<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC Session timeout and Dot1x timeout in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413270#M230107</link>
    <description>&lt;P&gt;Well you should define it in one place and typically that is on the controller since session timer is mandatory.&amp;nbsp; You don't want different values in different locations as that will not line up.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 19:10:47 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2021-06-04T19:10:47Z</dc:date>
    <item>
      <title>WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4412602#M230044</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm experiencing a problem that from time to time I have a disconnection from the wifi and it seems that everytime that it happens its perform the whole 802.1x authentication.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;From debugging a client I`ve found these two timeouts:&lt;/P&gt;&lt;PRE&gt;Jun 01 11:06:41.646 *Dot1x_NW_MsgTask_5 Client will be required to Reauthenticate in 1800
seconds
Jun 01 11:06:41.646 *Dot1x_NW_MsgTask_5 Client will be required to Reauthenticate in 14400
seconds&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;The first is the session timeout from WLC and the second from the re-authorization that ISE push.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, my questions are:&lt;BR /&gt;&amp;nbsp;1 - I tried to extend the session timeout in the WLC from 1800s to 28800(8hrs) and it seems that the day after the users were not able to connect, &amp;nbsp;I had to revert back the sessions timeout to 1800s and they were able to connect again.&amp;nbsp;Is there any way to check the sessions hang in the wlc ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 - Is this re-authentication from 802.1x is messing with the wifi connections ? On the ISE side I enabled the option to resume PEAP connections.(&lt;/P&gt;&lt;P&gt;Enable PEAP Session Resume&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to hear your thoughts on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 20:23:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4412602#M230044</guid>
      <dc:creator>Guilherme Gianotto Bratfisch</dc:creator>
      <dc:date>2021-07-05T20:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4412836#M230050</link>
      <description>&lt;P&gt;Without seeing how things are setup, I typically set the session timer to max (86400). When the session expires, that forces the client to perform a full authentication. This is by default, so if you don’t want devices to authenticate often, you adjust this timer higher. Session timer must be greater than idle timer. If clients fail to connect or having issues, it’s hard to believe that it’s increasing the session timer. Make sure that ISE is not defined to send a session timer and also take a look at the logs and possible open a tac case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 01:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4412836#M230050</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2021-06-04T01:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413104#M230095</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the comment, I`m not sure but everytime I tweak the timers in the WLC some clients have a hard time to connect, like not getting ip addresses&amp;nbsp;even though I can see the authentication being successful on the ISE side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I forgot to mention, our wifi is integrated in the sd-access fabric.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I'll have a TAC case open to help me figure it out where the problem is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 13:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413104#M230095</guid>
      <dc:creator>Guilherme Gianotto Bratfisch</dc:creator>
      <dc:date>2021-06-04T13:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413137#M230099</link>
      <description>&lt;P&gt;I was testing the timers for re-authentication in ISE on the Authorization profile we push to the client different from the values in the image.&lt;/P&gt;&lt;P&gt;And it seems that the iphone clients were unable to connect after I removed it or set ip very high (28800s).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a debug of the failling client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why the client is failling only when I change the re-authentication timers in ISE ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 14:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413137#M230099</guid>
      <dc:creator>Guilherme Gianotto Bratfisch</dc:creator>
      <dc:date>2021-06-04T14:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413145#M230100</link>
      <description>&lt;P&gt;No idea.... I run 802.1x at home for testing and have all sort of iPhones and iPads with no issues.&amp;nbsp; I don't change the defaults on ISE, the timers I change is on the controllers.&amp;nbsp; I have no idea where the screen shot is from in ISE also.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 15:13:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413145#M230100</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2021-06-04T15:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413146#M230101</link>
      <description>&lt;P&gt;I also don't have that checked in ISE under the authorization profile.&amp;nbsp; Use the one on the WLAN.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 15:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413146#M230101</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2021-06-04T15:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413153#M230102</link>
      <description>&lt;P&gt;If I remove the option unde the authorization profile my iphone clients cant reconnect to the wlan after being disconnected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it might be a mismatch somewhere...I`m trying to go over the debugs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the support!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 15:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413153#M230102</guid>
      <dc:creator>Guilherme Gianotto Bratfisch</dc:creator>
      <dc:date>2021-06-04T15:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413223#M230104</link>
      <description>&lt;P&gt;I've created an Authorization profile from scratch and it seems to work.&lt;/P&gt;&lt;P&gt;-I removed the re-authentication option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that the client, ise or the wlc dont like when I change a authorization profile already in place but I still dont know why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 17:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413223#M230104</guid>
      <dc:creator>Guilherme Gianotto Bratfisch</dc:creator>
      <dc:date>2021-06-04T17:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Session timeout and Dot1x timeout</title>
      <link>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413270#M230107</link>
      <description>&lt;P&gt;Well you should define it in one place and typically that is on the controller since session timer is mandatory.&amp;nbsp; You don't want different values in different locations as that will not line up.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 19:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-session-timeout-and-dot1x-timeout/m-p/4413270#M230107</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2021-06-04T19:10:47Z</dc:date>
    </item>
  </channel>
</rss>

