<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HiPath Wireless Assistant RADIUS attributes needed in order to authenticate management level access in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/hipath-wireless-assistant-radius-attributes-needed-in-order-to/m-p/41248#M42</link>
    <description>Article ID: 12497 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
HiPath, HiPath Wireless Assistant (Web GUI), RADIUS, Service-Type, Filter-ID &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
When using RADIUS Authentication under the Login Management option, a user cannot login as a Guest Portal Admin to create new Guest Portal login accounts. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
By default the RADIUS return attribute Service-Type is sending back a value called "Framed". This attribute will move every user into a role of read only access. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution/Workaround&lt;/B&gt;&lt;BR /&gt;
Here is a list of supported RADIUS return attributes which get created in the Remote Access Policy on your RADIUS server. The return attribute Service-Type will allow for different access levels into the HiPath Wireless Assistant (Web GUI): &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;V7.11 firmware and below:&lt;/B&gt; &lt;BR /&gt;
  Service-Type&lt;BR /&gt;
 &lt;BR /&gt;
  Registry:&lt;BR /&gt;
  Value  Description            Reference&lt;BR /&gt;
  -----  ---------------------  ---------&lt;BR /&gt;
  1      Login&lt;BR /&gt;
  2      Framed                 Read Only&lt;BR /&gt;
  3      Callback Login&lt;BR /&gt;
  4      Callback Framed&lt;BR /&gt;
  5      Outbound&lt;BR /&gt;
  6      Administrative         Super User&lt;BR /&gt;
  7      NAS Prompt&lt;BR /&gt;
  8      Authenticate Only      Guest Portal Manager Access only&lt;B&gt;V7.21 firmware and higher:&lt;/B&gt; &lt;BR /&gt;
  Service-Type&lt;BR /&gt;
 &lt;BR /&gt;
  Registry:&lt;BR /&gt;
  Value  Description            Reference&lt;BR /&gt;
  -----  ---------------------  ----------&lt;BR /&gt;
  1      Login&lt;BR /&gt;
  2      Framed&lt;BR /&gt;
  3      Callback Login&lt;BR /&gt;
  4      Callback Framed&lt;BR /&gt;
  5      Outbound&lt;BR /&gt;
  6      Administrative         Super User&lt;BR /&gt;
  7      NAS Prompt             Read Only&lt;BR /&gt;
  8      Authenticate Only      Guest Portal Manager Access onlyYou can use the Enterasys proprietary &lt;B&gt;Filter-ID&lt;/B&gt; format as well, but it can only assign the following roles (&lt;I&gt;No Guest Portal Manager Access&lt;/I&gt;) &lt;BR /&gt;
- Mgmt=ro == Read-Only administrator privileges &lt;BR /&gt;
- Mgmt=rw == Full administration privileges &lt;BR /&gt;
- Mgmt=su == Full administration privilege &lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;Example: Enterasys:mgmt=su:policy=IT Team&lt;/I&gt;</description>
    <pubDate>Wed, 01 Jan 2014 03:58:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2014-01-01T03:58:00Z</dc:date>
    <item>
      <title>HiPath Wireless Assistant RADIUS attributes needed in order to authenticate management level access</title>
      <link>https://community.extremenetworks.com/t5/faqs/hipath-wireless-assistant-radius-attributes-needed-in-order-to/m-p/41248#M42</link>
      <description>Article ID: 12497 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
HiPath, HiPath Wireless Assistant (Web GUI), RADIUS, Service-Type, Filter-ID &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
When using RADIUS Authentication under the Login Management option, a user cannot login as a Guest Portal Admin to create new Guest Portal login accounts. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
By default the RADIUS return attribute Service-Type is sending back a value called "Framed". This attribute will move every user into a role of read only access. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution/Workaround&lt;/B&gt;&lt;BR /&gt;
Here is a list of supported RADIUS return attributes which get created in the Remote Access Policy on your RADIUS server. The return attribute Service-Type will allow for different access levels into the HiPath Wireless Assistant (Web GUI): &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;V7.11 firmware and below:&lt;/B&gt; &lt;BR /&gt;
  Service-Type&lt;BR /&gt;
 &lt;BR /&gt;
  Registry:&lt;BR /&gt;
  Value  Description            Reference&lt;BR /&gt;
  -----  ---------------------  ---------&lt;BR /&gt;
  1      Login&lt;BR /&gt;
  2      Framed                 Read Only&lt;BR /&gt;
  3      Callback Login&lt;BR /&gt;
  4      Callback Framed&lt;BR /&gt;
  5      Outbound&lt;BR /&gt;
  6      Administrative         Super User&lt;BR /&gt;
  7      NAS Prompt&lt;BR /&gt;
  8      Authenticate Only      Guest Portal Manager Access only&lt;B&gt;V7.21 firmware and higher:&lt;/B&gt; &lt;BR /&gt;
  Service-Type&lt;BR /&gt;
 &lt;BR /&gt;
  Registry:&lt;BR /&gt;
  Value  Description            Reference&lt;BR /&gt;
  -----  ---------------------  ----------&lt;BR /&gt;
  1      Login&lt;BR /&gt;
  2      Framed&lt;BR /&gt;
  3      Callback Login&lt;BR /&gt;
  4      Callback Framed&lt;BR /&gt;
  5      Outbound&lt;BR /&gt;
  6      Administrative         Super User&lt;BR /&gt;
  7      NAS Prompt             Read Only&lt;BR /&gt;
  8      Authenticate Only      Guest Portal Manager Access onlyYou can use the Enterasys proprietary &lt;B&gt;Filter-ID&lt;/B&gt; format as well, but it can only assign the following roles (&lt;I&gt;No Guest Portal Manager Access&lt;/I&gt;) &lt;BR /&gt;
- Mgmt=ro == Read-Only administrator privileges &lt;BR /&gt;
- Mgmt=rw == Full administration privileges &lt;BR /&gt;
- Mgmt=su == Full administration privilege &lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;Example: Enterasys:mgmt=su:policy=IT Team&lt;/I&gt;</description>
      <pubDate>Wed, 01 Jan 2014 03:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/hipath-wireless-assistant-radius-attributes-needed-in-order-to/m-p/41248#M42</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2014-01-01T03:58:00Z</dc:date>
    </item>
  </channel>
</rss>

