>If I change the fall through to yes it still matches as many groups as the >user is in. How can I tell freeradius which attributes to send back?
If you want to send sets of attributes according to the NAS user is trying to log into use huntgroups. >For example, bevege is a member of the following groups, packetshapper, >cisco_priv_15, cisco_priv_1, linux. Your group allocation is wrong. You can't have the same user(name) on the same device having priv levels 1 and 15. Pick one. Or have him log in as [EMAIL PROTECTED] and [EMAIL PROTECTED] and use realms to allocate correct set of attributes. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html