<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE: Reauthentication timer in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3752008#M96979</link>
    <description>&lt;P&gt;Additional information. I am authenticating these devices (printers) via MAB. Will the RADIUS reauthentication timer function while using MAB?&lt;/P&gt;</description>
    <pubDate>Fri, 23 Nov 2018 19:31:43 GMT</pubDate>
    <dc:creator>RSundstrom</dc:creator>
    <dc:date>2018-11-23T19:31:43Z</dc:date>
    <item>
      <title>ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/2315594#M96971</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am doing authentication of endpoint devices. The default reauthentication timer on switchports are 3600 seconds. Why is reauthentication needed? Isn't it enough that a device is authenticated when it connects only?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the reauthentication timer is set to server (&lt;EM&gt;authentication timer reauthenticate server&lt;/EM&gt;), I guess that the server is ISE. Where in ISE do I configure the timer?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/2315594#M96971</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2019-03-11T04:00:58Z</dc:date>
    </item>
    <item>
      <title>ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/2315595#M96972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Philip, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll provide you one of many use-cases of reauthentication, imagine that you authenticate with certificates.&lt;/P&gt;&lt;P&gt;If the certificate became invalid (expired/device stolen) you cannot kick a user off the network if it authnenticated prior to you noticing. &lt;/P&gt;&lt;P&gt;So in essence if the device was stolen but you have not noticed it before it was plugged in, without reauthentication, it potentially could be allowed on the network for quite some time. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said we recommend not using re-authentication for performance reasons or setting the timer to at least 2 hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ISE you can send auth timers from authorization policy&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/4/8/162848-Screen%20Shot%202013-10-18%20at%208.28.11%20PM.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 08:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/2315595#M96972</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2013-10-22T08:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3704632#M96973</link>
      <description>&lt;P&gt;Which method is recommended? Doing reauthentication with switchport configuration or doing reauthentication with ise &lt;SPAN&gt;authorization policy?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 08:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3704632#M96973</guid>
      <dc:creator>pgerstenberger</dc:creator>
      <dc:date>2018-09-11T08:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3704938#M96974</link>
      <description>Recommend looking at the best practice guide.&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-wired-access-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-documents/cisco-ise-wired-access-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Setting it on ISE allows you to globally control and change it across all your network&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Sep 2018 15:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3704938#M96974</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-11T15:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3711398#M96975</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323015"&gt;@Marcin Latosiewicz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Philip,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll provide you one of many use-cases of reauthentication, imagine that you authenticate with certificates.&lt;/P&gt;
&lt;P&gt;If the certificate became invalid (expired/device stolen) you cannot kick a user off the network if it authnenticated prior to you noticing.&lt;/P&gt;
&lt;P&gt;So in essence if the device was stolen but you have not noticed it before it was plugged in, without reauthentication, it potentially could be allowed on the network for quite some time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That being said we recommend not using re-authentication for performance reasons or setting the timer to at least 2 hours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On ISE you can send auth timers from authorization policy&lt;/P&gt;
&lt;P&gt;&lt;IMG class="jive-image" src="http://supportforums.cisco.com/sites/default/files/legacy/8/4/8/162848-Screen%20Shot%202013-10-18%20at%208.28.11%20PM.png" border="0" /&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323015"&gt;@Marcin Latosiewicz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Philip,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll provide you one of many use-cases of reauthentication, imagine that you authenticate with certificates.&lt;/P&gt;
&lt;P&gt;If the certificate became invalid (expired/device stolen) you cannot kick a user off the network if it authnenticated prior to you noticing.&lt;/P&gt;
&lt;P&gt;So in essence if the device was stolen but you have not noticed it before it was plugged in, without reauthentication, it potentially could be allowed on the network for quite some time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That being said we recommend not using re-authentication for performance reasons or setting the timer to at least 2 hours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On ISE you can send auth timers from authorization policy&lt;/P&gt;
&lt;P&gt;&lt;IMG class="jive-image" src="http://supportforums.cisco.com/sites/default/files/legacy/8/4/8/162848-Screen%20Shot%202013-10-18%20at%208.28.11%20PM.png" border="0" /&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Is really necessary to specify the Radius Idle Timeout value in addition to the reauth timer? Will the Radius Idle Timeout suffice?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 21:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3711398#M96975</guid>
      <dc:creator>toyip</dc:creator>
      <dc:date>2018-09-21T21:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3747655#M96976</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I will add the same question to this string. Does anyone know if the "Common Tasks" &amp;gt; "Reauthentication Timer" set at 65,534 will also require the "Advanced Attributes Settings" &amp;gt; Radius: Idle-Timeout to also be set at 65,534 seconds for the timed&amp;nbsp;reauth to function?&lt;/P&gt;
&lt;P&gt;I have my Reauthentication Timer set at 65,534 and I am having no timed reauthentications take place.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 20:54:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3747655#M96976</guid>
      <dc:creator>RSundstrom</dc:creator>
      <dc:date>2018-11-15T20:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3748360#M96977</link>
      <description>Doesn’t sound right to me. Let me research this&lt;BR /&gt;</description>
      <pubDate>Fri, 16 Nov 2018 19:54:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3748360#M96977</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-11-16T19:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3748382#M96978</link>
      <description>&lt;P&gt;As &lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790" target="_blank"&gt;Jason Kunst&lt;/A&gt;&amp;nbsp;pointed out, that is not expected behavior if the value input without the comma; i.e. 65534.&lt;/P&gt;
&lt;P&gt;Please check the RADIUS authentication detailed report and see whether ISE sending down the specified timer value. If ISE does not, it seems an issue in your ISE. If ISE does, then there might be an issue in your NAD to use the value; please verify the configuration, see whether the remaining session timeout value decrementing as expected in "show auth session &amp;lt;&amp;gt; detail", and enable RADIUS debug on the NAD.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 20:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3748382#M96978</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-16T20:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3752008#M96979</link>
      <description>&lt;P&gt;Additional information. I am authenticating these devices (printers) via MAB. Will the RADIUS reauthentication timer function while using MAB?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 19:31:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/3752008#M96979</guid>
      <dc:creator>RSundstrom</dc:creator>
      <dc:date>2018-11-23T19:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Reauthentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/4274671#M564837</link>
      <description>&lt;P&gt;Does this command cause disconnection of endpoints configured for posture. Is it recommended to use with NAM supplicant?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 15:37:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/4274671#M564837</guid>
      <dc:creator>aravikumar</dc:creator>
      <dc:date>2021-01-18T15:37:31Z</dc:date>
    </item>
  </channel>
</rss>

