Re: IAS - policy profile IP Packet Filter issue
- From: "Manjunath Bharadwaj [MSFT]" <mbhara@xxxxxxxxxxxxxxxxxxxx>
- Date: Mon, 11 Apr 2005 09:17:43 -0700
Hello Giulio,
This is happening because the profile element "IP filters" are a Microsoft
vendor specific RADIUS attribute (it is not a RFC standard) and only
Microsoft products (like RRAS) can understand them.
To have your Cisco NAS understand the filters, you need to configure IAS
to send Cisco vendor specific attributes. Go to profile->Advanced->add and
select "Vendor-Specific" and configure the attributes according to Cisco's
specs.
Hoep this helps.
Thanks, Manju
--
+++++++++++++++++++++++++++++++++++++++++++++++
This posting is provided "AS IS" with no warranties, and confers no rights
"Giulio" <anonymous@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:202a01c53ea4$da029c50$a601280a@xxxxxxxxxx
> Hi All,
> I've a problem with the configuration of a policy profile
> in IAS: it seems to me that the packet filter IP in the
> profile of the policy is not applyed.
>
> A user (say 'test') is configured in this way:
> - Dial-in tab: Remote Access: "Control Access through
> remote access policy"
> - NAS: Cisco 3700
> - IAS policy for this user:
> . Grant Remote Access Permission
> . profile - IP Deny all traffic except from 192.168.0.7 to
> user-IP
> . profile - IP Deny all traffic from user to 192.168.0.7
>
> The other profile configurations are set as default.
>
> The user is correctly authenticated and from the event log
> I can see that the policy used is the correct one.
>
> I expected I could not ping anything but 192.168.0.7 but,
> once authenticated, the test user can ping everything around!
>
> The strange thing is that the same policy in a RRAS server
> (without IAS) works in the correct way. It's exactly the
> same policy since I imported it from the old server with
> the netsh command.
>
> Please help me!!!
>
>
.
- Follow-Ups:
- Re: IAS - policy profile IP Packet Filter issue
- From: Giulio
- Re: IAS - policy profile IP Packet Filter issue
- From: Giulio
- Re: IAS - policy profile IP Packet Filter issue
- References:
- IAS - policy profile IP Packet Filter issue
- From: Giulio
- IAS - policy profile IP Packet Filter issue
- Prev by Date: IAS - policy profile IP Packet Filter issue
- Next by Date: Re: IAS - policy profile IP Packet Filter issue
- Previous by thread: IAS - policy profile IP Packet Filter issue
- Next by thread: Re: IAS - policy profile IP Packet Filter issue
- Index(es):
Relevant Pages
|
Loading