Protect Attribute from external rewriting!
Erling Paulsen
erling.paulsen at cc.uit.no
Mon Feb 26 10:22:56 CET 2007
I'm hoping someone can help me with the following problem:
Some of our users gets proxied to external home-servers. We assign them
to a wireless Vlan (guest-vlan) via rewriting the
'Tunnel-Private-Group-Id:0 := "xx"' Attribute.
Is there a convenient way of safeguarding/checking this attribute in the
reply message, so that it has not been rewritten externally and thus
giving users access to restricted Vlans?
I'm guessing it has something to do with the 'post-proxy' section, but
I'm kindof blanc to what must be done - so I would appreciate any hints
to get me started!
-
Erling Paulsen
More information about the Freeradius-Users
mailing list