08-15-2017 12:45 AM
Hi, ISE expert.
Would like to ask a question about ISE concurrent user session.
customer use GGSN with ISE as radius authentication server , if our user get authenticated , does ISE keep the user sessions until the account stop message come ? or Do we have some approach to shorten the session keeping time ?
thanks
hongtao
Solved! Go to Solution.
08-15-2017 05:17 AM
Short answer is that RADIUS Accounting will trigger Start and Stop of session. In lieu of RADIUS Accounting, other measures are taken to manage ISE sessions. This topic is covered in BRKSEC-3699 session (see reference presentation on CiscoLive.com). Here is excerpt:
Clearing Stale Sessions
Note: Session is cleared from MnT but does not generate CoA to prevent negative impact to connected endpoints. In other words, MnT session is no longer visible but it is possible for endpoint to still have network access, but no longer consumes license.
/Craig
08-15-2017 05:17 AM
Short answer is that RADIUS Accounting will trigger Start and Stop of session. In lieu of RADIUS Accounting, other measures are taken to manage ISE sessions. This topic is covered in BRKSEC-3699 session (see reference presentation on CiscoLive.com). Here is excerpt:
Clearing Stale Sessions
Note: Session is cleared from MnT but does not generate CoA to prevent negative impact to connected endpoints. In other words, MnT session is no longer visible but it is possible for endpoint to still have network access, but no longer consumes license.
/Craig
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide