Re: Matching realm in a connection policy



Manjunath Bharadwaj [MSFT] wrote:
Chris,

The event log gives the FQDN which IAS gets after processing the request to map the name to a domain name. It looks like the user name that IAS gets when it checks for the realm is "chills@xxxxxxxxxx" so your forwarding rule will not match. (You can confirm this by using a netmon/ethereal dump).
Can you tell how chills@xxxxxxxxxx is getting translated to ABC\user@xxxxxxxxxxxxxx? Do you have an attribute manipulation CRP rule?


Thanks, Manju

Manju

Thanks (growl, news server does not honor cancellations).

I have no idea how it's happening, as I have not set up any manipulation rules.

Regards

--
Chris Hills
IT Services
North East Worcestershire College
.



Relevant Pages

  • RE: check group membership in Connection Request Policy
    ... The access request does not contain a valid user password, ... Authentication is done at the VPN3000, ... So what data does the VPN3000 send to the IAS? ... a custom IAS extension would be really a solution. ...
    (microsoft.public.internet.radius)
  • RE: check group membership in Connection Request Policy
    ... The access request does not contain a valid user password, ... We already do 802.1x authentication with our Enterasys switches, ... IAS is not able to do authentication, since digital certificates are used on ... I am intereseted in your custom IAS extension. ...
    (microsoft.public.internet.radius)
  • RE: check group membership in Connection Request Policy
    ... IAS is not able to do authentication, since digital certificates are used on ... the request is matched against a CRP (based on certain rules a CRP ... I am intereseted in your custom IAS extension. ...
    (microsoft.public.internet.radius)
  • IAS-proxy and adding attributes part 2
    ... Access-Request when it passes the IAS and proxies it to ... intercept the request, Add additional attributes, before ... Does it require programming or extra dll- ... And if i would want to use the extension dll. ...
    (microsoft.public.internet.radius)
  • Re: IAS with PEAP and Airespace (now Cisco 1000)
    ... One of the IAS developers forwarded this comment and question to me about ... The rastls log entry "Unauthorized use of PEAP attempted" means that the ... >>> Access request for user DOMAIN\LoriTest was discarded. ... >>> I've gone over our configuration many times, ...
    (microsoft.public.internet.radius)

Loading