<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi, in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/3185564#M139973</link>
    <description>&lt;P&gt;Question, what do you mean by "In webauth the wlc transfer the authentication request to the authentication server when using LDAP?. Does the same apply for PEAP when using LDAP?&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2017 15:30:18 GMT</pubDate>
    <dc:creator>ajc</dc:creator>
    <dc:date>2017-09-18T15:30:18Z</dc:date>
    <item>
      <title>Excessive Web Authentication Failures -customize counters and timers</title>
      <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2925997#M139966</link>
      <description>&lt;P&gt;Hello everyone,&amp;nbsp;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;we are preparing the demo environment for our customer. configured web authentication with LDAP integration. everything is working normally, but have following question regarding Excessive Web Authentication Failures :&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;BR /&gt;1) &lt;STRONG&gt;can we control number of failed retries?it is currently 3, but wee need change it to 5 or any&amp;nbsp;other&amp;nbsp;number&lt;/STRONG&gt;&lt;BR /&gt;2)&lt;STRONG&gt; can we change duration between failed attempts&lt;/STRONG&gt;? currently it is 1 minute , but need to increase to 5 minutes , if failed login attempts will be 5 , during 5 minutes need exclude this client.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2925997#M139966</guid>
      <dc:creator>Temur Kalandia</dc:creator>
      <dc:date>2021-07-05T12:24:56Z</dc:date>
    </item>
    <item>
      <title>Hi Temur,</title>
      <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2925998#M139967</link>
      <description>&lt;P&gt;Hi Temur,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please clarify what retries you are referring to? Is it the&amp;nbsp;number of times the WLC tries to send an authentication request to the radius server?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;WiFi Trainers (&lt;A href="http://www.wifitrainers.com/" rel="nofollow" onmousedown="dataLayer.push({'event': 'eventTracker', 'eventCat': 'Outbound Links', 'eventAct': 'Click', 'eventLbl': 'www.wifitrainers.com/', 'eventVal': 0});"&gt;www.wifitrainers.com&lt;/A&gt;)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 10pt;"&gt;&lt;EM&gt;Your one stop solution for all your wireless training needs!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 10pt;"&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;******** Please rate if useful *********&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 11:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2925998#M139967</guid>
      <dc:creator>WiFi Trainers</dc:creator>
      <dc:date>2016-07-13T11:49:12Z</dc:date>
    </item>
    <item>
      <title>hi , </title>
      <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2925999#M139968</link>
      <description>&lt;P&gt;hi ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cisco wlc has&amp;nbsp;&lt;STRONG&gt;Client Exclusion Policies, one of that policies is "&lt;/STRONG&gt;Excessive Web Authentication Failures&lt;STRONG&gt;" it offers client&amp;nbsp;exclusion&amp;nbsp;&lt;SPAN&gt;after three consecutive failures. refer to this doc:&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_0111010.pdf" title="Configuring Client Exclusion Policies"&gt;http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_0111010.pdf&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;my tasks are :&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;1) somehow control failure counters, for example i need to exlude clients after 5 consecutive failures, or choose any other number.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;2) control the time between failures, in default configuration if 3 failures occur during one minute wips will exclude client at fourth try, but i need to increase this duration to 5 minutes. in this case if user fails authenticate 5 times , it will be excluded.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 21:49:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2925999#M139968</guid>
      <dc:creator>Temur Kalandia</dc:creator>
      <dc:date>2016-07-13T21:49:52Z</dc:date>
    </item>
    <item>
      <title>Hi Temur,</title>
      <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2926000#M139969</link>
      <description>&lt;P&gt;Hi Temur,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the clarification. There is no config option to change this even on the latest 8.2 code. We can only enable this feature and not change any of the default parameters.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;WiFi Trainers (&lt;A href="http://www.wifitrainers.com/" rel="nofollow" onmousedown="dataLayer.push({'event': 'eventTracker', 'eventCat': 'Outbound Links', 'eventAct': 'Click', 'eventLbl': 'www.wifitrainers.com/', 'eventVal': 0});"&gt;www.wifitrainers.com&lt;/A&gt;)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 10pt;"&gt;&lt;EM&gt;Your one stop solution for all your wireless training needs!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 10pt;"&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;******** Please rate if useful *********&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 05:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2926000#M139969</guid>
      <dc:creator>WiFi Trainers</dc:creator>
      <dc:date>2016-07-14T05:29:57Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2926001#M139970</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can change it on your LDAP server.&lt;/P&gt;
&lt;P&gt;In Web Authentication, WLC only transfer the authentication request to the authentication server , in your case "LDAP".&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 07:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2926001#M139970</guid>
      <dc:creator>hajia</dc:creator>
      <dc:date>2016-07-14T07:08:35Z</dc:date>
    </item>
    <item>
      <title>hello, </title>
      <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2926002#M139971</link>
      <description>&lt;P&gt;hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please tell me the duration time for three consecutive failures? in what time period should hacker try three consecutive failures? 3 tries during one minute or time does not meters, if there will be three consecutive failures during any time , client will be blocked?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 08:04:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2926002#M139971</guid>
      <dc:creator>Temur Kalandia</dc:creator>
      <dc:date>2016-07-14T08:04:29Z</dc:date>
    </item>
    <item>
      <title>hi, </title>
      <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2926003#M139972</link>
      <description>&lt;P&gt;hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;we have already configured this option : user account lockout, but customer needs to add additional security at wireless layer, to avoid offload the LDAP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;one option i think will be use radius server between LDAP and WLC and sent client exclusion attributes from the radius server itself. &amp;nbsp;if you have any guide for this typof config will be great &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 09:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/2926003#M139972</guid>
      <dc:creator>Temur Kalandia</dc:creator>
      <dc:date>2016-07-14T09:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Hi,</title>
      <link>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/3185564#M139973</link>
      <description>&lt;P&gt;Question, what do you mean by "In webauth the wlc transfer the authentication request to the authentication server when using LDAP?. Does the same apply for PEAP when using LDAP?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 15:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/excessive-web-authentication-failures-customize-counters-and/m-p/3185564#M139973</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2017-09-18T15:30:18Z</dc:date>
    </item>
  </channel>
</rss>

