User Group wise device limit in cisco ISE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-06-2023 10:23 PM
Dear Good People,
We have created wlan in cisco wlc 9800. WLC is integrated with ISE. Now we need to create some user groups as per wifi users like Group1 can access 3 devices (Mobile, Laptop, Gadget), Group2 can access 2 devices (Mobile, Laptop) etc. Please guide me how can we configure this in ISE ?
- Labels:
-
Identity Services Engine (ISE)

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2023 12:13 PM
Great question @King_1988
ISE has had such a feature for a long time. I have never used it myself. The trick is to be able to identify the user somehow. In this case, if your usernames are defined in ISE User Identity Groups, you can impose a limit per Group - what ISE does, is it counts the max number of MAC endpoints associated with that user. Not sure if this also works with users in Active Directory Groups.
What type of SSID is this? 802.1X?
If it's Pre-Shared SSID then I think you're out of luck, because you have no way to determine who the user is (no username).
Again, like I said, I have not used this before. Give it a try.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2023 07:09 PM
If the users are created as ISE guest users, then ISE allows different guest types to have different maximum devices guests can register. See Create or Edit Guest Types.
