Overview
The article explains how such RADIUS policies can be configured in the AAA to apply a double session restriction mechanism with intra-site and cross-site scenarios. Once implemented the Specific radius service policy will have restrictions on the concurrent session of user(s).
Solution
Configure the following on AAA SM -
- Plugin configured - CONCURRENT_POLICY_PLUGIN
- If Cross site session restrictions are needed configure the Cross-site Session Manager:
- The Cross-Site Session manager needs to be configured in the AAA attached in the auth service flow of Radius Service policies that were identified by the customer:
- After configuring these restart AAA
Verification
Verify that New Users will not be able to connect using the same login details on AAA, only Single Session will be allowed to such users.
It is recommended to implement such solutions in the test systems before applying in production.
Priyanka Bhotika
Comments