cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
205
Views
0
Helpful
1
Replies

ISE session limit vs Group Policy session limit who wins?

cgarringer
Beginner
Beginner

We have ISE authentication on VPN, when successful ISE returns the session timout, idle timeout and the Group Policy .    The Group Policy configured on the FMC also sets the session and idle timeouts.     We appear to be getting  mixed results, some users are getting ISE limits and some are getting the Group Policy limits.   Which is supposed to have priority?

1 Reply 1

Milos_Jovanovic
Engager
Engager

Hi @cgarringer,

There is a priority for standard attributes which can be defined in multiple points (e.g. IP pool can be defined under tunnel-group, but also under group-policy). You can find more details here. Depending on how you configured these attributes, they will either take presedence from AAA server or from local ASA configuration.

Kind regards,

Milos

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers