Assuming you are using Checkpoint you can create a user called generic star
and point him to your RADIUS server to achieve your desired result.  I would
suggest using a Win2k machine that belongs to your domain running the IAS
service (which provides RADIUS as an option).  This is what we are doing and
it works great!

Regards,
Tim Anderson

-----Original Message-----
From: Francois Dessart [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, December 12, 2001 3:40 AM
To: [EMAIL PROTECTED]
Subject: [FW-1] Securemote and Radius


Hello,

I would like to use VPN Securemote on my firewall.

However I have a lot of users and they have to get different rights when
connecting to the gateway with securemote.

I would like to use Radius or LDAP. Is it possible (and how) to define
several different groups using Radius or LDAP attributes, without
enumerating all users in my policy editor?

Thanks for your help.
------------------------------------------------------
Francois DESSART
Network Engineer - SEGI/ULG

=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
If you have any questions on how to change your
subscription options, email Ron Alcatraz at:
[EMAIL PROTECTED]
=================================================

=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
If you have any questions on how to change your
subscription options, email Ron Alcatraz at:
[EMAIL PROTECTED]
=================================================

Reply via email to