NATed Proxy

2002-04-01 Thread Julio Faerman
Is it possible to run a Proxy Radius Server (Freeradius) under a firewall (nat'ed) ? Has anyone done it ? Thnx a lot ! Julio - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Proxy on the value of an attribute?

2002-04-01 Thread Erling Paulsen
Is it possible to proxy requests based on the value of an attribute? Currently I proxy with the realm specifier. Another question, when I'm running radiusd in debug mode (-xxs); the attributes I see listed as beeing sent from the NAS, are this all the attributes sent or is it just a de

bug with L2TP and proxy

2002-03-30 Thread coccolesto
hi folks, using freeRADIUS 0.5 as a proxy to a cistron 1.6.6, I obtain a segmentation fault on my freeradius when the replies contain tagged attributes with tag specified (i.e. Tunnel-Assignment-Id:1="some_tunnel"). My confs are very simple

Re: External Exec for Proxy

2002-03-28 Thread Alan DeKok
"Darren Nay" <[EMAIL PROTECTED]> wrote: > I'm looking for a radius server that will allow me run an external script, > or at least make a SQL database update upon a successfull proxy > authentication request. Is this possible with freeradius? Yes. They ke

External Exec for Proxy

2002-03-28 Thread Darren Nay
Hi All, I'm looking for a radius server that will allow me run an external script, or at least make a SQL database update upon a successfull proxy authentication request. Is this possible with freeradius? The reason for this is that we don't always recieve accurate accounting record

External Exec for Proxy

2002-03-27 Thread Darren Nay
Hi All, I'm looking for a radius server that will allow me run an external script, or at least make a SQL database update upon a successfull proxy authentication request. Is this possible with freeradius? The reason for this is that we don't always recieve accurate accounting record

Re: Proxy reply problem..

2002-03-27 Thread Alan DeKok
s does NOT forward this reply >back to the client. > > Log says as follows: > > No request found for proxy reply from server laalaa - ID 1 When the server forwards a request to another server, it keeps a copy of the request internally. This is so that it can know which N

Re: Proxy Thru NAT

2002-03-27 Thread Julio Faerman
Em Qua, 2002-03-27 às 12:18, Mike Cathey escreveu: > > > Chris Parker wrote: > > At 09:54 AM 3/27/2002 -0300, Julio Faerman wrote: > > > >> Hi. > >> > >> I have my FreeRadius server under NAT, so its IP is 192.168.X.Y, and > >> maps dire

Re: Proxy Thru NAT

2002-03-27 Thread Mike Cathey
Chris Parker wrote: > At 09:54 AM 3/27/2002 -0300, Julio Faerman wrote: > >> Hi. >> >> I have my FreeRadius server under NAT, so its IP is 192.168.X.Y, and >> maps directly to a valid ip, say A.B.C.D. >> >> When i proxy a request, the adress of my

Re: Proxy Thru NAT

2002-03-27 Thread Chris Parker
At 09:54 AM 3/27/2002 -0300, Julio Faerman wrote: >Hi. > >I have my FreeRadius server under NAT, so its IP is 192.168.X.Y, and >maps directly to a valid ip, say A.B.C.D. > >When i proxy a request, the adress of my server in the acess-request >goes as the internal network adr

Proxy Thru NAT

2002-03-27 Thread Julio Faerman
Hi. I have my FreeRadius server under NAT, so its IP is 192.168.X.Y, and maps directly to a valid ip, say A.B.C.D. When i proxy a request, the adress of my server in the acess-request goes as the internal network adress. How can i change this to send the external IP, so the other server can

Proxy reply problem..

2002-03-27 Thread Erling Paulsen
arded nicely to the respective servers and replies also gets back to freeradius, BUT freeradius does NOT forward this reply back to the client. Log says as follows: No request found for proxy reply from server laalaa - ID 1 (laalaa is just shortname for one of the remote servers) - E

Freeradius: Proxy-To-Realm question.

