ip admission: To create a Layer 3 network admission control rule to be applied to the interface, or to create a policy that can be applied on an interface when the authentication, authorization and accounting (AAA) server is unreachable, use the ip admission command in interface configuration mode. To create a global policy that can be applied on a network access device, use the ip admission command with the optional keywords and argument in global configuration mode
max-nodata-conns: Maximum number of idle ("no data") TCP connections that can exist globally for the IP authentication feature. The range is 1 to 1,000. The default is 3