<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ok, I need to make sure that in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677187#M55820</link>
    <description>&lt;P&gt;ok, I need to make sure that I understand this correctly.&amp;nbsp; First, I need to active the Group mapping policy under the Access Service.&lt;/P&gt;&lt;P&gt;Then, in the Group Mapping policy, I would need to Select Rule based selection and create a rule that will account for compound conditions.&amp;nbsp; It looks like this is required because the compound conditions will allow me to use other sources besides the local ACS groups.&lt;/P&gt;&lt;P&gt;It looks like I need to select a Dictionary (in this case it would be AD) and then an attribute (in this case the name of the AD group).&amp;nbsp; That would be the condition set.&amp;nbsp; Then the result would be mapping it to some local wifi group on ACS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the next part of this would be to use the Max Session user settings to limited the sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is my understanding accurate?&amp;nbsp; It sounds very promising!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 May 2015 20:46:24 GMT</pubDate>
    <dc:creator>jlhainy</dc:creator>
    <dc:date>2015-05-07T20:46:24Z</dc:date>
    <item>
      <title>How to limit number of devices users can authenticate to wifi</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677181#M55814</link>
      <description>&lt;P&gt;We are using PEAP to authenticate wireless users via their Active Directory Accounts.&amp;nbsp; Is there any way to keep a user by username from authenticating to more than 2 devices?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677181#M55814</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2019-03-11T05:42:01Z</dc:date>
    </item>
    <item>
      <title>What type of wireless setup</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677182#M55815</link>
      <description>&lt;P&gt;What type of wireless setup do you have and what do you use for a Radius server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 07:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677182#M55815</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-05-04T07:12:51Z</dc:date>
    </item>
    <item>
      <title>We have over 1000 APs at 40</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677183#M55816</link>
      <description>&lt;P&gt;We have over 1000 APs at 40 locations, The APs are controlled by 4 WiSM2 blades.&amp;nbsp; We are using ACS 5.5x as our radius source and it is joined to AD to take advantage of AD groups.&lt;/P&gt;&lt;P&gt;What we are finding is that when users are prompted to change their passwords, they do so on their workstation, but forget to change their credentials on their wireless device.&amp;nbsp; With client exclusion, that helps, but if they have 2 or 3 personal devices, they exceed their failed login attempt count on their AD account and they get locked.&amp;nbsp; What we would like to do is somehow limit them so that they can only use their AD account on one or two devices and if they try a 3rd, the wireless system would automatically deny them and not even try to authenticate, thus stopping more login attempts and not locking accounts.&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 13:41:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677183#M55816</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2015-05-04T13:41:55Z</dc:date>
    </item>
    <item>
      <title>Have you tried the "Max User</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677184#M55817</link>
      <description>&lt;P&gt;Have you tried the "Max User Session" setting in ACS?&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-3/user/guide/acsuserguide/access_policies.html#77244"&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-3/user/guide/acsuserguide/access_policies.html#77244&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 16:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677184#M55817</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-05-04T16:00:00Z</dc:date>
    </item>
    <item>
      <title>But, that appears to only</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677185#M55818</link>
      <description>&lt;P&gt;But, that appears to only apply to local users on ACS.&amp;nbsp; These users are Active Directory and ACS just relays the authentication requests to AD.&amp;nbsp; Would this still work?&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 18:33:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677185#M55818</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2015-05-05T18:33:54Z</dc:date>
    </item>
    <item>
      <title>Yes, you are correct about</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677186#M55819</link>
      <description>&lt;P&gt;Yes, you are correct about this feature only applying to internal groups/users. However, you can map the AD based groups to Internal ACS groups and that way this feature would apply to the AD based groups too &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Check out the user guide and let us know if you have issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 22:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677186#M55819</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-05-05T22:46:18Z</dc:date>
    </item>
    <item>
      <title>ok, I need to make sure that</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677187#M55820</link>
      <description>&lt;P&gt;ok, I need to make sure that I understand this correctly.&amp;nbsp; First, I need to active the Group mapping policy under the Access Service.&lt;/P&gt;&lt;P&gt;Then, in the Group Mapping policy, I would need to Select Rule based selection and create a rule that will account for compound conditions.&amp;nbsp; It looks like this is required because the compound conditions will allow me to use other sources besides the local ACS groups.&lt;/P&gt;&lt;P&gt;It looks like I need to select a Dictionary (in this case it would be AD) and then an attribute (in this case the name of the AD group).&amp;nbsp; That would be the condition set.&amp;nbsp; Then the result would be mapping it to some local wifi group on ACS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the next part of this would be to use the Max Session user settings to limited the sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is my understanding accurate?&amp;nbsp; It sounds very promising!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2015 20:46:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677187#M55820</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2015-05-07T20:46:24Z</dc:date>
    </item>
    <item>
      <title>You got it boss! :) Give it a</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677188#M55821</link>
      <description>&lt;P&gt;You got it boss! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Give it a try and let me/us know if you have any issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2015 17:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677188#M55821</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-05-11T17:53:40Z</dc:date>
    </item>
    <item>
      <title>OK.  I completed the group</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677189#M55822</link>
      <description>&lt;P&gt;OK.&amp;nbsp; I completed the group mapping policy.&amp;nbsp; I am assuming it's working because I do see a hit count on the rule I created to map an AD group to an internal ACS group.&lt;/P&gt;&lt;P&gt;Then I went to the Max Session Group Setting and set the max sessions for the group as a whole as unlimited and the Max Session for User in Group to two, because I only want a users to connect two devices.&lt;/P&gt;&lt;P&gt;So, I went ahead and connect 2 devices and when I connected the 3rd device, I expected not to be able to connect with some kind of error to show up in the ACS logs... the 3rd devices connected.&amp;nbsp; So, I am wondering if I am misunderstanding the Max Sessions settings.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2015 20:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677189#M55822</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2015-05-11T20:06:23Z</dc:date>
    </item>
    <item>
      <title>Hi Neno,is this feature also</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677190#M55823</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;&lt;P&gt;is this feature also works onTACACS+ ?&amp;nbsp;&lt;BR /&gt;i had some trouble on this feature too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2015 03:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677190#M55823</guid>
      <dc:creator>alek.gozali</dc:creator>
      <dc:date>2015-05-12T03:45:49Z</dc:date>
    </item>
    <item>
      <title>It has been a while since I</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677191#M55824</link>
      <description>&lt;P&gt;It has been a while since I have worked with ACS but what you have outlined sounds good. I am away from home now and can't test this in my lab so I would advise you reach out to TAC or double check your configs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 00:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-limit-number-of-devices-users-can-authenticate-to-wifi/m-p/2677191#M55824</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-05-14T00:58:37Z</dc:date>
    </item>
  </channel>
</rss>

