Now, i am deploying the Remote Access VPN authentication base on User-Group by Radius server on Cisco ACS.
I followed step by step in Sk105542 and R80.10 Admin Guide to configure on Checkpoint and Cisco ACS.
But it is unexpected working, the Cisco ACS have responded the Access-Acept packet included the attribute 25 - Class Group. On the other hand, the CP did not tie this attribute into thier behavior. I create two policy matching 2 groups but there are not packet match the policy.
20:00:19.350737 Out 00:1c:7f:85:5e:3b (oui Unknown) ethertype IPv4 (0x0800), length 107: (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 91) bv-int-fw02.48968 > 10.39.121.10.radius: RADIUS, length: 63
Access Request (1), id: 0xe4, Authenticator: da1fb726052960a63fb58e366554a211
Username Attribute (1), length: 7, Value: ctin1
0x0000: 6374 696e 31
Password Attribute (2), length: 18, Value:
0x0000: b701 030e c4d8 6794 36b6 f16f e088 266a
Service Type Attribute (6), length: 6, Value: Login
0x0000: 0000 0001 [|radius]
20:00:19.359403 In 00:23:eb:02:5f:e0 (oui Unknown) ethertype IPv4 (0x0800), length 116: (tos 0x0, ttl 60, id 0, offset 0, flags [DF], proto: UDP (17), length: 100) 10.39.121.10.radius > bv-int-fw02.48968: RADIUS, length: 72
Access Accept (2), id: 0xe4, Authenticator: 43e16daa10949447c34e7aa2f9652d47
Username Attribute (1), length: 7, Value: ctin1
0x0000: 6374 696e 31
NAS IP Address Attribute (4), length: 6, Value: 172.30.1.4
0x0000: ac1e 0104
Class Attribute (25), length: 7, Value: TEST1
0x0000: 5445 5354 31
Class Attribute (25), length: 32, Value: [|radius]
0x0000: 4341 4353 3a44 522d 4143
20:02:06.397796 Out 00:1c:7f:85:5e:3b (oui Unknown) ethertype IPv4 (0x0800), length 107: (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto: UDP (17), length: 91) bv-int-fw02.48968 > 10.39.121.10.radius: RADIUS, length: 63
Access Request (1), id: 0xe5, Authenticator: dd00bd73b7f4a1edf4e66b036ab06ead
Username Attribute (1), length: 7, Value: ctin2
0x0000: 6374 696e 32
Password Attribute (2), length: 18, Value:
0x0000: 0d9f c172 7cf5 b6ae 0fa9 fc20 2aeb 51f4
Service Type Attribute (6), length: 6, Value: Login
0x0000: 0000 0001 [|radius]
20:02:06.406418 In 00:23:eb:02:5f:e0 (oui Unknown) ethertype IPv4 (0x0800), length 116: (tos 0x0, ttl 60, id 0, offset 0, flags [DF], proto: UDP (17), length: 100) 10.39.121.10.radius > bv-int-fw02.48968: RADIUS, length: 72
Access Accept (2), id: 0xe5, Authenticator: 1d1f84df246c278a8d5f865c4d2f875a
Username Attribute (1), length: 7, Value: ctin2
0x0000: 6374 696e 32
NAS IP Address Attribute (4), length: 6, Value: 172.30.1.4
0x0000: ac1e 0104
Class Attribute (25), length: 7, Value: TEST2
0x0000: 5445 5354 32
Class Attribute (25), length: 32, Value: [|radius]
0x0000: 4341 4353 3a44 522d 4143
Thank you in advance.