Hello again.
I'm now trying to match on Directory Attributes returned by one of my Radius Identity Servers in my 'Authorization Policy'.
The log comes back with this:
Evaluating Service Selection Policy |
15004 Matched rule |
15012 Selected Access Service - ras |
Evaluating Identity Policy |
15006 Matched Default Rule |
15013 Selected Identity Store - SBR-Vasco |
24609 RADIUS token identity store is authenticating against the primary server. |
11100 RADIUS-Client about to send request |
11101 RADIUS-Client received response |
24613 Authentication against the RADIUS token server failed. |
24614 RADIUS token server authentication failure is translated as Unknown user failure. |
24609 RADIUS token identity store is authenticating against the primary server. |
11100 RADIUS-Client about to send request |
11101 RADIUS-Client received response |
24101 Some of the retrieved attributes contain multiple values. These values are discarded. The default values, if configured, will be used for these attributes. |
24612 Authentication against the RADIUS token server succeeded. |
24628 User cache not enabled in the RADIUS token identity store configuration. |
22037 Authentication Passed |
22023 Proceed to attribute retrieval |
24432 Looking up user in Active Directory - schramke.fabian |
24416 User's Groups retrieval from Active Directory succeeded |
24420 User's Attributes retrieval from Active Directory succeeded |
22036 Retrieved Attributes successfully from current IDStore |
22016 Identity sequence completed iterating the IDStores |
Evaluating Group Mapping Policy |
15006 Matched Default Rule |
Evaluating Exception Authorization Policy |
15042 No rule was matched |
Evaluating Authorization Policy |
15006 Matched Default Rule |
15016 Selected Authorization Profile - DenyAccess |
15039 Selected Authorization Profile is DenyAccess |
11003 Returned RADIUS Access-Reject |
I tried to use the 'Class' attribute, but the msg 24101 stated mulitvalued attributes are ignored. So i tried non mulitvalued fields, for example 'Framed-Apple-Talk-Zone[39]' with no luck.
Any help would be appreciated.