07-26-2016 04:27 AM
Hi All
This question comes up every so often, do we currently(v2.1?) or are there any plans to support the capability to limit RADIUS authenticated users to a single concurrent user session?
I know this is currently possible for Guest users but my question and the customer use case is specifically focused on non guest users.
This is possibly in ACS and there is a existing ISE feature request, tracked by CSCuq04372
P
Solved! Go to Solution.
07-26-2016 08:08 AM
I would recommend getting this over to the Product PM surasky as a request
From what I understand you can limit it on the active directory side of things but can't find the thread on that right now
07-26-2016 08:08 AM
I would recommend getting this over to the Product PM surasky as a request
From what I understand you can limit it on the active directory side of things but can't find the thread on that right now
07-27-2016 05:29 AM
Thanks for the reply Jason
Also found a quick and dirty workaround using the Cisco WLC. Will probably only work with a single mobility group as multiple group will create an auth issue when roaming if concurrency is limited to 1.
config advanced eap max-login-ignore-identity-response ?
enable | ignore the same username reaching max in the EAP identity response |
disable | check the same username reaching max in the EAP identity response |
This is from slide 122 of BRKEWN-2005 presented at Cisco Live Berlin:
https://cisco.box.com/s/omn1dzhf5l005gxvvpx4xtklo4fr0khs
Will be better if implemented on ISE.
07-27-2016 08:03 AM
agree and thanks! we are looking to add this into an upcoming release, if you are a customer and have this request please make sure you reach out to your account team to get in a request
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide