A
A
Andrey Barbolin2018-11-02 02:32:00
RADIUS
Andrey Barbolin, 2018-11-02 02:32:00

Use Vendor-Specific attribute as condition in NPS on MS Radius?

There is an interesting problem. I set up a bunch of MS Radius (MSR) and WIFI Ruckus (ZD). There is a need to use the NPS Vendor-Specific attribute (VSA) from Ruckus, but MSR does not know how to configure such filters through the GUI.
What do we have.
There is a similar problem and solution, but there is no confirmation of the solution.
https://community.hpe.com/t5/M-and-MSM-Series/Filt...
There is a dump between MSR and ZD in which VSA is visible.
5bdb8a47d3352021387974.jpeg
There is an added condition in NPS via configuration import/export and XML editing.
String from XML

<msNPConstraint xmlns:dt="urn:schemas-microsoft-com:datatypes" dt:dt="string">MATCH("Vendor-Specific=01000061DD0506LCHS")</msNPConstraint>

Of course, the added filter is not visible through the GUI, but is visible through the CMD request (Condition3).
netsh nps show np
5bdb8a62b0d25561325643.jpeg
Tried to specify "Vendor-Specific=.*" as an argument. The policy works, but does not filter the VSA accordingly.
Who can help? In what format it is necessary to write the argument in order for the filter to start working.

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question