currently i am using cistron radius 1.5.but i want to use
ascend-Data -filter.it is not suppporting.therefore i installed freeradius
1.3 .i i try to connect dial users to the system it is generating log as
follows


Date Time :Error :Ignoring request from unknown client 193.220.28.9:1025

if anybody familier whit this plese response me

thanking you

saman
----- Original Message -----
From: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, October 31, 2001 5:11 PM
Subject: Freeradius-Users digest, Vol 1 #315 - 21 msgs


> Send Freeradius-Users mailing list submissions to
> [EMAIL PROTECTED]
>
> To subscribe or unsubscribe via the World Wide Web, visit
> http://lists.cistron.nl/mailman/listinfo/freeradius-users
> or, via email, send a message with subject or body 'help' to
> [EMAIL PROTECTED]
>
> You can reach the person managing the list at
> [EMAIL PROTECTED]
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Freeradius-Users digest..."
>
>
> Today's Topics:
>
>   1. Configuration of radius to Authenticate from Oracle (Smirk Smirk)
>   2. Help (Smirk Smirk)
>   3. Re: NAS/Radius discrepancy (Bogdan)
>   4. hi guys...help needed!! (Mayur Deodhar)
>   5. Re: hi guys...help needed!! (Kostas Kalevras)
>   6. example ascend l2tp users (Toni Demmel)
>   7. MPPE (Matt Nowina)
>   8. Re: one client login needs to login in two servers. (Chris Parker)
>   9. Re: Configuration of radius to Authenticate from Oracle (Chris
Parker)
>   10. Re: NAS/Radius discrepancy (Chris Parker)
>   11. Re: radclient question ([EMAIL PROTECTED])
>   12. Re: hi guys...help needed!! (Chris Parker)
>   13. Re: example ascend l2tp users (Chris Parker)
>   14. Re: MPPE (Chris Parker)
>   15. Re: one client login needs to login in two servers.
([EMAIL PROTECTED])
>   16. Re: FW: Failed to link to module 'rlm_unix': file not found
([EMAIL PROTECTED])
>   17. MPPE (Matt Nowina)
>   18. Re: radclient question (jason)
>   19. core dumps where? (Matt Rose)
>   20. Re: core dumps where? ([EMAIL PROTECTED])
>   21. Re: core dumps where? (Chris Parker)
>
> --__--__--
>
> Message: 1
> From: "Smirk Smirk" <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: Configuration of radius to Authenticate from Oracle
> Date: Wed, 31 Oct 2001 13:19:44 +0500
> Reply-To: [EMAIL PROTECTED]
>
> Dear All,
>
> I am a trying to use Free-Radius. I downloaded it Last week. But I am
failed
> to get the authentication from oracle. Do any body knows how to put an
entry
> in the Radiusd.Conf for Oracle further in the Users file and SQL.Conf.
>
> I will be very thankfull to you all for this help.
>
> Bye
>
> Shafiq
>
> _________________________________________________________________
> Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp
>
>
>
> --__--__--
>
> Message: 2
> From: "Smirk Smirk" <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: Help
> Date: Wed, 31 Oct 2001 13:24:56 +0500
> Reply-To: [EMAIL PROTECTED]
>
> Dear All,
>
> Sorry for again. Cuz I got my subcription mail and read the instruction
> about sending the mail to you all. So I am again describing my problem.
>
> I have configured the oracle server running on my machine and i have
already
> created the radius recommended schema in the oracle. Please tell me what
> entries i have to post into the radiusd.conf, users file to get the
> authentication from the oracle table.
>
> I will be very thankfull to you all
>
> Thanks & Bye
>
> Shafiq
>
> _________________________________________________________________
> Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp
>
>
>
> --__--__--
>
> Message: 3
> From: "Bogdan" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: Re: NAS/Radius discrepancy
> Date: Wed, 31 Oct 2001 23:37:02 +1100
> charset="iso-8859-1"
> Reply-To: [EMAIL PROTECTED]
>
> I was wondering,
> I still use "users" file for DEFAULTs, because we don't change them so
often
> and it seems to work OK, (when i change login times it stops user from
login)
> wouldn't smnpget module check the NAS username and state and report
> no login for that user on the fly, I though that this what the sample
said, that
> radius checks for user login in the radutmp first and then confirms with
NAS that
> user is or is not loged in, but i am just a beginnner with radius, so i'm
probably wrong.
> Alan have mentioned about the patch, if it is possible could i get a copy,
please?
> Thanks a'lot
> Bogdan
>
> ----- Original Message -----
> From: <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Wednesday, October 31, 2001 2:48 AM
> Subject: Re: NAS/Radius discrepancy
>
>
> > "Bogdan" <[EMAIL PROTECTED]> wrote:
> > > I still have a problem however, with "Simultaneus-Use :=1"
> > > rradius.log error is
> > >     Error: rlm_sql: Stop packet with zero sesion length (ueser
'testtwo', nas 'rt1.ccentre.net.au')
> >
> >   That error is not related to Simultaneous-Use
> >
> > > But NAS lets me in as a second user
> >
> >   Yes.  The SQL tables don't support operators.  I have a patch
> > sitting around somewhere to do it...
> >
> >   Alan DeKok.
> >
> > -
> > List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html
> >
>
>
>
>
> --__--__--
>
> Message: 4
> From: "Mayur Deodhar" <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: hi guys...help needed!!
> Date: Wed, 31 Oct 2001 14:19:14 +0100
> Reply-To: [EMAIL PROTECTED]
>
> hi guys,
> am a new user to this group. would want help on how to install the radius
on redhat 7.1 system. also would like to know the options for the backend
database for the password access like ldap, mysql etc
> its urgent guys,
> thanks in advance
> Mayur.
> smartmay
> e-mail: [EMAIL PROTECTED]
>
>
>
>
> --__--__--
>
> Message: 5
> Date: Wed, 31 Oct 2001 16:30:19 +0200 (EET)
> From: Kostas Kalevras <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: Re: hi guys...help needed!!
> Reply-To: [EMAIL PROTECTED]
>
> On Wed, 31 Oct 2001, Mayur Deodhar wrote:
>
> > hi guys,
> > am a new user to this group. would want help on how to install the
> > radius on redhat 7.1 system. also would like to know the options for the
> > backend database for the password access like ldap, mysql etc
> > its urgent guys,
> > thanks in advance
> > Mayur.
> > smartmay
> > e-mail: [EMAIL PROTECTED]
> >
> >
> >
> > -
> > List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html
> >
>
> ./configure  --prefix=/usr/local/radiusd
> --with-rlm-ldap-lib-dir=/usr/local/openldap/lib
> --with-rlm-ldap-include-dir=/usr/local/openldap/include
> --with-mysql-lib-dir=/usr/local/mysql/lib/mysql
> --with-mysql-include-dir=/usr/local/mysql/include
>
> Look at doc dir,edit radiusd.conf and sql.conf to match your setup.
> Add nases in clients.conf,naslist and naspasswd
>
> If you want to do auth from ldap then you will have to add the
radiusprofile
> schema in the ldap and change the corresponding user entries (add
> objectclass:radiusprofile and any radius attribute you want).
> You could place the default attributes in the users file in DEFAULT
entries and
> only place non default radius attributes in ldap.
>
> --
> kkalev
>
>
>
>
> --__--__--
>
> Message: 6
> Date: Wed, 31 Oct 2001 15:45:03 +0100
> From: Toni Demmel <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: example ascend l2tp users
> Reply-To: [EMAIL PROTECTED]
>
> Hi there
>
> Could someone post me an example of the users file
> when trying to setup an L2TP Tunnnel between an Ascend
> Max2000/Max6000 and a cisco box, whilst the max is the LAC
> Box??
>
> Cheers
>
>
> --__--__--
>
> Message: 7
> From: "Matt Nowina" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: MPPE
> Date: Wed, 31 Oct 2001 10:00:36 -0500
> charset="us-ascii"
> Reply-To: [EMAIL PROTECTED]
>
> Hi Again,
>
> I've finally succeeded in successfully setting up MS-CHAP authentication
> for pptp clients (Thanks to Alan for his assistance with the rlm_mschap
> module), but I have hit a snag negotiating mppe encryption. It appears
> that the cisco router doesn't understand or is not receiving mppe keys
> from the radius server.
>
> In looking through the RFC for MS-CHAP, it states that the access-accept
> packet should contain one or no instances of the following:
>
> 7 MS-MPPE-Encryption-Policy
> 8 MS-MPPE-Encryption-Type
> 12 MS-CHAP-MPPE-Keys
> 16 MS-MPPE-Send-Key
> 17 MS-MPPE-Recv-Key
>
> Although I can set these values under the 'users' file to send back
> during the negotiation, I cant seem to figure out the proper syntax to
> declare them in octet form. The 2 other questions I had were first, is
> the des function included with rlm_mschap able to negotiate 40bit &
> 128bit encryption or is it limited to 56-bit? And secondly whether there
> is a way to use the radius server only for authentication and then punt
> the encryption process back to the router after a user has been
> successfully authenticated?
>
> Thanks again for your help,
>
> Matt
>
> -----------------------
> Matt Nowina
> Network Operations
> InQuent Technologies
> 416-645-4633
>
>
>
>
>
> --__--__--
>
> Message: 8
> Date: Wed, 31 Oct 2001 09:17:46 -0600
> To: [EMAIL PROTECTED]
> From: Chris Parker <[EMAIL PROTECTED]>
> Subject: Re: one client login needs to login in two servers.
> com>
> Reply-To: [EMAIL PROTECTED]
>
> At 09:53 AM 10/31/2001 +0530, you wrote:
>
> >Hi,
> >         I am using freeradius for SNMP application.
> >         I have security manager and SNMP++ manager.
> >         My problem is...
> >         When a client logs in it needs to login in both security manager
and
> >SNMP++ manager.
> >         Is there any way to do it?
>
> Not quite sure what you are asking here.  Perhaps a little more detail
> on what you are trying to get FreeRADIUS to do would help.
>
> Thanks,
> -Chris
>
> --
>     \\\|||///  \  Chris Parker    -    Manager, Development Engineering
>     \ ~   ~ /   \       WX *is* Wireless!    \   [EMAIL PROTECTED]
>     | @   @ |    \   http://www.starnetwx.net \      (847) 963-0116
> oOo---(_)---oOo--\------------------------------------------------------
>                    \ Without C we would have 'obol', 'basi', and 'pasal'
>
>
>
> --__--__--
>
> Message: 9
> Date: Wed, 31 Oct 2001 09:19:28 -0600
> To: [EMAIL PROTECTED]
> From: Chris Parker <[EMAIL PROTECTED]>
> Subject: Re: Configuration of radius to Authenticate from Oracle
> Reply-To: [EMAIL PROTECTED]
>
> At 01:19 PM 10/31/2001 +0500, Smirk Smirk wrote:
> >Dear All,
> >
> >I am a trying to use Free-Radius. I downloaded it Last week. But I am
> >failed to get the authentication from oracle. Do any body knows how to
put
> >an entry in the Radiusd.Conf for Oracle further in the Users file and
SQL.Conf.
>
> What types of errors or failures are you getting?  Running the server
> in debug mode:  radiusd -x -x will give you a lot of information on what
> it is doing at each stage.
>
> Also, you may want to try running one of the latest snapshots, as they
> have more things fixed than the 0.3 release.
>
> -Chris
> --
>     \\\|||///  \  Chris Parker    -    Manager, Development Engineering
>     \ ~   ~ /   \       WX *is* Wireless!    \   [EMAIL PROTECTED]
>     | @   @ |    \   http://www.starnetwx.net \      (847) 963-0116
> oOo---(_)---oOo--\------------------------------------------------------
>                    \ Without C we would have 'obol', 'basi', and 'pasal'
>
>
>
> --__--__--
>
> Message: 10
> Date: Wed, 31 Oct 2001 09:21:17 -0600
> To: [EMAIL PROTECTED]
> From: Chris Parker <[EMAIL PROTECTED]>
> Subject: Re: NAS/Radius discrepancy
> Reply-To: [EMAIL PROTECTED]
>
> At 11:37 PM 10/31/2001 +1100, Bogdan wrote:
> >I was wondering,
> >I still use "users" file for DEFAULTs, because we don't change them so
often
> >and it seems to work OK, (when i change login times it stops user from
login)
> >wouldn't smnpget module check the NAS username and state and report
> >no login for that user on the fly, I though that this what the sample
> >said, that
> >radius checks for user login in the radutmp first and then confirms with
> >NAS that
> >user is or is not loged in, but i am just a beginnner with radius, so i'm
> >probably wrong.
>
> That is how the Simultaneous-Use checking is supposed to work, yes.  :)
>
> >Alan have mentioned about the patch, if it is possible could i get a
copy,
> >please?
>
> I believe this was just committed to the current source, so you might want
> to try the latest snapshot/cvs version.
>
> -Chris
>
> --
>     \\\|||///  \  Chris Parker    -    Manager, Development Engineering
>     \ ~   ~ /   \       WX *is* Wireless!    \   [EMAIL PROTECTED]
>     | @   @ |    \   http://www.starnetwx.net \      (847) 963-0116
> oOo---(_)---oOo--\------------------------------------------------------
>                    \ Without C we would have 'obol', 'basi', and 'pasal'
>
>
>
> --__--__--
>
> Message: 11
> To: [EMAIL PROTECTED]
> Subject: Re: radclient question
> <25CCC6566D01D411885B00A024559FB70145435E@EXCHANGE_GERAL>
> Date: Wed, 31 Oct 2001 10:22:53 -0500
> From: [EMAIL PROTECTED]
> Reply-To: [EMAIL PROTECTED]
>
> Luis Azevedo <[EMAIL PROTECTED]> wrote:
> > I have this known problem:
> >
http://lists.cistron.nl/pipermail/freeradius-users/1999-August/001490.html
> >
> > But i dont know how to build with shared libraries... :-(
>
>   FreeRADIUS uses shared libraries by default, when you do
> './configure;make;make install'.
>
>   The only way to NOT use shared libraries is to pass an option to
> 'configure' telling it that you don't want shared libraries.
>
>   Alan DeKok.
>
>
> --__--__--
>
> Message: 12
> Date: Wed, 31 Oct 2001 09:22:39 -0600
> To: [EMAIL PROTECTED]
> From: Chris Parker <[EMAIL PROTECTED]>
> Subject: Re: hi guys...help needed!!
> Reply-To: [EMAIL PROTECTED]
>
> At 02:19 PM 10/31/2001 +0100, Mayur Deodhar wrote:
> >hi guys,
> >am a new user to this group. would want help on how to install the radius
> >on redhat 7.1 system.
>
> ./configure
> make
> make install
>
> >also would like to know the options for the backend database for the
> >password access like ldap, mysql etc
>
> See the various docs in the '/docs' directory in the package.
>
> -Chris
> --
>     \\\|||///  \  Chris Parker    -    Manager, Development Engineering
>     \ ~   ~ /   \       WX *is* Wireless!    \   [EMAIL PROTECTED]
>     | @   @ |    \   http://www.starnetwx.net \      (847) 963-0116
> oOo---(_)---oOo--\------------------------------------------------------
>                    \ Without C we would have 'obol', 'basi', and 'pasal'
>
>
>
> --__--__--
>
> Message: 13
> Date: Wed, 31 Oct 2001 09:23:57 -0600
> To: [EMAIL PROTECTED]
> From: Chris Parker <[EMAIL PROTECTED]>
> Subject: Re: example ascend l2tp users
> Reply-To: [EMAIL PROTECTED]
>
> At 03:45 PM 10/31/2001 +0100, you wrote:
> >Hi there
> >
> >Could someone post me an example of the users file
> >when trying to setup an L2TP Tunnnel between an Ascend
> >Max2000/Max6000 and a cisco box, whilst the max is the LAC
> >Box??
>
> Full Tunnel Support is currently being added to the server.  Try back
> in a couple days, and it should be fully possible.
>
> -Chris
> --
>     \\\|||///  \  Chris Parker    -    Manager, Development Engineering
>     \ ~   ~ /   \       WX *is* Wireless!    \   [EMAIL PROTECTED]
>     | @   @ |    \   http://www.starnetwx.net \      (847) 963-0116
> oOo---(_)---oOo--\------------------------------------------------------
>                    \ Without C we would have 'obol', 'basi', and 'pasal'
>
>
>
> --__--__--
>
> Message: 14
> Date: Wed, 31 Oct 2001 09:31:57 -0600
> To: [EMAIL PROTECTED]
> From: Chris Parker <[EMAIL PROTECTED]>
> Subject: Re: MPPE
> Reply-To: [EMAIL PROTECTED]
>
> At 10:00 AM 10/31/2001 -0500, Matt Nowina wrote:
> >Hi Again,
> >
> >I've finally succeeded in successfully setting up MS-CHAP authentication
> >for pptp clients (Thanks to Alan for his assistance with the rlm_mschap
> >module),
>
> Excellent!  :)
>
> >but I have hit a snag negotiating mppe encryption. It appears
> >that the cisco router doesn't understand or is not receiving mppe keys
> >from the radius server.
> >
> >In looking through the RFC for MS-CHAP, it states that the access-accept
> >packet should contain one or no instances of the following:
> >
> >7 MS-MPPE-Encryption-Policy
> >8 MS-MPPE-Encryption-Type
> >12 MS-CHAP-MPPE-Keys
> >16 MS-MPPE-Send-Key
> >17 MS-MPPE-Recv-Key
> >
> >Although I can set these values under the 'users' file to send back
> >during the negotiation, I cant seem to figure out the proper syntax to
> >declare them in octet form.
>
> What are the dictionary entires you have currently, and what does your
> users file look like now for the value?
>
> >The 2 other questions I had were first, is
> >the des function included with rlm_mschap able to negotiate 40bit &
> >128bit encryption or is it limited to 56-bit?
>
> Not sure on this one, as I'm not as familiar with that module.
>
> >And secondly whether there
> >is a way to use the radius server only for authentication and then punt
> >the encryption process back to the router after a user has been
> >successfully authenticated?
>
> Not quite sure what you mean by this.  Can you elaborate a little more?
>
> -Chris
> --
>     \\\|||///  \  Chris Parker    -    Manager, Development Engineering
>     \ ~   ~ /   \       WX *is* Wireless!    \   [EMAIL PROTECTED]
>     | @   @ |    \   http://www.starnetwx.net \      (847) 963-0116
> oOo---(_)---oOo--\------------------------------------------------------
>                    \ Without C we would have 'obol', 'basi', and 'pasal'
>
>
>
> --__--__--
>
> Message: 15
> To: [EMAIL PROTECTED]
> Subject: Re: one client login needs to login in two servers.
> <[EMAIL PROTECTED]>
> Date: Wed, 31 Oct 2001 10:39:22 -0500
> From: [EMAIL PROTECTED]
> Reply-To: [EMAIL PROTECTED]
>
> "Prasad Valmeti" <[EMAIL PROTECTED]> wrote:
> > My problem is...
> > When a client logs in it needs to login in both security manager and
> > SNMP++ manager.
> > Is there any way to do it?
>
>   Exec-Program-Wait
>
> DEFAULT
> Exec-Program-Wait = "/path/to/program"
>
>
>   That is, you can write an external shell script to do that work for
> you.  It gets passed the username && password.  See the 'doc'
> directory for more information.
>
>   Alan DeKok.
>
>
> --__--__--
>
> Message: 16
> To: [EMAIL PROTECTED]
> Subject: Re: FW: Failed to link to module 'rlm_unix': file not found
> <25CCC6566D01D411885B00A024559FB701454361@EXCHANGE_GERAL>
> Date: Wed, 31 Oct 2001 10:27:18 -0500
> From: [EMAIL PROTECTED]
> Reply-To: [EMAIL PROTECTED]
>
> Luis Azevedo <[EMAIL PROTECTED]> wrote:
> > I just tried to change "Make.inc" in the parameters:
> > USE_SHARED_LIBS = yes
> > USE_STATIC_LIBS = no
> >
> > But it doesn't work and after #make I get:
> >
> > *** Warning: inter-library dependencies are not known to be supported.
> > *** All declared inter-library dependencies are being dropped.
>
>   So your system cannot do inter-library dependencies.  What the heck
> kind of Unix is it?
>
>   Note that the output of the 'configure' script says whether or not
> it can build shared libraries.  Reading it's output may help ytou
> understand why shared libraries won't work.
>
>
>   The build system for the server still has to be updated for certain
> weird configurations.  I guess yours doesn't work yet, sorry.
