Hi, > Beside that, i noticed that when using a wrong ssl cert and user+pw > (to get vlan300) freeradius *first* checks the edirectory, and THEN > the eap/ttls stuff - shouldn't this be exactly the other way around?
err, no, because you have told it to behave like this. change the order of the modules in authorize and athenticate sections of your config if you want it any other way! alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html