I'm new to Juniper products and have been tasked to implement SSL access using the MAG 4610 appliance. I've got a pretty good handle on creating roles and how they are assigned to users. We have approximately 150 Active Directory groups that will be accessing the system and each will need to be mapped to a different role. The role names will mirror the AD group names. Is it possible to create a custom expression that would match the AD group with a role and if there are no matches then drop the user into a catch-all role. Ideally I'd only have one or two custom expressions to accomplish this. If someone could provide and example I'd much appreciate it, I've read a lot of documentation on custom expressions but there aren't a lot of examples. I've got the system successfully authenticating to our domain controllers and can see the groups so that part is complete. Thanks for any and all help
... View more