cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2444
Views
2
Helpful
3
Replies

Limit Concurrent RADIUS User Session

pbeyleve
Cisco Employee
Cisco Employee

Hi All

This question comes up every so often, do we currently(v2.1?) or are there any plans to support the capability to limit RADIUS authenticated users to a single concurrent user session?

I know this is currently possible for Guest users but my question and the customer use case is specifically focused on non guest users.

This is possibly in ACS and there is a existing ISE feature request, tracked by CSCuq04372

P

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

I would recommend getting this over to the Product PM surasky as a request

From what I understand you can limit it on the active directory side of things but can't find the thread on that right now

View solution in original post

3 Replies 3

Jason Kunst
Cisco Employee
Cisco Employee

I would recommend getting this over to the Product PM surasky as a request

From what I understand you can limit it on the active directory side of things but can't find the thread on that right now

Thanks for the reply Jason

Also found a quick and dirty workaround using the Cisco WLC. Will probably only work with a single mobility group as multiple group will create an auth issue when roaming if concurrency is limited to 1.

config advanced eap max-login-ignore-identity-response ?

enable  

ignore the same username reaching max in

the EAP identity response

disablecheck the same username reaching max in the EAP identity response

This is from slide 122 of BRKEWN-2005 presented at Cisco Live Berlin:

https://cisco.box.com/s/omn1dzhf5l005gxvvpx4xtklo4fr0khs

Will be better if implemented on ISE.

agree and thanks! we are looking to add this into an upcoming release, if you are a customer and have this request please make sure you reach out to your account team to get in a request