02-05-2014 06:20 AM - edited 07-05-2021 12:05 AM
need to configure Max Concurrent Logins for a user name on SSID wise in WLC 5508.
I don't want to use the below,
Choose SECURITY > AAA > User Login Policies to navigate to the User Policies page.
This page enables you to specify the maximum number of concurrent logins for a single username, 0 (unlimited) through eight.
because this cannot be configured for an specific SSID or for an specific user, it is global for all users and all SSIDs
In simple ways i have two SSID, want to configure like below.
"SSID1" - need to allow unlimited concurrent users for a single username
"SSID2" - need to limit concurrent users for a single username.
Is there any way to achive this?
Solved! Go to Solution.
02-05-2014 06:38 AM
HI Muthu,
Are you using ISE(identity service engine ) ????
If yes then after ISE version 1.2 you can use this feautre:
This is a global setting affecting all Guest portals.
Step 1 Choose Administration > Web Portal Management > Settings > Guest > Portal Policy.
Step 2 Check the Allow only one guest session per user option.
Step 3 Click Save.
Check this screenshot:
Or the other method is(which u dont want to use) Choose SECURITY > AAA > User Login Policies to navigate to the User Policies page.
as per my knowledge you can use ionly these two option.
Reagrds
Dont forget to rate helpful posts
02-05-2014 08:31 AM
The concurrent login is for both... you will not be able to do what you want.
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
02-05-2014 06:38 AM
HI Muthu,
Are you using ISE(identity service engine ) ????
If yes then after ISE version 1.2 you can use this feautre:
This is a global setting affecting all Guest portals.
Step 1 Choose Administration > Web Portal Management > Settings > Guest > Portal Policy.
Step 2 Check the Allow only one guest session per user option.
Step 3 Click Save.
Check this screenshot:
Or the other method is(which u dont want to use) Choose SECURITY > AAA > User Login Policies to navigate to the User Policies page.
as per my knowledge you can use ionly these two option.
Reagrds
Dont forget to rate helpful posts
02-05-2014 06:40 AM
Using the WLC, there is not a good way of doing what you want. That login limit is global. The other thing is how are you authenticating users? If your using 802.1x, users should only be able to associate to one SSID, not both or else the policies can be tricky and not work. If users can only authenticate to one SSID, then you might be able to add a condition to the policy to check if the login has been used. If you don't have a radius server and just trying to use the WLC, then it's not possible.
Sent from Cisco Technical Support iPhone App
02-05-2014 06:46 AM
I'm using [WPA2][Auth(802.1X)] - "SSID1" and Web-Auth - "SSID2"
02-05-2014 06:50 AM
Well unless the WebAuth is also hitting your radius, there is no way to do what you want.
Sent from Cisco Technical Support iPhone App
02-05-2014 07:03 AM
02-05-2014 08:31 AM
The concurrent login is for both... you will not be able to do what you want.
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide