two user authentication groups for one AS

Alan DeKok aland at deployingradius.com
Wed Dec 30 12:15:09 CET 2009


Eric wrote:
> Hi
> There is one VPN server that I want to authenticate some of its users
> with ldap-1
> and others with ldap-2. how should I differ them?

  What is different about the packets for users in ldap-1, and users in
ldap-2?

> I defined:
> DEFAULT Client-IP-Address == 192.168.200.21, Auth-Type := ldap-1,
> Autz-Type := Vpn
> DEFAULT Client-IP-Address == 192.168.200.21, Auth-Type := ldap-2,
> Autz-Type := Vpn
>  
> but it only sees first line.

  Uh... see "man users".  Yes, it only sees the first line, because the
first line matches.

  Alan DeKok.



More information about the Freeradius-Users mailing list