...
To disconnect already active sessions from User Manager, accept must be set to yes on RADIUS client side. If simultaneous session limits are not unlimited (shared-users) and it has reached maximal allowed number, then router will try to disconnect older user session firstly.
User-Manager attempts to disconnect active session, before new user will be accepted (when appropriate limit is set), that's why in such setups it is suggested to use 1s for /radius client timeout.
Warning |
---|
IPsec service in RouterOS does not support rate limitations. |
...