Cisco :: WLC 5508 - Passive Client Vs User Idle Timeout?

Apr 18, 2012

I'm on WLC 5508 . It doesn't matter if passive client feature is turned on or turned off , when you try to increase "User Idle Timeout" you can see this message:
  
In our network, a lot of clients gets deauthenticated. I thought it would be useful to enable "Passive-client" feature, or increase "user idle timeout" , but how these works with each other?  

View 15 Replies


ADVERTISEMENT

Cisco Routers :: Rv082 Can Set Client Idle Timeout Someway

Nov 16, 2011

If i set up a pptp vpn between a Cisco rv082 router and a microsoft client,Can i set the client idle timeout someway? or Have a default value pre- configured for this?Because this device support 5 users to connect at the same time. It would be best for me, if the device drop the client if it does not use the tunel.

View 3 Replies View Related

Cisco Wireless :: WLC 5508 Controller Idle Timeout Limit

Dec 20, 2011

The behavior of some mobile devices ( as Iphone , Itouch, not Blackberry, not labtops ) with WL Controller (5508) is that, when the client doesn't use it, it disconnects after 480 sec.
 
The idle timeout configured is 900 sec.
 
Why the behavior is different in this type of devices? Increase the idle timeout is a solution?

View 2 Replies View Related

Cisco Wireless :: 5508 WLC - Associate Client From AP If Idle For Certain Time

Sep 16, 2012

Is it possible to rename the default webauthentication URL from [URL] to something like [URL]. We are running on 7.0.98.0, is it possible to do http for web authentication and https for Mgmt access if we upgrade the controller software?
 
We configured our guest wireless with no layer 2 authetication so users can associate with an AP and get an ip adress but they can't go anywhere unless they have a valid username and password(web authentication) - does this affect the performance of an AP since there will be many people associated with each AP, is there any setting in the WLC to de associate a client from an AP  if its idle for certain time.

View 9 Replies View Related

Cisco :: WLC-5508 - Change Timeout For Client Excluded (MACAddress Status)

Feb 7, 2012

Is there a way to change the timeout for the Client Excluded: MACAddress status?  It seems like the exclusion is rather short.  I'd like to have the ability to control the exclusion time.  Using WLC-5508 7.0.116.0.

View 2 Replies View Related

Cisco Firewall :: Verify Idle-timeout On ASA 5510?

Apr 13, 2011

How to verify on the asa 5510 , the vpn-idle timeout,is running on default setting(30mts)

View 3 Replies View Related

Netgear Dgn2200 Unable To Change Idle Timeout?

Oct 30, 2012

Modem is a Netgear dgn2200

On the modem page with all the settings Under basic settings For connection it says Always Connected The box underneath says idle timeout 5 (that's in minutes)

I am unable to change that number or even get a cursor to appear in that box (I want to change it to a 0 - my internet connection has been dropping out when going idle). I can't right click or anything. That is using Firefox. When I say dropping out, I mean, the 3 computers on the network become unuseable - nothing works and things don't appear to be connected to the internet even though my green ADSL light stays on like it's connected - it is not.

I tried the same modem page in IE, and that box with the 5 in it is still showing 5, but this time it's just grayed out - again, can't be changed. The firmware updates are all upto date (apparently - according to it's check)

View 1 Replies View Related

Cisco Firewall :: Asa5510 Idle TCP Connection Timeout With Flags

May 14, 2012

I have ASA 5510 with 8.2.4 and 8.0.x OS and all seem to have common problem of idle TCP connections not timing out. The host to host connections are coming over VPN tunnels. I have default timeouts on all the firewalls. I have tried changing global timeouts and as well as host specific timeouts using MPF but doesn't work at all ! The problem is when TCP connections are sitting idle in conn table for days and when connection limit of 50,000 conns reach the firewall starts behaving unpredictably dropping packets or unresponsive! I need the unused idle connections to timeout which is NOT happening either by changing global values or MPF.

View 1 Replies View Related

Cisco Application :: CSS 11503 Flow Idle Timeout Not Working As Expected?

Jan 20, 2012

I have a CSS 11503 with a basic content rule for TCP 10000 going to a few backend servers. I was looking into the default timeout values for flows and when testing using telnet the flow didn't terminate as expected?
 
