08-17-2020 01:44 AM - edited 07-05-2021 12:24 PM
I wonder if it is possible to extend session on WLC or ISE? On WLC, I know about Session Timeouts (300-86400s for 802.1X(EAP)), but I need to extend more than that. I need features like Sleeping Clients, but for L2 security. I need my session to remain for more than one day. Is it possible on ISE, maybe?
Thanks in advance,
Nik
Solved! Go to Solution.
08-17-2020 09:21 AM
Main reason is because client asked me to do that. They want to extend sessions so when user leaves office nobody can join network with his user/pass if they are somehow exposed.
Just keep in mind that this is not possible and that is what you need to explain to your customer. The simple solution for this is to use certificates (EAP-TLS) or look at computer authentication. The idea that a users AD credentials would get exposed is an issue to wired and wireless and that should be addressed another way. If using ISE and AD username/password, then you would need to define a policy on ISE to look if already authenticated. This would not allow any users to access from another device which many might have more than one machine.
08-17-2020 02:00 AM
08-17-2020 02:17 AM
Hello Scott,
Thank you for fast reply.
Main reason is because client asked me to do that. They want to extend sessions so when user leaves office nobody can join network with his user/pass if they are somehow exposed. It was a bit confusing to me, so I wanted to check with community.
08-17-2020 02:28 AM
08-17-2020 09:21 AM
Main reason is because client asked me to do that. They want to extend sessions so when user leaves office nobody can join network with his user/pass if they are somehow exposed.
Just keep in mind that this is not possible and that is what you need to explain to your customer. The simple solution for this is to use certificates (EAP-TLS) or look at computer authentication. The idea that a users AD credentials would get exposed is an issue to wired and wireless and that should be addressed another way. If using ISE and AD username/password, then you would need to define a policy on ISE to look if already authenticated. This would not allow any users to access from another device which many might have more than one machine.
08-17-2020 10:27 AM
Thank you Scott. Your explanation is really great. I wanted to be sure that WLC is not place where this problem can be solved.
08-17-2020 12:31 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide