<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I'm having the same problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467332#M86964</link>
    <description>I'm having the same problem on our network using ACS VM 5.5 with the latest update patch, it is used to authenticate wireless users from a Cisco WLC 4402 7.0.220 using aaa radius, authentication and accounting is working fine acs is receiving radius start / stop accounting messages but user session limit for a group is set to 1 but not working, users are authenticated either via AD with group mapping to a local identity group or a local internal user from a specific identity group, the issue is for both type of users</description>
    <pubDate>Sat, 02 Aug 2014 09:42:10 GMT</pubDate>
    <dc:creator>habib.souag</dc:creator>
    <dc:date>2014-08-02T09:42:10Z</dc:date>
    <item>
      <title>ACS 5.5 - AD user session limit</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467330#M86960</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been looking for the solution of my problem since quite long but still no luck. My client needs to restrict Active Directory users to login to one device at a time and he wants this to be done by ACS. He has been using ACS 4.2 and he has recently upgraded it to version 5.5. I have tried the Maximum user session limit option but it is not working as per the requirement. Is there any way that this can be achieved? The limit needs to be applied on Per user basis as some of the executives need to be excluded as well. Looking forward for your response.&lt;/P&gt;&lt;P&gt;Regards, Sohail&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467330#M86960</guid>
      <dc:creator>Sohail Muhammad</dc:creator>
      <dc:date>2019-03-11T04:35:25Z</dc:date>
    </item>
    <item>
      <title> Hi Sohail, We need to keep</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467331#M86962</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Hi Sohail,&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;We need to keep in mind that:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;To make the maximum sessions work for user access like wireless, vpn etc, the administrator should configure RADIUS accounting.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;To make the maximum sessions work for device management, the administrator should configure TACACS+ session authorization and accounting&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;For optimal performance, you can limit the number of concurrent users accessing network resources. ACS 5.5 imposes limits on the number of concurrent service sessions per user.&lt;BR /&gt;The limits are set in several different ways. You can set the limits at the user level or at the group level. Depending upon the maximum user session configurations, the session count is applied to the user.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;The below listed link may come handy while confguring the same feature.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/user/guide/acsuserguide/access_policies.html#pgfId-1176806&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="verdana, geneva, sans-serif"&gt;&lt;SPAN style="font-size: 11.818181991577148px;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="verdana, geneva, sans-serif"&gt;&lt;SPAN style="font-size: 11.818181991577148px;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Mar 2014 07:46:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467331#M86962</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-03-30T07:46:28Z</dc:date>
    </item>
    <item>
      <title>I'm having the same problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467332#M86964</link>
      <description>I'm having the same problem on our network using ACS VM 5.5 with the latest update patch, it is used to authenticate wireless users from a Cisco WLC 4402 7.0.220 using aaa radius, authentication and accounting is working fine acs is receiving radius start / stop accounting messages but user session limit for a group is set to 1 but not working, users are authenticated either via AD with group mapping to a local identity group or a local internal user from a specific identity group, the issue is for both type of users</description>
      <pubDate>Sat, 02 Aug 2014 09:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467332#M86964</guid>
      <dc:creator>habib.souag</dc:creator>
      <dc:date>2014-08-02T09:42:10Z</dc:date>
    </item>
    <item>
      <title>Hello, everyone!I have the</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467333#M86967</link>
      <description>&lt;P&gt;Hello, everyone!&lt;/P&gt;&lt;P&gt;I have the same problem.&amp;nbsp;ACS 5.5.0.46.7, WLC 5508, authentication with AD.&lt;/P&gt;&lt;P&gt;I made AD group mapping, configured RADIUS accounting (I can see "start" &amp;nbsp;and "stop" RADIUS messages in log). All things work fine (Group mapping works right, authentication passing is OK). But&amp;nbsp;&amp;nbsp;the maximum session for one user&amp;nbsp;restriction doesn't work at all. I tried to make&amp;nbsp;it at global and at group level, but ACS just ignore this condition.&lt;/P&gt;&lt;P&gt;Do you have any idea how to troubleshoot this problem?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2015 07:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-5-ad-user-session-limit/m-p/2467333#M86967</guid>
      <dc:creator>Aleksey Bolotin</dc:creator>
      <dc:date>2015-01-29T07:46:10Z</dc:date>
    </item>
  </channel>
</rss>

