One of my clients requested to refresh PMK (more about PMK) every 5 minutes during deployment of Cisco ISE and Meraki solution.
1. Create new Authorization Profile in Cisco ISE (Policy -> Policy Elements -> Results -> Authorization Profile)

Reauthentication—To choose, select the check box and enter a value in seconds for maintaining connectivity during reauthentication. You can also choose attribute values from the Timer drop-down list. You choose to maintain connectivity during reauthentication by selecting to use either the default (a value of 0) or RADIUS-Request (a value of 1) from the drop-down list. Setting this to the RADIUS-Request value maintains connectivity during the reauthentication process.

Creating and Configuring Permissions for a New Standard Authorization Profile

Create new Authorization Profile with Reauthentication attribute

2. Associate the new Authorization Profile with the active 802.1x policy. Done!

Testing

Check your Live Logs panel (Operations -> RADIUS -> Live Logs). You should be able to see authorizations roughly every 45 seconds.

Authentication logs

Also, you can capture traffic in the Meraki Web Panel.

Packet Capture Overview
The packet capture utility can be used to observe live network traffic passed by Cisco Meraki devices. Since captures provide a live snapshot of traffic on the network, they can be immensely helpful in diagnosing and troubleshooting networking issues. This article outlines how to remotely take a pac…


Use filter expression port 1812 or port 1813 or port 3799 to capture only RADIUS traffic.

Wireshark capture output.