<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Groups in Radius in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-groups-in-radius/m-p/554477#M426707</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not all RADIUS servers are created equal... which one are you talking about?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Aug 2006 07:40:54 GMT</pubDate>
    <dc:creator>darpotter</dc:creator>
    <dc:date>2006-08-07T07:40:54Z</dc:date>
    <item>
      <title>Multiple Groups in Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-groups-in-radius/m-p/554476#M426706</link>
      <description>&lt;P&gt;HI all - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quick questions that will be easy for all you experts.  I am using Juniper Steel-belted Radius for Remote Access Authenticaion off of our Concentrator right now.  I want to start deploying 802.1x for vlan assignment and login authentication for the network boxes.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been looking around here, and have deducted that Radius has difficulties when you have the same username in multiple groups.  Currently, the domain group VPNUSERS is allowing remote access, and that pretty much encompasses all the 1000+ employess for the company.  For login authentication, I added a check list for the VPNUSERS (to ensure not everyone can login into my switches) group on the radius server to only allow requests from that of the concentrator, but if I create a new AD group (NETADMINS), put the users that will be allowed to login to the individual network devices, add that group as a user on the radius box, I am receiving an authentication failed error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this because those usernames are currently being denied because those usernames are also a part of the VPNUSERS group, which is failing authentication because the attributes don't match according to the check list?  Is there anyway around this without having multiple radius server groups on the network.  Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-groups-in-radius/m-p/554476#M426706</guid>
      <dc:creator>ryan.bachman</dc:creator>
      <dc:date>2019-03-10T21:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Groups in Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-groups-in-radius/m-p/554477#M426707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not all RADIUS servers are created equal... which one are you talking about?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2006 07:40:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-groups-in-radius/m-p/554477#M426707</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-08-07T07:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Groups in Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-groups-in-radius/m-p/554478#M426711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Juniper (funk) Steel Belted Radius.  v5.02&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2006 12:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-groups-in-radius/m-p/554478#M426711</guid>
      <dc:creator>ryan.bachman</dc:creator>
      <dc:date>2006-08-07T12:59:47Z</dc:date>
    </item>
  </channel>
</rss>

