<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE: 802.1x Timers Best Practices / Re-authentication Time in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/3393177#M98133</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am also facing the same issue , any suggestions pls&lt;/P&gt;</description>
    <pubDate>Sun, 03 Jun 2018 09:43:51 GMT</pubDate>
    <dc:creator>mohan.doss19</dc:creator>
    <dc:date>2018-06-03T09:43:51Z</dc:date>
    <item>
      <title>Cisco ISE: 802.1x Timers Best Practices / Re-authentication Timers [EAP-TLS]</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/2284992#M98106</link>
      <description>&lt;P&gt;Dear Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly, suggest the best recommended values for the timers in 802.1x (EAP-TLS)... Should i keep default all or change or some of them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, what do we need reauthentication timers? Any benefit to use it? Does it prompt to users or became invisible? and What are the best values, in case if we need to use it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mubasher&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Interface Configuration is as below;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/34&lt;/P&gt;&lt;P&gt; switchport access vlan 131&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 195&lt;/P&gt;&lt;P&gt; ip access-group ACL-DEFAULT in&lt;/P&gt;&lt;P&gt; authentication event fail action authorize vlan 131&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 131&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication open&lt;/P&gt;&lt;P&gt; authentication order dot1x mab&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; snmp trap mac-notification change added&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt; storm-control broadcast level 30.00&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/2284992#M98106</guid>
      <dc:creator>Mubasher Sultan - 2x CCIE # 20149 (R&amp;S | Sec)</dc:creator>
      <dc:date>2019-03-11T03:50:46Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE: 802.1x Timers Best Practices / Re-authentication Time</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/2284993#M98112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mubashir, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many timers can be modified as needed in a deployment. Unless you are experiencing a specific problem where adjusting the timer may correct unwanted behavior, it is recommended to leave all timers at their default values except for the 802.1X transmit timer (tx-period).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tx-period timer defaults to a value of 30 seconds. Leaving this value at 30 seconds provides a default wait of 90 seconds (3 x tx-period) before a switchport will begin the next method of authentication, and begin the MAB process for non-authenticating devices.&lt;/P&gt;&lt;P&gt;Based on numerous deployments, the best-practice recommendation is to set the tx-period value to 10 seconds to provide the optimal time for MAB devices. Setting the value below 10 seconds may result in the port moving to MAC authentication bypass too quickly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 12.0pt;"&gt;Configure the tx-period timer. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;C3750X(config-if-range)#dot1x timeout tx-period 10&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Sep 2013 18:31:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/2284993#M98112</guid>
      <dc:creator>Anas Naqvi</dc:creator>
      <dc:date>2013-09-02T18:31:29Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE: 802.1x Timers Best Practices / Re-authentication Time</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/2284994#M98118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already configured it as "&lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;dot1x timeout tx-period 5".&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the situation that e.g., our users put the PC on sleep (or hibernate) on a regular basis... Sometimes, the dot1x gets stuck longer in POSTURE and sometime meets with the default policy, which is not acceptable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, what does re-authentication timer do ? Can it help in this case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mubasher Sultan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 11:01:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/2284994#M98118</guid>
      <dc:creator>Mubasher Sultan - 2x CCIE # 20149 (R&amp;S | Sec)</dc:creator>
      <dc:date>2013-09-04T11:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE: 802.1x Timers Best Practices / Re-authentication Time</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/3393177#M98133</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am also facing the same issue , any suggestions pls&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jun 2018 09:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-timers-best-practices-re-authentication-timers/m-p/3393177#M98133</guid>
      <dc:creator>mohan.doss19</dc:creator>
      <dc:date>2018-06-03T09:43:51Z</dc:date>
    </item>
  </channel>
</rss>

