<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newbie Pix 501 HTTP authentication timeout in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226819#M6015</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First rule is to never trust your salesman on technical issues ;).  Your reseller is wrong.  You can indeed change the time that a user is re-prompted to enter their credentials.  There are essentially 2 settings you should know about on the PIX with respect to authentication timeouts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) the inactivity timer.  This is just like it sounds.  It will time out an authenticated session going through the PIX after it has reached X amount of time without passing any traffic.  The default timer on the PIX for this setting is 0 which means we do no monitor (by default) inactivity time by the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) the absoltue timer.  This, again, is at sounds.  This timer starts as soon as the user is authenticated and runs continuously.  When the time is reached, the user is forced to re-authenticate when they attempt to start a new connection (such as clicking on a link in a web page).  The default setting for the absolute timer is 5 mins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recommend that you do keep an absolute timer set for security purposes but for ease of access, you may want to tweak these settings.  Something like this would not be an "off the wall" setting:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout uauth 1:00:00 absolute uauth 0:10:00 inactivity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These settings will force the user to re-authenticate every hour (absolute) and/or every 10 mins after the connection becomes idle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And finally, no idea on #2 above.  Does it happen with all users.  Anyone tried Netscrape to see if this is an IE only issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Mar 2004 14:58:32 GMT</pubDate>
    <dc:creator>scoclayton</dc:creator>
    <dc:date>2004-03-02T14:58:32Z</dc:date>
    <item>
      <title>Newbie Pix 501 HTTP authentication timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226818#M6014</link>
      <description>&lt;P&gt;two questions here:&lt;/P&gt;&lt;P&gt;1.  Users who connect to the Internet through the Pix 501 are asked about every three minutes to enter their username and password.  There must be a setting to change this, my reseller says there isn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.  Users who connect to the Internet the first time have their IE session hang.  Clicking stop then refresh or home brings up the page.  Any ideas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any insights you might have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff Charland&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226818#M6014</guid>
      <dc:creator>jeff_charland</dc:creator>
      <dc:date>2020-02-21T18:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie Pix 501 HTTP authentication timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226819#M6015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First rule is to never trust your salesman on technical issues ;).  Your reseller is wrong.  You can indeed change the time that a user is re-prompted to enter their credentials.  There are essentially 2 settings you should know about on the PIX with respect to authentication timeouts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) the inactivity timer.  This is just like it sounds.  It will time out an authenticated session going through the PIX after it has reached X amount of time without passing any traffic.  The default timer on the PIX for this setting is 0 which means we do no monitor (by default) inactivity time by the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) the absoltue timer.  This, again, is at sounds.  This timer starts as soon as the user is authenticated and runs continuously.  When the time is reached, the user is forced to re-authenticate when they attempt to start a new connection (such as clicking on a link in a web page).  The default setting for the absolute timer is 5 mins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recommend that you do keep an absolute timer set for security purposes but for ease of access, you may want to tweak these settings.  Something like this would not be an "off the wall" setting:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout uauth 1:00:00 absolute uauth 0:10:00 inactivity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These settings will force the user to re-authenticate every hour (absolute) and/or every 10 mins after the connection becomes idle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And finally, no idea on #2 above.  Does it happen with all users.  Anyone tried Netscrape to see if this is an IE only issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2004 14:58:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226819#M6015</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2004-03-02T14:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie Pix 501 HTTP authentication timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226820#M6018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I wanted to attach some reading in case you wanted to sanity check me:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/tz.htm#1026093" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/tz.htm#1026093&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2004 14:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226820#M6018</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2004-03-02T14:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie Pix 501 HTTP authentication timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226821#M6021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You were right on the money.  Went into PDM found the settings and made the changes.  happy users = happy me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After making the changes to the timeout settings, the problem with IE hanging seems to have gone away.  Very strange.  Also downloaded Netscape 7.1 and tried it.  No problem at all.  I guess I'll have to wait and see what happens from her on in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff Charland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2004 18:10:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/newbie-pix-501-http-authentication-timeout/m-p/226821#M6021</guid>
      <dc:creator>jeff_charland</dc:creator>
      <dc:date>2004-03-02T18:10:46Z</dc:date>
    </item>
  </channel>
</rss>

