<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Switch/ISE Configuration / Timeouts while using 802.1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4474459#M569950</link>
    <description>&lt;P&gt;Good day everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use 802.1x in conjunction with the ISE.&lt;/P&gt;&lt;P&gt;Switch Port -&amp;gt; Avaya Telephone -&amp;gt; Notebook&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we have a few problems with clients losing their connection. (Reauth. 802.1x maybe ?)&lt;BR /&gt;Furthermore there are problems when clients switch quickly from port to port.&lt;/P&gt;&lt;P&gt;We have set a low idle time out so that employees can authenticate themselves "quickly" on another port.&lt;/P&gt;&lt;P&gt;Without the idle time out, the session remains active on the "old" switch-port and authentication on other ports no longer works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Some thoughts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to avoid packet loss during reauthentication, the sessions remain active for a correspondingly long time (&lt;STRONG&gt;Session-Timeout = 36000&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;Maybe "&lt;STRONG&gt;authentication periodic&lt;/STRONG&gt;" is causing problems as we use ISE to set a timeout ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i missed something or you need further information, just let me know.&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our configuration looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch Port:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet121/4/0/44&lt;BR /&gt;description VOIP/PC&lt;BR /&gt;switchport&lt;BR /&gt;switchport trunk allowed vlan 1&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport nonegotiate&lt;BR /&gt;switchport voice vlan 310&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;no cdp enable&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;Tunnel-Private-Group-ID = 1:1&lt;BR /&gt;Tunnel-Type = 1:13&lt;BR /&gt;Tunnel-Medium-Type = 1:6&lt;BR /&gt;Session-Timeout = 36000&lt;BR /&gt;Termination-Action = RADIUS-Request&lt;BR /&gt;Idle-Timeout = 30&lt;/P&gt;</description>
    <pubDate>Mon, 27 Sep 2021 10:18:07 GMT</pubDate>
    <dc:creator>andreasalberti</dc:creator>
    <dc:date>2021-09-27T10:18:07Z</dc:date>
    <item>
      <title>Switch/ISE Configuration / Timeouts while using 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4474459#M569950</link>
      <description>&lt;P&gt;Good day everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use 802.1x in conjunction with the ISE.&lt;/P&gt;&lt;P&gt;Switch Port -&amp;gt; Avaya Telephone -&amp;gt; Notebook&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we have a few problems with clients losing their connection. (Reauth. 802.1x maybe ?)&lt;BR /&gt;Furthermore there are problems when clients switch quickly from port to port.&lt;/P&gt;&lt;P&gt;We have set a low idle time out so that employees can authenticate themselves "quickly" on another port.&lt;/P&gt;&lt;P&gt;Without the idle time out, the session remains active on the "old" switch-port and authentication on other ports no longer works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Some thoughts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to avoid packet loss during reauthentication, the sessions remain active for a correspondingly long time (&lt;STRONG&gt;Session-Timeout = 36000&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;Maybe "&lt;STRONG&gt;authentication periodic&lt;/STRONG&gt;" is causing problems as we use ISE to set a timeout ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i missed something or you need further information, just let me know.&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our configuration looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch Port:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet121/4/0/44&lt;BR /&gt;description VOIP/PC&lt;BR /&gt;switchport&lt;BR /&gt;switchport trunk allowed vlan 1&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport nonegotiate&lt;BR /&gt;switchport voice vlan 310&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;no cdp enable&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;Tunnel-Private-Group-ID = 1:1&lt;BR /&gt;Tunnel-Type = 1:13&lt;BR /&gt;Tunnel-Medium-Type = 1:6&lt;BR /&gt;Session-Timeout = 36000&lt;BR /&gt;Termination-Action = RADIUS-Request&lt;BR /&gt;Idle-Timeout = 30&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 10:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4474459#M569950</guid>
      <dc:creator>andreasalberti</dc:creator>
      <dc:date>2021-09-27T10:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Switch/ISE Configuration / Timeouts while using 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4474576#M569957</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Furthermore there are problems when clients switch quickly from port to port.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Have you attempted to implement (global config) and test the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;#authentication mac-move permit&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In legacy config this allows clients that are authenticated on one port to disconnect, reconnect on another port, and be authenticated automatically.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 12:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4474576#M569957</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-09-27T12:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: Switch/ISE Configuration / Timeouts while using 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4474695#M569959</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1128331"&gt;@andreasalberti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Besides what Mike already suggested also make sure that &lt;STRONG&gt;pass-through with proxy logoff&lt;/STRONG&gt; is enabled on your Avaya phone. You do that by configuring DOT1X=1 in the phone config file (or directly on the phone via the menu). Do not use DOT1X=0 or 2 on the phone as these options do not activate the EAPoL proxy-logoff function.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 14:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4474695#M569959</guid>
      <dc:creator>martin.fischer</dc:creator>
      <dc:date>2021-09-27T14:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Switch/ISE Configuration / Timeouts while using 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4475587#M569993</link>
      <description>&lt;P&gt;Thank you in advance for your answers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pass-through with proxy logoff is already "enabled".&lt;/P&gt;&lt;P&gt;Tomorrow I will implement the "authentication mac-move permit" proposal and check whether this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any suggestions for improvement in the current configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should i remove "authentication-periodic" from the port configuration, since i give a session timeout via Radius (ISE)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 12:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4475587#M569993</guid>
      <dc:creator>andreasalberti</dc:creator>
      <dc:date>2021-09-28T12:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Switch/ISE Configuration / Timeouts while using 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4476392#M570010</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my understanding authentication periodic is just like a master directive, that is optionally configured to use the timers server is sending (for reauth and idle). If you don't configure reauth and idle timers to be applied from what server is sending, then default or set local timers will be used.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Long story short, you said that you're sending the idle timeout from ISE, but on the switchport config I don't see that configured:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication periodic&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication timer reauthenticate server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;authe&lt;/STRONG&gt;&lt;STRONG&gt;ntication timer inactivity server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 07:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4476392#M570010</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2021-09-29T07:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Switch/ISE Configuration / Timeouts while using 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4478862#M570122</link>
      <description>&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;Especially the authentication mac-move helped a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only Problem that still occours&amp;nbsp; is that the mac-adresses behind our telephones stay active even if disconnected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Sun, 03 Oct 2021 17:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-ise-configuration-timeouts-while-using-802-1x/m-p/4478862#M570122</guid>
      <dc:creator>andreasalberti</dc:creator>
      <dc:date>2021-10-03T17:40:04Z</dc:date>
    </item>
  </channel>
</rss>

