<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Anton. Have you checked if in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563023#M75642</link>
    <description>&lt;P&gt;Hi Anton. Have you checked if printing a page resets the inactivity timer? Perhaps a ping packet is not sufficient enough to reset the timer.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Dec 2014 06:51:44 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2014-12-11T06:51:44Z</dc:date>
    <item>
      <title>802.1x printers idle timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563018#M75636</link>
      <description>&lt;P&gt;ello, I am looking for solution or best practice how to deal with printers and MFUs in 802.1x environment.&lt;/P&gt;&lt;P&gt;I use MAB for them and put them in a separate vlan for security reasons, vlan number is provided from radius.&lt;/P&gt;&lt;P&gt;I also enabled the ip device tracking and inactivity timer to track connected printers and deauthentificate them in case the port will be up but the printer will be deattached (someone put a hub/small switch between a 802.1x port and a printer)&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this stage I cant understand the behavior of idle timeout because it is allways decreasing and then reauthentiication begins, even if I constantly ping the printer. Does it have to trigger only if there is no traffic from the device?&lt;/P&gt;&lt;P&gt;sw3560-test#sh authentication sessions int fa0/1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface: &amp;nbsp;FastEthernet0/1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC Address: &amp;nbsp;f4ce.4648.6626&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP Address: &amp;nbsp;192.168.251.2&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name: &amp;nbsp;f4ce46486626&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status: &amp;nbsp;Authz Success&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Domain: &amp;nbsp;DATA&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Security Policy: &amp;nbsp;Should Secure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Security Status: &amp;nbsp;Unsecure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Oper host mode: &amp;nbsp;multi-domain&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Oper control dir: &amp;nbsp;both&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Authorized By: &amp;nbsp;Authentication Server&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vlan Policy: &amp;nbsp;25&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Session timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Idle timeout: &amp;nbsp;60s (local), Remaining: 26s&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Common Session ID: &amp;nbsp;C0A8A5920000001100564C94&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Acct Session ID: &amp;nbsp;0x00000015&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Handle: &amp;nbsp;0x46000011&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Method &amp;nbsp; State&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;Failed over&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;mab &amp;nbsp; &amp;nbsp; &amp;nbsp;Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the port config:&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;BR /&gt;&amp;nbsp;description MFU test&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 7&lt;BR /&gt;&amp;nbsp;ip device tracking maximum 10&lt;BR /&gt;&amp;nbsp;authentication event fail action authorize vlan 4094&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 4094&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 4094&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;authentication timer inactivity 60&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;dot1x max-reauth-req 5&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563018#M75636</guid>
      <dc:creator>Anton Klementyev</dc:creator>
      <dc:date>2019-03-11T05:15:24Z</dc:date>
    </item>
    <item>
      <title>Hi,for printers i don´t use</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563019#M75637</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;for printers i don´t use inactivity timer and no reauthentication.&lt;/P&gt;&lt;P&gt;Inactivity timers are good in an enviromet were a PC ist connected on IP-Phone port and authenticated via MAB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 09:57:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563019#M75637</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2014-12-10T09:57:27Z</dc:date>
    </item>
    <item>
      <title>I think it will be more</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563020#M75638</link>
      <description>&lt;P&gt;I think it will be more secure to enable use them. I case if someone will put a switch between the printer and the port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway I would like to know hos the inactivity timer works and why it is always decreasing.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 11:47:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563020#M75638</guid>
      <dc:creator>Anton Klementyev</dc:creator>
      <dc:date>2014-12-10T11:47:08Z</dc:date>
    </item>
    <item>
      <title>You can set the idle-timer</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563021#M75639</link>
      <description>&lt;P&gt;You can set the idle-timer for your VLAN via RADIUS under: (see attachment)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Policy Elements/Authorization and Permissions/Network Access/Authorization Profiles&lt;/STRONG&gt;&lt;BR /&gt;On the Switch you need to configure: &lt;STRONG&gt;authentication timer inactivity server&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;But it makes no sence in a Printer-Vlan. If there is no trafiic in within your configured time, the session will be cleared. Then you need to restart the printer to start the authentication process.&lt;/P&gt;&lt;P&gt;You´ll need good shoes.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 12:33:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563021#M75639</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2014-12-10T12:33:58Z</dc:date>
    </item>
    <item>
      <title>Thanks, I already set set the</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563022#M75641</link>
      <description>&lt;P&gt;Thanks, I already set set the timer via the Network Policy Server, I dont understand only why it is decreasing even if I have the traffic.&lt;/P&gt;&lt;P&gt;I use ip device tracking feature to keep devices connected.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2014 06:47:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563022#M75641</guid>
      <dc:creator>Anton Klementyev</dc:creator>
      <dc:date>2014-12-11T06:47:56Z</dc:date>
    </item>
    <item>
      <title>Hi Anton. Have you checked if</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563023#M75642</link>
      <description>&lt;P&gt;Hi Anton. Have you checked if printing a page resets the inactivity timer? Perhaps a ping packet is not sufficient enough to reset the timer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2014 06:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563023#M75642</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-11T06:51:44Z</dc:date>
    </item>
    <item>
      <title>Here is also a link to the</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563024#M75643</link>
      <description>&lt;P&gt;Here is also a link to the MAB deployment guide that has some more info about the inactivity and other related timers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/config_guide_c17-663759.html"&gt;http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/config_guide_c17-663759.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2014 06:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563024#M75643</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-11T06:55:19Z</dc:date>
    </item>
    <item>
      <title>no, I did ping -t to the</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563025#M75644</link>
      <description>&lt;P&gt;no, I did ping -t to the printer address, same thing.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2014 11:06:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563025#M75644</guid>
      <dc:creator>Anton Klementyev</dc:creator>
      <dc:date>2014-12-11T11:06:45Z</dc:date>
    </item>
    <item>
      <title>thnx, I saw this document,</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563026#M75645</link>
      <description>&lt;P&gt;thnx, I&amp;nbsp;saw this&amp;nbsp;document, there is not much about inactivity timer.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2014 11:10:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563026#M75645</guid>
      <dc:creator>Anton Klementyev</dc:creator>
      <dc:date>2014-12-11T11:10:53Z</dc:date>
    </item>
    <item>
      <title>Sorry, does anyone know the</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563027#M75646</link>
      <description>&lt;P&gt;Sorry, does anyone know the answer?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2014 07:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563027#M75646</guid>
      <dc:creator>Anton Klementyev</dc:creator>
      <dc:date>2014-12-15T07:57:53Z</dc:date>
    </item>
    <item>
      <title>Hi Anton. I haven't had the</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563028#M75647</link>
      <description>&lt;P&gt;Hi Anton. I haven't had the chance to test this but my gut feeling is telling me that "ping/icmp" alone does not count as "printer traffic" on the wire, thus, not resetting the counter. I would recommend that:&lt;/P&gt;&lt;P&gt;1. You do some different tests and see if the counter is reset...such as:&lt;/P&gt;&lt;P&gt;- Print a page&lt;/P&gt;&lt;P&gt;- Use a TCP based ping&lt;/P&gt;&lt;P&gt;2. You can also contact Cisco TAC and obtain more information about the inactivity counter. For instance, what type of traffic actually resets the counter&lt;/P&gt;&lt;P&gt;3. It is also possible that the "dumb" hub/switch that sits between the dot1x port and the printer is not passing the relative information, thus preventing the inactivity timer from resetting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2014 11:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/2563028#M75647</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-15T11:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry, does anyone know the</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/3391903#M75648</link>
      <description>&lt;P&gt;I see this is a question from a long time ago, but it still seems relevant today as I was debugging a similar situation.&lt;BR /&gt;If i do a "sh authentication sessions interface X"&lt;BR /&gt;I would see the "Remaining" counter on "Idle timeout" decrease even if there is traffic.&lt;/P&gt;
&lt;P&gt;It seems it does count correctly internal though, because when the timer hits zero it starts again with the actually remaining inactive time left. (also seen in the debug)&lt;/P&gt;
&lt;P&gt;So f.e. if i have defined on the interface&lt;/P&gt;
&lt;P&gt;authentication timer inactivity 120&lt;/P&gt;
&lt;P&gt;and suppose you have traffic the first 90seconds.&lt;/P&gt;
&lt;P&gt;Then you would see the timer go down from 120 until it reaches 0 (you won't see it reset during the 90 seconds of traffic as you would expect) and then it restart with remaining counter 90 (as you have been 30 seconds inactive by now, and it's deducted from the 120 you would normally start with)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know if I explain it well enough, but basically, you only see the real inactive time remaining at the times the timer reaches 0 and is then reset to the real inactive time remaining.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 12:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-printers-idle-timeout/m-p/3391903#M75648</guid>
      <dc:creator>Tom Vanhout</dc:creator>
      <dc:date>2018-05-31T12:55:23Z</dc:date>
    </item>
  </channel>
</rss>

