Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Voucher User how long authenticated

This thread has been viewed 8 times
  • 1.  Voucher User how long authenticated

    Posted Feb 06, 2017 05:01 AM

    Hi Airheads,

    sorry for my many postings but it`s my first project using Aruba WiFi Products. 

     

    My scenario: 

    1. Create a voucher with username and password

    2. Connect to wifi_guest

    3. Enter Username and password on captive portal (internal captive portal of my Aruba7005)

    4. Enjoy!

    Question:

    How long is the user authenticated before he need to fill username and password on the captive portal again? Where can i define this period?

     

    Hope i explain that right. Thanks for your fast help



  • 2.  RE: Voucher User how long authenticated

    Posted Feb 06, 2017 07:27 AM

    Sounds like this will be the idle user timeout. 

     

    They will be asked to re-authenticate when this timeout expired. 

     

    User Idle Timeout

     

    Maximum period after which a client is considered idle if there is no wireless traffic from the client.The timeout period is reset if there is wireless traffic. If there is no wireless traffic in the timeout period, the client is aged out. Once the timeout period has expired, the user is removed. If the keyword seconds is not specified, the value defaults to minutes at the command line.

    Range: 1–255 minutes (30–15300 seconds)

    Default: 5 minutes (300 seconds)

    Setting an Authentication Timer

    To set an authentication timer, complete one of the following procedures:

    Using the WebUI

     1.Navigate to the Configuration > Security > Authentication > Advanced page.
     2.Configure the idle user timeout as described above.
     3.Click Apply before moving on to another page or closing the browser window. If you do not perform this step, you will lose your configuration changes.

    Using the CLI

    The commands below configure timers you can apply to clients. If the optional seconds keyword is not specified for the idle-timeout and stats-timeout parameters, the value defaults to minutes.

     

    (host)(config) #aaa timers

    idle-timeout <time> [seconds]

     



  • 3.  RE: Voucher User how long authenticated

    Posted Feb 06, 2017 09:14 AM

    I think the idle user timeout is not my solution, it looks like this setting is for defining the time how long a user can idle on the GUI or SSH before he will be automaticly disconnected.

     

    I will describe my quiestion again, sry.

     

    1. I create a voucher for User A (username and password) he will be able to use the guest_wifi for 1 year.

    2. User A connect to the guest_wifi and will be forwarded to the captive portal where he can use the provided voucher with username and password to get access to the internet.

    3. User A need access for one year, he`s in office every monday and thusday. I don`t want him to logon on the captive portal every day.

     

    Example:  User A arrived the office on monday, he connect to guest_wifi and enter his username and password, so he can work online.

    One day later, he is back in the office and want to access the guest_wifi again BUT NOW WITHOUT ENTERING USERNAME AND PASSWORD. This is what i mean, i will define a time range like 48 hours or so, to keep User A`s machine authenticated.

     

    I hope this describtion is better.

     

     



  • 4.  RE: Voucher User how long authenticated

    Posted Feb 06, 2017 09:23 AM

    Hi,

     

    You're describing guest access with MAC caching. For ths you will need ClearPass. I'd recommend speaking with your local Aruba partner to design the solution out for you.

     



  • 5.  RE: Voucher User how long authenticated

    Posted Feb 14, 2017 10:41 AM

    Hey jrwhitehead, thanks for your reply.

    I will get some infos about clearpass from HPE Aruba, but for now, i need to know, how long a user is authenticated (User connect to guest_wifi and enter username/password in the morning, go to lunch for about 2 hours, come back and access guest_wifi again without entering the credentials) if i use the Controller 7005 most default settings without PEF and Clearpass.

     

    I tested it allready but only for 15-20 minutes.

    1. Connect guest_wifi

    2. Enter credentials on captive portal

    3. Surf the internet for a few minutes

    4. Shutdown my machine

    5. Wait about 15-20 minutes

    6. Power on my machine again

    7. Connect guest_wifi

    8. Surf the internet without authentication on the captive portal

     

    So for me it looks like there must be a "default value" for keeping my machine authenticated without the extra use of Clearpass or PEF. It`s okay if i can`t change that value without extra usage of clearpass but i want to know the defaults.