NPS -> Policies -> Network Policies - 802.1X Additional attributes for RADIUS


greetings experts.

kind of new on microsoft servers (ws08-r2), , not having bing luck find solution dynamic vlan configuration on switch-  issues in opinion how radius  sending avp values switch, switch reports radius message did not contained expected vlan id - please find screen shoot of parameters being sent radius server (192.168.16.4) http://i53.tinypic.com/102mnug.png (f1) switch 192.168.2.12, , here wireshark capture switch  http://i52.tinypic.com/k4judx.png (f2) looking authorization - see on f1 radius accepting request, unable send avp values tunnel-type, tunnel-medium-type, , tunnel-private-group-id

here configuration in the  sending additional attributes radius clients network policies standard radius attributes -http://i55.tinypic.com/205w76w.png (f3)

for sure missing here!   please help!

thank in advance
kwery





hi kwery,

 

thank post.

 

> issues in opinion how radius  is sending avp values switch, switch reports radius message did not contained expected vlan id

 

if don't misunderstand, want deploy wired 802.1x authentication nps. send additional attributes radius clients (such wireless access points, 802.1x-capable switches, vpn servers), should configure radius attributes first. if not configure attribute, not sent switches. default, filter-id, tunnel-type, tunnel-medium-type, tunnel-pvt-group-type, tunnel-assignment-id set nps 802.1x wizard.

 

meanwhile, might contact switch vendor or see switch documentation attributes required switches.

 

the radius standard attributes , vendor-specific attributes listed in following links.

 

radius attributes:

http://technet.microsoft.com/en-us/library/dd197472(ws.10).aspx

 

vendor-specific attributes:

http://technet.microsoft.com/en-us/library/dd197616(ws.10).aspx

 

for more information 802.1x authenticated wired access deployment, please take at:

 

802.1x authenticated wired access deployment guide:

http://technet.microsoft.com/en-us/library/dd348468(ws.10).aspx

 

best regards,

james zou



Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...