Security

 View Only
last person joined: 14 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass calculated value for Session-Timeout

This thread has been viewed 11 times
  • 1.  ClearPass calculated value for Session-Timeout

    Posted Apr 26, 2024 01:28 AM

    Hi community,

    Has anyone been able to create a session-timeout value for a specific time of the day?

    I've got a use case where we want to have our wireless AV devices re-authenticate after business hours (e.g. daily at 2am), rather than after a fixed number of seconds after authentication.

    Currently we have the Radius: IETF Session-Timeout to 10800, which means every 3hrs the device re authenticates.

    Issue with this is if a user is projecting to the device they lose connection and have to reconnect.

    We could extend the session timeout, but that would still have the potential issue where a user during business hours is connected and it drops.

    Thoughts?



  • 2.  RE: ClearPass calculated value for Session-Timeout

    EMPLOYEE
    Posted Apr 26, 2024 10:40 AM

    Create a new query in [Time Source] that returns number of seconds between Now() and your desired time, return that value as the Session-Timeout.

    Are you using MAC auth or 802.1X for the devices?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: ClearPass calculated value for Session-Timeout

    Posted 9 hours ago

    Hi Carlson,

    Assume you mean changing the Attribute filters in the following default time source authentication source?

    Typically MAC auth as majority of the AV devices do not have the ability to install certificates, but there are some such as Apple TVs that we can deploy certs and use EAP-TLS.