For example, i have no 'timeout multiplier' specified in the config and when i look at the output of 'show flow-timeout default' it tells me the default 16 seconds timeout is in effect for *. With that in mind, i telnet to the content rule vip on TCP 10000 and on the backend server using wireshark i can see the TCP threeway handshake. With no data passing i'd expect the CSS to terminate this flow after 16 seconds.. yet it takes exactly 128 seconds before wireshark shows the RST and the flow is terminated. 128 being 8 times the default 16 second flow timeout.
 
If i try to force the connection to close early by specifiying 'flow-timeout-multiplier 2' in the content rule, or even a multiplier of 40, it still waits 128 seconds to close the telnet connection.

View 1 Replies View Related

Cisco Switches :: SG300-20 - Radius Idle And Session Timeout Does Not Work

Jan 25, 2012

I have an SG300-20 here for testing (firmware: 1.1.2.0, boot version: 1.0.0.4, language version: 1.1.1.6 English). Everything seems to work on it, except, that if I choose Radius authentication by mac address only, then the switch does not honor the Idle-Timeout and Session-Timeout attributes from the Radius server (freeradius).
 
The setup is the following: I have a no name access point plugged in to switch port gi1. The port gi1 is set up for Radius authentication by mac address only. The access point itself is authenticated, no problem with that. If I connect through the access point by (say) a mobile phone, it is authenticated, no problem. The radius server does send the Idle-Timeout and Session-Timeout attributes, I checked it by running "freeradius -X", both are set to 30 seconds. Then I turn off the wireless card in my mobile phone and check the dot1x users by "show dot1x users". My mobile phone's mac address remains there for 5-10 minutes, so the Idle-Timeout and Session-Timeout  does not work.
 
Another way I could resolv this problem is by explicitely asking the switch to reauthenticate the user. Unfortunately there is no CLI command to do just that, I can do however a reauthentication on a port using "dot1x re-authenticate gi1" (for example). But it does not work as it is expected: the switch uses the stored mac-address to reauthenticate the user, so nothing changes on the port (unless something changes in the radius server). I think it should work like the following: remove the authenticated user from the port, and whenever that mac address makes some network traffic, then reauthenticate as if it were a completely new connection. BTW: it would work for me also if I could just remove an authenticated user from a port, but I did not find a command to do that.
 
As a last resort I can simply shutdown the port, bring it up again ("shutdown" and "no shutdown" in the interface config), then all users are removed from the port and they all mush reauthenticate. But it causes a network outage for a couple of seconds for all users on that port, on a busy access point it is quite disturbing, and it is not an elegant way to do this.
 
So my actual question is: is there a way to remove an authenticated user either automatically (Idle-Timeout and Session-Timeout) or manually from this switch?
 
I enclose the relevant part of the running config.

interface range gi1-2
dot1x host-mode multi-sessions
exit
vlan database
vlan 2-4
exit

[code]....

View 2 Replies View Related

Cisco Wireless :: WLC 2504 Passive Client Feature Usage

Apr 1, 2012

Is it possible to use this feature on WLC 2504 ? ( Passive client feature). I found just this note :" The passive client feature is supported on Cisco 5500 and Cisco 2100 Series Controllers. "

View 8 Replies View Related

Cisco Firewall :: 5510 - Display User Message When User Connects Using AnyConnect Client?

Apr 20, 2009

We are using an ASA 5510 and remote access (SSL VPN) using the AnyConnect client.
 
Is it possible to display a user message when a user connects using the AnyConnect client, matching a specific dynamic access policy?  Can the message be displayed when the action is "Continue" rather than "Terminate"?  I can't seem to get this to work and wondered if there was a LUA function to do this.
 
We have a DAP which gives a restricted ACL when the user's anti-virus is out of date, and I wanted to notify the user to update their anti-virus and reconnect.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ISE 1.1.3.124 / Machine And User Authentication / MAR / Timeout?

Apr 12, 2013

I am using ISE 1.1.3.124.My first question:I want to know the relation between the attribute "WasMachineAuthenticated" and the MAR (MAchine access restriction in advanced setting for AD).Is-it the same  or not ?Once you time out, you need to do machine auth again. What is the timer ?Using the attribute "WasMachineAuthenticated", is-it the same timer that you configure in MAR ? In a distributed environnement, is the information about machine previously authenticated  replicated to all policy node ?Because, if a swicth has 2 radius-server, we are not sure that it will point everytime to the same server.

View 1 Replies View Related

Cisco Wireless :: Activity Timeout In Aironet 1140 - User Gets Disconnected

Nov 30, 2011

Users are facing issue since a long time now . Whenever user connected to wireless is idle say 10 -20 seconds he gets disconnected This happens for all the users and even Mac/Win 7 I changed Activity Timeout on AP and even rebooted but still when I do show dot11 associations all-client I see activity-timeout
 
Users don't get disconnected when there is continous flow of data its only when user is idle
 
When user disconnects and hit refersh it starts working again

View 1 Replies View Related

Cisco :: 5508 Web Authentication Timeout?

Aug 1, 2011

If any authenticated user uses protocol other than (http, https) within timeout period, that user #is deuthenticated

View 1 Replies View Related

Cisco VPN :: 3825 IOS EZVPN Client Timeout

Jul 10, 2011

I have a 3825 configured as an EZVPN server with 881 routers as clients.  One issue I am seeing is that sessions don't seem to time out, such as when a peer's public IP changes.  Show crypto ISAKMP peer shows the same host (using device certificates for authentication) with multiple public IPs establishing sessions.  I have ISAKMP keepalives configured on the router. 

View 2 Replies View Related

Cisco :: WLC 5508 External Web Authentication Mismatch With Session Timeout?

Aug 27, 2012

For guest clients , we have configured guest vlan and applied external web authenication on WLC 5508 , the session timeout value is 2700secons . When a client open a browser to internet page , wlc will redirect to URL and get the login page . After completed the login , he can go to internet page .

We find the iPhone and ipad clients will get the login page again ahfter ~ 5 mins , it is mismatch with session timeout value 2700 sec (45 mins) .

View 5 Replies View Related

Cisco Firewall :: ASA 8.2(5) - Uauth Absolute Timeout Disabled And Inactivity Timeout Set To 48 Hour

Nov 26, 2012

ASA 8.2(5), uauth absolute timeout is disabled and inactivity timeout is set to 48 hours:
 
timeout xlate 48:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:00:00 absolute uauth 48:00:00 inactivity
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
 
Users still get kicked out every 8 hours and they have to reauth. This is a logging message:
 
%ASA-5-109012: Authen Session End: user 'john', sid 839, elapsed 28801 seconds

View 1 Replies View Related

Cisco :: WCS (v5.2.193.0) Client User Name (unknown)

Feb 16, 2011

We are running Cisco Wireless Control Sytem (v7.0.164.0) with 4 - WLCs (v5.2.193.0) and about a 100 Aironets and I was wondering how to get WCS to identify the Client usernames?  When trying to view monitored clients usernames, all it shows is Client Username <unknown>, though their MAC and IPs are correct. I'm not sure if this has to do with mobility anchors or not, but currently we have none setup in case. How to resolve the machine name or actual username that is logged in... either one.

View 2 Replies View Related

Cisco :: WLC 5508 Cannot Have Similar User Logged Twice

Aug 26, 2012

I was having users on a Cisco WLC 440x controllers. Some service accounts were logged several time with the same AD-Account.Since I migrated them on the new controller (5508), it seems that we cannot have the same AD user logged several time.
 
I changed the Radius server with the one we were using on the old 440x but situation seems to be same,I checked the error message when trying to start a second similar connection they looks like :
 
*Dot1x_NW_MsgTask_4: Aug 24 14:04:51.558: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3062 Max EAP identity request retries (3) exceeded for client xxxxxxxxxxx
*Dot1x_NW_MsgTask_4: Aug 24 14:04:51.558: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:447
Authentication aborted for client xxxxxxxxxxx
 
If I move back to the other 440x similar logins are allowed without any problems.

View 3 Replies View Related

Cisco Firewall :: Remote VPN User Client Type On ASA 8.3?

Jun 21, 2011

It seemed that show vpn-sessiondb ra-ikev1-ipsec will not provide the client type of the remote vpn user as show vpn-sessiondb remote did before.
 
Is there a way to find it out on ASA running 8.3?

View 1 Replies View Related

Cisco :: 5508 WLC / Show Net User Summary Output

Dec 2, 2012

I have a 5508 WLC running on 7.0.116, I need to be able to pull all configured users off the WLC and import into excel, I have 900 odd users configured. When I run a show net user summary it only displays a third of users. I'm hitting space to tab through each page, then eventually I just get dumped back to the command prompt.

View 5 Replies View Related

Cisco :: Wireless User Session Authorization With WLC 5508

Oct 8, 2012

I have a user authentication issue with our WLAN deployment. My issue relates to the guest access WLAN. First a brief descrition of our setup. We have a local WLC in the branch office (5508) with two SSIDs configured, CorpNet for the internal network and GuestNet of external guest access. We also have a WLC (5508) in the DMZ to provide the guest access. We are using Cisco ISE server to authenticate guest users via a web portal.
 
