HP ProCurve 802.1x Session Timeout - Idle Timeout via RADIUS Attribute possible ?

  • 0
  • 1
  • Question
  • Updated 1 year ago
  • Answered
On a current project we use HP2920 Switches with Extreme Management and Control.

For avoid problems with printers we use "aaa port-access authenticator X/X logoff-period xxxxx"

For VoIP Phones we use a triggered Re-Authentication with "aaa port-access authenticator X/X reauth-period XXXXX"

Because this commanda are port related and not as i prefer device or mac related i want to switch over to apply these Timer values via Standard RADIUS Attributes during Authentication process (as i do that with EXOS / EOS sswitches).

Is this working ? I do not see anywhere the information if this is possible NOR the negativ information that this is not working.
During tests it seem the HP does not understand these Attributes. Are there maybe special HP VSA ?

These link is a good information source but does not explain my question:
https://wiki.freeradius.org/vendor/HP

Anyone how try this successfully before ?


Regards
Photo of M.Nees

M.Nees, Embassador

  • 9,414 Points 5k badge 2x thumb

Posted 1 year ago

  • 0
  • 1
Photo of M.Nees

M.Nees, Embassador

  • 9,414 Points 5k badge 2x thumb
Nobody out there who has ever try that ?
Photo of M.Nees

M.Nees, Embassador

  • 9,414 Points 5k badge 2x thumb
After 2 months HP Support have an answer:

I have been able to successfully change the Session-Timeout(27) value on the switch by sending a value (greater than 60sec) in the radius Accept-Accept message together with the Termination-Action (set to “1”), and the switch does take this new value into account.

However when sending the Idle-Timeout, the switch doesn’t react to the new value. The Lab confirmed that this one cannot be changed. Changing the Idle-Timeout value is not supported. Unfortunately, there are no HPE specific Attributes (VSA) available which would do the same.

I am glad for this help - but waiting 2 months for that answer is not what i am accustomed by Extreme GTAC ;-)))

Hope this helps any other guy who working with Extreme NAC and 3rd Party switches.

Regards
Photo of Drew C.

Drew C., Community Manager

  • 39,334 Points 20k badge 2x thumb
Sorry the community let you down on this one, Matthias. Glad you found an answer though!
(Edited)