Manage user authorization attributes in remote access VPN policies
The Firewall Threat Defense device allows you to apply user authorization attributes, also called entitlements or permissions, to VPN connections. These attributes can come from an external AAA server (such as RADIUS) or through a group policy on the device, allowing precise control of user access during remote VPN sessions.
Authorization attribute order
Firewall Threat Defense applies user authorization attributes in this order:
-
User attributes in the external AAA server—The server returns these attributes after a successful user authentication, authorization, or both.
-
User attributes in the device's group policy—If a RADIUS server returns the RADIUS Class attribute IETF-Class-25 with the value
OU=group-policyfor a user, the Firewall Threat Defense device assigns the user to the group policy with the same name and enforces any attributes from that group policy which are not provided by the server. -
User attributes in the device's group policy assigned by a connection profile—The connection profile defines the initial settings for a remote access VPN connection and includes a default group policy that is applied to the user before authentication.
NoteThe Firewall Threat Defense device does not inherit system default attributes from the default group policy,
DfltGrpPolicy. Instead, it uses the attributes from the group policy assigned to the connection profile for the user session, unless overridden by user attributes or a group policy from the AAA server.