Hello,
NGS acts as a Radius Server for the WLC to authenticate the guest users. It doesn't notify when the guest user lifetime is over, this is out of Scope of Radius Protocol.
Rather a session timeout radius attribute is sent from NGS to WLC upon login of the guest user on the web auth SSID. This takes effect on the WLC and the user is removed from WLC when the timeout is over.
You need to have AAA Override enabled on the SSID.
Check: http://www.cisco.com/en/US/products/ps6366/products_tech_note09186a00809d6b9a.shtml
From that link:
Choose the the Advanced tab.
Enable Allow AAA Override. This allows the per client session timeout to be set from the NAC Guest Appliance.
Thanks
Serge