FreeRadius is not sending attributes to the Wireless Controller on the Access-Accept package

  • 0
  • 2
  • Problem
  • Updated 2 months ago
  • Not a Problem
We have configured a FreeRadius to work along with an IdentiFi Wireless Controller, but even when it is authenticating correctly, the FreeRadius server it's not sending the attributes on the Access-Accept package. We are trying to send specifically the Filter-Id attribute in order to have one single SSID and send the users to their respective VLAN or Topology matching the Roles with the Filter-Id.

When doing a packet capture from the controller, we see that none attribute is sent from the FreeRadius server to the Controller on the Access-Accept message, therefore the users are note getting redirected to the right Role and Topology.

Seems that the issue might be on the FreeRadius server but we haven't figured how to solve it.

We would appreciate any comment you may have.

Thank you.
Photo of Manuel Diaz

Manuel Diaz

  • 110 Points 100 badge 2x thumb

Posted 5 months ago

  • 0
  • 2
Photo of Doug Hyde

Doug Hyde, Technical Support Manager

  • 20,394 Points 20k badge 2x thumb
You have to edit the user's file under the group of users or the specific user to include the filter-id

Filter-Id = "Role on controller"  ### this is case sensitive 
Photo of Manuel Diaz

Manuel Diaz

  • 110 Points 100 badge 2x thumb
Hello Doug,

Thank you for your reply, even though I have already tried that but with no luck. It seems that I must do something with the file "default" on the "post-auth" section for it to send the attributes I am defining for the users, included the Filter-Id.
Photo of Doug Hyde

Doug Hyde, Technical Support Manager

  • 20,394 Points 20k badge 2x thumb
I'm not sure about any default setting I needed to change the last time I had this working. I couldn't find anything in any of our databases either. 
Photo of Glissie G

Glissie G

  • 60 Points
Hi Manuel, 

Did you get the filter-id in Radius-Accept packet working? Thanks!