<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maximum Concurrent User Sessions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716243#M490171</link>
    <description>The 2 aren’t supposed to work together as likely there is no mechanism to kick the user off if the device is not currently in the guest flow (remember me which is straight mab)&lt;BR /&gt;Removing from guest endpoint group likely won’t remove the device radius session &lt;BR /&gt;&lt;BR /&gt;Would recommend instead you disable remember me if you want that functionality&lt;BR /&gt;Or only allow them to register a few devices &lt;BR /&gt;</description>
    <pubDate>Mon, 01 Oct 2018 12:15:13 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-10-01T12:15:13Z</dc:date>
    <item>
      <title>Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3715788#M490168</link>
      <description>&lt;P&gt;I am trying to understand the Maximum Concurrent User Sessions from the below link &amp;amp; in my network&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/204463-Configure-Maximum-Concurrent-User-Sessio.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/204463-Configure-Maximum-Concurrent-User-Sessio.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per the link, I understand once the guest user maximum limit is reached, the new device which tries to login should not be allowed to access network( based on newest or oldest connection configured ).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I configured maximum session as 2 &amp;amp; when my 3rd client tries to login, the user is given a warning saying "maximum number of clients is reached, do you wish to continue. " The moment continue is pressed, the 1st logged in MAC address is deleted from the ISE database. However all the 3 clients still continue to access wireless network&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this expected&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nikhil&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Sep 2018 18:02:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3715788#M490168</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2018-09-30T18:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3715798#M490169</link>
      <description>How are you authorizing guest endpoints? If you have a rule that permits guest endpoints access then it won’t matter if you’re using max concurrent user sessions. This only applies to devices that consistently login thru the guest portal&lt;BR /&gt;&lt;BR /&gt;Read the remember me section of the guest deployment guide&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-access-deployment-guide/ta-p/3640475" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-guest-access-deployment-guide/ta-p/3640475&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 30 Sep 2018 19:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3715798#M490169</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-30T19:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3715912#M490170</link>
      <description>&lt;P&gt;Hi Jason,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the quick&amp;nbsp; reply.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes I have configured remember me ( MAB) option, so that the users don't have to login again. However, I didn't understand how this&amp;nbsp;is related to my issue. In my guest portal, I have mentioned to delete the Newest Connection &amp;amp; ISE is deleting the oldest mac from ENDpoint group &amp;amp; all 3 devices are still connected to the network&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have also created a rule for Max Session Reached, redirect to the Web-auth page. This is also not working . May be I am missing something, let me know&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nikhil&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 03:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3715912#M490170</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2018-10-01T03:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716243#M490171</link>
      <description>The 2 aren’t supposed to work together as likely there is no mechanism to kick the user off if the device is not currently in the guest flow (remember me which is straight mab)&lt;BR /&gt;Removing from guest endpoint group likely won’t remove the device radius session &lt;BR /&gt;&lt;BR /&gt;Would recommend instead you disable remember me if you want that functionality&lt;BR /&gt;Or only allow them to register a few devices &lt;BR /&gt;</description>
      <pubDate>Mon, 01 Oct 2018 12:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716243#M490171</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-01T12:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716353#M490172</link>
      <description>&lt;P&gt;I haven't tested this recently, but if you set your maximum registered endpoints to 2 and a person tries to connect a 3rd one, the very first one should be deleted from the endpoint identity group.&amp;nbsp; You should easily be able to see that by looking at the endpoints on the Context Visibility screen.&amp;nbsp; Now just because an endpoint is deleted from the endpoint identity group doesn't mean they are kicked off wireless.&amp;nbsp; That is two different things.&amp;nbsp; You would have to remove them from the SSID on the WLC and see if ISE allows them to connect back again.&amp;nbsp; They should get sent back to the portal on that first MAC address.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 13:07:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716353#M490172</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-01T13:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716374#M490173</link>
      <description>&lt;P&gt;Below are things which I tried&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;I have configured guest portal with max 2 user session allowed&lt;/LI&gt;
&lt;LI&gt;I have configured mab to do remember me&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;I have set the max user session to 2 &amp;amp; disconnect the newest connection&lt;/LI&gt;
&lt;LI&gt;I have connected 2 users &amp;amp; both users haven't disconnected from the first connection&lt;/LI&gt;
&lt;LI&gt;As per point #4, I expect the users are in the GUESTFLOW, with a RADIUS session &amp;amp; not a MAB flow&lt;/LI&gt;
&lt;LI&gt;My 3rd user comes in ( I hope the 3rd user will be using GUEST user initially) &amp;amp; user is given warning of max device limit reached &amp;amp; the user click on the button to "Continue"&lt;/LI&gt;
&lt;LI&gt;When the 3rd user comes in, 1st MAC is removed when I click on continue. I don't think, this is in agreement with my max user session&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;ISE also send a CoA to disconnect the 3rd client, which is expected as per the point #3&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;End result I get all the users in the network, which is not in agreement with the configuration&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 13:23:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716374#M490173</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2018-10-01T13:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716379#M490174</link>
      <description>&lt;P&gt;when I have selected the " Disconnect the newest connection " why the ISE is deleting the oldest mac&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 13:25:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3716379#M490174</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2018-10-01T13:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3717285#M490175</link>
      <description>&lt;P&gt;I could see a close match with an enhancement bug&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCva34969/" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCva34969/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 11:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3717285#M490175</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2018-10-02T11:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3717296#M490176</link>
      <description>Please work through the tac. Your experience doesn’t sound right &lt;BR /&gt;</description>
      <pubDate>Tue, 02 Oct 2018 11:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3717296#M490176</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-02T11:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Concurrent User Sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3717310#M490177</link>
      <description>&lt;P&gt;The bug was shared with me by the TAC&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 12:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-concurrent-user-sessions/m-p/3717310#M490177</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2018-10-02T12:02:58Z</dc:date>
    </item>
  </channel>
</rss>

