Specifying RADIUS Authentication and Authorization for a Group (Network Request Policy)
- Last Updated: June 11, 2025
- 4 minute read
- LoadMaster
- LoadMaster GA
- Documentation
Specifying RADIUS Authentication for a Group
To set up a network policy, follow the steps below in the Server Manager.
- In the panel on the left, go to
Policies > Network Policies.
- Click New
in the panel on the right.
- Enter a Policy name.
- Click Next.
- Click the Add…
button.
- Select the relevant group type.
- Click the Add…
button.
- Click the Add
Groups… button.
- Enter the group name in the text area provided.
- Click Check Names.
- If the name is alright, click OK.
- Click OK.
- Click Next.
- Select the relevant Access Permission option.
- Click Next.
- Remove the tick from the Microsoft Encrypted Authentication version 2 (MS-CHAP-v2) check box.
- Ensure that Microsoft Encrypted Authentication (MS-CHAP) is selected.
- Ensure that User can change password after it has expired is selected.
- Select the Unencrypted authentication (PAP, SPAP) check box.
- Click Next.Note: If idle timeout is used on the server it should match the idle timeout settings in the LoadMaster. Generally, we recommend not setting this on the server.
- Click Next.
Note: The Progress Kemp RADIUS policies should be
moved to the top of the policy list on the Windows RADIUS server. The policies are
executed in the order they are displayed.
Specify RADIUS Authorization for a Group
Note: The Attributes on
this screen need to be in a certain order for the settings to work correctly.
The order is as follows: 1. Reply-Message2. Framed-Protocol3.
Service-Type
Note: Unfortunately, these attributes are not
movable. So, to order these attributes correctly, you need to Remove and then Add them.
- Select Framed-Protocol and click Remove.
- Select Service-Type and click Remove.
- Click the Add…
button.
- Select Reply-Message.
- Click the Add…
button.
- Click the Add… button.
- Enter the relevant permission
option(s) and click OK.Note: The available permission options are as follows:real,vs,rules,backup,certs,cert3,certbackup,users,root,addvsThese correspond to the permission options in the LoadMaster Web User Interface (WUI). The root permission grants all permissions. Multiple attributes can be specified here, but they must be separated by a comma (with no space).
- Click OK again.
- Select Framed-Protocol.
- Click the Add… button.
- Select PPP from the Commonly used for Dial-Up or VPN drop-down list.
- Click OK.
- Select Service-Type.
- Click the Add… button.
- Select Framed from the Commonly used for Dial-Up or VPN drop-down list.
- Click OK.
- Click Close.
- Click Next.
- Click Finish.
- Repeat this process as needed to set permissions for other groups.