<section index="2.3" title="No HTTP(S) Server Session Timeout or HTTP(S) Server Idle Timeout Set" ref="ADMINISTRATION.WEBTIMEOUT.NO.HTTP.OR.HTTPS.SESSION.OR.IDLE.TIMEOUT.four">
<device name="Switch" type="Cisco Catalyst Switch" osversion="16.3" />
<ratings type="Nipperv1">
<section index="2.3.1" title="Finding" ref="FINDING">
<section index="2.3.4" title="Recommendation" ref="RECOMMENDATION">
<text>Nipper Studio recommends that a HTTP(S) server session timeout period of 10 minutes or less should be configured.</text>
<text>Notes for Cisco Catalyst Switch devices:</text>
<text>The HTTP server timeout can be configured with the following command:<code><command>ip http timeout-policy idle <cmduser>seconds</cmduser> life <cmduser>seconds</cmduser> requests <cmduser>number</cmduser></command>
ip http timeout-policy idle seconds life seconds requests number
