Restrict authentication types per user
    Alan DeKok 
    aland at deployingradius.com
       
    Wed Apr 20 15:34:11 CEST 2016
    
    
  
On Apr 20, 2016, at 9:21 AM, A.L.M.Buxey at lboro.ac.uk wrote:
> reject is fail....and client would just try again....and again.... what you want to do,
> its for a particular user, NAK that EAP type so the client DOES try another one...
  That may help... but it's still a negotiation.
> which means.....you need to use different inner-tunnels, with different available EAP
> types available in each, for each type/class of user....
  I don't think that's necessary.  But it is necessary to send custom NAKs back... which isn't supported right now.
  Alan DeKok.
    
    
More information about the Freeradius-Users
mailing list