<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Session-timeout on ISE 2.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193459#M553582</link>
    <description>&lt;P&gt;&lt;SPAN&gt;AuthZ profile re-authenticate is the same as&amp;nbsp;"Enable Session Timeout"&amp;nbsp;on WLC. Just make sure you also have "Allow AAA Override" enabled on that WLAN for this to work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are several reasons why clients could get disconnected. Do you also have "Client user idle timeout" enabled on the WLAN?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2017 08:47:06 GMT</pubDate>
    <dc:creator>agrissimanis</dc:creator>
    <dc:date>2017-10-04T08:47:06Z</dc:date>
    <item>
      <title>Session-timeout on ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193411#M553581</link>
      <description>&lt;P&gt;I'm looking for session-timeout attribute on ISE 2.2. When I checked on attributes&amp;gt;Radius, I can't find that attribute.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to enable it because there are users which are disconnected randomly on wireless connection though we already set WLAN&amp;gt;Advanced&amp;gt;Enable Session timeout as 28800.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I found was on AuthZ profile Re-authenticate check box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the Radius attribute session-timeout is the same with AuthZ profile re-authenticate? If not, how can I add this session-timeout attribute on ISE?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just want to make sure that authenticated users will have session of 28800 and will not be disconnected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193411#M553581</guid>
      <dc:creator>Mady</dc:creator>
      <dc:date>2020-02-21T18:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: Session-timeout on ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193459#M553582</link>
      <description>&lt;P&gt;&lt;SPAN&gt;AuthZ profile re-authenticate is the same as&amp;nbsp;"Enable Session Timeout"&amp;nbsp;on WLC. Just make sure you also have "Allow AAA Override" enabled on that WLAN for this to work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are several reasons why clients could get disconnected. Do you also have "Client user idle timeout" enabled on the WLAN?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 08:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193459#M553582</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-10-04T08:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Session-timeout on ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193474#M553583</link>
      <description>&lt;P&gt;Hi&amp;nbsp;agrissimanis thanks for your reply! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client idle timeout is not enabled on WLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about the session timeout on Radius attribute. I've checked on Dictionary &amp;gt; IETF &amp;gt; Radius and found that there is session timeout attrubute #27. But when I will use it on the policy, it does not appear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any config on ISE that I need to enable before using the session timeout attribute?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;A href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/282818" target="_self"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 04 Oct 2017 09:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193474#M553583</guid>
      <dc:creator>Mady</dc:creator>
      <dc:date>2017-10-04T09:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: Session-timeout on ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193501#M553584</link>
      <description>&lt;P&gt;You shouldn't need to do anything else to use session timeout attribute. On the Authorization profile that is assigned to the affected users, select "Reauthentication" checkbox and enter the value in seconds. You should also be able to specify it manually from the "Advanced attributes settings" section of the authorization profile, select "Radius:Session-Timeout". The result will be the same.&lt;/P&gt;
&lt;P&gt;Then in the "Attributes details" section you will see currently configured attributes&amp;nbsp;that will be sent to the WLC.&lt;/P&gt;
&lt;P&gt;In&amp;nbsp;the WLC you can then go to the Monitor -&amp;gt; Clients section, select the client, and look at the "&lt;SPAN&gt;Re-authentication timeout&lt;/SPAN&gt;" value assigned to the client.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 09:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193501#M553584</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-10-04T09:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Session-timeout on ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193971#M553585</link>
      <description>&lt;P&gt;On the subject of setting a custom Session-Timeout in the Authorization profile, has anyone else noticed that in the Results sent to the NAS,&amp;nbsp;ISE has a cosmetic bug and things the Session-Timeout is in milliseconds?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a cosmetic bug because the&amp;nbsp;radius attribute is correctly interpreted by the NAS in seconds, therefore the operation is not impacted.&amp;nbsp; I have raised this as a TAC case ages ago - no bug has been filed as yet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="milliseconds.png" style="width: 682px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/1599iCB45024C72E554D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="milliseconds.png" alt="milliseconds.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 23:32:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-timeout-on-ise-2-2/m-p/3193971#M553585</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-10-04T23:32:36Z</dc:date>
    </item>
  </channel>
</rss>

