cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1108
Views
5
Helpful
6
Replies

Smart device: Android/ BB requiring multiple web logons

pprasad
Level 1
Level 1

We use WEB based authentication.

.

Laptops seem to manage to keep the authentication even if it is not connected for 24 Hours

but Smart devices:Android/ BB/ IPhone requiring multiple web logons in a day

The CIsco Logs do not show multiple logons.

but the smart devices show the web logons very often.

it is a pain to type the web authentication  more that once a day.

How does  Cisco maintains session

and how does client maintains session.

Any help in troubleshooting / solution is welcome

We would like to  see the average session last for a two-week signing on once, and being away from the wi-fi for mare thatn 72 Hours

Thanks

Pradeep

1 Accepted Solution

Accepted Solutions

Stephen Rodriguez
Cisco Employee
Cisco Employee

By default the user idle timer is set to 5 minutes, 300 seconds. Once a client is nit heard for this interval, the WLC removes the client from the MSCB. Once this has been done the client would need to reauthenticate via the web page.

This timer can be adjusted, but I wouldn't I crease it too much. If you push this too high you will have issues with clients connecting as the MSCB can only hold so many entries, I what to say 5,000. If you allow 'stale' entries to remain in the MSCB, other users will not be able to connect.

Sent from Cisco Technical Support iPad App

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

View solution in original post

6 Replies 6

Stephen Rodriguez
Cisco Employee
Cisco Employee

By default the user idle timer is set to 5 minutes, 300 seconds. Once a client is nit heard for this interval, the WLC removes the client from the MSCB. Once this has been done the client would need to reauthenticate via the web page.

This timer can be adjusted, but I wouldn't I crease it too much. If you push this too high you will have issues with clients connecting as the MSCB can only hold so many entries, I what to say 5,000. If you allow 'stale' entries to remain in the MSCB, other users will not be able to connect.

Sent from Cisco Technical Support iPad App

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

We have already extended the session timeout to 100,000 seconds out to permit the laptops stay for 24 Hours without sending any packent on the wi-fi.

But why are smartphone suffering more than laptops

Are they sending any thing which cause the IPS/IDS to kick in.

how can i mesure to see the  MSCB status

For a full day, you would only need to set the timer to 86,400, but that is kinda moot really.

It sounds more like it's an issue with the mobile broswer/phone OS, than anything, if this is working with laptops.

Again, I really wouldn't push the user idle timer out that far, unless you know for sure that you are going to have farily low client counts.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

We have ~500 Guests on the wifi / week.  peaking to ~3000 / week The guests are not interested in loging on more than once a week. These guests have more than 1 device. Laptop and Smart device.

We have 4 WLC's in our campus.

As the smart devices are more mobile. They suffer more due to resource exhaustion on the wi-fi.

What trouble shooting can we do to find this challenge

Smart-phones Android, Iphone and BB are all having the problem.

so i donot think the problem is based on the clinet end.

Still sounds like an issue with the Mobile device to me, and expecting a mobile device to act the way a laptop does, just isn't entirely possible at this time.  They are getting better, but they still have limitations.

If you are going to use webauth only, best to set the expectation that they may need to login multiple times.  Or put a PSK on the network vs using webauth.  then just rotate the key as you will.

As with most issues of this nature, setting the proper expectations from the start saves time later.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Stephan

I do agree that setting expectations is correct,

The Users compare the solution we have provided as Wi-Fi access  and comapre that to that provided at hotels,

They would like to have a situation that they can work and be sure to

get e-mail updates without having to pay high mobile roaming charges.

Trying to type the password on the smart devices is also a pain.

if we put a key based operation. we will not be able stop the access after a certain period.

ex. one month as chaning the key would mean informing all teh users and making them change it also.

How have others done it in hospitality locations?

Pradeep

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card