Thanks for your reply. The problem is, I can assign role 'reject' only after the radius has sent an access-accept response. My end device sends tagged packets and as soon as radius response is accept the device goes into forwarding mode regardless that the radius server assigns a registration VLAN or 'reject role'. Since the VLAN is tagged it is not possible to influence it. Therefore, I wanted to ask if there is a way that the radius server can send response reject at the first place so the port doesn't allow any device to go into forwarding mode. Regards, Sajawal Ghani Network Engineer _________________________________
iternas GmbH Niederlassung Stuttgart Mobil: +49 172 894 52 77 Hauptsitz: iternas GmbH Pappelallee 78/79 10437 Berlin Tel: +49 30 609 800 24-0 E-Mail: [email protected] Web: http://www.iternas.com Amtsgericht Berlin (Charlottenburg), HRB 204123 B Geschäftsführer: Morris Görke
_______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users
