Configuring RADIUS Group Extraction
Configuring RADIUS on Windows Server 2003
-
Vendor ID is the vendor-specific code that you entered in IAS.
-
Type is the vendor-assigned attribute number.
-
Attribute name is the type of attribute name that you defined in IAS. The default name is CTXSUserGroups=
-
Select local computer.
-
Select Remote Access Policies and create a custom policy.
-
Select Windows-Groups for the policy.
-
Select one of the following protocols:
-
Microsoft Challenge-Handshake Authentication Protocol version 2 (MS-CHAP v2)
-
Microsoft Challenge-Handshake Authentication Protocol (MS-CHAP)
-
Challenge-Handshake Authentication Protocol (CHAP)
-
Unencrypted authentication (PAP, SPAP)
-
-
Select the Vendor-Specific Attribute.The Vendor-Specific Attribute needs to match the users whom you defined in the group on the server with the users on NetScaler Gateway. To meet this requirement, you send the Vendor-Specific Attributes to NetScaler Gateway. Make sure you select RADIUS=Standard.
-
The RADIUS default is 0. Use this number for the vendor code.
-
The vendor-assigned attribute number is 0.This is the assigned number for the User Group attribute. The attribute is in string format.
-
Select String for the Attribute format.The Attribute value requires the attribute name and the groups.For the Access Gateway, the attribute value is CTXSUserGroups=groupname. If two groups are defined, such as sales and finance, the attribute value is CTXSUserGroups=sales;finance. Separate each group with a semicolon.
-
Remove all other entries in the Edit Dial-in Profile dialog box, leaving the one that says Vendor-Specific.
Configuring RADIUS for Authentication on Windows Server 2008
-
For the vendor name, select RADIUS Standard.
-
Make note of the shared secret because you will need to configure the same shared secret on NetScaler Gateway.
-
Connection Request Policies where you configure the settings for the NetScaler Gateway connection including the type of network server, the conditions for the network policy, and the settings for the policy.
-
Network Policies where you configure the Extensible Authentication Protocol (EAP) authentication and the vendor-specific attributes.
-
Select Remote Access Server (VPN Dial-up) as the type of network access server.
-
Select Encrypted Authentication (CHAP) and Unencrypted Authentication (PAP and SPAP) for the EAP.
-
Select RADIUS Standard for the Vendor-Specific Attribute.The default attribute number is 26. This attribute is used for RADIUS authorization.NetScaler Gateway needs the vendor-specific attribute to match the users defined in the group on the server with those on NetScaler Gateway. This is done by sending the vendor-specific attributes to the NetScaler Gateway.
-
Select String for the attribute format.The Attribute value requires the attribute name and the groups.For NetScaler Gateway, the attribute value is CTXSUserGroups= groupname. If two groups are defined, such as sales and finance, the attribute value is CTXSUserGroups=sales;finance. Separate each group with a semicolon.
-
The separator is that which you used on the NPS to separate groups, such as a semicolon, a colon, a space, or a period.