cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Announcements
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

1175
Views
2
Helpful
3
Replies
Highlighted
Cisco Employee

Limit Concurrent RADIUS User Session

Hi All

This question comes up every so often, do we currently(v2.1?) or are there any plans to support the capability to limit RADIUS authenticated users to a single concurrent user session?

I know this is currently possible for Guest users but my question and the customer use case is specifically focused on non guest users.

This is possibly in ACS and there is a existing ISE feature request, tracked by CSCuq04372

P

Everyone's tags (5)
1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Cisco Employee

Re: Limit Concurrent RADIUS User Session

I would recommend getting this over to the Product PM surasky as a request

From what I understand you can limit it on the active directory side of things but can't find the thread on that right now

View solution in original post

3 REPLIES 3
Highlighted
Cisco Employee

Re: Limit Concurrent RADIUS User Session

I would recommend getting this over to the Product PM surasky as a request

From what I understand you can limit it on the active directory side of things but can't find the thread on that right now

View solution in original post

Highlighted
Cisco Employee

Re: Limit Concurrent RADIUS User Session

Thanks for the reply Jason

Also found a quick and dirty workaround using the Cisco WLC. Will probably only work with a single mobility group as multiple group will create an auth issue when roaming if concurrency is limited to 1.

config advanced eap max-login-ignore-identity-response ?

enable  

ignore the same username reaching max in

the EAP identity response

disablecheck the same username reaching max in the EAP identity response

This is from slide 122 of BRKEWN-2005 presented at Cisco Live Berlin:

https://cisco.box.com/s/omn1dzhf5l005gxvvpx4xtklo4fr0khs

Will be better if implemented on ISE.

Highlighted
Cisco Employee

Re: Limit Concurrent RADIUS User Session

agree and thanks! we are looking to add this into an upcoming release, if you are a customer and have this request please make sure you reach out to your account team to get in a request