cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question
Juan_Lobera
Nickel

Allowing specific access to different RADIUS users based on User Groups

   Hi Team,

Based on sk24858, im trying to give different kind of permissions based on user groups for remote access clients.

On the SK it talks about an attribute to return to the checkpoint. Can anyone tell me which this attribute is on microsfts NPS? 

Groups are called: RAD_attribute

I need the checkpoint to get this attribute. 


Thanks

Tags (2)
2 Replies

Re: Allowing specific access to different RADIUS users based on User Groups

This would be the class attribute. See this ASA configuration guide to see where to configure it in Microsoft NPS (Pass Group-policy Attribute (Attribute 25) from the NPS RADIUS Server). On the Check Point side if you're using R80.10, then navigate to Global Properties -> Advanced -> SecuRemote/SecureClient and enable add_radius_groups. This is probably also available in R77 if you don't want to edit objects.C as it says in sk24858. 

Juan_Lobera
Nickel

Re: Allowing specific access to different RADIUS users based on User Groups

Worked as a charm.  Thank you Bob Bent

0 Kudos