2002-03-26 Thread Julio Faerman
Hi ... I have a my local users registered on Mysql, and i want to set-up a proxy to another provider, say ISP2. When i use radclient, it all works fine (user userISP2 , for example). I have in my users file : userISP2Proxy-To-Realm := "ISP2" and the respective realm correc

Re: Proxy not forwarding Access Accept to client

2002-03-25 Thread Alan DeKok
Anchal Arora <[EMAIL PROTECTED]> wrote: > The debug messages showed " No request found for proxy reply from server > - ID 1" The actual RADIUS server returns the > correct request Id and Proxy State. But it's buggy. > Sending Access-Request of id 1 to 10.3.

Proxy not forwarding Access Accept to client

2002-03-25 Thread Anchal Arora
Hi I am using freeRADIUS 0.4 on Red Hat linux 7.2 and have set it up as a Proxy. The proxy forwards the radius request from the client to the actual RADIUS server to which the RADIUS server responds with an Accept. But then the Proxy does not send back the Accept to the client. (tcpdump shows

Re: Freeradius as Proxy and CHAP-Authentication

2002-03-21 Thread Alan DeKok
"Bernd Sontheimer" <[EMAIL PROTECTED]> wrote: > But how can i influcence the chap-challenges sent as above. Or is > that a bug? Sorry, i'm no programmer, so a look into the source > doesn't help me really. Is that a bug or can i do anything? It's a bug. You can try changing the source by goi

Re: Freeradius as Proxy and CHAP-Authentication

2002-03-21 Thread Bernd Sontheimer
happening. > > But off of the top of my head, I'd say having two CHAP challenges in > the packet isn't a good thing. hm, that may be the problem. But how can i influcence that? If i do radtest to my home-server i get an Access-Accept. If i setup my NAS to directly ask the h

Re: Freeradius as Proxy and CHAP-Authentication

2002-03-20 Thread Alan DeKok
"Bernd Sontheimer" <[EMAIL PROTECTED]> wrote: > It still doesn't work. As i told if i remove the proxy in between it > works, and with the proxy it works also, as long as i use pap. ... > Sending Access-Request of id 1 to 194.88.160.4:7002 > User-Nam

Re: Freeradius as Proxy and CHAP-Authentication

2002-03-20 Thread Bernd Sontheimer
On 18 Mar 02, at 11:20, Alan DeKok wrote: > "Bernd Sontheimer" <[EMAIL PROTECTED]> wrote: > > i'm using freeradius as a radiusd-proxy with NAS which are > > PAP/CHAP enabled. All works well as long as the authentication is > > tried by using PAP. W

Re: Freeradius as Proxy and CHAP-Authentication

2002-03-18 Thread Alan DeKok
"Bernd Sontheimer" <[EMAIL PROTECTED]> wrote: > i'm using freeradius as a radiusd-proxy with NAS which are > PAP/CHAP enabled. All works well as long as the authentication is > tried by using PAP. With CHAP it is refused all the times. If i > remove the prox

Freeradius as Proxy and CHAP-Authentication

2002-03-18 Thread Bernd Sontheimer
Hi, i'm using freeradius as a radiusd-proxy with NAS which are PAP/CHAP enabled. All works well as long as the authentication is tried by using PAP. With CHAP it is refused all the times. If i remove the proxy in between, CHAP-Authentication succeeds, so the problem should have to do

Re: Proxy Username Problem

2002-03-15 Thread Frank Cusack
On Fri, Mar 15, 2002 at 06:34:38PM +0530, Anchal Arora wrote: > When I send it an authentication request for username having the letter > "P" in the front it strips the first letter "P" from the name and sends > the request to the actual radius server. If you searched the mailing list (via google

Re: Proxy Username Problem

2002-03-15 Thread namor
]> Sent: Friday, March 15, 2002 7:04 AM Subject: Proxy Username Problem > Hi > > I am using freeRadius version 0.4. I have set it up as a proxy. > > When I send it an authentication request for username having the letter > "P" in the front it strips the first letter "

Proxy Username Problem

2002-03-15 Thread Anchal Arora
Hi I am using freeRadius version 0.4. I have set it up as a proxy. When I send it an authentication request for username having the letter "P" in the front it strips the first letter "P" from the name and sends the request to the actual radius server. I have tried other

Proxy accounting woes

2002-03-14 Thread Chris A. Kalin
I would expect. Now, for the three different domains I proxy to, I get just: Thu Mar 14 14:18:00 2002 User-Name = "al@proxydomain" And that's ALL (other than the IPs and whatnot) ...no Stripped-User-Name, no Realm. It's also important to mention that this also happens in

Re: Dead Proxy

2002-03-14 Thread Alan DeKok
Eric Dean <[EMAIL PROTECTED]> wrote: > I found the problem. The customer firewalls accounting which results in > the proxy client being disabled. There's a DEAD_TIME variable that can be > changed as well. raddb/proxy.conf has a "dead_time" variable. The only D

Re: Dead Proxy

2002-03-13 Thread Eric Dean
I found the problem. The customer firewalls accounting which results in the proxy client being disabled. There's a DEAD_TIME variable that can be changed as well. On Wed, 13 Mar 2002, Eric Dean wrote: > > In my radius.log I see > > Proxy: marking server radius.foo.com

Dead Proxy

2002-03-13 Thread Eric Dean
In my radius.log I see Proxy: marking server radius.foo.com for realm foo.com dead We are having an issue whereby we stop proxying a realm for a certain period. It appears that maybe it doesn't get a radius response and then marks that server as unresponsive/dead which causes problem

Multiple Proxy State Attributes

2002-03-04 Thread David Birkbeck
Hello, I am experiencing a problem with multiple "proxy state" attributes. When our partner network (UUNet) runs a test on our new Radius server (Linux 7.2 w/ FreeRADIUS 0.4) it returns multiple proxy state attributes in the access-accept packet. Any ideas on how to get rid of this (

Re: radius proxy and accounting

2002-02-23 Thread Igor Chen
On Sat, 23 Feb 2002, Alan DeKok wrote: > Igor Chen <[EMAIL PROTECTED]> wrote: > > I have a problem with radius accounting, seems like other proxy radius > > (old cistron) sends duplicate Stop queries, and sometimes even Stop > > queries with equal acctsessionid,user

Re: radius proxy and accounting

2002-02-23 Thread Alan DeKok
Igor Chen <[EMAIL PROTECTED]> wrote: > I have a problem with radius accounting, seems like other proxy radius > (old cistron) sends duplicate Stop queries, and sometimes even Stop > queries with equal acctsessionid,username,nasipaddress but wrong time (set > to now(). Then

radius proxy and accounting

2002-02-23 Thread Igor Chen
I have a problem with radius accounting, seems like other proxy radius (old cistron) sends duplicate Stop queries, and sometimes even Stop queries with equal acctsessionid,username,nasipaddress but wrong time (set to now(). Can anyone tell me, is any workaround for that situation? How can i

Re: Unknown error message on radius proxy

2002-02-11 Thread Alan DeKok
Daniel Yeung <[EMAIL PROTECTED]> wrote: > Fri Feb 8 09:50:42 2002 : Error: Dropping conflicting authentication packet from >client xxx.xxx.xxx.xxx:1646 - ID: 254 That's bad. The client is sending a new request before it's received an answer from the old request. > Feb 8 06:24:23 2002 : Inf

Unknown error message on radius proxy

2002-02-11 Thread Daniel Yeung
I got a large number of messages like below on the radius proxy. The request from one out of two radius proxy radius is unable to authenticate (even the input password is correct). The number of accounting was also droppend sharpenly. I try to read the source code. But I can't get

Re: Unknown error message on radius proxy

2002-02-08 Thread Alan DeKok
Daniel Yeung <[EMAIL PROTECTED]> wrote: > Fri Feb 8 09:50:42 2002 : Error: Dropping conflicting authentication packet from >client xxx.xxx.xxx.xxx:1646 - ID: 254 That's bad. The client is sending a new request before it's received an answer from the old request. > Feb 8 06:24:23 2002 : Inf

