<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limiting user login access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543312#M519277</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no alarm to alert the same user logging more than once.&lt;/P&gt;&lt;P&gt;Like Charles and Ognyan said, ISE 2.2+ has max sessions to limit per user, which applies to external users as well, and per internal-user-group. These settings are per PSN, unlike the guest max sessions, which are per deployment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 10 Dec 2017 01:52:31 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-12-10T01:52:31Z</dc:date>
    <item>
      <title>Limiting user login access</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543309#M519271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know we can control the number of sessions per user&lt;/P&gt;&lt;P&gt;Is there a way to alert if a user attempts more then one login, while policy permits multiple logins?&lt;/P&gt;&lt;P&gt;This would be ISE 2.3&lt;/P&gt;&lt;P&gt;Maybe Stealthwatch integration&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 16:57:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543309#M519271</guid>
      <dc:creator>lcammara</dc:creator>
      <dc:date>2017-12-07T16:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting user login access</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543310#M519274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was introduced in ISE 2.3.&amp;nbsp; Go to Administration &amp;gt; System &amp;gt; Settings &amp;gt; Max Sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can choose to enforce Maximum session based upon user, group&lt;/P&gt;&lt;P&gt;&lt;IMG alt="MaxSessionsPerUser.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114011_MaxSessionsPerUser.PNG" style="height: 287px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This applies to Internal ISE Users and groups only.&amp;nbsp; Also the enforcement is the max PER POLICY NODE.&amp;nbsp; Here's the page in the Admin Guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01110.html#id_30990" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01110.html#id_30990"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.3 - Manage Users and External Identity Sources [Cisco Ide…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 17:55:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543310#M519274</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-12-07T17:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting user login access</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543311#M519276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ise 2.2 support this future too.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114025_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2017 09:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543311#M519276</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2017-12-08T09:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting user login access</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543312#M519277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no alarm to alert the same user logging more than once.&lt;/P&gt;&lt;P&gt;Like Charles and Ognyan said, ISE 2.2+ has max sessions to limit per user, which applies to external users as well, and per internal-user-group. These settings are per PSN, unlike the guest max sessions, which are per deployment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Dec 2017 01:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543312#M519277</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-12-10T01:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting user login access</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543313#M519282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi hslai,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to confirm the per user limit also apply for RADIUS authentication? (802.1x to be specified)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Wing Churn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:38:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543313#M519282</guid>
      <dc:creator>wileong</dc:creator>
      <dc:date>2018-03-19T15:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting user login access</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543314#M519287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct. This is mainly used for RADIUS authentications.&lt;/P&gt;&lt;P&gt;It's not working well for T+, due to some existing bug, such as CSCvg26552.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:09:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3543314#M519287</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-19T16:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting user login access</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3680053#M519291</link>
      <description>Is this known to work with certificates as the external user database? &lt;BR /&gt;&lt;BR /&gt;Is there anything planned to make this work across multiple PSNs using the MnT or some other solution?&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Thu, 02 Aug 2018 14:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3680053#M519291</guid>
      <dc:creator>ruhearn</dc:creator>
      <dc:date>2018-08-02T14:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting user login access</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3681394#M519295</link>
      <description>&lt;P&gt;I have not tested it with certificates myself but am expecting it working with the username/subject based on the cert auth profile(s).&lt;/P&gt;
&lt;P&gt;Sure, we are looking into multiple PSN. Please discuss your use cases and customer requirements with our PM.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Aug 2018 00:40:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-user-login-access/m-p/3681394#M519295</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-08-05T00:40:12Z</dc:date>
    </item>
  </channel>
</rss>

