- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
WC7600v2 really RFC 2866 Radius Accounting Compliant?
Hi Netgear Community,
Before I contact Netgear support to give feedback in regards to the quality of their wireless controllers I wanted to seek clarification from Netgear community about an issue we are currently facing at our site.
We would like to utilise the Radius accounting information generated by our WC7600v2 (firmware v6.5.1.11) to be utilised by our Windows 2012r2 NPS server. The specific attribute we need is the "Framed-IP-Address" attribute to contain the IP address of the client / user requesting the authentication. This attribute is helpful in identifying successfully authenticated clients to be simultaneously authenticated against other systems i.e. like internet filters. Some internet filters providers utilise agent software that can sit on a Windows NPS server and read the logs generated by the NPS service and automatically apply the appropriate internet access policy to the client devices / users at the moment of wireless authentication essentially providing a Single Sign On process.
After attempting to undertake this process at a site that utilises a Netgear WC7600v2 we have come to the conclusion that the WC7600v2 does not provide the Framed-IP-Address. This has been confirmed by reviewing the NPS server logs where Framed-IP-Address radius attribute is 0.0.0.0 for all clients authenticating via the WC7600v2
Thanks to previous advice on this forum, we were able to make contact with Netgear text based support and after sometime the Netgear technician, he was able to confirm that the WC7600v2 does not provide the Framed-IP-Address as part of its radius account response to the NPS (radius) server. This feature maybe included sometime in the future but could not give any ETA on its implementation; he was also able to confirm that other customers of the WC7600 series have requested this feature to be implemented.
What my site is trying to perform is something that is not to complex, I have done it many times via cisco / h3c / Aruba controllers and wireless implementations. These devices are more compliant with the RFC 2866 radius standard than what Netgear equipment is, even though your product information sheet (https://www.netgear.com/images/datasheet/wireless/wirelessmanagement/WC7600v2.pdf) states that the controller is complaint with this spec.
How are we meant to recommend Netgear equipment to clients in enterprise when the device does not standard up against large enterprise network equipment manufactures. I can understand something like "it will be included in the next firmware release" but when something like "No ETA at this time" it makes us feel like recommending to the site management the entire removal the Netgear wireless implementation and going for something "more enterprise".
Do you think if the site invested in Prosafe support agreement it would carry more weight with Netgear in implementing a basic feature like a more extensive implementation of the RFC 2866 accounting standard?
I hope that I do not come across as too negative in this forum thread, but was hoping to provide constructive feedback to help improve your products and the process to improve them.
Peter
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.