>OK, I've tried using a proxy and now it fails on rlm_eap and says the >User-Name doesn't match EAP Identity. Is there a way to have EAP >processed on the local machine but authentication happen on the >remote? Is that even the problem? >
DEFAULT FreeRADIUS-Proxied-To == 127.0.0.1, Proxy-To-Realm := DOMAIN That will proxy only the inner tunnel. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html