NPS send additional attribute Filter-ID (0xb)

Hello
Our environment – Active Directory forest level 2003, users dial-in properties are ignored, NPS server MS Windows 2008 R2 Enterprise Edition patched with all updates and used only
for authentication, Watchguard VPN server XTM 510, software version 11.8.1. I want to allow access to network resources based on group membership. For example – members of domain group A have access only to servers/services A, members of group B have access
only to servers/services B, etc. I configured watchguard server:
https://www.watchguard.com/help/docs/wsm/XTM_11/en-US/index.html#cshid=en-US/authentication/radius_how_works_c.html
https://www.watchguard.com/help/docs/wsm/XTM_11/en-US/index.html#en-US/authentication/radius_server_auth_about_c.html%3FTocPath%3DAuthentication|Configure%20%20RADIUS%20Server%20Authentication|_____0
First I create global domain group VPN_SSL_IT_Admins, then I create connection request policy and network policy, both policies have the same Filter-Id parameter, which was the
same as group name VPN_SSL_IT_Admins, then I create packet filter rules in VPN server, then I create the next domain group, next NPS policies, etc.
During testing I’ve found very strange problem – NPS server sends back to radius client (VPN server) two Filter ID attributes (hex code 0xb) in access accept message, although
user is member only of one group. One filter ID attribute is correct, the other is always the same as the first policy (I didn’t test which policy need to be first – connection request or network policy). When I change the order of policies in NPS the Filter
ID attribute is also changed.
I think this is security flaw because user has access to two network resources. As a workaround I create empty domain global group (no members), one connection request and one
network policy in NPS, both policies were first in processing order. NPS still send two filter-id (0xb) attributes but connected user has only access to allowed network resources/services.
I've also prepared PDF document with pictures, if anyone is interested (NPS settings and network monitor captures).
Regards Milan

Hi
I did as Greg suggested (configure Filter-Id attribute only in network policy) and radius (NPS) sends only one Filter-Id attribute. Maybe this is "behavior by design"?
I must admit - I've never understood why we need Connection Request Policies and Network Policies.
J
PDF file:
http://1drv.ms/1eucHrQ
Regards Milan

Similar Messages

  • Add Additional Attributes/Metadata to a Question to Enable Deeper Segmentation Analysis?

    In Captivate, is it possible to add additional attributes/metadata to a quiz question, to allow for more flexible and effective reporting?  For example, I want to categorize questions in two different buckets: Difficulty (Easy, Medium and Difficult) and Concept/Subject (Math, Verbal and Science etc..).
    That way, I can analyze a students performance by not only their aggregate score, but also where their strenghts and weaknesses lie - if I see that a student is struggling with all Easy Math questions, I'll know what to focus on during our next lesson?
    Any assistance would be much appreciated.

    Hi,
    We can create Question Pools with Questions of different difficulty level called directly to the slides.
    But this would not give the advantage on LMS end, this would simply filter questions and would present them in the order you like, attaching meta data to a specific question would not be possible from Captivate, neither would you be able to call it on LMS report directly. You can assign a unique Interaction ID to each question item though capture the questions corresponding to the ids. If you LMS can refine the resuklts based upon the pre-assigned id, that should be great.
    Meanwhile, this would be in a different line, but have you checked the pre-test quiz, can that fit somehow, in you requirements?
    http://help.adobe.com/en_US/captivate/cp/using/WS6029a80579ffffcd5a87e66f135bd55f8cc-7ffc. html
    Thanks,
    Anjaneai

  • Additional attributes (such as "xmlns:xsi") in document

    How can I add some additional attributes in in my toplevel element when creating
    a new XML document from scratch using XMLBeans. For example the attributes "xmlns:xsi"
    and "xsi:schemaLocation" in the sample below:
    <?xml version="1.0" encoding="UTF-8"?>
    <MyDoc xmlns="http://www.xxx.nl/yyy" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.xxx.nl/yyy myXsd.xsd">
    <..../>
    <..../>
    </MyDoc>
    XML does add the "xmlns" attribute itself. How can I add the two other attributes?
    Currently I have a workaround. I read an "empty" XML-file containing these attributes
    using XMLBeans (parse) and then I fill the empty structure. But I feel that there
    has to be a better solution. Unfortunately I cannot find it.
    Any help is appreciated. Thank you in advance.

    Hello Olaf -- You might trying using an XML cursor. So assuming you've
    compiled a schema to generate XMLBeans types, you might do something like
    the following.
    MyDocDocument myDocDoc = MyDocDocument.Factory.newInstance();
    MyDoc myDoc = MyDocDocument.getMyDoc();
    // Create a cursor and move it to where you want to start inserting
    attributes.
    XmlCursor cursor = myDoc.newCursor();
    cursor.toFirstContentToken();
    cursor.toLastAttribute();
    // Insert your attributes.
    cursor.insertAttributeWithValue("schemaLocation","http://www.w3.com/2001/XML
    Schema-instance", "http://www.xxx.nl/yyy myXsd.xsd");
    // ...add other attributes in a similar way...
    // Dispose of the cursor.
    cursor.dispose();
    Without a schema, you'd be working with the XmlObject returned from your
    newInstance or parse method.
    Steve
    "Olaf Wienk" <[email protected]> wrote in message
    news:4029ee05$[email protected]..
    >
    How can I add some additional attributes in in my toplevel element whencreating
    a new XML document from scratch using XMLBeans. For example the attributes"xmlns:xsi"
    and "xsi:schemaLocation" in the sample below:
    <?xml version="1.0" encoding="UTF-8"?>
    <MyDoc xmlns="http://www.xxx.nl/yyy"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://www.xxx.nl/yyy myXsd.xsd">
    <..../>
    <..../>
    </MyDoc>
    XML does add the "xmlns" attribute itself. How can I add the two otherattributes?
    >
    Currently I have a workaround. I read an "empty" XML-file containing theseattributes
    using XMLBeans (parse) and then I fill the empty structure. But I feelthat there
    has to be a better solution. Unfortunately I cannot find it.
    Any help is appreciated. Thank you in advance.

  • Additional Attributes in Mail Forms

    Hi
    I want to create mail form templates and want to add some custom attributes in the additional attributes category of attributes and then write my own logic for filling up the values in those additional attributes at runtime.
    What are the structures and BADIs I need to enhance in order to do this?
    Thanks in advance
    Vishal

    Hi,
    Check if below helps you (Maintain Attribute Contexts for Mail Forms)
    SPRO->Customer Relationship Management->Marketing->Marketing Planning and Campaign Management->Personalized Mail->Maintain Attribute Contexts for Mail Forms.
    Just go through the SPRO documentation for same, it might help you.
    Regards,
    Dipesh.

  • Internet Sales Order - Additional attributes

    Hi,
    I have a requirement to enable Certification Requirements for products being sold.  Process goes like this -
    Customer places a Sales Order on Internet via Internet Sales Solution.  While placing the order, customer would select the types of certifications required for the product for example: certificate on country of origin, Quality certificate etc.  User should be able to select multiple such certificates as required, while creating the Sales Order.  Is there any way I can achieve this?  I am thinking about using additional attributes (via Set Types and attributes) assigned to the product master.  But, by assigning these to the product master, can I see the same attirbutes in the Sales Order in Internet Sales?  Secondly, can these attributes (with values) be transferred back to R/3 Sales Order? Any suggestions will be appreciated and properly rewarded for good answers.
    Thanks in advance

    Hi Gopala,
    Yes. You can use additional products attributes to display the required certification parameters.
    But these attributes can't be transfered onto the sales order by default. You need to some java development / abap development to extend the sales order.
    If you want to transfer the same attributes to R/3 order then you have enhance the BAPIMATICS strucuture so that the middleware transfers them.
    Also you need to extend R/3 sales order to hold these attributes. This is a complex scenario and you need to design a good functional specification document before even attempting the design
    Let me know, if you need any further info.
    <b>
    Do not forget to reward if it helps,</b>
    Regards,
    Paul Kondaveeti

  • Additional Attributes in AS2 Header using Seeburger Adapter

    Hello,
    our business partner required that we include some additional attributes in the AS2 mime header that are used for internal routing purposes (in addition to the AS2 ID).
    Attributes for example include a submissionType etc. Is it somehow possible to add this attributes? According to the documentation I can only add dynamicAttributes for standard fields, such as content type etc.
    Thank you for your support.
    Edited by: Florian Guppenberger on Oct 6, 2009 7:14 PM

    Hi,
    I think you can.. but not recommended to modify standard Adapters.
    Check the below blog.
    http://www.sdn.sap.com/irj/scn/weblogs;jsessionid=(J2EE3417500)ID0328214750DB00705897531357746266End?blog=/pub/wlg/4645
    Why dont you use Message subject or Content type ?
    Thanks
    Deepthi.

  • Additional attributes in F4 Help

    Hi all,
    For a certain InfoObject we want to add an attribute in the F4-search help. Besides the Key and Description also this attribute appears when the user activates the F4-button on the selection-screen. We activated this attribute for F4-search in the InfoObject (“Order for F4 Help”) with value 01. However: the additional attribute does appear when executing the query in the Bex Analyzer but not on the Web. Anyone knows how to achieve this also for the web?
    Henk.

    Hi,
    I think you can.. but not recommended to modify standard Adapters.
    Check the below blog.
    http://www.sdn.sap.com/irj/scn/weblogs;jsessionid=(J2EE3417500)ID0328214750DB00705897531357746266End?blog=/pub/wlg/4645
    Why dont you use Message subject or Content type ?
    Thanks
    Deepthi.

  • Dynamic calc account using an attribute filter

    Hi experts,
    I have an account member as a dynamic calc tagged as two-pass, Its formula is: StoreMember1 / (StoreMember2/StoreMember3->MEMBER_IN_SPARSE_DIM),
    When i'm using an attribute filter that´s linked to one of my sparse dimensions the values of the account is not correct because it´s a percentage and the attribute filter just SUM the percentage of the values.
    What i really need and i don't know if it´s possible, is a way to recalculate my dynamic calc member after the attribute aggregate the value.
    Product1 Tagged as (Atribute XYZ)
    Product2 Tagged as (Atribute XYZ)
    StoreMember1->Product1 = 80
    StoreMember2->Product1 = 100
    StoreMember3->MEMBER_IN_SPARSE_DIM->NA_PRODUCT = 10
    80 / (100/10) = 8
    Dynamic_%->Product1 = 8% (Correct)
    StoreMember1->Product2 = 80
    StoreMember2->Product2 = 100
    StoreMember3->MEMBER_IN_SPARSE_DIM->NA_PRODUCT = 10
    80 / (100/10) = 8
    Dynamic_%->Product2 = 8% (Correct)
    StoreMember1->(Atribute XYZ) = 160
    StoreMember2->(Atribute XYZ) = 200
    StoreMember3->MEMBER_IN_SPARSE_DIM->NA_PRODUCT = 10
    160 / (200/10) = 8
    But in My calc
    Dynamic_%->(Atribute XYZ) = 16%  (But i need 8%)
    I'm using Plannig\Essbase 11.1.2
    Thank you in advance for your help

    The numbers are just to illustrate what is happening, my real numbers are others, there are about thousands products more.
    StoreMember2->(Atribute XYZ) = 200 it´s probably ok
    Because is the sum of the Product1 Tagged as (Atribute XYZ) = 100 + Product2 Tagged as (Atribute XYZ) = 100
    What´s happened is that when i look in XYZ attribute its simply sum after my dynamic calc
    StoreMember1->Product1 = 80
    StoreMember1->Product2 = 80
    StoreMember1->(Atribute Filter XYZ) = 160 (Ok)
    StoreMember2->Product1 = 100
    StoreMember2->Product2 = 100
    StoreMember2->(Atribute Filter XYZ) = 200 (OK)
    StoreMember3->MEMBER_IN_SPARSE_DIM->NA_PRODUCT = 10 (OK)
    160 / (200/10) = 8
    DynamicCalc% = 16 (wrong probably the attribute is a dynamic dimension that sum after dynamic calc Member)

  • Extending Role Object with additional attributes

    All,
    I understand that there are 5 attributes available for the Object type as displayed in the 'object' table in the Sun IdM DB repository. As such, i would like to add to the Role object a couple of primitive type attributes. I would appreciate if anyone who has done this or has the knowledge do this would tell me how and where i can go about configuring the role object to have additional attributes besides the 'name' attribute. Thank you.

    Wilfred,
    we are trying out IDM 8.0 and release notes and administration guide for that version says that you can
    extend attributes for Roles in IDM Schema Configuration Object.
    But, documentation only specifies how to add a User extended attrbute, we tried adding
    an attribute called escalators in the following way:
    <IDMObjectClassConfiguration name='Role' extends='Object' displayName='UI_OBJECTCLASS_ROLE' description='Role description'>
    <IDMObjectClassAttributeConfiguration name='escalators' queryable='true' summary='true'/>
    </IDMObjectClassConfiguration>
    we then modified Role Form.xml object and added the following for testing purposes:
    <Field name='escalators'>
    <Display class='MultiSelect'>
    <Property name='title' value='Escalators'/>
    <Property name='availableTitle' value='UI_ROLES_XML_AVAILABLE_OWNERS_LABEL'/>
    <Property name='selectedTitle' value='UI_ROLES_XML_CURRENT_OWNERS_LABEL'/>
    <Property name='allowedValues'>
    <List>
    <String>roleapprover</String>
    <String>approver1</String>
    </List>
    </Property>
    </Display>
    </Field>
    but the value in the Multiselect just goes to /dev/null....
    Can you help us with describing how to add an extended role attribute for IDM 8.0
    Thank you in advance

  • Sending additional information to Receiver Determination

    I have a need to send additional data to the receiver determination so I can use the condition steps to decide which service to call. But this data is not part of the payload. Is it possible to send this via the context object. Can add or modify the context object.
    Thank you,
    Parimala

    Hi Parimala,
    can't you use the switch step in BPM?
    >>> But this data is not part of the payload
    maybe you can get this data inside the payload (from java function or java mapping) in a transformation step and the use the switch step to decide with receiver should get this data?
    Regards,
    michal

  • SIT - Workflow -- Additional Attributes in SIT MSG

    Hi,
    In the SIT Process (Change Special Information) there is a sub process
    (Approvers Notification Process) inside this, there is one notification *"Notify Approver"*.
    This notification is having an HTML attribute in the body
    *"&HR_NTF_EMBEDDED_REGION"* which is calling an OAF-Region
    *"JSP:/OA_HTML/OA.jsp?OAFunc=-&HR_EMBEDDED_REGION-&NtfId=-&#NID-"*
    Problem is, We have add additional attribute which will pick some values
    randomely like &x &y &z
    If we will add our custom attribute along with the existing attribute
    "&HR_NTF_EMBEDDED_REGION" application is throwing error stating custom
    attributes (&X, &Y, &Z) is not recoginized by Region
    1. Attribute &X does not refer to a framework region
    2. Attribute &Y does not refer to a framework region
    3. Attribute &Z does not refer to a framework region
    In this case i dont want to customize framework region, to call my values of attribute X,Y and Z.
    How can i invoke values from Workflow Notification for the Custom Attribute with in the same notification
    Please help it's bit urgent.
    Thanks.
    Bachan

    Hi,
    We worked around for the issue. in a straight way it's not possible. Oracle has mentioned that you cant use Tokens with Attributes which is calling an JSP - Region.
    We removed the attribute which is calling JSP-Region (&HR_EMBEDDED_REGION) from the notification and added our custom Attributes which will call the segments of the SIT along with our required attributes.
    It's working fine.
    Thanks.
    Bachan.

  • Additional Attributes in DMS

    Hi
    I am defining characteristics for additional data for sap DMS, now my problem is I want to suppress some of attributes (characters) in additional data tab. For ex: I have 3 characteristics called 1.Vertical 2. Unit_Metal 3.Unit_Hyd in additional data. In Vertical I have two values called Metal and Hydrocarbon. Now my requirement is if I select Metal from Vertical then character (additional attribute) Unit_Hyd should suppress and if I select Hydrocarbon from Vertical, then Unit_ Metal should suppress.
    Thanks in Advance

    Hi Sham,
    regarding your question I would kindly recommend you to maintain specific relations between the different criteria.
    In transaction CT04 you can maintain the classification characteristics and also
    create dependencies on tab "Basic Data".
    The object dependency is used to define dependencies between different objects in configuration.
    By defining object dependencies, you can determine, for example:
    which combinations of characteristic values are allowed in a configuration
    which characteristics are to appear in the configuration
    which BOM items are selected
    which operations, sequences of operations, sub-operations, and PRTs are selected for a routing
    I hope this information is usefull for you.
    Best regards,
    Christoph

  • ISA 7.0 - Advanced search not picking up additional attributes

    Hello Folks,
    We are in the process of implemting ISA 7.0 (SP 16) aka E-Commerce for ERP - B2B senario. We have defined additional attributes (using the BADI during replication) for ISA 7.0 These can now be seen in the product details on ISA. However adding the bigSearch (below) or the advanceSearch (below) to the property file crmisaisacore~resources_en.properties does not display the additional searchable attributes. Anybody know what else I need to do ? Does this require modification/enhancement on the ISA Java side ?
    b2c.advSearch.field.MATKL=Brand family
    b2c.advSearch.field.SPART=Brand
    b2c.advSearch.field.J_3ASEAN=Season
    b2c.advSearch.field.PRODH1=Class
    b2c.advSearch.field.ZCOLOR=Color
    b2c.advSearch.field.J_3AKORD1=Size
    b2c.advSearch.field.J_3AKORD2=Width
    catalog.isa.bigsearch.MATKL=Brand family
    catalog.isa.bigsearch.SPART=Brand
    catalog.isa.bigsearch.J_3ASEAN=Season
    catalog.isa.bigsearch.PRODH1=Class
    catalog.isa.bigsearch.ZCOLOR=Color
    catalog.isa.bigsearch.J_3AKORD1=Size
    catalog.isa.bigsearch.J_3AKORD2=Width
    Thanks,
    Sid Joshi

    Hello SAP EMPLOYEE,
    The transaction you quote "comm_pcat_loc" does not exist in ECC. Please note I am working with ISA 7.0 for ERP (aka ECO for ERP). I appreciate any help provided.
    Thanks,
    Sid Joshi

  • SPNego login using additional attribute in LDAP

    Hello experts,
    We have a situation here to implement SPNego login for portal.
    We have integrated LDAP with portal and the j_user is mapped to an additional parameter (for ex, employee number) to enable the user to use this as a login-id instead of the default user-id.
    Say if the user is logged in with user-id : XYZ and for portal we are picking up the additional parameter (ex ,. ABC) from LDAP for login.
    But SPNego takes only the default user-id (XYZ) from windows. Can we cusomize SPNego to pick up additional attribute (ABC) to authenticate portal?
    Regards,
    Nirmal Sivakumar G
    Edited by: Nirmal G on Feb 3, 2009 12:47 PM

    Hi,
    pls. check steps provided in documentation:
    http://help.sap.com/saphelp_nwce711/helpdata/en/0b/d82c4142aef623e10000000a155106/frameset.htm
    Best regards,
    Johannes

  • How to make additional attributes mandatory

    Hi Experts,
    I want to make Additional fields mandatory.
    I went to CT04 and ticked entry required check box.
    But this tick gives only a warning message but not the error.
    How I can achieve the effect like error.
    I dont want to get DIR saved without Additional attributes.

    Hi Sunil,
    Please check following fields which we have used for my current project for BDC purpose:
    doknr(025) type c,
    dokar(003) type c,
    doktl(003) type c,
    dokvr(002) type c,
    dktxt(040) type c,
    stabk(002) type c,
    labor(003) type c,
    begru(004) type c,
    mwert_01(40) type c,
    mwert_02(40) type c,
    mwert_03(40) type c,
    mwert_04(40) type c,
    mwert_05(40) type c,
    mwert_06(40) type c,
    mwert_07(40) type c,
    mwert_08(40) type c,
    mwert_09(40) type c,
    mwert_10(40) type c,
    matnr(18) type c,
    lifnr(10) type c,
    These are some additional fields used while coding BDC.
    Now , with help of abap'r please check for enhancement spots and coding needs to be done to achieve your requirement.
    I hope this will help more
    Regards,
    Ravindra

Maybe you are looking for

  • Ipod Mini Battery Drain

    My Ipod Mini battery drains down without any use. Is this normal. My HP Ipaq 4155 battery does not drain down without any usage. Can anyone help me please. Thanks, Jeff

  • Why CONTROL_FLUSH_ERROR exception is occuring

    why CONTROL_FLUSH_ERROR exception is occuring and whats meanind of this exception. this exception is in function module GUI_DOWNLOAD. PLEASE GIVE ME SUGGESTION THANKS IN ADVANCED.

  • Photoshop Color Picker not popping up?

    Whenever I click on the color picker in Photoshop CS5, it is defaulting to opening up the eyedropper tool instead of the color chooser option. The eyedropper tool is not working correctly either. Does anybody know what setting might be causing the is

  • HT1660 How can I get my library from my i pod back to the computer after a crash?

    I lost my library after a computer crash.  I'd like to transfer everything back from my I Pod if possible.  I reinstalled I tunes and the screen looks totally different  There is no 'file' to work from and the disc does not get picked up from the dri

  • Scrubbing numbers problem.

    Ever since I updated a long time ago, I have been having issues with scrubbing numbers by clicking on the number and dragging my mouse left or right to increase or decrease the value. Issues meaning: when I begin to move the mouse to the left or righ