cancel
Showing results for 
Search instead for 
Did you mean: 

Configuring windows Radius to accept Extreme wifi VSA SSID to authenticate users to the wireles network

Configuring windows Radius to accept Extreme wifi VSA SSID to authenticate users to the wireles network

Renne_Stuart
New Contributor
We nee to configure windows Radius to accept Extreme wifi VSA SSID to authenticate users to the wireles network. We have Radius authentication working fine however due to both pupils and staff being in the radius server they can both authenticate and connect. The SSID is a "Staff" SSID which we only want "Staff" to be able to connect to and not "pupils". I have seen in the "Radius TLV's" within the "WLAN Service/Auth&Acct/RadiusTLV's" you can send the "SSID" to the Radius server. How do we make the radius server read this and how do we configure the Radius server to only allow the group "Staff" connect and not the group "pupils"?
3 REPLIES 3

Ronald_Dvorak
Honored Contributor
Hi Reene,

you don't need to send the SSID/VSAs just filter on the NAS identifier (default = VNS name).
So in the WLAN controller GUI > VNS > WLAN services > Auth&Acc > select the RADIUS and click configure.
In the below screenshot you'd see the default for NAS identifier is the VNS name, if you'd like to send another keyword remove the checkmark and put in the name that you'd like to filter in the field on the right.

d21a5a33d6cd450a8e354dfb114434e3_RackMultipart20150626-17828-gtv1fm-NPS_SSID01_inline.png



On the NPS now create a network policy with the conditions for the correct NAS identifier and the Windows group name.
In my example below the condition is that the request is from a Wifi device (the controller), NAS ID = SecureAccess, Windows group = WL3.

d21a5a33d6cd450a8e354dfb114434e3_RackMultipart20150626-30347-17cn2lo-NPS_SSID02_inline.png



If you like you'd send all VSAs and add even more conditions on the network policy but for your scenario that isn't really necessary.

-Ron

Drew_C
Valued Contributor III
Come back and let us know if it worked 🙂

Thanks for details, i will ask the customer to set this up on their Radius server and confirm if it works. appreciated.
GTM-P2G8KFN