<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cisco authentication timer restart in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4631099#M575451</link>
    <description>&lt;P&gt;Do your fiber converters support Link Fault Pass Through (LFP)? This function can shutdown the converter fiber link if the copper link goes down (I'm assuming the converter fiber link connects to your switch).&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jun 2022 21:28:10 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2022-06-13T21:28:10Z</dc:date>
    <item>
      <title>cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4630557#M575418</link>
      <description>&lt;P&gt;Hello, we have a problem with a fiber converter. If the device is changed behind the converter, the link on the switch port remains at the top. This results in a security breach. The port goes into error disable status because it sees a new MAC for the same AuthSessionID. Behavior per desgin. Can you restart 1 with the Commando authentication timer ... create a new SessionID? the command authentication timer reauthenticate server .... would be with the same AuthID at the ISE Server or get an new o802.1x, AAA, Identity Services Engine (ISE)nce?dot1x, ISE , Port Sec&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 07:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4630557#M575418</guid>
      <dc:creator>Thomas Kohb</dc:creator>
      <dc:date>2022-06-13T07:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4630699#M575432</link>
      <description>&lt;P&gt;Try multi-auth is port connect to multi host (or host is change in port),&lt;BR /&gt;this make SW detect new host and auth it with AAA.&lt;BR /&gt;&lt;BR /&gt;please try in one port if success apply it to all other port.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 11:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4630699#M575432</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-13T11:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4631099#M575451</link>
      <description>&lt;P&gt;Do your fiber converters support Link Fault Pass Through (LFP)? This function can shutdown the converter fiber link if the copper link goes down (I'm assuming the converter fiber link connects to your switch).&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 21:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4631099#M575451</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-06-13T21:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4631258#M575460</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes ... i will try it today &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt; ...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 05:44:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4631258#M575460</guid>
      <dc:creator>Thomas Kohb</dc:creator>
      <dc:date>2022-06-14T05:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4631261#M575462</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes the converter support&amp;nbsp;&lt;SPAN&gt;LFP ...but with this setting ... the first sean mac is the mac of the Converter -.- auth fail ^^&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 05:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4631261#M575462</guid>
      <dc:creator>Thomas Kohb</dc:creator>
      <dc:date>2022-06-14T05:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4633493#M575559</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1366124"&gt;@Thomas Kohb&lt;/a&gt;&amp;nbsp; - that's an unfortunate situation, that the media converter presents its own MAC address. Is there no transparent mode (passthrough mode) so that the media converter operates at Layer 1 only?&lt;/P&gt;
&lt;P&gt;Anyway - as MHM correctly pointed out, if your switch port must support more than one MAC address, then you will be forced to use a host mode like multi-auth, or multi-host - either of these will allow more than one MAC address - they differ slightly:&lt;/P&gt;
&lt;P&gt;multi-host - only the first MAC is subject to AAA authentication, and then the port allows the others to piggy back&lt;/P&gt;
&lt;P&gt;multi-auth - allows one voice MAC, and multiple DATA domain MACs - each DATA domain MAC must be AAA authenticated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;single-host and multi-domain only support one MAC address in the DATA domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 21:32:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4633493#M575559</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-06-16T21:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4633860#M575582</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1366124"&gt;@Thomas Kohb&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;beyond what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;said ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;When you asked about:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st&amp;nbsp;&lt;/STRONG&gt;"&lt;EM&gt; ...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;Can you &lt;U&gt;restart&lt;/U&gt; 1 with the command &lt;U&gt;authentication timer&lt;/U&gt; ... create a new &lt;STRONG&gt;SessionID&lt;/STRONG&gt;? ...&lt;/EM&gt; ", no, the &lt;STRONG&gt;authentication timer restart&lt;/STRONG&gt; &lt;U&gt;attempts to authenticate&lt;/U&gt; an &lt;STRONG&gt;Unauthorized Port&lt;/STRONG&gt;&amp;nbsp;(no &lt;STRONG&gt;SessionID&lt;/STRONG&gt; at this point).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd&lt;/STRONG&gt; " &lt;EM&gt;...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;the command &lt;U&gt;authentication timer reauthenticate server&lt;/U&gt; .... would be with the same AuthID at the ISE Server or get an new ...&lt;/EM&gt; ",&amp;nbsp;&lt;/SPAN&gt;the &lt;STRONG&gt;authentication timer reauthenticate server&lt;/STRONG&gt; uses the &lt;U&gt;same&lt;/U&gt; &lt;STRONG&gt;Session ID&lt;/STRONG&gt; (it &lt;U&gt;reauthenticate&lt;/U&gt; an &lt;STRONG&gt;Authorized Port&lt;/STRONG&gt;).&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 15:39:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4633860#M575582</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-06-17T15:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4634534#M575605</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;- can you please explain more about the difference between AuthID and SessionID?&amp;nbsp; What is the reason/purpose of either one of these and what is the relationship etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the explanation of these two might be very useful. Then there is also the Accounting ID - or is that just an alias for one of the above?&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2022 20:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4634534#M575605</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-06-19T20:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4634675#M575607</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we replaced the Fibre Converter .. all fine...thx for time &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 06:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4634675#M575607</guid>
      <dc:creator>Thomas Kohb</dc:creator>
      <dc:date>2022-06-20T06:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: cisco authentication timer restart</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4635104#M575623</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;we have the:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. &lt;STRONG&gt;Accounting Session ID&lt;/STRONG&gt; (&lt;STRONG&gt;Acct Session ID&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;U&gt;&lt;STRONG&gt;RADIUS Attribute 44&lt;/STRONG&gt;&lt;/U&gt; is a unique &lt;STRONG&gt;Accounting Identifier&lt;/STRONG&gt; that makes it &lt;U&gt;easy to match&lt;/U&gt; &lt;STRONG&gt;Start&lt;/STRONG&gt; and &lt;STRONG&gt;Stop&lt;/STRONG&gt; records in a &lt;STRONG&gt;log file&lt;/STRONG&gt;. The &lt;STRONG&gt;Start&lt;/STRONG&gt; and &lt;STRONG&gt;Stop&lt;/STRONG&gt; records for a given session &lt;U&gt;MUST&lt;/U&gt; have &lt;U&gt;the same&lt;/U&gt; &lt;STRONG&gt;Acct-Session-ID&lt;/STRONG&gt;. &lt;STRONG&gt;RADIUS Attribute 44&lt;/STRONG&gt; is &lt;U&gt;automatically enabled&lt;/U&gt; when &lt;STRONG&gt;AAA Accounting&lt;/STRONG&gt; is configured. &lt;STRONG&gt;Acct Session ID&lt;/STRONG&gt; was sent &lt;U&gt;ONLY&lt;/U&gt; as part of the &lt;STRONG&gt;Accounting Request&lt;/STRONG&gt; and an &lt;STRONG&gt;Accounting Request&lt;/STRONG&gt; packet &lt;U&gt;MUST&lt;/U&gt; have an &lt;STRONG&gt;Acct Session ID&lt;/STRONG&gt;. &lt;STRONG&gt;Acct Session ID&lt;/STRONG&gt; numbers restart at &lt;STRONG&gt;1&lt;/STRONG&gt; each time the &lt;STRONG&gt;Router&lt;/STRONG&gt; is &lt;U&gt;power-cycled&lt;/U&gt; or &lt;U&gt;the software is reloaded&lt;/U&gt;. The &lt;STRONG&gt;Acct Session ID&lt;/STRONG&gt;&amp;nbsp;can take on &lt;U&gt;values from&lt;/U&gt; &lt;STRONG&gt;00000000&lt;/STRONG&gt; to &lt;STRONG&gt;FFFFFFFF&lt;/STRONG&gt;. &lt;STRONG&gt;Acct Session ID&lt;/STRONG&gt; is an attribute supported for the &lt;STRONG&gt;RADIUS CoA&lt;/STRONG&gt; feature (&lt;STRONG&gt;CoA Requests&lt;/STRONG&gt;).&lt;BR /&gt;Ex.: (debug)&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;...&lt;BR /&gt;00:03:13: RADIUS: &lt;U&gt;&lt;STRONG&gt;Acct-Session-Id&lt;/STRONG&gt; [&lt;STRONG&gt;44&lt;/STRONG&gt;]&lt;/U&gt; 10 "&lt;STRONG&gt;&lt;U&gt;00000002&lt;/U&gt;&lt;/STRONG&gt;"&lt;BR /&gt;...&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;. &lt;STRONG&gt;Audit Session ID&lt;/STRONG&gt; (referred to as a &lt;STRONG&gt;Common Session ID&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Audit Session ID&lt;/STRONG&gt; is a &lt;U&gt;&lt;STRONG&gt;Cisco VSA&lt;/STRONG&gt;&lt;/U&gt; (&lt;EM&gt;Vendor-Specific Attribute&lt;/EM&gt;). &lt;STRONG&gt;Authentication Manager&lt;/STRONG&gt; uses a &lt;STRONG&gt;Single Session ID&lt;/STRONG&gt; (referred to as a &lt;STRONG&gt;Common Session ID&lt;/STRONG&gt; or &lt;STRONG&gt;Audit Session ID&lt;/STRONG&gt;) for a &lt;STRONG&gt;Client&lt;/STRONG&gt; no matter which authentication method is used. This &lt;STRONG&gt;ID&lt;/STRONG&gt; is used for &lt;U&gt;ALL reporting purposes&lt;/U&gt;, such as the &lt;STRONG&gt;show commands&lt;/STRONG&gt; and &lt;STRONG&gt;MIBs&lt;/STRONG&gt;. The &lt;STRONG&gt;Common Session ID&lt;/STRONG&gt; includes &lt;U&gt;&lt;EM&gt;&amp;lt;NAS IP Addr&amp;gt;&amp;lt;Session Count&amp;gt;&amp;lt;Session Start Time Stamp&amp;gt;&lt;/EM&gt;&lt;/U&gt;, for ex.: &lt;U&gt;AC14FE01 00000FB5 2A8CF418&lt;/U&gt;.&lt;BR /&gt;&lt;STRONG&gt;Audit Session ID&lt;/STRONG&gt; is an attribute supported for the &lt;STRONG&gt;RADIUS CoA&lt;/STRONG&gt; feature (&lt;STRONG&gt;CoA Requests&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Ex.:&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;...&lt;BR /&gt; cisco-av-pair=&lt;U&gt;audit-session-id&lt;/U&gt;=0A3E946C00000073559C0123&lt;BR /&gt;...&lt;/PRE&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;PRE&gt;# show authentication sessions&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface MAC Address    Method Domain Status        &lt;U&gt;Session ID&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Fa4/0/4   0000.0000.0001 mab    DATA   Authz Success 160000050000000B288508E5&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example for both:&lt;/P&gt;
&lt;PRE&gt;#show authentication sessions interface FastEthernet0/10&lt;BR /&gt;...&lt;BR /&gt;Common Session ID: 0A70081A0000012D2A8CD1BF&lt;BR /&gt;Acct Session ID: 0x00000671&lt;BR /&gt;...&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 16:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-authentication-timer-restart/m-p/4635104#M575623</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-06-20T16:21:26Z</dc:date>
    </item>
  </channel>
</rss>

