ETExamTower
Q23Policy Enforcement

Which RADIUS attribute dynamically assigns the active Inactivity timer for MAB users from the Cisco ISE node?

← → navigate · a answer
Community votes
D
100% (2)
A
0% (0)
B
0% (0)
C
0% (0)
Discussion · 4
D 4
Selected Answer: D D is correct The inactivity timer for MAB can be statically configured on the switch port, or it can be dynamically assigned using the RADIUS Idle-Timeout attribute (Attribute 28). Cisco recommends setting the timer using the RADIUS attribute because this approach gives you control over which endpoints are subject to this timer and the length of the timer for each class of endpoints. For example, endpoints that are known to be quiet for long periods of time can be assigned a longer inactivity timer value than chatty endpoints. Do not confuse it with session timeout!
3
From the link above: "The inactivity timer for MAB can be statically configured on the switch port, or it can be dynamically assigned using the RADIUS Idle-Timeout attribute (Attribute 28)."
2
D.) idle timeout The "idle timeout" RADIUS attribute sets the maximum time an endpoint can stay idle before the authentication session is ended. It matters in situations where you want to set a specific inactivity timer for MAB users dynamically through RADIUS attributes.
1
D is correct. https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/MAB/MAB_Dep_Guide.html#wp392385