Hi, Yes, your use-case requires 10 different realms. You might not be able to do role-mapping based on Radius-attributes if authentication server is system-local, AD, LDAP etc.. However, role-mapping based on radiu-attributes is allowed if backend is again another Radius server. Radius request policies are available at realm level to enforce the checks or restrictrictons even before actual authentication and it makes perfect sense to me. Role mapping happens after authentication against local or backend server, and it is costly operation. Note: If I have answered your question, you could mark this post as accepted solution, that way it would help others as well. A kudos will be bonus thanks!! Thank you. Regards, Raveen
... View more