09-15-2017 02:50 AM
Hi all,
Currently I have PoV in my customer with a use case where they want to secure multiple user session from single Windows Host PC.
So it basically like this:
Anyone have idea or experience how to achieve this?
Maybe with implement Trustsec SGT can achieve this?
I tried to use multi-auth in switch port, but failed. only the first user have to authenticate, the rest will be automatically authenticated.
Any idea will help.
Thank you in advanced.
Regards,
Kevin
Solved! Go to Solution.
09-15-2017 07:23 AM
You're saying that at one time on same operating system multiple people will be logged in?
No there is no way for the client to do this
The client would have to provide a Dot1x session for each user that logs in so that we can authenticate and provide different access permissions (Tag)
09-15-2017 03:55 AM
I tried to use multi-auth in switch port, but failed. only the first user have to authenticate, the rest will be automatically authenticated.
This is a limitation of RDP. Microsoft has no plans (publicly) to change this.
09-15-2017 07:23 AM
You're saying that at one time on same operating system multiple people will be logged in?
No there is no way for the client to do this
The client would have to provide a Dot1x session for each user that logs in so that we can authenticate and provide different access permissions (Tag)
09-17-2017 07:58 PM
Hi Jason,
So you're saying that there's no way to authenticate each user that log in from same windows OS at the same time?
09-17-2017 08:14 PM
Correct. 802.1X is for the endpoint client device as a whole. Thus, either allow one user login at a time, or authenticate computer instead of user.
09-17-2017 08:17 PM
Hi hslai,
You say that authenticate computer instead, is it mean machine authentication? Can this be use to authenticate multiple user login?
09-17-2017 08:25 PM
The computer auth is on the 802.1X supplicant level for network access. RDP user login will be done by the regular Windows remote terminal access, either local or by Active Directory.
09-18-2017 12:16 AM
So it means, for the time being, there's no way to authenticate multiple users that are login to a single windows, even with Trustsec SGT solution? I just need to clarified that so I can move to alternative solution to secure the environment with ISE.
09-18-2017 06:37 AM
That is correct.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide