<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33840#M1214</link>
    <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
then there is the idea to monitor printer availability by sending a ping every 5 minutes (or a bit more often). This can show you if your printers are up and it will refresh the FDB entry.&lt;BR /&gt;
&lt;BR /&gt;
Another possibility is to synchronize ARP and FDB timeouts (a good idea in general if you have layer 3 ECMP in the network) and use EXOS' ARP refresh mechanism to keep the ARP and thus the FDB entry current.&lt;BR /&gt;
&lt;BR /&gt;
Yet another possibility is to use&lt;BR /&gt;
configure netlogin ports [port_list | all] allow egress-traffic [none | unicast| broadcast | all_cast]to allow broadcasts and thus ARP requests to reach the printer. That way the printer will re-authenticate whenever someone tries to use it.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Erik</description>
    <pubDate>Mon, 20 Mar 2017 14:02:00 GMT</pubDate>
    <dc:creator>Erik_Auerswald</dc:creator>
    <dc:date>2017-03-20T14:02:00Z</dc:date>
    <item>
      <title>EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33828#M1202</link>
      <description>Hi, &lt;BR /&gt;
&lt;BR /&gt;
i want trigger reauth of printers via RADIUS Session Timeout Attribute. Because i have X440-G1 switches i do not use the policy framework. EXOS 16.1.4.2-Patch-1-3. I use the standard RADIUS Attribute Session-Timeout, with value of 604800.&lt;BR /&gt;
&lt;BR /&gt;
604800 secs  is 1 time a week - this is enough for this demand - and i want to avoid unnecessary communication breaks based on reauth.&lt;BR /&gt;
&lt;BR /&gt;
If i use a short period let's say 5 minutes (for testing purpose) it works - but this long term period seem not to work.&lt;BR /&gt;
&lt;BR /&gt;
Unfortunately there is no information which is the largest possible value. Does anybody know this for X440-G1.&lt;BR /&gt;
&lt;BR /&gt;
Same question is regarding Value of RADIUS Attribute Idle-Timeout !&lt;BR /&gt;
&lt;BR /&gt;
Best Regards &lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 15:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33828#M1202</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2017-03-18T15:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33829#M1203</link>
      <description>According to the command ref guide the netlogin reauth period can be 0 or between 30 and 7200 seconds where 0 means disabled. So I guess it is also 7200 seconds for session timeout.&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 16:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33829#M1203</guid>
      <dc:creator>AnonymousM</dc:creator>
      <dc:date>2017-03-18T16:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33830#M1204</link>
      <description>Hi Olaf,&lt;BR /&gt;
&lt;BR /&gt;
that's not really long ...&lt;BR /&gt;
&lt;BR /&gt;
For my demand it is not usable then. I wish i had G2 switches there - OnePolicy Framework (netlogin) all using higher values (- i believe).&lt;BR /&gt;
&lt;BR /&gt;
So because we cannot change this - i have to look for another solution.&lt;BR /&gt;
&lt;BR /&gt;
Maybe Product Manager will equalize that within G1 and G2 possibilities (because i believe that is only a software limitation).&lt;BR /&gt;
&lt;BR /&gt;
Do you know anything about the allowed idle-timeout ?&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Matthias&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 16:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33830#M1204</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2017-03-18T16:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33831#M1205</link>
      <description>If you mean after which period of time a client is removed when sending no pakets, this is bound to the FDB aging timer. Or what exactly do you mean by idle-timeout?&lt;BR /&gt;
&lt;BR /&gt;
Cheers&lt;BR /&gt;
Olaf&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 16:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33831#M1205</guid>
      <dc:creator>AnonymousM</dc:creator>
      <dc:date>2017-03-18T16:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33832#M1206</link>
      <description>i mean first. &lt;BR /&gt;
For an example Printers or phones are sending no packets for longer than the standard fdb/netlogin timer of 5 minutes is. So i want extend this to lets so 2hours. &lt;BR /&gt;
&lt;BR /&gt;
This is very smart if i do that with RADIUS Attribute Idle-Timeout. &lt;BR /&gt;
&lt;BR /&gt;
So what is the maximum value of this regarding G1 Switches ? &lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 16:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33832#M1206</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2017-03-18T16:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33833#M1207</link>
      <description>OK Olaf - i though twice a time about me question - you tell me already in EXOS G1 Idle timeout of a netlogin session is bind to the FDB aging time. If i increase fdb aging time is also ingress netlogin idle-timeout.&lt;BR /&gt;
&lt;BR /&gt;
Looking at manual i see a wide range of 15 to 1,000,000 seconds. Thats OK!&lt;BR /&gt;
&lt;BR /&gt;
I was happy if session timeout maybe also get this wide range in future EXOS ...&lt;BR /&gt;
&lt;BR /&gt;
Thanks for clarify that!&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 16:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33833#M1207</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2017-03-18T16:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33834#M1208</link>
      <description>No idea. Sorry! I am not even sure if this works at all. The only method I have been using in those kind of scenarios was adjusting the FDB aging timer. Maybe someone else has tested this before.&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 16:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33834#M1208</guid>
      <dc:creator>AnonymousM</dc:creator>
      <dc:date>2017-03-18T16:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33835#M1209</link>
      <description>You could try session refresh timer which is upt to 3600 seconds. But that would also require adjusting FDB aging timer.&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 16:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33835#M1209</guid>
      <dc:creator>AnonymousM</dc:creator>
      <dc:date>2017-03-18T16:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33836#M1210</link>
      <description>One general hint to all who are playing around with this:&lt;BR /&gt;
&lt;BR /&gt;
If you wants to check which is possible on EXOS G1 switches (regarding netlogin) you have to look at manuals pre EXOS 16.1.&lt;BR /&gt;
&lt;BR /&gt;
Starting with EXOS 16.1 the new netlogin OnePolicy Framework is coming with enhance features. Which are only working an G2 Switches.&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 17:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33836#M1210</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2017-03-18T17:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33837#M1211</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
for silent machines, there're several ways to manage it.&lt;BR /&gt;
&lt;BR /&gt;
- mac address lockdown with timeout is maybe what you will want to use. &lt;BR /&gt;
&lt;BR /&gt;
configure mac-lockdown-timeout ports [all | port_list] aging-time seconds&lt;BR /&gt;
enable mac-lockdown-timeout ports [all | port_list]&lt;BR /&gt;
&lt;BR /&gt;
range is between 15 and 2,000,000 seconds. Would that be enough &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
- you can configure port restart, so that once the mac is flush from the port, that port will do a quick disable/enable that will force the device to speak and re-authenticate.&lt;BR /&gt;
&lt;BR /&gt;
- do a script&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 18:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33837#M1211</guid>
      <dc:creator>Stephane_Grosj1</dc:creator>
      <dc:date>2017-03-18T18:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33838#M1212</link>
      <description>Hallo Matthias,&lt;BR /&gt;
&lt;BR /&gt;
(testet with vm-22.1.1.5)&lt;BR /&gt;
&lt;BR /&gt;
if you enable logging you can see:&lt;BR /&gt;
&lt;BR /&gt;
03/18/2017 19:09:39.30 &lt;AAA.RADIUS.SRVRRTRNACCESSVAL&gt; Authorization values for B2-EF-FB-7C-BE-26(userName 'B2EFFB7CBE26') on port 1: Access level - unknown, Tunnel Type - none, Tunnel Medium - none, Tunnel Group Id - 0, Session Timeout - 4294967295, Idle Timeout - 4294967295.&lt;BR /&gt;
With Session-Timeout/Idle-Timeout set:&lt;BR /&gt;
&lt;BR /&gt;
03/18/2017 19:12:09.30 &lt;AAA.RADIUS.SRVRRTRNACCESSVAL&gt; Authorization values for B2-EF-FB-7C-BE-26(userName 'B2EFFB7CBE26') on port 1: Access level - unknown, Tunnel Type - none, Tunnel Medium - none, Tunnel Group Id - 0, Session Timeout - 4222222222, Idle Timeout - 4111111111.&lt;BR /&gt;
So the switch accepts large values.&lt;BR /&gt;
&lt;BR /&gt;
But I'm not sure if Idle-Timeout is used. I testet the following values:&lt;BR /&gt;
Session Timeout - 20, Idle Timeout - 10, fdb - 300&lt;BR /&gt;
&lt;BR /&gt;
I stopped the client. After 20 seconds the switch reauthenticated the client via radius.&lt;BR /&gt;
This happend every 20 seconds till the fdb expired after 300 seconds.&lt;BR /&gt;
&lt;BR /&gt;
If the fdb expires before the Session-Timeout, the client session is removed.&lt;BR /&gt;
&lt;BR /&gt;&lt;/AAA.RADIUS.SRVRRTRNACCESSVAL&gt;&lt;/AAA.RADIUS.SRVRRTRNACCESSVAL&gt;</description>
      <pubDate>Sun, 19 Mar 2017 01:42:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33838#M1212</guid>
      <dc:creator>Patrick_Koppen</dc:creator>
      <dc:date>2017-03-19T01:42:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33839#M1213</link>
      <description>mac-lockdown-timeout seems to work as documented:&lt;BR /&gt;
&lt;BR /&gt;
mac-lockdown-timeout - 100, fdb - 50, Session-Timeout - 20, Idle-Timeout - 10&lt;BR /&gt;
&lt;BR /&gt;
After 77 seconds:&lt;BR /&gt;
#show mac-lockdown-timeout fdb ports 1&lt;BR /&gt;
Mac                     Vlan       Age  Flags  Port &lt;BR /&gt;
----------------------------------------------------&lt;BR /&gt;
b2:ef:fb:7c:be:26    Default(0001) 0075 F      1&lt;BR /&gt;
# show fdb ports 1&lt;BR /&gt;
Mac                     Vlan       Age  Flags           Port / Virtual Port List&lt;BR /&gt;
--------------------------------------------------------------------------------&lt;BR /&gt;
b2:ef:fb:7c:be:26    Default(0001) 0077 nd m    L      1And after 100 seconds:&lt;BR /&gt;
&lt;NL.MAC.DELETECLIENT&gt; Delete client request, 1, B2:EF:FB:7C:BE:26Reauth every 20 seconds&lt;BR /&gt;
&lt;BR /&gt;&lt;/NL.MAC.DELETECLIENT&gt;</description>
      <pubDate>Sun, 19 Mar 2017 03:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33839#M1213</guid>
      <dc:creator>Patrick_Koppen</dc:creator>
      <dc:date>2017-03-19T03:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS: X440-G1 maximum value of RADIUS Attributes:  session timeout, idle-timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33840#M1214</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
then there is the idea to monitor printer availability by sending a ping every 5 minutes (or a bit more often). This can show you if your printers are up and it will refresh the FDB entry.&lt;BR /&gt;
&lt;BR /&gt;
Another possibility is to synchronize ARP and FDB timeouts (a good idea in general if you have layer 3 ECMP in the network) and use EXOS' ARP refresh mechanism to keep the ARP and thus the FDB entry current.&lt;BR /&gt;
&lt;BR /&gt;
Yet another possibility is to use&lt;BR /&gt;
configure netlogin ports [port_list | all] allow egress-traffic [none | unicast| broadcast | all_cast]to allow broadcasts and thus ARP requests to reach the printer. That way the printer will re-authenticate whenever someone tries to use it.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Erik</description>
      <pubDate>Mon, 20 Mar 2017 14:02:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/exos-x440-g1-maximum-value-of-radius-attributes-session-timeout/m-p/33840#M1214</guid>
      <dc:creator>Erik_Auerswald</dc:creator>
      <dc:date>2017-03-20T14:02:00Z</dc:date>
    </item>
  </channel>
</rss>

