Using RADIUS with multiple proxy sources

From: Jonathan Keffer (jkeffer@mail.jwk.lawrence.ks.us)
Date: 08/07/02


From: jkeffer@mail.jwk.lawrence.ks.us (Jonathan Keffer)
Date: 7 Aug 2002 10:58:20 -0700

I'm interested in best practices or past experiences setting up RADIUS
to use multiple proxy sources.

In particular, I want some of my users to have to use token based
authentication and others to only be required to use a simple user ID
and password.

I can set up a RADIUS server to proxy the login request to a token
system like ACE. I can also configure a RADIUS server to proxy the
login request to my LDAP database or to a standalone userID/password
database.

However, if I do both, the RADIUS server will allow a user access to
the system if they have EITHER account type.

To resolve this, I could append a proxy identifer to the end of the
user ID to force the RADIUS server to choose a particular proxy
source. Again, the user could simply choose to enter a different
proxy identifer and route his/her request to the least secure proxy
source.

I'm particularly interested in how this problem has been addressed in
the past.



Relevant Pages

  • Using RADIUS with multiple proxies
    ... I'm interested in best practices or past experiences setting up RADIUS ... I can set up a RADIUS server to proxy the login request to a token ...
    (comp.security.firewalls)
  • Re: Radius question
    ... just proxy based on the dialed number ... you can use any radius attribute to make auth decisions with radiator using ... Subject: Radius question ...
    (freebsd-isp)
  • Re: Windows 2000 server as Radius proxy
    ... Windows 2000 IAS can not do proxy ... You can ask about RADIUS, IAS, 802.1x, Active directory configuration and Certificate services, related to IAS and RADIUS ... > from our organization and from other organization, so I need an radius> server for our own users and radius proxy server to other organization> users. ...
    (microsoft.public.internet.radius)
  • Re: Radius question
    ... The AS5300 can do this directly - without the need for the proxy ... on the proxy radius server should also work for you. ... > like to split in this way as it requires no config by the customer. ... > Ask us about our online Antivirus and Junk mail scanning service ...
    (freebsd-isp)
  • Re: IAS Proxy - adding reply attributes
    ... The proxy will add both. ... > We are using Activcard to authenticate users, but I can't seem to be> able to get Activcard to supply the correct RADIUS reply attributes,> with the result that the PPTP connection attempts fail. ... > What I need to find out is: can IAS proxy requests to the Activcard> RADIUS server, and then add RADIUS-reply attributes to the replies that> get sent back to my Cisco PIX firewall? ... Or will it only send back the> attributes that come from the Activcard RADIUS server? ...
    (microsoft.public.internet.radius)