Radius providing AD groupmembership
I have a problem I was hoping to get some help with. First some background.
We use Securenvoy for two factor authentication. Securenvoy is a quite limited radius server. We want to allow users to log on to ssl vpn with securenvoy providen second factor, while we limit permissions in the policy set with other ldap groups.
So the user is member of one group which makes securenvoy to authenticate the user, and also one or more AD groups which are supposed to grant access to different parts of the network. We are hoping there is a possibility to pass back the username from radius and use this to populate firewall ldap groups. I don't know if this is making sense, but I'll continue anyhow.
We have tried to to do this with RSSO, but we have 3 problems with this approach:
1. Securenvoy is a limited radius server and does not support multiple network policies
2. Using NPS to forward radius request to securenvoy works, but I cannot get the accounting to work.
3. How will this work with user being member of multiple ad groups?
Our other SSL VPN solution from juniper solves this by using both Radius and LDAP in the authorization process. First it authenticates with radius, then checks ldap for group membership. We were hoping to do much the same here with one group to allow access to a tunnel based portal, and ad groups in firewall policies to grant access to networks. We can still use juniper, but I would like to get ridd of it to keep operational complexity at a minimum.
Hopefully someone can shed some light on this, and tell me if it is possible or not.
Best regards
Andreas Grumheden
