<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Guest - Configure Maximum Simultaneous Logins for Endpoint Users in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414138#M547975</link>
    <description>&lt;P&gt;Addendum: I figured that my guest wifi config might be part of the problem. We use Anchors to send the guest ssid to a separate WLC behind a firewall for guest internet access. thought this might be complicating things so i re-configured my guest-test ssid to stay local to the WLC the test WAP is attached to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and after an error getting thrown to me by the browser being unable to access the successful login page redirect and hitting refresh i got sent to the CWA portal and i'm seeing the notification i was expecting! so this seems to be a mobility anchor complication.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="success-local.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/14550i8DFFCC684392C6A3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="success-local.jpg" alt="success-local.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jul 2018 16:17:12 GMT</pubDate>
    <dc:creator>ben.posner</dc:creator>
    <dc:date>2018-07-11T16:17:12Z</dc:date>
    <item>
      <title>ISE Guest - Configure Maximum Simultaneous Logins for Endpoint Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414061#M547973</link>
      <description>&lt;P&gt;Has anyone got the configuration for ISE to limit the maximum simultaneous logins for endpoint users? I'm trying to limit the number of sessions our guest wireless accounts can have and am getting partial success.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example Wireless guest type i'm using has a session limit of 3.&amp;nbsp; in the guest type setup it mentions that you need to check the online help for details on how to build an authZ policy to enforce this. it details setting up an authZ rule that uses the NetworkAccess.SessionLimitExceeded attribute and then setting up a new web redirection. I have done all this and can see in my Live Logs that the 4th login attempt for the guest user IS hitting the new authZ rule for the Session Limit Exceeded attribute and is supposed to be sent the new web redirection. all data from ISE points to this working correctly, except its not. the user gets in, does not get sent to page saying they've hit the limit and then are disconnected 30 seconds later due to the reauthentication timer setup in the authZ result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so it seems like ISE is doing what its supposed to but my WLC's aren't. they are acknowledging the new reauth timer but NOT the URL redirect for the user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:00:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414061#M547973</guid>
      <dc:creator>ben.posner</dc:creator>
      <dc:date>2020-02-21T19:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest - Configure Maximum Simultaneous Logins for Endpoint Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414087#M547974</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="AuthZ Policy" style="width: 618px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/14538i087961340FDFD95A/image-dimensions/618x241?v=v2" width="618" height="241" role="button" title="authZ.jpg" alt="AuthZ Policy" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;AuthZ Policy&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Live Log" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/14551i9A8616BEDAECB098/image-size/large?v=v2&amp;amp;px=999" role="button" title="LiveLog.jpg" alt="LiveLog.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Session Detail" style="width: 629px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/14553iB24119E9572C93CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="livelog-detail.jpg" alt="livelog-detail.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="WLC Session Detail" style="width: 502px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/14552i5367268AF2DCA503/image-size/large?v=v2&amp;amp;px=999" role="button" title="wlc-session.jpg" alt="wlc-session.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 16:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414087#M547974</guid>
      <dc:creator>ben.posner</dc:creator>
      <dc:date>2018-07-11T16:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest - Configure Maximum Simultaneous Logins for Endpoint Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414138#M547975</link>
      <description>&lt;P&gt;Addendum: I figured that my guest wifi config might be part of the problem. We use Anchors to send the guest ssid to a separate WLC behind a firewall for guest internet access. thought this might be complicating things so i re-configured my guest-test ssid to stay local to the WLC the test WAP is attached to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and after an error getting thrown to me by the browser being unable to access the successful login page redirect and hitting refresh i got sent to the CWA portal and i'm seeing the notification i was expecting! so this seems to be a mobility anchor complication.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="success-local.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/14550i8DFFCC684392C6A3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="success-local.jpg" alt="success-local.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 16:17:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414138#M547975</guid>
      <dc:creator>ben.posner</dc:creator>
      <dc:date>2018-07-11T16:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest - Configure Maximum Simultaneous Logins for Endpoint Users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414228#M547976</link>
      <description>&lt;P&gt;addendum 2: moved test WAP and test SSID to the other WLC in the anchor setup and the redirect works there as well so it doesn't seem to be an ACL issue. both WLCs work when setup individually but when in Anchor mode they do not... strange. anyone have any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so this still doesn't work in a production Anchor configuration but will work with ssids running on single WLC setups. so still need help with this since i need it to work with my anchor setup.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 15:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-configure-maximum-simultaneous-logins-for-endpoint/m-p/3414228#M547976</guid>
      <dc:creator>ben.posner</dc:creator>
      <dc:date>2018-07-13T15:20:45Z</dc:date>
    </item>
  </channel>
</rss>

