Solved

How to configure IAS in Server 2003 to configure a Radius server for use with Cisco VPN Concentrators

Posted on 2011-02-15
4
765 Views
Last Modified: 2012-06-21
Currently I have a three Cisco VPN Concentrators that are load balanced.  I have a Windows 2003 server for my Radius server.  This allows users to log in to the Cisco VPN Client with their Active Directory User name and password.  This is my question.  Is there anywhere in the Cisco Concentrator or the IAS Server that will allow for example "John Doe" to only be able to log in once.  What I'm trying to prevent is the same user logging in multiple times.  When I look in the concentrator and go to the general tab of the group, there is an option for Simultaneous Logins, but this is for simultaneous logins for this group, not per user.  Is there a way to accomplish what I am trying to do?  Thanks.
0
Comment
Question by:denver218
  • 2
  • 2
4 Comments
 
LVL 3

Expert Comment

by:mikegatti
ID: 34910479
inside your default group policy you can add the command:

group-policy DfltGrpPolicy attributes
 vpn-simultaneous-logins 1

that should stop users from simultaneous logins

Also, on the IAS side there is nothing to do (as far as I know), we are evaluating replacing our RADIUS solution with CISCO ACS, OCS RADIATOR or another vendor.

-------------------------------------
vpn-simultaneous-logins

To configure the number of simultaneous logins permitted for a user, use the vpn-simultaneous-logins command in group-policy configuration mode or username configuration mode. To remove the attribute from the running configuration, use the no form of this command. This option allows inheritance of a value from another group policy. Enter 0 to disable login and prevent user access.


http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/uz_72.html#wp1413067


0
 
LVL 4

Author Comment

by:denver218
ID: 34911080
Thanks but this seems to be for a ASA.  I'm am using a cisco VPN concentrator 3060.
0
 
LVL 3

Accepted Solution

by:
mikegatti earned 500 total points
ID: 34911691
No problem, navigate Configuration>User Managemtn>Groups, select a group in the list and click on  on modify group, click the General tab of you vpn group,  there is an option Simultaneous Logins, you can set that option to 1. Or you can go in your Base group and set that option to 1 and it will apply to all groups
0
 
LVL 4

Author Closing Comment

by:denver218
ID: 34916734
Thanks
0

Featured Post

ScreenConnect 6.0 Free Trial

Discover new time-saving features in one game-changing release, ScreenConnect 6.0, based on partner feedback. New features include a redesigned UI, app configurations and chat acknowledgement to improve customer engagement!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Router DMZ 5 63
Access List 4 32
Cisco ASA IOS 9.x - no route to host for Internet 4 52
macos sierra "Destination Net Unreachable" 7 22
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now