<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reauthenticacion ISE is not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3710997#M543568</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have realized that authenticated users remain indefinitely authenticated. There is no type of timeout that closes the session. We have configured the reauthenticacion for 30 minutos&amp;nbsp;but the users remain permanent.&lt;BR /&gt;Why is not the timeout working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Here you can see the reauthentication timer is configured to 30 minutes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;T&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CETE1.jpg" style="width: 560px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/19049iFEC198A01AF2B4DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="CETE1.jpg" alt="CETE1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CETE2.jpg" style="width: 630px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/19050i77762AB4F8A8B103/image-size/large?v=v2&amp;amp;px=999" role="button" title="CETE2.jpg" alt="CETE2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But we see idle timeout N/A (not 30), and users are always authenticated.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 08:49:45 GMT</pubDate>
    <dc:creator>SupportAC</dc:creator>
    <dc:date>2019-03-11T08:49:45Z</dc:date>
    <item>
      <title>Reauthenticacion ISE is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3710997#M543568</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have realized that authenticated users remain indefinitely authenticated. There is no type of timeout that closes the session. We have configured the reauthenticacion for 30 minutos&amp;nbsp;but the users remain permanent.&lt;BR /&gt;Why is not the timeout working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Here you can see the reauthentication timer is configured to 30 minutes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;T&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CETE1.jpg" style="width: 560px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/19049iFEC198A01AF2B4DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="CETE1.jpg" alt="CETE1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CETE2.jpg" style="width: 630px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/19050i77762AB4F8A8B103/image-size/large?v=v2&amp;amp;px=999" role="button" title="CETE2.jpg" alt="CETE2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But we see idle timeout N/A (not 30), and users are always authenticated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3710997#M543568</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2019-03-11T08:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Reauthenticacion ISE is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3711005#M543569</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Do you have these interface level commands configured?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;authentication periodic&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;authentication timer reauthenticate server&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The last command will instruct the switch the to use the timer sent from the RADIUS server, which you are already doing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 09:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3711005#M543569</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-09-21T09:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Reauthenticacion ISE is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3711861#M543570</link>
      <description>&lt;P&gt;We have the ports like that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&lt;FONT color="#1F497D"&gt;authentication event fail action next-method&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&lt;FONT color="#1F497D"&gt;authentication host-mode multi-host&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&lt;FONT color="#1F497D"&gt;authentication order dot1x mab&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&lt;FONT color="#1F497D"&gt;authentication priority dot1x mab&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&lt;FONT color="#1F497D"&gt;authentication port-control auto&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&lt;FONT color="#1F497D"&gt;&lt;STRONG&gt;authentication periodic&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&lt;FONT color="#1F497D"&gt;&lt;STRONG&gt;authentication timer reauthenticate server&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;but the reauthentication is not working.&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 24 Sep 2018 07:22:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3711861#M543570</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2018-09-24T07:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Reauthenticacion ISE is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3712347#M543571</link>
      <description>Please post your aaa and radius configuration.</description>
      <pubDate>Mon, 24 Sep 2018 18:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3712347#M543571</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-09-24T18:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Reauthenticacion ISE is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3712698#M543572</link>
      <description>&lt;P&gt;This is the AAA config and switch ports:&lt;/P&gt;
&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;
&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;
&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;
&lt;P&gt;aaa authorization console&lt;/P&gt;
