<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Web Authentication Behavior and Timeouts in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/web-authentication-behavior-and-timeouts/m-p/4495256#M235059</link>
    <description>&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some doubts about the behavior of a scenario with Web Authentication and Timeouts configured. In this company there is an SSID with Web Authentication and it has the following timers configured:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Session Timeout.................................. 28800 seconds&lt;BR /&gt;User Idle Timeout................................ Disabled&lt;BR /&gt;Sleep Client..................................... disable&lt;BR /&gt;Sleep Client Timeout............................. 720 minutes&lt;BR /&gt;Sleep Client Auto Auth Feature................... Enabled&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;Web Authentication Timeout.................... 300&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;PMF........................................... Disabled&lt;/P&gt;&lt;P&gt;PMF Association Comeback Time................. 1&lt;BR /&gt;PMF SA Query RetryTimeout..................... 200&lt;BR /&gt;Tkip MIC Countermeasure Hold-down Timer....... 60&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;802.11v BSS Transition Disassoc Timer............ 200&lt;BR /&gt;802.11v BSS Transition OpRoam Disassoc Timer..... 40&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;11ax Target Wake Time............................ Enabled&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. Is it normal behavior for a user to disconnect from the SSID and after a few minutes reconnect and be asked for credentials?&lt;/P&gt;&lt;P&gt;2. If the above is expected, however, I have noticed that I can disconnect from that SSID and when I reconnect it has not asked me for credentials, how long do I have to wait for that to happen?&lt;/P&gt;&lt;P&gt;3. I also noticed the session timeout is independent of whether the user is currently using the network or not? that is, I'm working using the Internet but after 8 hours it logs me out of the session and I have to enter my credentials again. I assume I have to increase the session timeout.&lt;/P&gt;&lt;P&gt;4. What are the best practices for configuring wlan timers? Are there other timers, apart from what I mentioned above, in play?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 29 Oct 2021 23:24:09 GMT</pubDate>
    <dc:creator>Andy Ruiz Inami</dc:creator>
    <dc:date>2021-10-29T23:24:09Z</dc:date>
    <item>
      <title>Web Authentication Behavior and Timeouts</title>
      <link>https://community.cisco.com/t5/wireless/web-authentication-behavior-and-timeouts/m-p/4495256#M235059</link>
      <description>&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some doubts about the behavior of a scenario with Web Authentication and Timeouts configured. In this company there is an SSID with Web Authentication and it has the following timers configured:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Session Timeout.................................. 28800 seconds&lt;BR /&gt;User Idle Timeout................................ Disabled&lt;BR /&gt;Sleep Client..................................... disable&lt;BR /&gt;Sleep Client Timeout............................. 720 minutes&lt;BR /&gt;Sleep Client Auto Auth Feature................... Enabled&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;Web Authentication Timeout.................... 300&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;PMF........................................... Disabled&lt;/P&gt;&lt;P&gt;PMF Association Comeback Time................. 1&lt;BR /&gt;PMF SA Query RetryTimeout..................... 200&lt;BR /&gt;Tkip MIC Countermeasure Hold-down Timer....... 60&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;802.11v BSS Transition Disassoc Timer............ 200&lt;BR /&gt;802.11v BSS Transition OpRoam Disassoc Timer..... 40&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;11ax Target Wake Time............................ Enabled&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. Is it normal behavior for a user to disconnect from the SSID and after a few minutes reconnect and be asked for credentials?&lt;/P&gt;&lt;P&gt;2. If the above is expected, however, I have noticed that I can disconnect from that SSID and when I reconnect it has not asked me for credentials, how long do I have to wait for that to happen?&lt;/P&gt;&lt;P&gt;3. I also noticed the session timeout is independent of whether the user is currently using the network or not? that is, I'm working using the Internet but after 8 hours it logs me out of the session and I have to enter my credentials again. I assume I have to increase the session timeout.&lt;/P&gt;&lt;P&gt;4. What are the best practices for configuring wlan timers? Are there other timers, apart from what I mentioned above, in play?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 23:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-authentication-behavior-and-timeouts/m-p/4495256#M235059</guid>
      <dc:creator>Andy Ruiz Inami</dc:creator>
      <dc:date>2021-10-29T23:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Web Authentication Behavior and Timeouts</title>
      <link>https://community.cisco.com/t5/wireless/web-authentication-behavior-and-timeouts/m-p/4495316#M235065</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;1. No.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;2. You have idle timeout and sleeping client disabled. So only until session timeout.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;3 &amp;amp; 4. You can set the session timeout as per your business requirements. There is no industry standard. You also need to understand how these timers work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Session Timeout - This will make sure that the Wireless client is deauthenticated after the set timer even it is actively transmitting and receiving data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Idle Timeout - This is there to make sure that the wireless client is deauthenitcated after client is idle for certain time, where the time is defined in the WLC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Web Authentication Timeout - If the user has not completed the web auth he will be prompted a new login page after the defined timer.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Sleeping client - Once the user complete the web auth how long controller has to remember the client.&amp;nbsp;Sleeping client doesnt work for CWA.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Oct 2021 05:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-authentication-behavior-and-timeouts/m-p/4495316#M235065</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2021-10-30T05:03:59Z</dc:date>
    </item>
  </channel>
</rss>

