Radius Proxy for Authorization

Alan DeKok aland at deployingradius.com
Tue Oct 21 07:48:42 CEST 2008


Lutrika Mufti Rachmat wrote:
> I have an existing radius server running on Cisco ACS 4.2. In the
> current configuration, all users are configured using priv ID 15. I
> wanted to setup a proxy radius, where the proxy will relay an
> authentication and authorization request to the Cisco ACS, but when
> relaying back the authentication and authorization message back to the
> clients, I want to overwrite the priv ID with something other than 15
> (for eg, user XXX -> priv 14, user YYY -> priv10, etc).

  This can be done.  See "man unlang" for re-writing attributes.

> Is there a way for me to do that? Or is this behavior is actually
> prohibited by the standards?

  It's not prohibited.

  Alan DeKok.



More information about the Freeradius-Users mailing list