Amaru Netapshaak wrote:
> Right now, if a user
> isnt found in the LDAP database, a reject is returned to the switch and
> the port goes
> offline. What I'd rather have,is RADIUS reply with a standard response
> (if the LDAP
> auth fails).

  See doc/configurable_failover for over-riding return codes.

> I tried to do this in the users file, by moving 'files' to below 'ldap'
> in sites-enabled/default
> and then creating a DEFAULT entry in users that returned the VLAN
> information I wanted,
> but then it didnt include other relevant info that the switch needs.

  That won't work.

  What you want is:

        ldap
        if (notfound) {
                update reply {
                        ... insert attributes here...
                }
        }

  You don't need the "users" file.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to