Details authentication strategies for sleeping clients on WLANs, covering mobility guidelines, restrictions, and step-by-step procedures for configuration using GUI and CLI interfaces.
A sleeping client is a wireless device that
-
has completed web authentication and been granted guest access
-
is allowed to enter sleep mode and wake up without reauthenticating through the login page, and
-
the controller stores sleeping client information for a configurable duration before requiring reauthentication.
The valid range is 10 minutes to 43200 minutes, with the default being 720 minutes. You can also configure this duration on WebAuth parameter map that is mapped to a WLAN. The sleeping client timer is activated when conditions such as idle timeout, session timeout, WLAN disabling, or AP nonoperational status occur.
If the MAC address of a client in sleep mode is spoofed, a fake device, such as a laptop, can be mistakenly authenticated.
Feature History
| Feature Name |
Release |
Description |
|---|---|---|
| Webauth Sleeping Client Support |
Cisco IOS XE 17.1.1s |
The web authentication sleeping clients feature supports multiple combinations of authentications for a given client, which are configured on the WLAN profile. |
Scenarios where sleeping clients do not need reauthentication
-
Suppose there are two controller s in a mobility group. A client that is associated with one controller goes to sleep and then wakes up and gets associated with the other controller .
-
Suppose there are three controller s in a mobility group. A client that is associated with the second controller that is anchored to the first controller goes to sleep, wakes up, and gets associated with the third controller .
-
A client sleeps, wakes up and gets associated with the same or different export foreign controller that is anchored to the export anchor.