09-11-2018 12:53 AM
Hello Community,
we want to reauthenticate our Endpoints. Which way is recommended? Set reauthentication at the Cisco ISE Authorization Profile or at the switch port? And which timers are best practice? We use ISE version 2.1.
Thanks and best regards,
Philipp
Solved! Go to Solution.
09-11-2018 04:02 AM
Hey Philipp
I assume you're talking about wired NAS?
I found this document really handy to answer your question
Check out pages 19 and 20. The Termination-Action attributes are quite interesting too. I think I might have to start using those myself ;-)
09-11-2018 05:48 AM
Use ISE to control the reauthentication timer by setting the following on the switchports:
authentication periodic
authentication timer reauthenticate server
Then set the reauthentication timer in ISE. I set a reauthentication timer of 65,000 seconds on all my wired results. Reauthentications ensures two things:
09-11-2018 04:02 AM
Hey Philipp
I assume you're talking about wired NAS?
I found this document really handy to answer your question
Check out pages 19 and 20. The Termination-Action attributes are quite interesting too. I think I might have to start using those myself ;-)
09-11-2018 05:48 AM
Use ISE to control the reauthentication timer by setting the following on the switchports:
authentication periodic
authentication timer reauthenticate server
Then set the reauthentication timer in ISE. I set a reauthentication timer of 65,000 seconds on all my wired results. Reauthentications ensures two things:
09-11-2018 06:28 AM
09-11-2018 06:31 AM
09-11-2018 11:01 PM - edited 09-11-2018 11:04 PM
Hi Paul,
thanks for the detailed information. But I think that our phones do not support EAP Proxy Logoff.... :( Yes, the PCs behind the phones doing 802.1x. So we have to look for the inactivity timer.
Again thank you very much for the support!
For those who are interested in setup 802.1x behind VOIP Phone refer to this cisco guide:
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html
Cheers,
Philipp
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide