<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timeout Value in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409281#M207617</link>
    <description>&lt;P&gt;Lets go over the timers you have mentioned. &amp;nbsp;The arp, is just what it says and not really important to this. &amp;nbsp;You have two main timers for clients, the session and the idle timer. &amp;nbsp;The session timer is a hard forced deauth when a device is in the RUN state. &amp;nbsp;This will force the device to re-authenticate after that timer expires. &amp;nbsp;Now the idle timer is when the device goest to sleep and doesn't respond back to the AP. &amp;nbsp;iPhones and iPads for example do this. &amp;nbsp;The idle timer has to be less than the session timer. &amp;nbsp;The session timer should be long (max 86400) so that you are not forcing a device to re-auth and cause user experience. &amp;nbsp;The idle timer should be long enough to force an idea client to have to re-authenticate. &amp;nbsp;Webauth causes devices to hit the login page in which sleeping client feature is preferred to be configured for this.&lt;/P&gt;
&lt;P&gt;If a device has successfully auth and is in the RUN state and then the user switches to wired or another SSID, the NIC will or should I say might send a disassociation to the ap and thus you would see this in the log also.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jul 2018 19:38:30 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2018-07-02T19:38:30Z</dc:date>
    <item>
      <title>Timeout Value</title>
      <link>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409240#M207616</link>
      <description>&lt;P&gt;Hello.&amp;nbsp; On our WLC we have the following&lt;/P&gt;
&lt;P&gt;User Idle Timeout: 600 seconds&lt;/P&gt;
&lt;P&gt;ARP Timeout: 300 seconds&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WLAN in Use&lt;/P&gt;
&lt;P&gt;Enable Session Timeout: 900 seconds&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I successfully authenticated to the wlan I noted 09:33:13 which correlates to the same in the wlc logs.&amp;nbsp; When I plugged my laptop back into the LAN I noted 09:52:30.&amp;nbsp; However, in the wlc logs the first indication of any de-authentication shows at 09:55:30.&amp;nbsp; See below log message.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2018-07-02 09:55:30&amp;nbsp;Local6.Warning WLC_Controller: *Dot1x_NW_MsgTask_7: Jul 02 10:55:30.172: %DOT1X-4-MAX_EAP_RETRIES: [PA]1x_auth_pae.c:5717 Max EAP identity request retries (3) exceeded for client e4:b3:18:5f:b5:c7&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2018-07-02 09:55:30&amp;nbsp;Local6.Error&amp;nbsp;WLC_Controller: *Dot1x_NW_MsgTask_7: Jul 02 10:55:30.173: %CCAUDIT-3-CC_MSG: [PA]apf_80211.c:3527 WLC - User ID: e4:b3:18:5f:b5:c7 - Wireless user deauthenticated&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;2018-07-02 09:55:50&amp;nbsp;Local6.Error WLC_Controller: *apfReceiveTask: Jul 02 10:55:50.172: %CCAUDIT-3-CC_MSG: [PA]apf_80211.c:3527 WLC - User ID: e4:b3:18:5f:b5:c7 - Wireless user deauthenticated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, this is approximately a 3 minute gap.&amp;nbsp; I was wondering what timeout value if any would I find configured on the controller to justify this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409240#M207616</guid>
      <dc:creator>CompCJtoo</dc:creator>
      <dc:date>2021-07-05T15:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Timeout Value</title>
      <link>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409281#M207617</link>
      <description>&lt;P&gt;Lets go over the timers you have mentioned. &amp;nbsp;The arp, is just what it says and not really important to this. &amp;nbsp;You have two main timers for clients, the session and the idle timer. &amp;nbsp;The session timer is a hard forced deauth when a device is in the RUN state. &amp;nbsp;This will force the device to re-authenticate after that timer expires. &amp;nbsp;Now the idle timer is when the device goest to sleep and doesn't respond back to the AP. &amp;nbsp;iPhones and iPads for example do this. &amp;nbsp;The idle timer has to be less than the session timer. &amp;nbsp;The session timer should be long (max 86400) so that you are not forcing a device to re-auth and cause user experience. &amp;nbsp;The idle timer should be long enough to force an idea client to have to re-authenticate. &amp;nbsp;Webauth causes devices to hit the login page in which sleeping client feature is preferred to be configured for this.&lt;/P&gt;
&lt;P&gt;If a device has successfully auth and is in the RUN state and then the user switches to wired or another SSID, the NIC will or should I say might send a disassociation to the ap and thus you would see this in the log also.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 19:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409281#M207617</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2018-07-02T19:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Timeout Value</title>
      <link>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409282#M207618</link>
      <description>&lt;P&gt;My timers that I use:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Session: disabled (86400)&lt;/P&gt;
&lt;P&gt;Idle Time: 300&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With WebAuth:&lt;/P&gt;
&lt;P&gt;Sleeping Client: 24 hours (depends on how often you want users to login)&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 19:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409282#M207618</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2018-07-02T19:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Timeout Value</title>
      <link>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409288#M207619</link>
      <description>&lt;P&gt;Scott,&lt;/P&gt;
&lt;P&gt;Thanks for the explanation of the timers.&amp;nbsp; Maybe I missed something, because I was simply searching the wlc logs by my wlan nic mac address and redirecting the output to a text file.&amp;nbsp; I was more focused on why the 3 minute gap between me going back wired and then something being logged by the wlc?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 20:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409288#M207619</guid>
      <dc:creator>CompCJtoo</dc:creator>
      <dc:date>2018-07-02T20:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Timeout Value</title>
      <link>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409317#M207620</link>
      <description>&lt;P&gt;Well run a degbgoing to see a change until one of the timers expire. &amp;nbsp;Run different test like switching to a different SSID, powering down the laptop while connected to the SSID and connecting your laptop to wired. &amp;nbsp;The latter depends on if the bios shuts the wireless down after the wired port is detected. &amp;nbsp;Again.... look at the state of the device.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 21:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/timeout-value/m-p/3409317#M207620</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2018-07-02T21:14:55Z</dc:date>
    </item>
  </channel>
</rss>

