NPS -> Policies -> Network Policies - 802.1X Additional attributes for RADIUS
greetings experts.
kind of new on microsoft servers (ws08-r2), , not having bing luck find solution dynamic vlan configuration on switch- issues in opinion how radius sending avp values switch, switch reports radius message did not contained expected vlan id - please find screen shoot of parameters being sent radius server (192.168.16.4) http://i53.tinypic.com/102mnug.png (f1) switch 192.168.2.12, , here wireshark capture switch http://i52.tinypic.com/k4judx.png (f2) looking authorization - see on f1 radius accepting request, unable send avp values tunnel-type, tunnel-medium-type, , tunnel-private-group-id
here configuration in the sending additional attributes radius clients network policies standard radius attributes -http://i55.tinypic.com/205w76w.png (f3)
for sure missing here! please help!
thank in advance
kwery
hi kwery,
thank post.
> issues in opinion how radius is sending avp values switch, switch reports radius message did not contained expected vlan id
if don't misunderstand, want deploy wired 802.1x authentication nps. send additional attributes radius clients (such wireless access points, 802.1x-capable switches, vpn servers), should configure radius attributes first. if not configure attribute, not sent switches. default, filter-id, tunnel-type, tunnel-medium-type, tunnel-pvt-group-type, tunnel-assignment-id set nps 802.1x wizard.
meanwhile, might contact switch vendor or see switch documentation attributes required switches.
the radius standard attributes , vendor-specific attributes listed in following links.
radius attributes:
http://technet.microsoft.com/en-us/library/dd197472(ws.10).aspx
vendor-specific attributes:
http://technet.microsoft.com/en-us/library/dd197616(ws.10).aspx
for more information 802.1x authenticated wired access deployment, please take at:
802.1x authenticated wired access deployment guide:
http://technet.microsoft.com/en-us/library/dd348468(ws.10).aspx
best regards,
james zou
Windows Server > Network Access Protection
Comments
Post a Comment