cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
12925
Views
11
Helpful
3
Replies

Assign VPN Group Policy via Radius and Microsoft NPS server

branfarm1
Level 4
Level 4

Hi there,

I'm using Microsoft Network Policy server (formerly known as IAS server) for Radius Authentication. Is there a way to configure NPS so it will assign a VPN Group Policy on the ASA? Basically, I'd like to create multiple VPN group policies for different types of users and assign them via AD groups so when the user logs in to the VPN they get the Policy designed for them.

Thanks in advance,

--Brandon

3 Replies 3

Peter Noble
Level 1
Level 1

Yes, this works just fine with Microsoft NPS.  In a nutshell, you tell NPS to return the radius attribute 25 (It's called "Class") and assign it the value of ou=MyVPNGroupPolicy  where MyVPNGroupPolicy is the name of your group policy in the ASA.

I want to say this option is under the standard radius attributes on one of the last configuration screens of the wizard.  You do NOT need to configure this using an LDAP setup, you can continue to use NPS, just like you did IAS.

I did like you said with multiple group policy name in an ASA 5512. But my problem is that any user from AD can log in any group even if they are not in the group in AD. Please help

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: