Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Use address pool from RADIUS with concentrator 3005

Status
Not open for further replies.

Farmoor

IS-IT--Management
Apr 3, 2003
11
SE
Hello again :)

I have the following configuration:
Cisco VPN concentrator 3005 (latest software)
Cisco VPN Client (latest version)
Windows 2000 advanced server running both IAS (RADIUS) and Active Directory

I can authenticate users via RADIUS and so on, but I don't know how to assign an IP pool to users connecting through the concentrator. I could use the concentrators' internal pool, but I want to control resource access by IP addresses and that would make the internal pool solution rather worthless (since the idea with using RADIUS is centralized management). So, does anyone know how to send back IP addresses with RADIUS for groups configured in Active Directory? (It is easy to set on a per-user basis, but that won't be happening since there will be quite a lot of users).

Many thanks in advance
Farmoor
 
i dont know the answer to your particular question but i wanted to ask YOu a question....

how did you position your concentrator in your network?

did you put in before or after your firewall??

thanks
 
Right now this configuration is in a laboratory environment, so there is no firewall. However, we have reached the conclusion that the firewall should be placed after the concentrator, and the firewall will then control access to resources in the network based on IP addresses. That is actually the main reason why I need to get the IP pool working via RADIUS.
 
I know this thread is quite old, but did you ever get RADIUS to assign the ip addresses by group. I am currently doing the same thing as you have outlined, and do not want to re-invent the wheel.

Thanks in advance.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top