cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
423
Views
0
Helpful
2
Replies

Auto generate a new session key every 30 minutes

c.ong
Level 1
Level 1

Dear Sir,

I would like to auto generate a new session key every 30 minutes running LEAP using AP 1200 Local RADIUS authentication? How can I configure it? I noticed there is a session timeout option under Security-->Local RADIUS Server-->User Group, is this the locaiton for me to specify the duration of a session key? Does it mean that I have to define a User Group and tie the users under it in order to have dynamic encryption key every 30 minutes? Does the user need to login the authentication prompt every 30 minutes? Can it be transparent to the user?

What is the difference between Session Timeout and Lockout?

Thank you.

Regards,

Delon

2 Replies 2

vkapoor5
Level 5
Level 5

You can configure the following:

interface Dot11Radio0

dot1x reauth-period 1800

broadcast-key change 1800

Now all users will reauthenticate every 1800 seconds and subsequently renew their unicast session key. Also the broadcast key will be renewed every half hour.

If anybody knows a more elegant solution I would like to hear about it.

Casper

Review Cisco Networking for a $25 gift card