cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
734
Views
0
Helpful
5
Replies

Vendor Attribute for Concentrator and IAS Radius?

whiteford
Level 1
Level 1

Does anyone know what the vendor Attribute to use a Concentrator which an IAS windows Radius server is?

I want to lock the Radius requests to a policy that only accepts from teh IP address of the cisco concentrator?

5 Replies 5

Jagdeep Gambhir
Level 10
Level 10

Hi,

You need to use ,

IETF RADIUS : attribute 25

Regards,

~JG

Please rate helpful posts

Thanks, is that an option in IAS? I want to bind a radius policy to a radius client that is a Cisco concentrator. So if a request comes from the concentrator then use a particular radius policy? Does that make sense?

To lock a user to a certain VPN group the Authentication server needs to push this information into the concentratro through Class Attribute 25 (OU=group_name)

This example is with acs, but it is quite helpful.

http://www.cisco.com/en/US/tech/tk59/technologies_configuration_example09186a00800946a2.shtml

Does Class Attribute 25 (OU=group_name) point to a Windows OU?

This attribute contains the VPN Concentrator group name which the administrator wants the user to be locked into. This attribute is the Class attribute (IETF RADIUS attribute number 25), and has to be returned to the VPN Concentrator in this format:

OU=groupname;

where groupname is the name of the group on the VPN Concentrator that the user locks into. OU has to be in capital letters, and there must be a semicolon at the end.

Please rate if helps

Regards,

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: