> Is it possible to select > based on EAP-type (i.e. if TTLS, do LOCAL authentication?) Right not we > are doing it based on prefix/suffix.
Stick to it. Since radius server has no say in what authentication protocol is used (that is determined between NAS and supplicant) such policy would be easily defeated. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html