IAS - policy profile IP Packet Filter issue



Hi All,
I've a problem with the configuration of a policy profile
in IAS: it seems to me that the packet filter IP in the
profile of the policy is not applyed.

A user (say 'test') is configured in this way:
- Dial-in tab: Remote Access: "Control Access through
remote access policy"
- NAS: Cisco 3700
- IAS policy for this user:
. Grant Remote Access Permission
. profile - IP Deny all traffic except from 192.168.0.7 to
user-IP
. profile - IP Deny all traffic from user to 192.168.0.7

The other profile configurations are set as default.

The user is correctly authenticated and from the event log
I can see that the policy used is the correct one.

I expected I could not ping anything but 192.168.0.7 but,
once authenticated, the test user can ping everything around!

The strange thing is that the same policy in a RRAS server
(without IAS) works in the correct way. It's exactly the
same policy since I imported it from the old server with
the netsh command.

Please help me!!!


.



Relevant Pages

  • Re: IAS - policy profile IP Packet Filter issue
    ... This is happening because the profile element "IP filters" are a Microsoft ... To have your Cisco NAS understand the filters, you need to configure IAS ... > profile of the policy is not applyed. ...
    (microsoft.public.internet.radius)
  • Re: Do Not Execute Group Policy for Admins Group
    ... The intent of policy loopback is to replace or merge user configuration ... The computer configuration settings from this list are applied to the ... > so that the group policy will only apply to a certain group of users ...
    (microsoft.public.win2000.group_policy)
  • Re: More than one GPO on the same OU
    ... How does the Group Policy 'No Override' and 'Block Inheritance' work? ... NO OVERRIDE option of a GPO ... > COMPUTER CONFIGURATION ... [Christoffer Andersson] ...
    (microsoft.public.win2000.group_policy)
  • RE: ISA Server failed to load the firewall policy configuration.
    ... the "Error while loading the Firewall policy "policy name" with string ... configuration issue that gets the loading stuck. ... registry then try to start ISA console. ...
    (microsoft.public.isa.configuration)
  • Re: GPO Question
    ... If you only have the computer account in the OU, the User Configuration half ... of the policy won't apply. ... OU heirarchy below) to which the GPO is linked for it to apply. ... > Group Policy was applied from: ...
    (microsoft.public.win2000.group_policy)