Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Calling Station ID needs to be an IP address

This thread has been viewed 3 times
  • 1.  Calling Station ID needs to be an IP address

    Posted Jul 25, 2014 04:30 PM

    I am trying to make things a little easier for our users by setting up Single Sign On. In order for it to work porperly our firewall needs to receive an IP address from the Calling Station ID attribute in the Radius start and stop messages.

     

    I am using IAP-105's with and external Radius server, Server 2008R2. The Radius server is forwarding the start and stop messages but the Calling Station ID is a MAC address and not an IP address.

     

    Is there a way to change it?



  • 2.  RE: Calling Station ID needs to be an IP address

    EMPLOYEE
    Posted Jul 25, 2014 07:46 PM

    The framed-ip-address attribute is typically assigned to the ip address of the user in radius accounting packets, according to the standard.  Find out if your firewall can use that attribute instead. http://tools.ietf.org/html/rfc2866



  • 3.  RE: Calling Station ID needs to be an IP address

    EMPLOYEE
    Posted Jul 25, 2014 07:48 PM

    Does it happen to be a Palo Alto firewall?



  • 4.  RE: Calling Station ID needs to be an IP address

    Posted Jul 25, 2014 10:12 PM

    The firewall is a Fortigate.



  • 5.  RE: Calling Station ID needs to be an IP address

    EMPLOYEE
    Posted Jul 25, 2014 10:33 PM

    http://docs-legacy.fortinet.com/fos50hlp/50/index.html#page/FortiOS%25205.0%2520Help/RADIUS-SSO.037.06.html

     

    "For RADIUS SSO to work, FortiOS needs to know the user’s endpoint identifier (usually IP address) and RADIUS user group. There are default RADIUS attributes where FortiOS expects this information, but you can change these attributes in the config user radius CLI command."

     

     



  • 6.  RE: Calling Station ID needs to be an IP address

    Posted Aug 25, 2014 09:50 AM

    did you get this to work Todd?



  • 7.  RE: Calling Station ID needs to be an IP address

    Posted Aug 25, 2014 02:42 PM
    Yes. I believe it was caused by the firewall looking at the wrong attribute in the RADIUS message.

    Todd