Configure RADIUS dynamic authorization

You can use RADIUS servers to authorize users in remote access VPN using dynamic access control lists (ACLs) or ACL names per user. When a user authenticates, the RADIUS server pushes a downloadable ACL or an ACL name directly to the device. This ACL determines the services the user can access. When the user's session expires, the device deletes the ACL. If a user's trust level or posture changes during an active session, the RADIUS server can update ACLs or disconnect the session in real time.

Before you begin

  • Configure a RADIUS server as the authorization server for the remote access VPN policy.

  • Configure a single interface in the security zone or interface group if the RADIUS server references it.

  • Posture VPN in Threat Defense devices does not support group policy change through dynamic authorization or RADIUS change of authorization (CoA).

Procedure


Step 1

In Cloud-Delivered Firewall Management Center, choose Objects > AAA Server > RADIUS Server Group to configure a RADIUS server object.

  1. Configure the required parameters for the RADIUS server object.

  2. Check the Enable dynamic authorization check box.

  3. In the Port field, enter the port for RADIUS dynamic authorization requests.

    The valid range is 1024 to 65535 and the default value is 1700. The RADIUS server group that is registered for dynamic authorization notification listens to the port for the dynamic authorization policy updates from the RADIUS server.

Step 2

Configure a route from the device to the RADIUS server, such as an ISE server, using the interface enabled for dynamic authorization.

For more information, refer to Configure ISE for user control.

Step 3

Configure the DNS server and domain-lookup interfaces using Platform Settings.

For more information, refer to Configure DNS and DNS server groups.

Step 4

Configure split tunneling in the remote access VPN group policy to allow DNS traffic through the VPN tunnel.

For more information, refer to Configure a group policy object.

Step 5

Deploy the configuration on the device.