cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
440
Views
5
Helpful
5
Replies

block simultaneous logins by the same user on wired 802.1x

nir-r
Level 4
Level 4

Is it possible to block simultaneous logins by the same user, meaning is userX login on port gi1/0/1 and after that the same user (UserX) is trying to login on a different port, it will be blocked.

 

 

5 Replies 5

nspasov
Cisco Employee
Cisco Employee

The policies that you apply on your Radius server would apply to all ports on the switch (unless you have some exceptions), thus it wouldn't matter where the user is connecting as he/she would get "access-reect" thus preventing him/her from getting access to the network. 

I hope this helps!

 

Thank you for rating helpful posts!

This isn't what I am looking for. ISE has the information about live sessions, I would like to prevent multiple authentication with the same username on wired dot1x

nspasov
Cisco Employee
Cisco Employee

Sorry I did not read your original question correctly. So at the moment, you can only restrict the number of concurrent connections for users that are only going through the web authentication process. If you are using EAP-TLS, PEAP, etc, then there is no method to restrict those users from performing multiple authentications on the network.

 

Thank you for rating helpful posts!

Thanks, Hope to have this feature in ISE or PEAP and EAP-TLS.

nspasov
Cisco Employee
Cisco Employee

Yeah, unfortunately, it is not an option as of the latest version. I know that it has been suggested before so hopefully Cisco will develop this enhancement.

 

Thank you for rating helpful posts!