Unknown error message on radius proxy

2002-02-07 Thread Daniel Yeung
I got a large number of messages like below on the radius proxy. The request from one out of two radius proxy radius is unable to authenticate (even the input password is correct). The number of accounting was also droppend sharpenly. I try to read the source code. But I can't get

Re: Proxy-To-Realm Question - Revisited

2002-01-24 Thread Wild Apache Support
I really want to thank you guys for all the help and your patience. Everything seems to be working okay now. freeradius is really an amazing tool and my congrats go out to the development team. Thanks again, Murrah Boswell [EMAIL PROTECTED] wrote: > > Wild Apache Support <[EMAIL PROTECTED]> w

Re: Proxy-To-Realm Question - Revisited

2002-01-24 Thread aland
Wild Apache Support <[EMAIL PROTECTED]> wrote: > Now another question. In my proxy.conf file I have a realm setup and > defined the "detail" file for this realm to be: > > detailfile += /usr/adm/radacct/verdenet/detail > > however, the logging for this realm are going to the standard detail > f

Re: Proxy-To-Realm Question - Revisited

2002-01-23 Thread Wild Apache Support
Thanks, That fixed the authentication problem. Now another question. In my proxy.conf file I have a realm setup and defined the "detail" file for this realm to be: detailfile += /usr/adm/radacct/verdenet/detail however, the logging for this realm are going to the standard detail file. I want

Re: Proxy-To-Realm Question - Revisited

2002-01-23 Thread Wild Apache Support
Thanks, That fixed the authentication problem. Now another question. In my proxy.conf file I have a realm setup and defined the "detail" file for this realm to be: detailfile += /usr/adm/radacct/verdenet/detail however, the logging for this realm are going to the standard detail file. I want

Re: Proxy-To-Realm Question - Revisited

2002-01-23 Thread Marcelo Ferreira
check the secrets at proxy.conf both servers have to have the same secret at proxy.conf and clients.conf []s Marcelo Wild Apache Support writes: > Hello again, > > I really do appreciate the help that I am getting from the list. > However I am still stumped, but I think that I am very clo

Re: Proxy-To-Realm Question - Revisited

2002-01-23 Thread Wild Apache Support
Hello again, I really do appreciate the help that I am getting from the list. However I am still stumped, but I think that I am very close!! Here is a new snippet from my debugging session: > Waking up in 6 seconds... > rad_recv: Access-Reject packet from host 209.145.209.2:1645, id=1, > lengt

Re: returned attributes and proxy-authentication, RFC compliance (was: attr_rewrite functions)

2002-01-18 Thread aland
ssing on the attributes from the proxy'd server or passing on the local > attributes? Neither. The attributes returned to the NAS are completely under the control of the proxy server. > Does anyone know what the current radius RFC is? (is it still > 2138)? I dunno... look

returned attributes and proxy-authentication, RFC compliance (was: attr_rewrite functions)

2002-01-18 Thread Michael Hare
I was searcing through the groups message archives and found a question/answer session of exactly what I was trying to ask in my last confusing message. With a production Merit 4.1.1E radius server (yeah, old).. We're proxying out for our authentication, but returning value pairs are based on

Re: Accounting Request through Proxy

2002-01-14 Thread aland
"Bartschies, Thomas" <[EMAIL PROTECTED]> wrote: > I'm running a newly configured freeradius-0.4 here. The only client > is a cisco 4000 with IOS 12.1. On every PPP logout I get this message > Error: Accounting: logout: login entry for NAS CVK_NAS port 20003 not found > but before that there is als

Accounting Request through Proxy

2002-01-14 Thread Bartschies, Thomas
[bar] (from nas CVK_FW port 20003 cli 5219719188) Both requests are going through a firewall application proxy. So the IP Source Address of the request packets is modified to the FW internal interface address. The FW Proxy is no application specific radius proxy. As for now, I suspect that the foll

Re: proxy setup help

2002-01-03 Thread aland
Duncan Drennan <[EMAIL PROTECTED]> wrote: > I presume that all I need to authenticate is add the info into the users > config file?? Yes. > DeKok? Where are you from? Sound very South African (my home) :) No, before that. The name comes from Holland, I was born in Canada. Alan DeKok.

