Web Token Timeout (s)

Information

APIC uses web session limits to restrict the number of web sessions that a given user account is permitted to access at any one time. The range is from 300 seconds to 9600 seconds. The default is 600 seconds.

Solution

Log into the Cisco APIC Web Console:
Navigate to 'Admin' -> 'AAA' -> 'Security'.

Click the 'Management Settings' tab.

In the 'Properties' section ensure 'Web Token Timeout (s)' is set to 600 or less

Item Details

Audit Name: Tenable Cisco ACI

Category: ACCESS CONTROL

References: 800-53|AC-12

Plugin: Cisco_ACI

Control ID: 6e0d17817d4b57a15acde618466235951588dcaee2319222ef14b9aabd8358b9