02-17-2010 02:06 PM
Configuring a Cisco Concentrator3005 using IPSEC client on PC and authenticating via radius w/ group assignment is a breeze - plus I'm not configuring an individual user - and don't want to.
But I'm banging my head trying to configure Webvpn to authenticate via radius and assigning the user to a group! The user always defaults itself to the Base Group. I want to figure out a way to have the user placed into a Group.
Anyone tackle this before?
Thx.
Robert
Solved! Go to Solution.
02-18-2010 09:38 AM
Robert,
First, you need to make sure that the Radius server is your first authentication method configured on the VPN3000, WEBVPN reads the authentication server list from top to bottom and the first one on the list is the one to be chosen, second to assign the user to a group you need to configure the class value on your radius server, this value has to be equal to the webvpn group you need to assign the user to.
02-18-2010 09:38 AM
Robert,
First, you need to make sure that the Radius server is your first authentication method configured on the VPN3000, WEBVPN reads the authentication server list from top to bottom and the first one on the list is the one to be chosen, second to assign the user to a group you need to configure the class value on your radius server, this value has to be equal to the webvpn group you need to assign the user to.
02-18-2010 02:50 PM
Ivan,
Thanks for the information. It was the "Class attribute" setting on the radius server that fixed my problem.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide