- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SecurePort auth timeout recovery
Hi ,
It is already snowing in Canada so the fun has started with many outages across the country and causing some issues for us.
Atleast 1 to 3 switchports are reported per week as : SecurePort authentication timeout
After looking at the doc : https://documentation.meraki.com/MS/Access_Control/SecurePort_(formerly_known_as_SecureConnect)
I don't see any recovery mechanism other than : The APs will have 3 attempts of 5 seconds each to authenticate If this authentication fails, the switch's port will fall into a restricted state.
What ends up happening is that the hardware is up but the VPN or the Internet access is still down ( MX and MS/MR are booting faster than the ISP router ). The APs are doing their 3 attempts and then times out.
Having a recovery timer of let's say every 5 min and the auth process starts again would be nice and would prevent me of cycling those ports.
Am I missing something obvious ?
- Labels:
-
Other
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's a bit of a silly but really annoying issue.
Depending on how it's architected, I imagine it can't be that hard to force a retry once the switch connects to the dashboard.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree.. even hourly wouldn't even be as bad as right now
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It makes no mention of how long between each attempt either, if its back to back you have 15 seconds......
A user variable parameter would be nice failing that a reasonable time to retry i.e every 15 mins as a fail safe would be nice.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yeah as is you will need to cycle the ports once the sites comes back online... It's really not ideal. There is also a risk that you don't notice before the users as the AP will be online and connected to the management network even thou the port isn't authenticated...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is exactly the main part of the problem !
