tested phone settings to see if you can make it release a MAB session on the switch.  I have used inactivity timers in the past.  Make sure you have “authentication timer inactivity server” set on the switch interfaces to allow ISE to set this value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 14:44:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603522#M524981</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-11T14:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603523#M524982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The preferred option is 2nd Port disconnect which will proactively notify switch when connected device disconnects: &lt;A href="http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html#pgfId-389517" title="http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html#pgfId-389517"&gt;IP Telephony for 802.1X Design Guide - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 15:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603523#M524982</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-11T15:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603524#M524983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its a non-Cisco IP Phone using LLDP.&lt;/P&gt;&lt;P&gt;Do you think LLDP might have any port-disconnect mechanism and Cisco switch would understand it ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 15:49:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603524#M524983</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-05-11T15:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603525#M524984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CDP Enhancement for 2nd Port Disconnect is a specific Cisco Phone feature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 16:11:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603525#M524984</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-11T16:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Inactivity Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603526#M524985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;EAP Proxy Logoff is specific to 802.1X and again, is a Cisco IP Phone feature.&amp;nbsp; 2nd Port Disconnect works with any auth options from connected device to Cisco Phone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 18:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/inactivity-timeout/m-p/3603526#M524985</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-11T18:25:00Z</dc:date>
    </item>
  </channel>
</rss>

