cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
143
Views
2
Helpful
2
Replies

RADIUS Attribute for Source IP

Doopzzy
Level 1
Level 1

Currently on a Cisco ASA, we use RADIUS authentication for WEBVPN users. For the logs on the RADIUS server we are not receiving the originating public IP of the users failed/successful attempts, rather we are getting OUR public IP of the gateway for WEBVPN. The RADIUS server is setup use attribute 31 for the source.

To attempt to find the correct attribute I did a "debug radius all" but only received the binary values for the attributes therefore not telling me the correct attribute that is giving the source.

I do know that Cisco has vendor specific attributes that gives a string with the source IP, but I am unsure if the RADIUS server can parse through this to just use the source IP. Please let me know if any experience or ideas to try.

2 Replies 2

Why use RADIUS at all?  What is the MFA strategy here?  Why not use a SAML Flow instead?

Review Cisco Networking for a $25 gift card