Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tank
New Contributor

802.1x Port Authentication - Default Timeout

Hello, Does anyone know what the default time-out value is for 802.1x port authentication on the FWF90D? I am running a custom version of 5.0.7, but that should not matter? I have researched the web site, but having absolutely no luck. I need to determine what the default value is, as well as what the commands are to modify. In the example below I have set the value to 1 minute and monitoring a Thin Client connection to see if the Re-Key period expires, but no luck. config user setting set auth-cert " self-sign" set auth-timeout 1 end Thanks,
13 REPLIES 13
Jeff_FTNT
Staff
Staff

Hi Tank, Do you have way to change timeout to 8 hours on Wyse Thin Clients ? FGT only de-auth when it received EAPOL logoff or link down.
Tank
New Contributor

Hello Jeff, Good question. I would assume you can, but not positive. I have asked our systems engineering group about the Thin Client (TC) timeout and will post an update if that option exists. I have learned more on the elusive 802.1x Re-Authentications. It turns out the developers have implemented " Sticky MAC" on the LAN ports to keep devices logged in and never time out. My hope is they will revisit and add a command option to force re-authentication within a range of 1 to 24 hours. As long as the device successfully authenticates they should remain connected, until either the port is disconnected, a user forces a logout, or the IP lease time expires in DHCP. Of course, if the devices have a static IP address you can not use DHCP as a means of forcing a re-authentication by trimming down the lease time. This is why Fortinet engineering should add additional functionality, so we meet proper security requirements and do not get flagged on audits! :) Thanks, George
Jeff_FTNT
Staff
Staff

Thanks Tank, You may ask Fortinet SE to add the feature you want, they may give you a good answer. If you do not have to use 802.1x. You may try " Captive Portal" feature on interface. It is level 3, use ftp/telnet/http to initiate authentication. config user setting set auth-timeout 480 set auth-timeout-type hard-timeout end It will force to re-authentication every 8 hours.
Tank
New Contributor

Hey Jeff, I checked with the Systems group and they have reviewed all of the remote configuration options and none exist to force the Thin Client to re-authenticate. As you mentioned, I have submitted a feature request to my local SE. I appreciate everyone' s input. Note: The custom version of 90D code also has the ability to manage Layer 3 switches. So basically the external switch becomes an extension of the 90D. Nice bonus! I am currently testing the FS-108D(requires special code also) and 90D combination. I am not on the forum as much as I should, so if anyone has questions, please email me at geburns@ashland.com. Thanks, George Roll Tide!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors