This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
Hi All
This question comes up every so often, do we currently(v2.1?) or are there any plans to support the capability to limit RADIUS authenticated users to a single concurrent user session?
I know this is currently possible for Guest users but my question and the customer use case is specifically focused on non guest users.
This is possibly in ACS and there is a existing ISE feature request, tracked by CSCuq04372
P
Solved! Go to Solution.
I would recommend getting this over to the Product PM surasky as a request
From what I understand you can limit it on the active directory side of things but can't find the thread on that right now
I would recommend getting this over to the Product PM surasky as a request
From what I understand you can limit it on the active directory side of things but can't find the thread on that right now
Thanks for the reply Jason
Also found a quick and dirty workaround using the Cisco WLC. Will probably only work with a single mobility group as multiple group will create an auth issue when roaming if concurrency is limited to 1.
config advanced eap max-login-ignore-identity-response ?
enable | ignore the same username reaching max in the EAP identity response |
disable | check the same username reaching max in the EAP identity response |
This is from slide 122 of BRKEWN-2005 presented at Cisco Live Berlin:
https://cisco.box.com/s/omn1dzhf5l005gxvvpx4xtklo4fr0khs
Will be better if implemented on ISE.
agree and thanks! we are looking to add this into an upcoming release, if you are a customer and have this request please make sure you reach out to your account team to get in a request