The authentication process works as it should. An external client gets an IP in the DMZ and is redirected to the web portal to authenticate their account. When they do they are able to access and browse the internet. No problems. My issue is that if we disable their account (ie suspend or delete it) in ISE it does not seem to terminate the users session and they can continue to have internet access. What I would like to happen is that when the account is disabled in ISE then the associated device's access to the internet is removed.

View 2 Replies View Related

Cisco VPN :: AnyConnect Error User Not Authorized For Client In 5505

Jan 9, 2013

it's probably just me but I have tried real hard to get a simple AnyConnect setup working in a lab environment on my ASA 5505 at home, without luck. When I connect with the AnyConnect client I get the error message "User not authorized for AnyConnect Client access, contact your administrator". I have searched for this error and tried some of the few solutions out there, but to no avail. I also updated the ASA from 8.4.4(1) to 9.1(1) and ASDM from 6.4(9) to 7.1(1) but still the same problem.

The setup of the ASA is straight forward, directly connected to the Internet with a 10.0.1.0 / 24 subnet on the inside and an address pool of 10.0.2.0 / 24 to assign to the VPN clients. Please note that due to ISP restrictions, I'm using port 44455 instead of 443. I had AnyConnect working with the SSL portal, but IKEv2 IPsec is giving me a headache. I have stripped down certificate authentication which I had running before just to eliminate this as a potential cause of the issue. When running debugging, I do not get any error messages - the handshake completes successfully and the local authentication works fine as well.

ASA Version 9.1(1)
!
hostname ASA
domain-name ingo.local
enable password ... encrypted
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
[Code] .....

View 9 Replies View Related

Cisco VPN :: Configure ASA5505 For Remote User Using EasyVPN Client?

Jul 5, 2011

I need to configure our ASA5505 firewall for remote access to our network using EasyVPN software installed on a laptop. That laptop will be connected in the different places, using DSL or 3G toggle or Public Wi-Fi. For some people it's very easy, but I don't have any experience with firewalls.

View 9 Replies View Related

Cisco Security :: ASA 5520 - VPN Client Remote User Limit

Jun 16, 2012

how many remote user connect using Cisco VPN client on Cisco Firewall ASA5520-BUN-K9? Already i read VPN Client FAQ But their have no information about user limitation.

View 1 Replies View Related

Cisco Wireless :: WCS Creates User Guest Access On WLC 5508

Feb 23, 2012

In my Wireless network, I have two appliances WLC 5508 running version 7.0.116.0.I have a WCS running version 7.0.172.0, deployed on a windows 2003 server.I've imported the two WLCs in my WCS in order to centralize the monitoring and the configuration tasks.Now I'm facing an issue when I want to create a guest user from the WCS, rather than creating this user access on each WLC. The creation of the user account is working good, the replication is done on the both WLCs, but on one of my WLC the guest user account is deleted after one hour(around).On the second WLC, the same user account remains during all its life time.In attachment a screen shot of the advanced parameter of the guest user.You can see that the user was created on the both WLC but is only active on one ... and unfortunately the wrong because the AP is associated with the other WLC.

View 2 Replies View Related

Cisco Wireless :: 5508 - Export Guest User Accounts To New WLC

Dec 19, 2012

I've got a WLC5508 (7.0.116.0) that is managed by WCS (7.0.172.0). I set up another WLC5508 with the same code and managed by the same WCS. Now I'd like to export all the 800 guest user accounts with the passwords from the old WLC and import them into the new WLC.

View 10 Replies View Related

Cisco :: WLC 5508 / Guest User Session Validation Failed

May 31, 2012

I am running a guest wireless network on a Cisco 5508 WLC with 6.0.202.0 code. My syslog is filling up with the following error message:

WLC: *May 15 12:32:59.244: %AAA-3-VALIDATE_GUEST_SESSION_FAILED: file_db.c:3968 Guest user session validation failed for guest_user10. Index provided is out of range..
 
The user that is assigned to the guest_user10 account works fine and has no idea this error is occurring.
 
This error message is occuring exactly every 15 minutes 24x7.
 
I believe I have a rogue user who has setup a device to try and login to the guest network automatically, every 15 minutes with the guest_user10 credentials. I need to track this device down. I need a way to find either the MAC or IP address of the device that is causing this error message. I have tried turning on AAA debugging on the controller but I dont get anything more than the above error. I have also tried using WCS to look at the client history but it only show the normal activity.

View 3 Replies View Related

Cisco Wireless :: DHCP In 5508 / Change WLC User Accounts Password Too?

Jul 24, 2012

I just get to hands-on on my new WLC 5508?

1) I'm using a single subnet eg 192.168.1.0/24 for my wireless clients and i'm assigning them via the DHCP server from the WLC. As the clients are however made up of laptops and scanners, i would like to assign a range from 50-150 for the laptops and 151-250 for the scanners for easier identification. But it seems that from the WLC DHCP menu i'm not able to do this unless i segment them into a different network with different gateways.
 
2) Is there anyway to change the WLC user accounts password too? I dont seems to be able to find the option unless i delete the account and re-create it with the new password.

View 5 Replies View Related

Cisco Wireless :: Set WLC 5508 To Allow Single Web-authentication User Account To Get Connected?

Aug 12, 2011

how to set WLC 5508 to allow single create web authentication user account to get connected in a same time. i found that i can use the same username and password combo to be login in 2 machine in the same time.

View 4 Replies View Related

Cisco Wireless :: WCS 5508 Accessing Users From User Site Database

Jan 18, 2013

I work at a campus and use the WCS to control access to my network for staff and only internet access for students.  The Staff are assigned Username/password thru active directory and the student uses another SSID with only WPA --a password for all.  I was tasked with adding more securing for students -- by adding a user/password.  I do not want them connecting to my Active Directory for two reason--security risk and I have too many to input (over 1000).  So, I wanted to use our internal database to validate users.  I create a webpage with "WebAuth" that opens my logon page from my site and validates the login fields against the database.  It works and this allows the user to navigate thru my website but not outside the site. If they try an outside url it redirect them to my logon script.  I now understand why, so I'm looking for code I can add to my logon page that would allow me to redirect me to the controller's (once users are authenticated by my database) to call the WCS controller so I can enter a preset username/password so the policy management file would allow them access.  I presently use "External" and don't know if "Custom" would work. Finding a way in using a database instead of adding one person at a time?

View 3 Replies View Related

Cisco Wireless :: 1142 / 5508 - User Switching Every Few Minutes Between 2.4ghz And 5ghz?

Aug 20, 2012

This  first started when a user said they were getting disconnected and  reconnected a few times a day to our wireless network.  He is in a  remote office with a 1142 which is set to H-Reap talking back to our  5508.  Our WLC is running 7.0.166 The laptop has an intel ulitmate 6300agn wireless card with the latest 15.x drivers.
 
We are using an SSID with wpa2 and 802.1x auth back to our ACS server using PEAP with our windows credentials.attached is what i am seeing on the wcs troubleshooting page.When i do a debug client on the WLC i see many reauthentications coming from the client on the different radio.
 
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c Reassociation received from mobile on AP 0c:85:25:f3:7d:40
*apfMsConnTask_2:  Aug 22 12:59:36.762: 00:24:d7:d1:16:6c 10.24.8.108 RUN (20) Changing  ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller  apf_policy.c:1621)
*apfMsConnTask_2: Aug 22 12:59:36.762:  00:24:d7:d1:16:6c Applying site-specific IPv6 override for station  00:24:d7:d1:16:6c - vapId 512, site 'VH-GasWorks', interface  'management'
*apfMsConnTask_2: Aug 22 12:59:36.762:  00:24:d7:d1:16:6c Applying IPv6 Interface Policy for station  00:24:d7:d1:16:6c - vlan 2, interface id 0, interface 'management'
*apfMsConnTask_2:  Aug 22 12:59:36.762: 00:24:d7:d1:16:6c Applying site-specific override  for station 00:24:d7:d1:16:6c - vapId 512, site 'VH-GasWorks', interface  'management'
*apfMsConnTask_2: Aug 22 12:59:36.762:  00:24:d7:d1:16:6c 10.24.8.108 RUN (20) Changing ACL 'none' (ACL ID 255)  ===> 'none' (ACL ID 255) --- (caller apf_policy.c:1621)
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c STA - rates (8): 140 18 24 36 48 72 96 108 48 72 96 108 0 0 0 0
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c Processing RSN IE type 48, length 38 for mobile 00:24:d7:d1:16:6c

[code]....
 
Now this may be not be the issue thats causing our dropouts a couple times a day as this is happening every 5 mins.

View 12 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved