we are using in our environment 2x fortigate’s 1000C with different ssl vpn
portal. To grant user access to these specific portals we have filter-ID’s
set in our RSA-Server which grant the user access to the right vpn portal
and deny access to other portals.
Is it possible to have these filter-ids set in privacyidea somehow? For
users or groups?
We are using on our SecureID Server different Profiles for vpn portals.
So each profile/user for the specific portal has a different Filter-ID, so
a general setting in the radius wouldn’t be an option.
The firewall expect a true or false from the radius-server if the user
matches the specific filter-id or not, if not the login is getting rejected
if yes it passes and the user can access the specific vpn portal.
the privacyIDEA API can return additional details on a successful
authentication. E.g. it returns the serial number of the token, the user
used to authenticate. It could also return the resolvername, realm or
some arbitrary value.
The freeRADIUS plugin can use these values to return it as an AVP.
If I understand the RFC correctly, the filter-ID is also a value
returned in ACCESS-ACCEPT packages.
Here the serial number in case of success is returned:
This should not be that a bid deal if you are willing to
together define the “key”, “identifiers” and workflows and
financially support this additional development.
Kind regards
CorneliusAm Freitag, den 29.07.2016, 05:10 -0700 schrieb privacyidea:
We are using on our SecureID Server different Profiles for vpn
portals.
So each profile/user for the specific portal has a different
Filter-ID, so a general setting in the radius wouldn’t be an option.
The firewall expect a true or false from the radius-server if the user
matches the specific filter-id or not, if not the login is getting
rejected if yes it passes and the user can access the specific vpn
portal.
In an enterprise environment you should get a SERVICE LEVEL AGREEMENT
which suites your needs for SECURITY, AVAILABILITY and LIABILITY: privacyIDEA Support Level