cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
624
Views
0
Helpful
1
Replies

How to limit max sessions per users and per group in Cisco ACS when using LDAP?

slizarraga
Level 1
Level 1

I am using an ACS that uses an external identity store which is an AD server, I have configured to use LDAP.

I want to limit the max sessions per user and per group, but the limit only works on the Identity Groups, and non of my users are in Identity groups.  I thought I had 2 options:

 - Limit in my external identity store (it seems not possible)
 - Associate my LDAP groups to my Identity group

How can I implement the 2nd option??

Thanks for your help!!

(I saw a forum note that ask pretty much the same, but the link does not show how to make this association). 
I have an attach with more info.

1 Reply 1

Gagandeep Singh
Cisco Employee
Cisco Employee

Hi,

You can map LDAP or AD groups to Group mapping option for internal group.

Under Access policy > Default Device Administration > Group Mapping.

Still session limitation is on internal users.

Regards

Gagan

PS: rate if it helps!!!!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: