Configure a Connection Request Policy for RADIUS Proxy

Connection request policies allow you to designate whether connection requests are processed locally or forwarded to remote RADIUS servers.
You can configure a connection policy request to look for <@guest> in the user name, and, if found, forward the request to the remote RADIUS server group. To configure a connection request policy for a RADIUS proxy, perform the following steps:
  1. On the NPS, expand Policies and select Connection Request Policy.
  2. From the Action menu, select New
    (Alternately, you can right-click and select New.)
  3. In the New Connection Request Policy window, enter a Policy name, and click Next.
  4. In the Specify Conditions window, click Add.
  5. In the Select Condition window, select NAS Port Type, and click Add.
  6. In the NAS Port Type window, check the box for the following settings:
    • Wireless IEEE 802.11 in the 802.1X connection tunnel types section.
    • Wireless - Other in the Others section.
    Click OK.

    NAS Port Type

  7. In the Specify Conditions window, click Add.
  8. Select User name and click Add.
  9. In the User Name window, enter .*@guest. Click OK.
  10. In the Specify Conditions window, click Next.
  11. In the Specify Connection Request Forwarding window, perform the following steps:
    1. In the left pane, select Authentication.
    2. In the right pane, select Forward requests to the following remote RADIUS server group for authentication.
    3. Select the ES remote RADIUS server group you previously created.
    4. Click Next.

    Specify Connection Request - Authentication

  12. In the Configure Settings window, perform the following steps:
    1. In the left pane, select Attribute under Specify a Realm Name.
    2. In the right pane, select User Name from the Attribute list.
    3. Click Next.
  13. Review the connection request policy configuration in the Completing Connection Request Policy Wizard window, and click Finish.
With this configuration, user@guest is forwarded by the NPS to Cloudpath for authentication, while user is authenticated directly by the NPS.