cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2355
Views
5
Helpful
16
Replies

Cisco controller 3504 - Session time out

aram.fars1
Level 1
Level 1

Dear colleagues,

 

I have purchased a Cisco Controller 3504 with two APs, I have configured and installed the controller with APs, our clients faced an issue, that they have to re-authentication every day because the session is expired, also when I reboot the controller the clients should re-authentication too.

what should we do so that the clients not to re-authentication?

I really read a lot of articles and test it everything from my side but unfortunately, I could not find a permanent solution.

 

I appreciate any help.

 

Thank you,

Best regards

16 Replies 16

marce1000
VIP
VIP

- Look for the session timeout paragraphs in the doc below :

 https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_01001101.pdf



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Dear marce,

 

Thank you, I followed this article and done on the controller but I could not find the solution. Moreover, when I reboot the controller then the clients should re-authentication.

What is the Authentication mechanism of the WLAN ?

 

Refer the below two links regarding the timeout configuration on WLC and Windows laptop.

 

Cisco Session Timeouts

 

Turning off the Power Saver Settings on WiFi Adapters

Regards,
Sathiyanarayanan Ravindran

Please rate the post and accept as solution, if my response satisfied your question:)

Dear Sathiyanarayanan,

I am using web authentication for the users, the problem is that the session is expired for the clients after one day or two days or whenever I reboot the controller. I want to configure the controller to not re-authentication the clients every day.

 

Best regards.

If the HA SSO is enabled on the controller, When you are rebooting the primary WLC. The clients will not re-authenticate, As Both the Controller will maintain the Client Sessions.

 

If you don't have the HA SSO and running a single WLC, The client has to authenticate again after the WLC reboot.

 

 

 

 

Regards,
Sathiyanarayanan Ravindran

Please rate the post and accept as solution, if my response satisfied your question:)

We have only one WLC, so whenever I reboot the controller then the clients should re-authentication? Isn't there a way to make the controller to not re-authentication after the reboot?

Thank you.

 

 - The question then becomes , why should you reboot your controller ?. The action also contradicts  with your initial query where you stated you wanted your clients to have a longer session timeout.

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

sometimes the controller shuts down due to the power cut, although we are using UPS. when the controller starts to work then the clients should re-authentication. this is not a big problem, because may this happens one time per month.

the biggest problem is the expiring the session timeout for the clients. 

 

 

 1) controller should not reboot neither to external power issues (resolve them) or internal failure. If the latter is suspected try a more recent software release, or at last option have the controller replaced if the problem persists after consulting your support organisation

 2) The document referred to in my initial reply explains very clearly how to increase the session timeout for a particular WLAN

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Dear Marce,

Thank you for your clarifications, I try to not reboot the device. Regarding your document, I really tried to test everything on the device but unfortunately was useless.

I appreciate your kind help.

regards.

Try out these commands and check the performance. Run on WLC CLI.

 

  • config wlan disable <WLAN id>
  • config wlan session-timeout <WLAN id> 0 (ZERO)
  • config wlan usertimeout 100000 <WLAN id>
  • config wlan enable <WLAN id>
Regards,
Sathiyanarayanan Ravindran

Please rate the post and accept as solution, if my response satisfied your question:)

I am using GUI, and I enabled session timeout on WLANs, Advance tab as you can see from the screenshots. 

I want to tell you that from yesterday till now, not required the re-authentication. Now I can see the clients from sleeping clients. The clients stay there for a longer time.

I just have done the following operations:

- Enabled session timeout to 65535 Seconds.

- unchecked the Client user idle timeout on WLANs, Advanced tab.

- Assigned 300 Seconds for User Idle Timeout (seconds) on the Controller tab.

- Assigned 300 Seconds for ARP Timeout (seconds) on the controller tab.

Now if the clients go to the sleeping clients on the monitor tab, then my problem will be solved because I have assigned 43200 min for Sleeping Client Timeout, it means the user can start up from this period without re-authentication.

 

Please correct me if I have any mistake and I appreciate any help or any other clarifications.

 

Thank you,

Aram.

Dear Marce,

please note that this is the first time that I am using WLC, so I don't have much information or good experience regarding this device. if I do some actions, this is not contradicted, its less experience from my end.

 

Thank you for your kind understanding 

Regards.

 

 - Then you should let your experience flow into less contradicting actions which will lead to increased productivity for your users.

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !
Review Cisco Networking products for a $25 gift card