EasyManuals Logo
Home>Cisco>Software>2509 - Router - EN

Cisco 2509 - Router - EN User Manual

Cisco 2509 - Router - EN
686 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #51 background imageLoading...
Page #51 background image
1-17
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 1 Overview of Cisco Secure ACS
AAA Server Functions and Concepts
In addition to simple User and Group Max Sessions control, Cisco Secure ACS
enables the administrator to specify a Group Max Sessions value and a
group-based User Max Sessions value; that is, a User Max Sessions value based
on the group membership of the user. For example, an administrator can allocate
a Group Max Sessions value of 50 to the group Sales and also limit each
member of the Sales group to 5 sessions each. This way no single member of a
group account would be able to use more than 5 sessions at any one time, but the
group could still have up to 50 active sessions.
For more information about the Max Sessions feature, see Setting Max Sessions
for a User Group, page 6-11, and Setting Max Sessions Options for a User,
page 7-16.
Dynamic Usage Quotas
Cisco Secure ACS enables you to define network usage quotas for users. Using
quotas, you can limit the network access of each user in a group or of individual
users. You define quotas by duration of sessions or the total number of sessions.
Quotas can be either absolute or based on daily, weekly, or monthly periods. To
grant access to users who have exceeded their quotas, you can reset session quota
counters as needed.
To support time-based quotas, we recommend enabling accounting update packets
on all AAA clients. If update packets are not enabled, the quota is updated only
when the user logs off and the accounting stop packet is received from the AAA
client. If the AAA client through which the user is accessing your network fails,
the session information is not updated. In the case of multiple sessions, such as
with ISDN, the quota would not be updated until all sessions terminate, which
means that a second channel will be accepted even if the first channel has
exhausted the quota allocated to the user.
For more information about usage quotas, see Setting Usage Quotas for a User
Group, page 6-13, and Setting User Usage Quotas Options, page 7-18.
Shared Profile Components
Cisco Secure ACS provides a means for specifying authorization profile
components that you can apply to multiple user groups and users. For example,
you may have multiple user groups that have identical network access restrictions.
Rather than configuring the network access restrictions several times, once per

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 2509 - Router - EN and is the answer not in the manual?

Cisco 2509 - Router - EN Specifications

General IconGeneral
BrandCisco
Model2509 - Router - EN
CategorySoftware
LanguageEnglish

Related product manuals