Wireless Access

last person joined: 15 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Returning radius attributes to a CP guest user?

This thread has been viewed 0 times
  • 1.  Returning radius attributes to a CP guest user?

    MVP
    Posted Dec 02, 2011 04:38 AM

    A customer has come up with an idea we need to implement.

    Basically, he wants to be able to apply  bandwidth controlls to his guest-users.

    Thing is, he wants to be able to set the bandwidth profile per user to one of the few bandwidth profiles..

     

     

    I was thinking about having the radius server retun the Aruba-User-Roleattribute. I know this works for WPA authentication, but can somebody configrm this also works when its a captive portal doing the request? Does it still pass the role onto the user?

     

    Is any aditional config needed to get this working?



  • 2.  RE: Returning radius attributes to a CP guest user?

    EMPLOYEE
    Posted Dec 02, 2011 04:41 AM

    Are the guest users located in the local database or radius?

     



  • 3.  RE: Returning radius attributes to a CP guest user?

    MVP
    Posted Dec 02, 2011 04:44 AM

    They can be in both. 

    Idea is to have a failthrough from radius to internal so we do need the radius to retun the role attribute.

    Just changing the role attached to an internal user is not enough :)



  • 4.  RE: Returning radius attributes to a CP guest user?

    EMPLOYEE
    Posted Dec 02, 2011 04:52 AM

    Okay.

     

    This does work with Captive Portal users, as well.  In the radius server, if you have a remote access policy allowing guests, just have it return an attribute and a value, like filter-id.  Attached to the Captive Portal authentication profile, there is a server group.  In that server group, add a server rule that looks for the attribute and the value above and it will change the role to whatever you want it to be.  

     

    Use the article here:  http://kb.arubanetworks.com/cgi-bin/arubanetworks.cfg/php/enduser/std_adp.php?p_faqid=826 to see what attributes are being sent back to the controller.