<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE with F5 and Concurrent Sessions per User in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4976115#M585664</link>
    <description>&lt;P&gt;The users are storred localy in ISE.&lt;/P&gt;
&lt;P&gt;Access method is Wireless&lt;/P&gt;
&lt;P&gt;Auth is 802.1x&amp;nbsp;&lt;SPAN&gt;username/password&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Dec 2023 11:28:18 GMT</pubDate>
    <dc:creator>Teymur Aghayev</dc:creator>
    <dc:date>2023-12-12T11:28:18Z</dc:date>
    <item>
      <title>ISE with F5 and Concurrent Sessions per User</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4975363#M585637</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I am, currently in the process of designing a network that requires specific limitations on the number of concurrent sessions per user, for example 3 sessions for regular employees and 6 sessions for managers. My understanding is that ISE can manage concurrent sessions per PSN node. However, in our configuration we have PSNs behind F5 load balancers.&lt;/P&gt;
&lt;P&gt;So, as I understand, we need to ensure that all RADIUS requests for the same user are directed to the same PSN, additionally, we need to ensure that all RADIUS packets with the same Calling-Station-ID are also routed to the same PSN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is my understanding right and if yes&amp;nbsp;how it can be implemented effectively.&lt;/P&gt;
&lt;P&gt;Upon reviewing the available documentation and support community topics, I have not been able to find a solution that specifically addresses this requirement.&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 09:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4975363#M585637</guid>
      <dc:creator>Teymur Aghayev</dc:creator>
      <dc:date>2023-12-11T09:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with F5 and Concurrent Sessions per User</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4975488#M585641</link>
      <description>&lt;P&gt;Where are the users?&amp;nbsp; Local on ISE?&amp;nbsp; AD?&amp;nbsp; SAML IDP?&amp;nbsp; Somewhere else?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also what are the use-cases?&amp;nbsp; Wired?&amp;nbsp; Wireless?&amp;nbsp; VPN?&amp;nbsp; What is the auth method?&amp;nbsp; Certificates?&amp;nbsp; username/password?&amp;nbsp; Machine and/or user authentication?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 13:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4975488#M585641</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-12-11T13:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with F5 and Concurrent Sessions per User</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4976115#M585664</link>
      <description>&lt;P&gt;The users are storred localy in ISE.&lt;/P&gt;
&lt;P&gt;Access method is Wireless&lt;/P&gt;
&lt;P&gt;Auth is 802.1x&amp;nbsp;&lt;SPAN&gt;username/password&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 11:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4976115#M585664</guid>
      <dc:creator>Teymur Aghayev</dc:creator>
      <dc:date>2023-12-12T11:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with F5 and Concurrent Sessions per User</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4976180#M585671</link>
      <description>&lt;P&gt;Administration &amp;gt; System &amp;gt; Settings &amp;gt; Max Sessions&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 12:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4976180#M585671</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-12-12T12:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with F5 and Concurrent Sessions per User</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4977950#M585723</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The primary concern in our network setup is ensuring that RADIUS requests from the same user consistently land on the same PSN when routed through F5 load balancers. This is crucial for the proper functioning of the Max Sessions feature in Cisco ISE, which operates on a per-PSN basis. We are looking for a solution that guarantees this consistent routing. Additionally, we need to manage RADIUS packets with the same Calling-Station-ID in a similar manner, ensuring they are also directed to the same PSN.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 12:21:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4977950#M585723</guid>
      <dc:creator>Teymur Aghayev</dc:creator>
      <dc:date>2023-12-14T12:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with F5 and Concurrent Sessions per User</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4977954#M585724</link>
      <description>You should be able to do both of these things with F5 persistence in an irule. You can match on the username for example.&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Dec 2023 12:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-f5-and-concurrent-sessions-per-user/m-p/4977954#M585724</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-12-14T12:33:32Z</dc:date>
    </item>
  </channel>
</rss>