>
>   What you may be able to do is to go to src/main/Makefile, and edit
> it.  Look for:
>
> ifneq ($(USE_SHARED_LIBS),yes)
> MODULE_LIBS += $(shell for x in ../modules/rlm_*/rlm_*.la;do
echo -dlpreopen $$x;done)
> endif
>
>   Replace the 'endif' with:
>
> else
> MODULE_LIBS   += $(shell for x in ../modules/rlm_*/rlm_*.la;do
echo -dlopen $$x;done)
> endif
>
>
>   that may help.
>
>   Alan DeKok.
>
>
> --__--__--
>
> Message: 17
> From: "Matt Nowina" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: MPPE
> Date: Wed, 31 Oct 2001 10:52:34 -0500
> charset="us-ascii"
> Reply-To: [EMAIL PROTECTED]
>
> >From [EMAIL PROTECTED]  Wed Oct 31 15:31:57 2001
> >Date: Wed, 31 Oct 2001 09:31:57 -0600
> >From: Chris Parker [EMAIL PROTECTED]
> >Subject: MPPE
> >
> >At 10:00 AM 10/31/2001 -0500, Matt Nowina wrote:
> >>Hi Again,
> >>
> >>I've finally succeeded in successfully setting up MS-CHAP
> authentication
> >>for pptp clients (Thanks to Alan for his assistance with the
> rlm_mschap
> >>module),
> >
> >Excellent!  :)
> >
> >>but I have hit a snag negotiating mppe encryption. It appears
> >>that the cisco router doesn't understand or is not receiving mppe keys
> >>from the radius server.
> >>
> >>In looking through the RFC for MS-CHAP, it states that the
> access-accept
> >>packet should contain one or no instances of the following:
> >>
> >>7 MS-MPPE-Encryption-Policy
> >>8 MS-MPPE-Encryption-Type
> >>12 MS-CHAP-MPPE-Keys
> >>16 MS-MPPE-Send-Key
> >>17 MS-MPPE-Recv-Key
> >>
> >>Although I can set these values under the 'users' file to send back
> >>during the negotiation, I can't seem to figure out the proper syntax
> to
> >>declare them in octet form.
> >
> >What are the dictionary entires you have currently, and what does your
> >users file look like now for the value?
>
> Hi Chris,
>
> The dictionary entries I have for the above attributes are from the
> dictionary.microsoft file:
>
> ATTRIBUTE       MS-MPPE-Encryption-Policy 7     octets
> ATTRIBUTE       MS-MPPE-Encryption-Type  8      octets
> ATTRIBUTE       MS-CHAP-MPPE-Keys       12      octets
> ATTRIBUTE       MS-MPPE-Send-Key        16      octets
> ATTRIBUTE       MS-MPPE-Recv-Key        17      octets
>
> I believe these should be set under the 'users' file in something like:
>
> DEFAULT         Auth-Type := MS-CHAP
>     MS-MPPE-Encryption-Policy = "0x(some_octet_here)",
> #This in my case should send back a value of 2 to indicate required
> encryption
>     MS-MPPE-Encryption-Type = "0x(some_octet_here)",
> #This should send back a value of 6 to indicate 40bit & 128bit
> encryption only
>     MS-CHAP-MPPE-Keys = "0x(some_octet_here)",
>     MS-MPPE-Send-Key = "0x(some_octet_here)",
>     MS-MPPE-Recv-Key = "0x(some_octet_here)"
> #I'm not sure what should be sent here, but I assumed it would be set by
> the algorithm automatically
>
> >
> >>The 2 other questions I had were first, is
> >>the des function included with rlm_mschap able to negotiate 40bit &
> >>128bit encryption or is it limited to 56-bit?
> >
> >Not sure on this one, as I'm not as familiar with that module.
> >
> >>And secondly whether there
> >>is a way to use the radius server only for authentication and then
> punt
> >>the encryption process back to the router after a user has been
> >>successfully authenticated?
> >
> >Not quite sure what you mean by this.  Can you elaborate a little more?
> >
>
> Well I guess what I was thinking, was that I don't want a constant
> stream of encryption/decryption packets streaming from the client to the
> router and then from the router to the radius server during the entire
> session. If the radius server was just used for authentication and then
> told the router to negotiate the encryption based on the settings above
> it would be a more efficient setup.
>
> --Matt
>
>
> >-Chris
> >--
> >    \\\|||///  \  Chris Parker    -    Manager, Development Engineering
> >    \ ~   ~ /   \       WX *is* Wireless!    \   [EMAIL PROTECTED]
> >    | @   @ |    \   http://www.starnetwx.net \      (847) 963-0116
> >oOo---(_)---oOo--\-----------------------------------------------------
> -
> >                   \ Without C we would have 'obol', 'basi', and
> 'pasal'
>
>
>
> --__--__--
>
> Message: 18
> From: "jason" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: Re: radclient question
> Date: Wed, 31 Oct 2001 10:00:21 -0600
> charset="iso-8859-1"
> Reply-To: [EMAIL PROTECTED]
>
> i probably should have mentioned that these were generated on a linux box,
> so you probably need to use vi or some editor that honors unix newlines..
if
> it would help, I can send a second set later today that are dos-ified ..
and
> probably put in the patch chris suggested..
>
> -j
>
> ----- Original Message -----
> From: "jason" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Tuesday, October 30, 2001 5:03 PM
> Subject: Re: radclient question
>
>
> > svr4 is the cistron and radius2 is a freeradius.  I generated these
using
> > radtest.
> > the payloads look pretty identical to my untrained eye.
> >
> > -j
> >
> >
> > > At 04:17 PM 10/30/2001 -0600, jason wrote:
> > > >But the packets are not *exactly* identical, though the part i
> truncated
> > was
> > > >identical.  The portion I attatched to my last mailing had
differences,
> > > >which due to my limited knowledge of how the radius packet is
> formatted,
> > I
> > > >am unable to understand.
> > >
> > > there is a 'vector' that is calculated on per-client basis.
> > >
> > > >I'm perfectly willing to believe that is in fact the hiperarc's that
> are
> > at
> > > >fault somehow, but I need some information of what is going on.
> Whether
> > the
> > > >fault be with the hyperarc or the radius server.
> > >
> > > Try a recent version of tcpdump that will display the attributes that
> are
> > > being sent.  I don't read radius attributes in hex yet ( though I'm
> closer
> > > than I'd like ).
> > >
> > > -Chris
> > >
> >
> >
>
>
>
> --__--__--
>
> Message: 19
> Date: Wed, 31 Oct 2001 12:09:47 -0500 (EST)
> From: Matt Rose <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: core dumps where?
> Reply-To: [EMAIL PROTECTED]
>
>
> where does freeradius core-dump to?
>
> --------------------------------------------------------------------------
> Matt Rose        [EMAIL PROTECTED]          http://www.folkwolf.net
> "I would question my sanity, but it's out of earshot"  -- Velma Bowen:w
>
>
>
>
> --__--__--
>
> Message: 20
> To: [EMAIL PROTECTED]
> Subject: Re: core dumps where?
> <[EMAIL PROTECTED]>
> Date: Wed, 31 Oct 2001 12:07:12 -0500
> From: [EMAIL PROTECTED]
> Reply-To: [EMAIL PROTECTED]
>
> Matt Rose <[EMAIL PROTECTED]> wrote:
> > where does freeradius core-dump to?
>
>   The current working directory, usually where-ever you started the
> server from.
>
>   However, I've occasionally seen it die, and NOT core dump.  I can't
> figure out why that's happening.
>
>   Alan DeKok.
>
>
> --__--__--
>
> Message: 21
> Date: Wed, 31 Oct 2001 11:08:40 -0600
> To: [EMAIL PROTECTED]
> From: Chris Parker <[EMAIL PROTECTED]>
> Subject: Re: core dumps where?
> et>
> Reply-To: [EMAIL PROTECTED]
>
> At 12:09 PM 10/31/2001 -0500, Matt Rose wrote:
>
> >where does freeradius core-dump to?
>
> If you have core dumps enabled, it should be to the directory you were
> in when you launched 'radiusd'.
>
> -Chris
>
> --
>     \\\|||///  \  Chris Parker    -    Manager, Development Engineering
>     \ ~   ~ /   \       WX *is* Wireless!    \   [EMAIL PROTECTED]
>     | @   @ |    \   http://www.starnetwx.net \      (847) 963-0116
> oOo---(_)---oOo--\------------------------------------------------------
>                    \ Without C we would have 'obol', 'basi', and 'pasal'
>
>
>
>
> --__--__--
>
> -
> List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html
>
>
> End of Freeradius-Users Digest-
> List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html
>


- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to