11-20-2019 04:58 AM
team, in ISE, device authenticated through a sponsor, needs to reauthenticate every 20 min. any idea how to change this and make it at least 8h? i already checked the WLC and the timeout value is set to maximum 65535. anything else to modify?
Solved! Go to Solution.
11-20-2019 06:03 PM - edited 11-20-2019 06:04 PM
The WLAN Session Timeout value that you refer to, only applies for unauthenticated sessions - in other words, the timer starts as soon as the client associates to the Open SSID and as long as the session is in WebAuth Requd state - this means the user session stays up for 65535 seconds (waiting for them to log in!).
To fix this you need to enabled AAA Override on the WLAN. Then you can return a Session-Timeout value of 28800 seconds in your ISE Authorization Profile (for a successful Portal Authentication).
Check in the WLC Client Details page - you should see that the Session timer counts down from 28800.
11-20-2019 06:03 PM - edited 11-20-2019 06:04 PM
The WLAN Session Timeout value that you refer to, only applies for unauthenticated sessions - in other words, the timer starts as soon as the client associates to the Open SSID and as long as the session is in WebAuth Requd state - this means the user session stays up for 65535 seconds (waiting for them to log in!).
To fix this you need to enabled AAA Override on the WLAN. Then you can return a Session-Timeout value of 28800 seconds in your ISE Authorization Profile (for a successful Portal Authentication).
Check in the WLC Client Details page - you should see that the Session timer counts down from 28800.
11-22-2019 12:35 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide