change the customer RADIUS attributes sent by switch

I recently started to use NPS to authenticate logins to my Cisco devices and I have the basics of work.  However, I have a need to add an additional constraint corresponding to my NPS network policies.

Now I use the friendly name of the RADIUS client and/or IP address but I can't find the template for the syntax of these constraints NPS can do what I need without I create literally dozens of policies.  I need somehow add an attribute to a certain group of switches so that I can "filter" which group AD Windows can connect to them by using a strategy that corresponds to that custom attribute.

In the constraint list NPS, I see I have a few options like 'Called Station ID', 'NAS ID' and 'Customer Vendor ID', etc. available.  Is there a way to change these attributes of the switch and send them to the NPS then I could achieve what I want.  For example, I could set up the 'Client Vendor ID' of my special switches with custom data that I could then use to match the political refusal NPS.

Any ideas?

TIA

Hello Diego again :)

I checked with a friend who used the NPS more than me and he was not aware of a way to create groups of location"in NPS or something similar where you can distinguish two different NADs.

However, it provided an interesting solution. He suggested that we use a regular expression in the field identifier Sin in NPS. The regular expression would be for the IP subnet for that particular site. For example, assume that you have two sites:

1 A: site with local subnet of 192.168.30.x 24

2. site B: with local subnet of 10.10.1.x 24

In NPS, you can build a rules like this:

 If NAS Identifier is 10\.10\.1\.* and AD Group is Site_B_Admins Then Full access

And for the Site A

 If NAS Identifier is 192\.168\.30\.* and AD Group is Site_A_Admins Then Full access

Of course, to do this, each site must have a single subnet that does not overlap with other sites.

Hope that gives you some kind of a solution

Tags: Cisco Security

Similar Questions

  • L2445m does not allow me to change the custom scale

    This is a new screen (1920 x 1200 px) on a desktop pc, which replaces a monitor 1280 x 1024.

    I have an application that should be used in the proportions of 1280/1024, but gets stretched on the new L2445m. The menu items of Image-Online Custom Scaling control monitor (and sharpness) are faded/grey. Why is this and how can I get change them the scale? Also, the pc video card does not offer any method to change the scaling for applications.

    Kind regards... Chris

    I think that you will also find that once you use a non-native resolution, the Image control Option is not greyed. Then, you can select fill Aspect if it is always tense.

    See you soon,.

  • Cannot change the reading file attributes only in Windows XP

    When I view the folder properties, they all show the 'read only' as selected.  The selection is a greyed out tick.  When I uncheck this, change seems to be accepted but is not change.  View the properties immediately after that do change the same greyed tick is still there.  All other problems with it seem when a transfer of the user it XP files to a new Vista system.  This isn't the case here, because the files are all over my existing XP system.  How can I continuous change the folder attributes to have the 'read only' deselected.

    Hi BarryGray,

    Please see the thread with a similar problem and fix possible:

    http://answers.Microsoft.com/en-us/Windows/Forum/windows_xp-files/cant-change-read-only-properties-of-files-in-XP/ef76dfee-0bf0-4D8D-8c12-acefe95ad38d

    I hope this helps!

  • I had no success to determine how to change the date, time, attributes etc (although the name can be changed) files in Vista Home Basic that I was able to do in Windows 98 Second edition. __Is their a reasonable solution to this? __Thanks

    It is my first visit to this feature of Microsoft Internet.  It defines a model for constructive citizen of the world form a more perfect union.
    Thank you.

    A "more perfect union"? Really? I'm not terribly interested in forming a union with a person, perfect or not, but I'll gladly try to help you with your it questions. To do this, you will need to provide more information about your computer and your questions clearly and concisely in the body of the message, not in the subject line. These links will help you with your next post:

    http://www.elephantboycomputers.com/page2.html#Usenet (you can ignore the references to Usenet discussion groups / as you post on a web forum, but any suggestions on how to write the post are applies here too)

    http://support.microsoft.com/default.aspx/kb/555375 - how to ask a Question

    Change the date and time of Vista:

    http://Windows.Microsoft.com/en-us/Windows-Vista/set-the-clock

    Don't know what you mean by "attributes".

    You change a file name in Vista right click on the file and then left-click 'Rename' or by clicking the file to select it by pressing F2. MS - MVP - Elephant Boy computers - don't panic!

  • Changing the current Visual attribute for all application property

    Hi all.
    I want to change the color of current Visual attribute of my form to the application level, reason being that I don't want to generate forms again from scratch.
    I know that we can modify it using the Visual attributes, but is there a way to change that through some parameters of the form? (Oracle 10g)

    I do not understand your question.
    You can use 'JDAPI' to programmatically change the Visual attribute on each form.

  • Update of the custom Annotation attributes in bulk

    Greetings!  I have put some custom for my virtual Center hosts attributes and want to know how to take the values of these attributes on all these hosts of a sheet of calculation (or csv) and in virtualcenter.

    The attributes are "deployed, location, MgmtIP, VmotionIP, ILO, PID, Serial, guaranteed".

    I have a csv file that contains the data in the same type of format with the host on the front of the line.

    How can I do this?

    Thank you!

    You can add an identifier to the CSV to make it easy to match fields csv w / a single host as hostname registered in vCenter.

    #this will import the csv file and place it in an object to work with.

    $CustomFields = import-CSV filename.csv

    #this brings together all of your ESX hosts

    $VMHosts = get-VMHost

    #This breaksdown your csv and looks @ each line one by one and uses a statement where clause to match the hostname column from your csv to a host registered in vCenter.  Then sets the custom field.

    {Foreach ($CustomField in $CustomFields)

    $VMHosts | WHERE-object {$_.} {Name of $CustomField.HostName - eq} | Game-CustomField-name 'Deployed' - value $CustomField.Deployed

    $VMHosts | WHERE-object {$_.} {Name of $CustomField.HostName - eq} | Game-CustomField-name 'Location' - value $CustomField.Location

    $VMHosts | WHERE-object {$_.} {Name of $CustomField.HostName - eq} | Game-CustomField-name "MgmtIP"-$CustomField.MgmtIP value

    $VMHosts | WHERE-object {$_.} {Name of $CustomField.HostName - eq} | Game-CustomField-name "VmotionIP"-$CustomField.VmotionIP value

    $VMHosts | WHERE-object {$_.} {Name of $CustomField.HostName - eq} | Game-CustomField-name 'ILO' - value $CustomField.iLO

    $VMHosts | WHERE-object {$_.} {Name of $CustomField.HostName - eq} | Game-CustomField-name 'PID' - value $CustomField.PID

    $VMHosts | WHERE-object {$_.} {Name of $CustomField.HostName - eq} | Game-CustomField-the 'series' name - value $CustomField.Serial

    $VMHosts | WHERE-object {$_.} {Name of $CustomField.HostName - eq} | The 'guarantee' game-CustomField-name - value $CustomField.Warranty

    }

  • change the custom cursor hot spot

    Hello. I've looked everywhere but I can't find a solution to this problem. I made a custom cursor and I want the hotspot not to be in the upper left part of the clip, but instead the clip that I choose. So, how do you change the hotspot to a custom cursor? I use Flash CS4 AS3.

    I can't believe nobody has asked this before.

    Thank you!

    We really don't know what you mean by hotspot, but if you're talking about the registration points, we talk about often enough.  Just open the cursor symbol for change and move the content so that the record is where you choose.

  • Change the default object attributes

    In a document that I created, I mistakenly put in place so that each new form, I create, a box for example, takes on several corners rounded such as effects drop shadow and outer glow, I want.

    I asked these attributes to an object sometimes return to this document, but it was intended only for that one. Now, it happens to every new object.

    How to simply set things back to neutral?

    Window > object Styles

    You may have created a new Style of object or changed the graphic block by default

  • Oracle Apex 5 schedule does not allow to change the custom target link

    The latest version of the calendar is amazing. You can create a date range and the css is very useful.

    The problem is that in Oracle Apex 4.2 I could navigate to different pages stated in a column of the query (Image 1) and with Oracle Apex 5 calendar is impossible for me (Image 2 and Image 3).

    -Image 1:

    apex_42.PNG

    -Image 2

    apex_5.png

    -Image 3:


    apex_5_2.png

    Kind regards

    Hi 1043429 (Please change the name of your forum).

    Use substitution syntax. Instead of #PAGINA # use & PAGE. as you would for items on the page. For consistency, new components such as the new schedule are now using the same substitution syntax like we always used it for items on the page.

    Concerning

    Patrick

    ----

    Member of the APEX development team

  • can I change the appearance of Acrobat Reader? switch from white to black (gray) color frame

    The new version is pretty clear, I would like to know if can bring up the menu easier to look for the eyes, from the white frame to something darker

    (changing the appearance)

    Thanks again!

    Hi alexandre p,.

    Currently, this feature is not available in Acrobat or Reader. You can fill out the feature request/Bug Report Form for her.

    Thank you

    Abhishek

  • HP Officejet 4635 - need assistance to change the custom print size

    I am trying to print a card - 3.5 "x 8.5" on my HP Officejet 4635 and can not find the place where to select a "custom size" in the paper/quality - advanced space.  Much choice is there, just not 3.5 x 8.5 "and nothing nearby in mm.

    Any ideas?

    Hello

    Size 3.5 x 8.5 inches is not supported by the device, custom paper size is not supported on Windows OS.

    You can give a try to the size of Japanese envelope Chou #4, which is the closest option to you to your needs, otherwise I'm afraid, is not a supported format.

    You can find paper Handaling specs below:

    http://support.HP.com/us-en/document/c03839855

    Shlomi

  • Cannot change the appearance of custom settings window

    Hello

    In the attached vi, I changed a few custom settings in the appearance window category vi properties box. What should I do to change the settings back to the 'top-level Application window"? Simply by clicking on the respective radio button doesn't seem to work. Even after registration, the proposed closure and reload the project and vi, the setting is always "personalized." I'm using LabVIEW 2011.

    Thanks for your help.

    Peter

    Hello Peter,.

    I opened your VI on my computer, and of course, I see the same behavior not being able to return to the "the top-level application window.

    If you create a new VI and then change the Custom window properties in the properties of VI, are you able to reproduce the same question? If this isn't the case, I would try to copy and paste all of the current code of the VI to the new and see if you still have the same results.

    The only solution is to put the settings customized to their original settings in order to reproduce the parameters of the top-level window.

  • change the IP address of a command-line switch 6248

    Hello
    could you tell me how to change the address of my management 6248 switch command line.
    I connect to the com port and I turn on I type my password
    and then I do not know the command?
    How to find my ip address?
    How to change?
    Thank you for your help

    Here is the link to the manual ftp://ftp.dell.com/Manuals/all-products/esuprt_ser_stor_net/esuprt_powerconnect/powerconnect-6248_User%27s%20Guide2_en-us.pdf

    Shows how to get the IP address on Page 90

    interface ip Show

    In the CLI page 358 guide, it shows how to set the IP address ftp://ftp.dell.com/Manuals/all-products/esuprt_ser_stor_net/esuprt_powerconnect/powerconnect-6248_Reference%20Guide_en-us.pdf

  • Change the attributes of Certificate SSL CUCM

    How can I change the values of attributes that CUCM uses to create self-signed certificates or CSR?  I am referring to the configured settings when CUCM is installed, as an organization, State, country, etc.

    Thanks, Mike

    http://www.Cisco.com/c/en/us/TD/docs/voice_ip_comm/CUCM/cli_ref/10_0_1/C...

  • Change the attribute - Configuration Item mapping in task Scriptable

    Hello

    is it possible to change the mapping of attributes to the elements of configuration with a scriptable tasks?

    Or do I have to map all possible configuration to decide later that you use attributes?

    example:

    configuration 1:

    UC = 4

    memory = 8

    disk_size = 16

    configuration 2:

    UC = 2

    memory = 4

    disk_size = 8

    Is it possible to have only three attributes (processors, memory, disk_size) and configuration card 2 via the script task or 1 configuration?

    Or should I do 6 attributes (cpus1, cpus2, memory1, memory2, disk1, disk2) a static mapping and use three of the six possible attributes?

    Thank you

    Michael

    The way I saw this fact is as follows:

    Define a ConfigurationElement (called configElement in the example below) as an attribute to your workflow.

    Create items in the ConfigurationElement prefixed by your size or configuration. (Ex: small_cpu, large_cpu, small_memory, large_memory, etc.).

    In your task scriptable:

    var cpuAttr = configElement.getAttributeWithKey (size + "_cpu");

    var cpu = cpuAttr.value;

    var memoryAttr = configElement.getAttributeWithKey (size + "_memory");

    memory of var = memoryAttr.value;

Maybe you are looking for

  • not enough space on the recovery partition

    I get a balloon saying that I have a not enough space on drive D: I disabled the system restore and monitoring of training. It's the recovery partition and I don't write at all to it. It gets real boring. Any suggestions will be appreciated.

  • I lost my language bar. I have a Windows Vista system

    I lost my language bar. When I go on the Control Panel regional & language Options Options regional-languages - and look are all rightHow can I make it reappear so that I can use the language again.Thank you

  • Service FGLAM

    Hello When you remove the monitoring server Foglight do we need to stop the service of fglam from the server or remove only foglight console sufficient? Thank you Vicky

  • BlackBerry Q10 how long Q10 notification LED light flashing?

    My led notification Q10 begins to Flash when a call, e-mail or any comes, but after about 15 minutes, it stops flashing. My previous is 9700, its LED keep flashing until you read or checked the notification. Because this useful when we expect importa

  • Port already in use exception...

    Hello Being a beginner in blackberry I have some problems while developing Java applications for blackberry. I am developing CLDC application that receives SMS on perticular port in a background thread. But when I sent sms to my application using thi