Cisco WS-SUP32-GE-3B - Supervisor Engine 32 Software Configuration Manual page 699

Software configuration guide
Hide thumbs Also See for WS-SUP32-GE-3B - Supervisor Engine 32:
Table of Contents
Chapter 41
Configuring Network Admission Control
Idle Timer
The idle timer controls how long the switch waits for an ARP packet from the postured host or a
refreshed entry in the IP device tracking table to verify that the host is still connected. The idle timer
works with a list of known hosts to track hosts that have initiated posture validation and the IP device
tracking table.
The idle timer is reset when the switch receives an ARP packet or when an entry in the IP device tracking
table is refreshed. If the idle timer expires, the switch ends the EAPoUDP session on the host, and the
host is no longer validated.
The default value of the idle timer is calculated as the probe interval times the number of probe retries.
By default, the idle timer default is 90 seconds which is the probe interval of 30 seconds times the
number of probe retries of 3.
The switch maintains a list of known hosts to track hosts that have initiated posture validation. When the
switch receives an ARP packet, it resets the aging timers for the list and the idle timer. If the aging time
of the list expires, the switch sends an ARP probe to verify that the host is present. If the host is present,
it sends a response to the switch. The switch updates the entry in the list of known hosts. The switch then
resets the aging timers for the list and the idle timer. If the switch receives no response, the switch ends
the session with the Cisco Secure ACS, and the host is no longer validated.
The switch uses the IP device tracking table to detect and manage hosts connected to the switch. The
switch also uses ARP or DHCP snooping to detect hosts. By default, the IP device tracking feature is
disabled on a switch. You must enable the IP device tracking feature to use NAC Layer 2 IP validation.
When IP device tracking is enabled, and a host is detected, the switch adds an entry to the IP device
tracking table that includes this information:
If NAC Layer 2 IP validation is enabled on an interface, adding an entry to the IP device tracking table
initiates posture validation.
For the IP device tracking table, you can configure the number of times that the switch sends ARP probes
for an entry before removing an entry from the table and you can also configure the number of seconds
that the switch waits before resending the ARP probe. If the switch uses the default settings of the IP
device tracking table, the switch sends ARP probes every 30 seconds for all the entries. When the host
responds to the probe, the host state is refreshed and remains active. The switch can send up to three
additional ARP probes at 30-second intervals if the switch does not get a response. After the maximum
number of ARP probes are sent, the switch removes the host entry from the table. The switch ends the
EAPoUDP session for the host if a session was set up.
Using the IP device tracking ensures that hosts are detected in a timely manner, despite the limitations
of using DHCP. If a link goes down, the IP device tracking entries associated with the interface are not
removed, and the state of entries is changed to inactive. The switch does not limit the number of active
entries in the IP device tracking table but limits the number of inactive entries. When the table reaches
the table size limit, the switch removes the inactive entries. If the table does not have inactive entries,
the number of entries in the IP device tracking table increases. When a host becomes inactive, the switch
ends the host session.
For the Catalyst 6500 series switch, the table size limit is 2048.
After an interface link is restored, the switch sends ARP probes for the entry associated with the
interface. The switch ages out entries for hosts that do not respond to ARP probes. The switch changes
the state of hosts that respond to an active host and initiates posture validation.
OL-11439-03
IP and MAC address of the host
Interface on which the switch detected the host
Host state that is set to ACTIVE when the host is detected
Catalyst Supervisor Engine 32 PISA Cisco IOS Software Configuration Guide, Release 12.2ZY
Understanding NAC
41-9

Hide quick links:

Table of Contents
loading

This manual is also suitable for:

Catalyst supervisor engine 32 pisa

Table of Contents