Controllerless Networks

last person joined: 20 hours ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

RADIUS attributes on IAP

This thread has been viewed 4 times
  • 1.  RADIUS attributes on IAP

    Posted Mar 18, 2014 11:28 AM

    Hello,

     

    I am trying to set up multiple VLANs on an SSID and assign them based on some attributes from LDAP, provided by the RADIUS server. I mapped an LDAP attribute businessCategory to User-Category in freeradius. I saw there was a way to show what attributes RADIUS was providing by running some console commands. I am not sure if these work on the IAP as well though?

     

    Long story short, it isn't working and I need to figure out why :)

     

    First step was to check and make sure the attribute was being provided to the IAPs.

     

    Thanks.



  • 2.  RE: RADIUS attributes on IAP

    Posted Mar 18, 2014 02:26 PM

    I did some troubleshooting on freeradius and found it is serving the attribute, but not sure if it is making it to the IAPs.

     

    radiusd[83078]: Login OK: [robert/<via Auth-Type = EAP>] (from client mustang port 0 cli 00:23:14:36:68:6C) sysadmin

     

    Note sysadmin at the end is the value of the attribute for robert (me).



  • 3.  RE: RADIUS attributes on IAP

    Posted Mar 18, 2014 02:32 PM

    not sure about the IAP, but you could see if you cant capture the network traffic before the IAP.



  • 4.  RE: RADIUS attributes on IAP

    Posted Mar 18, 2014 02:36 PM

    Will that work if I am using EAP-TTLS?



  • 5.  RE: RADIUS attributes on IAP

    Posted Mar 18, 2014 02:38 PM

    so far i have always been able to see radius packets and there content.



  • 6.  RE: RADIUS attributes on IAP

    EMPLOYEE
    Posted Mar 18, 2014 03:29 PM

    What is this attribute that you are sending back?  Aruba-User-Role?  filterid?  Something else?  Is the role based access in the SSID set up to apply the role based on these attributes?



  • 7.  RE: RADIUS attributes on IAP

    Posted Mar 18, 2014 03:32 PM

    The attribute is User-Category. I set up the SSID with the different VLANs, the role is currently unrestricted since we have separate VLANs and a firewall between the VLANs.



  • 8.  RE: RADIUS attributes on IAP

    EMPLOYEE
    Posted Mar 18, 2014 03:34 PM

    Can you try doing role based and doing the same logic.  

     

    Remove the VLAN assignment rules and switch to assigning a role based on the same attribute.  If you get the expected, attribute here, let us know.  If not, sounds like a RADIUS server issue



  • 9.  RE: RADIUS attributes on IAP

    Posted Mar 18, 2014 03:39 PM

    Success! That worked. Not sure why the other way is not however.



  • 10.  RE: RADIUS attributes on IAP

    EMPLOYEE
    Posted Mar 18, 2014 03:40 PM

    Hmmm - I would open up a case to see if this is as designed or something else.



  • 11.  RE: RADIUS attributes on IAP

    Posted Mar 18, 2014 03:53 PM

    OK! Thanks for the help!