Restrict authentication types per user

Alan DeKok aland at deployingradius.com
Wed Apr 20 15:34:11 CEST 2016


On Apr 20, 2016, at 9:21 AM, A.L.M.Buxey at lboro.ac.uk wrote:
> reject is fail....and client would just try again....and again.... what you want to do,
> its for a particular user, NAK that EAP type so the client DOES try another one...

  That may help... but it's still a negotiation.

> which means.....you need to use different inner-tunnels, with different available EAP
> types available in each, for each type/class of user....

  I don't think that's necessary.  But it is necessary to send custom NAKs back... which isn't supported right now.

  Alan DeKok.




More information about the Freeradius-Users mailing list