cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2204
Views
0
Helpful
9
Replies

Webauth asking again for credntials

ittechk4u
Level 1
Level 1

Hello Experts,

I am having an issue with webauth page.

I am using ISE as radius server and using sponsor account for guest account creation.

My Issue is: once I login with webauth i got internet connection but after few idle time (5-10min), I need to enter username and password again.

Can this problem can be solved??? I have guest acount for 1 year timepeariod and I dont want to enter crenditals again and again.

Is there any solution?

wlc- 2504, AP- 2602, ISE 1.1 version

Thanks

5 Accepted Solutions

Accepted Solutions

Scott Fella
Hall of Fame
Hall of Fame

Set the idle timer on the WLC to something like 7200 seconds or 14400 seconds. That will allows devices I stay idle for that long before having to login again.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

View solution in original post

Sandeep Choudhary
VIP Alumni
VIP Alumni

adding to above

You can set the session timeout up to 24 hours. That's the max and webauth users will have no other option than re-login every day.

If you want a guest PC to stay connected for longer periods, I doubt that the guest portal solution is the best for your use case.

Reagrds

Dont forget to rate helpful posts

View solution in original post

I dont think you can do it permanently with WLC.

Reagrds

View solution in original post

The issue is with certain devices especially Apple. The session timer has to be a higher value than the idle timer. You can use the sleeping client feature if you are just using WebAuth.

http://www.cisco.com/en/US/docs/wireless/controller/7.5/config_guide/b_cg75_chapter_0111100.html

Session timer is a hard timeout and you can leave that disabled and it default to 24 hours. The idle timer is how long you want the WLC to keep the device in the RUN state.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

View solution in original post

Hi,

As long as a client entry is not removed from the WLC, it should not have to re web-auth.

Session timeout is a hard stop, so yes you could limit the session timeout to 12 hours. The other problem is that the WLC will "remove" a client by default after 5 minutes of an AP not hearing from the client. So a client who is shut down, or in power-save (no wireless packets), will be deauthenticated after the idle timeout period.

The user idle timeout is when you shut down laptop, or move away, so no deauthenticate frame was sent the client just goes silent. The idle timeout defines how long the WLC waits before deleting the client entry when it's not hearing AT ALL a single frame from the client.

But still I feel this is not you want, you want permanent connection to guest users but I think it is not possible now.

Hope it helps.

Reagrds

Dont forget to rate helpful posts

View solution in original post

9 Replies 9

Scott Fella
Hall of Fame
Hall of Fame

Set the idle timer on the WLC to something like 7200 seconds or 14400 seconds. That will allows devices I stay idle for that long before having to login again.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

With the later code versions of the WLC, you can define this on the WLAN advanced tab instead of globally in the GUI Controller tab.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Cant I do it permanently that it never ask username and password till my account expires ??

Thanks

I dont think you can do it permanently with WLC.

Reagrds

The issue is with certain devices especially Apple. The session timer has to be a higher value than the idle timer. You can use the sleeping client feature if you are just using WebAuth.

http://www.cisco.com/en/US/docs/wireless/controller/7.5/config_guide/b_cg75_chapter_0111100.html

Session timer is a hard timeout and you can leave that disabled and it default to 24 hours. The idle timer is how long you want the WLC to keep the device in the RUN state.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Hi,

As long as a client entry is not removed from the WLC, it should not have to re web-auth.

Session timeout is a hard stop, so yes you could limit the session timeout to 12 hours. The other problem is that the WLC will "remove" a client by default after 5 minutes of an AP not hearing from the client. So a client who is shut down, or in power-save (no wireless packets), will be deauthenticated after the idle timeout period.

The user idle timeout is when you shut down laptop, or move away, so no deauthenticate frame was sent the client just goes silent. The idle timeout defines how long the WLC waits before deleting the client entry when it's not hearing AT ALL a single frame from the client.

But still I feel this is not you want, you want permanent connection to guest users but I think it is not possible now.

Hope it helps.

Reagrds

Dont forget to rate helpful posts

Sandeep Choudhary
VIP Alumni
VIP Alumni

adding to above

You can set the session timeout up to 24 hours. That's the max and webauth users will have no other option than re-login every day.

If you want a guest PC to stay connected for longer periods, I doubt that the guest portal solution is the best for your use case.

Reagrds

Dont forget to rate helpful posts

OK Thanks sandep & Scott

You guys are really great.

Reagrds

Just remember with Apple devices, it's when the device scene closes that the idle timer starts counting down. With Apple devices, I also way keep the session timer niche he and have the idle timer set at 7200 or 14400. This allows users to go to lunch etc and come back without logging back on. I would make sure that your on a code that allows this to be configured on the WLAN and not global. This can cause issues when using FlexConnect mode and keeping users in the run state.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card