WatchGuard Technologies SSL VPN default RADIUS=Standard, 23In Attribute format, select String

Models: SSL VPN

1 198
Download 198 pages 26.5 Kb
Page 81
Image 81
default RADIUS=Standard.

Using RADIUS Servers for Authentication and Authorization

18In the Add Attributes dialog box, select Vendor-Specificand click Add.

19In the Vendor-Specific Attribute Information dialog box, choose Select from list and accept the

default RADIUS=Standard.

The Firebox SSL VPN Gateway needs the Vendor-Specific Attribute to match the users defined in the group on the server with those on the Firebox SSL VPN Gateway.

This is done by sending the Vendor-Specific Attributes to the Firebox SSL VPN Gateway

20The RADIUS default is 0. When configuring RADIUS authorization on the Firebox SSL VPN Gateway, in the field Vendor Code, use this default number.

21Click Yes. It conforms and then click Configure Attribute.

22Under Vendor-assigned attribute number, type 0.

This is the assigned number for the User Group attribute. The attribute is in string format. The default is 0.

23In Attribute format, select String.

24In Attribute value, type the attribute name and the groups.

For the Firebox SSL VPN Gateway, the attribute value is CTXSUserGroups=groupname. If two groups are defined, such as sales and finance, the attribute value is CTXSUserGroups=sales;finance. Separate each group with a semicolon.

25Click OK.

26In the Edit Dial-in Profile dialog box, remove all the other entries, leaving the one that says Vendor-Specific.

27Click OK.

When you are finished configuring the Remote Access Policy in IAS, go to the Firebox SSL VPN Gateway and configure the RADIUS authentication and authorization.

Administration Guide

71

Page 81
Image 81
WatchGuard Technologies SSL VPN manual default RADIUS=Standard, 22Under Vendor-assignedattribute number, type