- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Reauthentication using clearpass captive portal after User idle TImeout
07-04-2018 09:43 PM - edited 07-04-2018 09:46 PM
Setup: Windows Desktops directly connected to Aruba 29xx series switchs. Login using clearpass captive portal authentication. No mac authentication.
Requirement : After succesfull login, when users reach windows User idle time out, switch should do "session expiry" for that user and should re-initiate captive portal login.
Challenge: We have disabled mac authentication and enable idle timeout in switch but Desktop PCs will always be connected to switch and there will be packet exchange so idle timeout is not helping when one user completes his shift and leaves his desk during time in which PC will be idle.
Detailed explination: Customer needs captive portal self registration and login for their Desktop users connecting to Aruba Switch.Since multiple users work on shift basis in a single PC where one guy leaves his desk he should have option to log off his Internet access in web and next user comes he should be presented with captive portal login where he has to provide his credentials for accessing Internet again.This should happen on daily basis as Customer requires accounting data of the employees accessing internet daily.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Reauthentication using clearpass captive portal after User idle TImeout
07-10-2018 12:09 AM
any update on above query?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Reauthentication using clearpass captive portal after User idle TImeout
07-10-2018 10:10 AM
Hi,
Can you share your config? Are you setting the idle timeout at the switch port? Are you using user roles?
There is a logoff-period option as well that you can set on the port that will kick off after no activity.
Switch(config)# aaa port-access authenticator <ports> logoff-period
<1-999999999> Enter a number.
Regards,
Justin
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Reauthentication using clearpass captive portal after User idle TImeout
07-10-2018 10:10 PM
Thanks justin for reply!
For using "Log-off period" option, there is a rule that 'traffic should not hit the switch port for specified time'. But PC always tries to push some traffic to Switch Port.
Is there any possiblity that we can use 'traffic threshold concept' in switch?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator