Assign VPN Group Policy via Radius and Microsoft NPS server

Unanswered Question
Jun 29th, 2009
User Badges:
  • Bronze, 100 points or more

Hi there,

I'm using Microsoft Network Policy server (formerly known as IAS server) for Radius Authentication. Is there a way to configure NPS so it will assign a VPN Group Policy on the ASA? Basically, I'd like to create multiple VPN group policies for different types of users and assign them via AD groups so when the user logs in to the VPN they get the Policy designed for them.

Thanks in advance,


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (1 ratings)
Peter Noble Wed, 07/14/2010 - 19:58
User Badges:

Yes, this works just fine with Microsoft NPS.  In a nutshell, you tell NPS to return the radius attribute 25 (It's called "Class") and assign it the value of ou=MyVPNGroupPolicy  where MyVPNGroupPolicy is the name of your group policy in the ASA.

I want to say this option is under the standard radius attributes on one of the last configuration screens of the wizard.  You do NOT need to configure this using an LDAP setup, you can continue to use NPS, just like you did IAS.


This Discussion