cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
591
Views
5
Helpful
3
Replies

ACS Authentication / DACL Timeout

JEFF SPRADLING
Level 1
Level 1

Hello all,

We have an ASA setup to authenticate users connecting into the DMZ via Radius (ACS), and if authorized, download an ACL from the ACS.

Users are timing out after about 15 minutes and have to re-authenticate.  I'm assuming it's an idle timeout value.

How do I increase that timeout value on the ACS?

 

Thanks!

1 Accepted Solution

Accepted Solutions

nspasov
Cisco Employee
Cisco Employee

If you are controlling this from the ASA you will need to adjust this setting:

vpn-session-timeout 

If you want to control this in ACS you can change/return the following attributes in the "Authorization Profile"

Radius Attribute 50 - CVPN3000/ASA/PIX7.x-Authd-User-Idle-Timeout

  Located under the "Radius Attributes TAB"

Reauthentication Timer: Value 

  Located under the "Common Tasks" tab

This is assuming that you are running ACS 5.x. 

 

Thank you for rating helpful posts! 

View solution in original post

3 Replies 3

nspasov
Cisco Employee
Cisco Employee

If you are controlling this from the ASA you will need to adjust this setting:

vpn-session-timeout 

If you want to control this in ACS you can change/return the following attributes in the "Authorization Profile"

Radius Attribute 50 - CVPN3000/ASA/PIX7.x-Authd-User-Idle-Timeout

  Located under the "Radius Attributes TAB"

Reauthentication Timer: Value 

  Located under the "Common Tasks" tab

This is assuming that you are running ACS 5.x. 

 

Thank you for rating helpful posts! 

Thanks, Neno!  That works great!

Glad I could help! :)