Skip to main content
robinct
New Member
March 13, 2017
Question

VPN users and radius groups

  • March 13, 2017
  • 0 replies
  • 2156 views

I'm trying to enable policy rules for VPN connections based on remote radius groups. I have defined a few different groups mapping to groups returned by the radius server.

 

I've debugged with 'diagnose test authserver radius' that my user belongs to several groups, and we also use on for the groups for a Remote+Wildcard administrator.

 

However, it doesn't seem to work when I add the same group to policy rules. Checking the "Firewall User Monitor" only lists the user as "ssl_vpn_group", which is a remote group defined as "Any".

 

The more specific groups are not defined under Authentication/Portal Mapping, only the "Any" group. Might that be the case?