So I found this page, which indicates that the policy attribute 'group-lock' is used to limit a vpn group-policy so that valid users can only login to groups to which the radius server says they ...
I have several Aironet 1100s and more than one is exhibiting this problem, making me think this is a network or firewall issue (there's an OpenBSD firewall between the WAPs and the RADIUS/IAS server).
Some results have been hidden because they may be inaccessible to you
Show inaccessible results
Feedback