cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3939
Views
0
Helpful
5
Replies

Terminate user session

f.colantoni
Level 1
Level 1

I use cisco ISE 1.4 and self-registered user portal.

All it's ok and an external user can register itself and login.

But the user session remain active also if I turn off the device.

Every active device use one license and if it's always active I have a license locked.

How can I terminate the sessions or disconnect the user ?

Thanks

 

5 Replies 5

Venkatesh Attuluri
Cisco Employee
Cisco Employee

Self registered guest accounts expire according to the time profile/guest types assigned to them and we have guest purge policy for expired guest account. Active self registered guest accounts can be manged from sponsor portal

OK. The users expire and I can manage them with the sponsor portal but the endpoint still use a license.

I'd like to know how can I configure the endpoint to expire and free the license count.

Thanks

In ISE 1.4 you could use endpoint purge, to remove the mac address registered in your guest endpoints group after x number of days.

I've tried both user and endpoint purge policy and it works but there are always some active endpoint, that I can see in Authentication menu (live) locked on "Radius account strat request", and licenses used in Administration/licenses even if there isn't Autenticated users or endpoint.

I notice that when I de-associate and endpoint the number of Active endpoint and licenses decrease.

Is possible to force SSID de-assciation of endpoint ?

It seems the only way to clean the license and active andpoint number number.

Thanks

I've tried both user and endpoint purge policy and it works but there are always some active endpoint, that I can see in Authentication menu (live) locked on "Radius account strat request", and licenses used in Administration/licenses even if there isn't Autenticated users or endpoint.

I notice that when I de-associate and endpoint the number of Active endpoint and licenses decrease.

Is possible to force SSID de-assciation of endpoint ?

It seems the only way to clean the license and active andpoint number number.

Thanks