> And, lastly, did you set copy_request_to_tunnel in eap.conf? > Don't, because > then your real inner user name gets overwritten by the outer one.
Strange... I've set copy_request_to_tunnel and I haven't seen my inner User-Name be overwritten ! Are you sure it would overwrite the inner User-Name attribute with the outer one ? Another question: if you don't set copy_request_to_tunnel, could you still have a rule in the users file matching the user's ldap group (for the users in the inner request) and the Called-Station-Id (from outer request) ? Thibault - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html