<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC / ISE Session extension in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136708#M168760</link>
    <description>&lt;P&gt;I wonder if it is possible to extend session on WLC or ISE? On WLC, I know about Session Timeouts (&lt;SPAN&gt;300-86400s for 802.1X(EAP)&lt;/SPAN&gt;), but I need to extend more than that. I need features like Sleeping Clients, but for L2 security.&amp;nbsp; I need my session to remain for more than one day. Is it possible on ISE, maybe?&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Nik&lt;/P&gt;&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;</description>
    <pubDate>Mon, 05 Jul 2021 19:24:18 GMT</pubDate>
    <dc:creator>niknik</dc:creator>
    <dc:date>2021-07-05T19:24:18Z</dc:date>
    <item>
      <title>WLC / ISE Session extension</title>
      <link>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136708#M168760</link>
      <description>&lt;P&gt;I wonder if it is possible to extend session on WLC or ISE? On WLC, I know about Session Timeouts (&lt;SPAN&gt;300-86400s for 802.1X(EAP)&lt;/SPAN&gt;), but I need to extend more than that. I need features like Sleeping Clients, but for L2 security.&amp;nbsp; I need my session to remain for more than one day. Is it possible on ISE, maybe?&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Nik&lt;/P&gt;&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;</description>
      <pubDate>Mon, 05 Jul 2021 19:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136708#M168760</guid>
      <dc:creator>niknik</dc:creator>
      <dc:date>2021-07-05T19:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: WLC / ISE Session extension</title>
      <link>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136717#M168761</link>
      <description>What is the reason you would want to extend this longer?  The reason to have sleeping client really was for webauth with iOS devices and to prevent the webauth page to appear to users.  With 802.1x and psk for example, what would be the purpose?  When the idle timer expires from the device not responding to probes, the controller removes the device from its tables and the device would have to perform a normal authentication to be allowed on the network.  Seems like you have devices that just stop working overnight or something?&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Aug 2020 09:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136717#M168761</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-08-17T09:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: WLC / ISE Session extension</title>
      <link>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136725#M168762</link>
      <description>&lt;P&gt;Hello Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for fast reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Main reason is because client asked me to do that. They want to extend sessions so when user leaves office nobody can join network with his user/pass if they are somehow exposed. It was a bit confusing to me, so I wanted to check with community.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 09:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136725#M168762</guid>
      <dc:creator>niknik</dc:creator>
      <dc:date>2020-08-17T09:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: WLC / ISE Session extension</title>
      <link>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136727#M168763</link>
      <description>Wow... that is typically the opposite.  Security wants this lower so that devices that are compromised gets the cert revoked or device gets removed from the domain and the device no longer can get connected. &lt;BR /&gt;</description>
      <pubDate>Mon, 17 Aug 2020 09:28:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136727#M168763</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-08-17T09:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: WLC / ISE Session extension</title>
      <link>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136971#M168764</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Main reason is because client asked me to do that. They want to extend sessions so when user leaves office nobody can join network with his user/pass if they are somehow exposed.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Just keep in mind that this is not possible and that is what you need to explain to your customer.&amp;nbsp; The simple solution for this is to use certificates (EAP-TLS) or look at computer authentication.&amp;nbsp; The idea that a users AD credentials would get exposed is an issue to wired and wireless and that should be addressed another way.&amp;nbsp; If using ISE and AD username/password, then you would need to define a policy on ISE to look if already authenticated.&amp;nbsp; This would not allow any users to access from another device which many might have more than one machine.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 16:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4136971#M168764</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-08-17T16:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: WLC / ISE Session extension</title>
      <link>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4137013#M168765</link>
      <description>&lt;P&gt;Thank you Scott. Your explanation is really great. I wanted to be sure that WLC is not place where this problem can be solved.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 17:27:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4137013#M168765</guid>
      <dc:creator>niknik</dc:creator>
      <dc:date>2020-08-17T17:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: WLC / ISE Session extension</title>
      <link>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4137067#M168766</link>
      <description>There is no wlc setting to allow that behavior.  &lt;BR /&gt;</description>
      <pubDate>Mon, 17 Aug 2020 19:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-ise-session-extension/m-p/4137067#M168766</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-08-17T19:31:34Z</dc:date>
    </item>
  </channel>
</rss>

