cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
711
Views
0
Helpful
1
Replies

How to limit max sessions per users and per group in Cisco ACS when using LDAP?

slizarraga
Level 1
Level 1

I am using an ACS that uses an external identity store which is an AD server, I have configured to use LDAP.

I want to limit the max sessions per user and per group, but the limit only works on the Identity Groups, and non of my users are in Identity groups.  I thought I had 2 options:

 - Limit in my external identity store (it seems not possible)
 - Associate my LDAP groups to my Identity group

How can I implement the 2nd option??

Thanks for your help!!

(I saw a forum note that ask pretty much the same, but the link does not show how to make this association). 
I have an attach with more info.

1 Reply 1

Gagandeep Singh
Cisco Employee
Cisco Employee

Hi,

You can map LDAP or AD groups to Group mapping option for internal group.

Under Access policy > Default Device Administration > Group Mapping.

Still session limitation is on internal users.

Regards

Gagan

PS: rate if it helps!!!!