- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Vendor Specific Attribute on Windows NPS for Cisco Meraki Radius
I was told to reduce or set the listening AVP/VSA on Windows NPS from the standard to only (below):
NAS-IP-Address (mgmt of the switch instead of 6.X)
NAS-Port-Type (Async instead of Ethernet)
User-Name
User-Password
How do I do this on Windows NPS for C9300 on meraki?
It works fine with MS120 without any specific attributes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe it will help you.
https://learn.microsoft.com/en-us/azure/virtual-wan/user-groups-radius
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't fully understand your question.
Are you saying you are being sent a set of attributes, but you don't want to receive all of them?
If so, you can't stop them being sent to you - but NPS will only act on the attributes you configure it to do so. So if you don't want to use an attribute, don't match on it.
You get the error above when you have not created a policy that matches any of the attributes being presented.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@PhilipDAth
I was told to limit the listening attributes on the NPS policy.
As you have pointed out:
If so, you can't stop them being sent to you - but NPS will only act on the attributes you configure it to do so. So if you don't want to use an attribute, don't match on it.
You get the error above when you have not created a policy that matches any of the attributes being presented.
I have tried with Ethernet only, with no vendor set attributes. Which then resulted in the CRP error.
With that said. I am unsure how or/and where to set these listening attributes. Thank you for reconfirming the miss configuration/issues I am having.
The link that @alemabrahao has linked, from first glance looks like that is what I am looking for. But I am not sure where to get the attribute prefix for the attributes I need.
NAS-IP-Address
NAS-Port-Type (Async instead of Ethernet)
User-Name
User-Password
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try authenticating. Go to the event viewer, security, and filter on event IDs 6272 and 6273. It will show you every attribute presented. You can match on what you see here - and nothing else.
