7-41
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 7 Setting Up and Managing User Accounts
Advanced User Authentication Settings
The single Cisco Aironet RADIUS VSA, Cisco-Aironet-Session-Timeout, is a
specialized implementation of the IETF RADIUS Session-Timeout attribute (27).
When Cisco Secure ACS responds to an authentication request from a Cisco
Aironet Access Point and the Cisco-Aironet-Session-Timeout attribute is
configured, Cisco Secure ACS sends to the wireless device this value in the IETF
Session-Timeout attribute. This enables you to provide different session timeout
values for wireless and wired end-user clients.
Note
To hide or display the Cisco Aironet RADIUS VSA, see
Setting Protocol
Configuration Options for Non-IETF RADIUS Attributes, page 3-16
. A VSA
applied as an authorization to a particular user persists, even when you remove or
replace the associated AAA client; however, if you have no AAA clients of this
(vendor) type configured, the VSA settings do not appear in the user configuration
interface.
To configure and enable the Cisco Aironet RADIUS attribute to be applied as an
authorization for the current user, follow these steps:
Step 1
Perform Step 1 through Step 3 of
Adding a Basic User Account, page 7-5
.
Result: The User Setup Edit page opens. The username being added or edited is
at the top of the page.
Step 2
Before configuring Cisco Aironet RADIUS attributes, be sure your IETF
RADIUS attributes are configured properly. For more information about setting
IETF RADIUS attributes, see
Setting IETF RADIUS Parameters for a User,
page 7-38
.
Step 3
In the Cisco Aironet RADIUS Attributes table, select the [5842\001]
Cisco-Aironet-Session-Timeout check box.
Step 4
In the [5842\001] Cisco-Aironet-Session-Timeout box, type the session timeout
value (in seconds) that Cisco Secure ACS is to send in the IETF RADIUS
Session-Timeout (27) attribute when the AAA client is configured in Network
Configuration to use the RADIUS (Cisco Aironet) authentication option. The
recommended value is 600 seconds.
For more information about the IETF RADIUS Session-Timeout attribute, see
Appendix C, “RADIUS Attributes,”
or your AAA client documentation.