Access-challenge timeout on IOS

Phil Mayers p.mayers at imperial.ac.uk
Thu Jul 4 12:34:07 CEST 2013


On 04/07/13 11:00, Franks Andy (RLZ) IT Systems Engineer wrote:
> Hi,
>
>    I’m experimenting with a system involving an access-challenge to a
> NAS. It works fine with FR so far on, say, the cisco ipsec vpn client,
> which waits a long time until timing out waiting for user input. I’d
> like to also discoverhowother NAS’s behave using this and have found the
> timeout on a particular cisco 1131 access point to be quite short.
>
> Does anyone know if there’s a radius attribute I can send that will

Not as far as I know.

> extend this timeout, or an internal setting that will change the default
> on the ap?

Maybe. This usually depends on link-layer timers, e.g. EAPOL timeouts, 
IPSec/IKE timeouts, etc. rather than anything radius-related.


>
> Session-timeout and Idle-timeout are attributes mentioned by the cisco
> docs but neither of these seem to be what I’m after.

Neither are relevant; they're for established sessions, not timeouts in 
*establishing* one.


More information about the Freeradius-Users mailing list