Configure RADIUS dynamic authorization
You can use RADIUS servers to authorize users in remote access VPN using dynamic access control lists (ACLs) or ACL names per user. When a user authenticates, the RADIUS server pushes a downloadable ACL or an ACL name directly to the device. This ACL determines the services the user can access. When the user's session expires, the device deletes the ACL. If a user's trust level or posture changes during an active session, the RADIUS server can update ACLs or disconnect the session in real time.
Before you begin
-
Configure a RADIUS server as the authorization server for the remote access VPN policy.
-
Configure a single interface in the security zone or interface group if the RADIUS server references it.
-
Posture VPN in Threat Defense devices does not support group policy change through dynamic authorization or RADIUS change of authorization (CoA).
Procedure
Step 1 | In Cloud-Delivered Firewall Management Center, choose to configure a RADIUS server object. |
Step 2 | Configure a route from the device to the RADIUS server, such as an ISE server, using the interface enabled for dynamic authorization. For more information, refer to Configure ISE for user control. |
Step 3 | Configure the DNS server and domain-lookup interfaces using Platform Settings. For more information, refer to Configure DNS and DNS server groups. |
Step 4 | Configure split tunneling in the remote access VPN group policy to allow DNS traffic through the VPN tunnel. For more information, refer to Configure a group policy object. |
Step 5 | Deploy the configuration on the device. |