&lt;P&gt;aaa authorization exec default group radius local&lt;/P&gt;
&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;
&lt;P&gt;aaa authorization auth-proxy default group radius&lt;/P&gt;
&lt;P&gt;aaa accounting update newinfo&lt;/P&gt;
&lt;P&gt;aaa accounting dot1x default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa accounting exec default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa accounting network default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa accounting connection default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa accounting system default start-stop group radius&lt;/P&gt;
&lt;P&gt;no aaa accounting system guarantee-first&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;
&lt;P&gt;client 10.70.11.13 server-key 7&amp;nbsp;xxxxxxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*****&lt;/P&gt;
&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;
&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;
&lt;P&gt;radius-server attribute 25 access-request include&lt;/P&gt;
&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;/P&gt;
&lt;P&gt;radius-server deadtime 10&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;radius server RADIUS&lt;/P&gt;
&lt;P&gt;address ipv4 10.70.11.13 auth-port 1812 acct-port 1813&lt;/P&gt;
&lt;P&gt;key 7&amp;nbsp;xxxxxxxxxxx&lt;/P&gt;
&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;radius server RADIUS_BCK&lt;/P&gt;
&lt;P&gt;address ipv4 10.70.13.13 auth-port 1812 acct-port 1813&lt;/P&gt;
&lt;P&gt;key 7&amp;nbsp;xxxxxxxxxxxxxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/0/6&lt;/P&gt;
&lt;P&gt;switchport access vlan 60&lt;/P&gt;
&lt;P&gt;switchport mode access&lt;/P&gt;
&lt;P&gt;switchport nonegotiate&lt;/P&gt;
&lt;P&gt;switchport block unicast&lt;/P&gt;
&lt;P&gt;switchport port-security maximum 4&lt;/P&gt;
&lt;P&gt;switchport port-security maximum 2 vlan access&lt;/P&gt;
&lt;P&gt;switchport port-security violation restrict&lt;/P&gt;
&lt;P&gt;switchport port-security aging time 10&lt;/P&gt;
&lt;P&gt;switchport port-security aging type inactivity&lt;/P&gt;
&lt;P&gt;switchport port-security&lt;/P&gt;
&lt;P&gt;authentication control-direction in&lt;/P&gt;
&lt;P&gt;authentication event fail action next-method&lt;/P&gt;
&lt;P&gt;authentication host-mode multi-host&lt;/P&gt;
&lt;P&gt;authentication order dot1x mab&lt;/P&gt;
&lt;P&gt;authentication priority dot1x mab&lt;/P&gt;
&lt;P&gt;authentication port-control auto&lt;/P&gt;
&lt;P&gt;authentication periodic&lt;/P&gt;
&lt;P&gt;authentication timer reauthenticate server&lt;/P&gt;
&lt;P&gt;mab&lt;/P&gt;
&lt;P&gt;no snmp trap link-status&lt;/P&gt;
&lt;P&gt;dot1x pae authenticator&lt;/P&gt;
&lt;P&gt;dot1x timeout tx-period 10&lt;/P&gt;
&lt;P&gt;dot1x max-req 10&lt;/P&gt;
&lt;P&gt;no cdp enable&lt;/P&gt;
&lt;P&gt;spanning-tree bpduguard enable&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 09:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3712698#M543572</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2018-09-25T09:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Reauthenticacion ISE is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3712699#M543573</link>
      <description>&lt;P&gt;This is the AAA config and switch ports:&lt;/P&gt;
&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;
&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;
&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;
&lt;P&gt;aaa authorization console&lt;/P&gt;
&lt;P&gt;aaa authorization exec default group radius local&lt;/P&gt;
&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;
&lt;P&gt;aaa authorization auth-proxy default group radius&lt;/P&gt;
&lt;P&gt;aaa accounting update newinfo&lt;/P&gt;
&lt;P&gt;aaa accounting dot1x default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa accounting exec default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa accounting network default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa accounting connection default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa accounting system default start-stop group radius&lt;/P&gt;
&lt;P&gt;no aaa accounting system guarantee-first&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;
&lt;P&gt;client 10.70.11.13 server-key 7&amp;nbsp;xxxxxxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*****&lt;/P&gt;
&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;
&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;
&lt;P&gt;radius-server attribute 25 access-request include&lt;/P&gt;
&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;/P&gt;
&lt;P&gt;radius-server deadtime 10&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;radius server RADIUS&lt;/P&gt;
&lt;P&gt;address ipv4 10.70.11.13 auth-port 1812 acct-port 1813&lt;/P&gt;
&lt;P&gt;key 7&amp;nbsp;xxxxxxxxxxx&lt;/P&gt;
&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;radius server RADIUS_BCK&lt;/P&gt;
&lt;P&gt;address ipv4 10.70.13.13 auth-port 1812 acct-port 1813&lt;/P&gt;
&lt;P&gt;key 7&amp;nbsp;xxxxxxxxxxxxxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 09:48:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3712699#M543573</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2018-09-25T09:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Reauthenticacion ISE is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3715447#M543574</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Don’t use port security with dot1x it won’t play well together.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Sep 2018 07:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reauthenticacion-ise-is-not-working/m-p/3715447#M543574</guid>
      <dc:creator>Aravind Ravichandran</dc:creator>
      <dc:date>2018-09-29T07:33:39Z</dc:date>
    </item>
  </channel>
</rss>

