Multiple Radius Group Name

Angel Elena craem at craem.net
Mon Apr 23 18:20:01 CEST 2018


Hi group.


I have a freeradius 2.2.5 in a debian 8 box with an OpenLdap database.

A simple query:

angel.elena at bulma:/etc/freeradius$ radtest angel.elena password localhost:1812 0 testing123
Sending Access-Request of id 100 to 127.0.0.1 port 1812
	User-Name = "angel.elena"
	User-Password = "password"
	NAS-IP-Address = 1.1.1.1
	NAS-Port = 0
	Message-Authenticator = 0x00000000000000000000000000000000 rad_recv: Access-Accept packet from host 127.0.0.1 port 1812, id=100, length=47
	Mikrotik-Group = "AAA_ADMIN"


Mikrotik group is a mapped attribute in a ldap.attrmap file and works fine:

replyItem       Mikrotik-Group                  radiusGroupName


for a new setup and to not modify all devices, we need specify two radiusGroupName / Mikrotik-Group in every query, ex:

Mikrotik-Group = "AAA_ADMIN"
Mikrotik-Group = "AAA_CORES"


Is possible specify two radiusGroupName in a simple reply or any idea to set this setup ?

Thanks.



--------------------------------
Ángel Elena Medina       _o)
craem at craem.net          / \\
http://blog.craem.net  _(___V
@craem_
www.linkedin.com/in/angel-elena-medina
--------------------------------
Zarafa Webapp.


More information about the Freeradius-Users mailing list