nerdexam
Cisco

300-715 · Question #247

An ISE administrator must change the inactivity timer for MAB endpoints to terminate the authentication session whenever a switch port that is connected to an IP phone does not detect packets from…

The correct answer is C. Change the idle-timeout on the Radius server to 3600 seconds for IP Phone endpoints. To control the inactivity (idle) timer for MAB-authenticated endpoints like IP phones in a centralized and scalable way, the idle-timeout should be configured on Cisco ISE (the RADIUS server) rather than individually on each switch port. ISE sends the RADIUS Idle-Timeout…

Policy Enforcement

Question

An ISE administrator must change the inactivity timer for MAB endpoints to terminate the authentication session whenever a switch port that is connected to an IP phone does not detect packets from the device for 30 minutes. Which action must be taken to accomplish this task?

Options

  • AAdd the authentication timer reauthenticate server command to the switchport.
  • BAdd the authentication timer inactivity 3600 command to the switchport.
  • CChange the idle-timeout on the Radius server to 3600 seconds for IP Phone endpoints.
  • DConfigure the session-timeout to be 3600 seconds on Cisco ISE.

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    6% (2)
  • C
    73% (24)
  • D
    15% (5)

Explanation

To control the inactivity (idle) timer for MAB-authenticated endpoints like IP phones in a centralized and scalable way, the idle-timeout should be configured on Cisco ISE (the RADIUS server) rather than individually on each switch port. ISE sends the RADIUS Idle-Timeout attribute (Attribute 28) in the Access-Accept response to the switch. When the switch detects no traffic from the endpoint for the specified duration, it terminates the session. Configuring this centrally on ISE ensures consistent behavior across all NADs without requiring per-port configuration on every switch. The value of 3600 seconds (60 minutes) appears in the answer choices - note there is a discrepancy with the 30-minute requirement stated in the question, but answer C represents the correct mechanism: setting the idle-timeout attribute on ISE/RADIUS server for IP Phone endpoint groups.

Topics

#MAB#RADIUS idle-timeout#Cisco ISE#Session management

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice