cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
536
Views
5
Helpful
4
Replies

Prevent Multiple Same Username Logon

CSCO11177789
Level 1
Level 1

Hi all,

We're using Catalyst 9800 cont.  and 801.x peap with ldap username on one of ssid profile. Unfortunately ,some users gave their credentials to others and they logon same username/password.

Is there any way to prevent this ? 

Best regards

4 Replies 4

I am not quite sure but during PEAP auth the WLC need user cert. And password.

Are you sure it PEAP not WPA2/WPA3

MHM

Actually profile has wpa2/wpa3 , 802.1x, aes settings also on AAA tab  i'm using NPS server for authentication for ldap users on active directory. This ssid  only using for users own android/ios devices internet connection because of this i prefer peap/mschapv2 (on NPS policy) instead of eap/tls.

if it wpa2/wpa3 we can not do anything 
you need to use different L2 security

MHM 

Haydn Andrews
VIP Alumni
VIP Alumni

Couple methods you could use:

  1. The NPS server may be able to have a policy created locking the number of logins down to X number of devices, alternatively it may allow you to do some MFA so the user has to accept the connection (although this would also impact good users).
  2. Management enforcing it and when caught breaching the corporate IT policy issuing disciplinary action against them, word will spread.
  3. EAP-TLS/ EAP-TEAP and certificates are really the only way to prevent it.

 

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card