<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic global timeout with CWA on Cisco ISE? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551169#M529749</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Is there a global timeout with CWA on Cisco ISE?&amp;nbsp; Where is this setting? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Segoe UI',sans-serif; color: #1f497d;"&gt;Hi. Here are some screen shots from when Gay was trying to use GuestP wifi today. Does this look like DHCP lease time out? What about the message about reaching the maximum number of devices?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Segoe UI',sans-serif; color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Segoe UI',sans-serif; color: #1f497d;"&gt;&lt;IMG alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/107137_pastedImage_8.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/107136_pastedImage_7.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;This happened when I was actively using the network and ipad and it happened in just a few minutes, 10 minutes maybe but definitely fewer than 30.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;When I refreshed the page, it said I had access again?&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;When I refreshed again, I got an internal error and it seems to have logged me out forcing me to login again. When I logged in again, I got the Maximum Devices reached error.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Then it bumped me off the network and put me back on HC_Guest.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 May 2017 16:56:18 GMT</pubDate>
    <dc:creator>dmadland@cisco.com</dc:creator>
    <dc:date>2017-05-10T16:56:18Z</dc:date>
    <item>
      <title>global timeout with CWA on Cisco ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551169#M529749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Is there a global timeout with CWA on Cisco ISE?&amp;nbsp; Where is this setting? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Segoe UI',sans-serif; color: #1f497d;"&gt;Hi. Here are some screen shots from when Gay was trying to use GuestP wifi today. Does this look like DHCP lease time out? What about the message about reaching the maximum number of devices?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Segoe UI',sans-serif; color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Segoe UI',sans-serif; color: #1f497d;"&gt;&lt;IMG alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/107137_pastedImage_8.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/107136_pastedImage_7.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;This happened when I was actively using the network and ipad and it happened in just a few minutes, 10 minutes maybe but definitely fewer than 30.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;When I refreshed the page, it said I had access again?&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;When I refreshed again, I got an internal error and it seems to have logged me out forcing me to login again. When I logged in again, I got the Maximum Devices reached error.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Then it bumped me off the network and put me back on HC_Guest.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 16:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551169#M529749</guid>
      <dc:creator>dmadland@cisco.com</dc:creator>
      <dc:date>2017-05-10T16:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: global timeout with CWA on Cisco ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551170#M529750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ive talked with a few SME and there is no option that we know of. Might be good to discuss issues with Tac as well as looks like troubleshooting issues mixed in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 17:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551170#M529750</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-05-10T17:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: global timeout with CWA on Cisco ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551171#M529751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The RADIUS session timeout should control portal timeout.&amp;nbsp; This is configurable in the Authorization Profile where you return the URL Redirect for CWA.&amp;nbsp; May need to verify that this session timeout is enforced and not overwritten by WLC when session in WebAuth Required state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Max Devices reached seams to be erroneous message based on My Devices Portal error, i.e. wrong error code returned for session timeout. Recommend open TAC case if able to recreate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 21:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551171#M529751</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-10T21:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: global timeout with CWA on Cisco ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551172#M529752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if you are hitting the 10 minute timeout state of being in a CWA condition on the WLC.&amp;nbsp; From my experience and what I have been told, the WLCs only allow you to reside in a redirect condition (Webauth REQ, Posture REQ, etc.) for 10 minutes.&amp;nbsp; If you don't move out of that condition you will be disconnected.&amp;nbsp; Your client will reconnect, but that would be a new session number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran into this issue doing posture monitor mode at a customer.&amp;nbsp; We redirect only port 80 to the gateway to roll out posturing in monitor mode without affecting end-users.&amp;nbsp; This works great on wired and VPN, but on wireless if the users don't have the posture module they get kicked off every 10 minutes.&amp;nbsp; For most users this isn't a big deal as their client reconnects under the covers, but for network admins that are SSH'd into devices it is a big deal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if you are running into this. My understanding is this 10 minute value is hard-coded on the WLC and can't be changed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 14:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551172#M529752</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-11T14:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: global timeout with CWA on Cisco ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551173#M529753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any documents that mentions this 10 minute value that is hard-coded? and possibility of a workaround? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Drew S &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2017 17:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551173#M529753</guid>
      <dc:creator>Drew Speltz</dc:creator>
      <dc:date>2017-06-16T17:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: global timeout with CWA on Cisco ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551174#M529754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Craig - i just opened a TAC case on it now.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Drew S &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2017 17:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551174#M529754</guid>
      <dc:creator>Drew Speltz</dc:creator>
      <dc:date>2017-06-16T17:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: global timeout with CWA on Cisco ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551175#M529755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was engaged on another request with some similar questions, so wanted to update this thread as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first screenshot shown above is due to the hard-coded browser timeout when you are first redirected to page.&amp;nbsp; This is independent from the RADIUS session timeout.&amp;nbsp;&amp;nbsp; It's purpose is to trigger a fresh redirect after the login page has been left idle.&amp;nbsp; Consider the following scenario...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;You attempt to access Google.com and are redirected to a PSN on a specific port and *session_id* for web login.&amp;nbsp; (The session ID tells ISE which RADIUS session to link for the web request.)&lt;/LI&gt;&lt;LI&gt;You walk away or work on another task without completing login and now the RADIUS session has timed out.&amp;nbsp; In the process, MAB auth will occur again and redirect session to a new portal URL which will have a different session ID and possibly a different PSN based on load balancing.&lt;/LI&gt;&lt;LI&gt;After returning to page (which appears as it did in step 1), you attempt to login but it fails with an invalid / missing session context.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue issue is that the browser is still pointing to the original redirect URL with the old session ID.&amp;nbsp; The intent of this 5-minute browser timeout is to force user to click button which will send a web request to the retry URL (default 1.1.1.1).&amp;nbsp; This will allow redirection to occur again to the updated redirect URL.&amp;nbsp; (Note that since the stale URL pointed to a PSN, it was being allowed without redirection!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the original error above (screenshot #2), the endpoint should not have registered yet so would be good to get update on what TAC determined to be issue with Max Devices being triggered.&amp;nbsp; Apparently ISE was tracking the first attempt even though never completed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jan 2018 16:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/global-timeout-with-cwa-on-cisco-ise/m-p/3551175#M529755</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-01-09T16:52:01Z</dc:date>
    </item>
  </channel>
</rss>

