Plan assignment based on nas and ugroups

Alan DeKok aland at deployingradius.com
Tue Jun 30 14:49:44 CEST 2020


On Jun 29, 2020, at 1:17 PM, Ganga R. Dhungyel <grdhungyel at gmail.com> wrote:\
> Should this be in the Authorize section of the configuration or the Post-Auth section? 

  It doesn't really matter.  Whatever works.

> Instead of evaluating. NAS-IP-Address, can we group the NASes in Huntgroups and use the Huntgroup value to do this since we using sql backend for both users and NASes?

  Yes.

> Tried this but when one user belongs to multiple groups, the group. Chosen is always the first one in the ordered list …

  Yes, that's how group checking works.  If you tell it to match on a group, and the user is in that group... it matches on that group.

  If you want it to do something else, try different unlang statements.  Right now, you're saying "I tried stuff and it didn't work".  That's not helpful.

> it is as if the SQL-Group to Huntgroup-Name mapping in radgroupicheck table is not considered (Group checking is enabled). Maybe I am missing something. I read somewhere that a Fallback needs to be enabled for it to work but not sure if that is the case?

  It depends on what you want do to.

  Please read the SQL module documentation in http://wiki.freeradius.org/ .  It explains in great detail how the SQL module works.  There is no reason for me to repeat that explanation here.

  Alan DeKok.




More information about the Freeradius-Users mailing list