Re: proxy setup help

2002-01-03 Thread Duncan Drennan
ain', and to forward the requests to you. > > They should also be able to strip off the '@your_domain', so it >looks to *you* like someone local is requesting authentication/ > >>The ISP has a radius server. I've been looking at the config files >>and it se

Re: Proxy Accounting proxy.conf authhost vs accthost v.0.3 and v.0.4

2002-01-02 Thread aland
Angus Stewart <[EMAIL PROTECTED]> wrote: > In searching the list, I see that this was a reported problem for v0.3 and that > there is a patch... so, after taking a look at v0.4 I decided to implement the > patch on 0.3 (still not ready to make the switch to 4 -- sorry). > > And - still didn't wor

Re: proxy setup help

2002-01-02 Thread aland
o strip off the '@your_domain', so it looks to *you* like someone local is requesting authentication/ > The ISP has a radius server. I've been looking at the config files > and it seems that this is done using the proxy file and clients or > users files. I'm not really

proxy setup help

2002-01-02 Thread Duncan Drennan
radius server. I've been looking at the config files and it seems that this is done using the proxy file and clients or users files. I'm not really sure how to do this, because I haven't ever worked with radius before. What needs to be done on our server to allow access for out c

Re: Access rejected during proxy failover.

2001-12-29 Thread aland
[EMAIL PROTECTED] wrote: > If the primary end-server is dead when a NAS send Access-Request, the proxy > should forward request automatically to the secondary end-server after > retry_delay and retry_count are came true, and access should be accepted. Ideally, yes. > In m

Access rejected during proxy failover.

2001-12-28 Thread Jukka . Karsimus
hi list ! I have configured FreeRADIUS 0.4 as a proxy server and realm failover with two end-servers. If the primary end-server is dead when a NAS send Access-Request, the proxy should forward request automatically to the secondary end-server after retry_delay and retry_count are came true, and

Re: Patch to ignore proxy response

2001-12-26 Thread Marcelo Ferreira
- Original Message - From: "Nathan Miller" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, December 26, 2001 4:31 PM Subject: Re: Patch to ignore proxy response > That would be great!!! > > At 02:35 PM 12/26/2001 -0200, y

Re: Patch to ignore proxy response

2001-12-26 Thread Nathan Miller
That would be great!!! At 02:35 PM 12/26/2001 -0200, you wrote: >I write a patch to ignore the ACCEPT/REJECT proxy response and pass >the value to a variable that can be use with Wait-Program-Exec. >If somebody thinks that would be helpful, I can make a patch to integrate >that >

Patch to ignore proxy response

2001-12-26 Thread Marcelo Ferreira
I write a patch to ignore the ACCEPT/REJECT proxy response and pass the value to a variable that can be use with Wait-Program-Exec. If somebody thinks that would be helpful, I can make a patch to integrate that at radiusd.conf too. []s

Proxy Accounting proxy.conf authhost vs accthost v.0.3 and v.0.4

2001-12-24 Thread Angus Stewart
Hi all, I recently configured a freeradius 0.3 realm in the proxy.conf file that used different IP addresses for authentication and accounting. It didn't work. -- the authentication IP address was used for both authentication and accounting. In searching the list, I see that this was a reporte

Proxy trouble

2001-11-17 Thread Ekkehard Burkon
Hi List, I have two problems concerning freeradius and proxying. I used some of the latest CVS snapshots (2006 was the latest) and a linux machine with kernel 2.2.17. First: there seems to bee a major memory leak in the proxy code. I set up a testenvironment with one client (radtest) a

Re: proxy problem

2001-11-13 Thread aland
Wadeegh Hendricks <[EMAIL PROTECTED]> wrote: > Is it possible to proxy authentication requests to another radius server > based on a prefix? See the examples in the 'raddb/radiusd.conf' file. Look for the words 'prefix' or 'IPASS'. It's reall

proxy problem

2001-11-13 Thread Wadeegh Hendricks
Is it possible to proxy authentication requests to another radius server based on a prefix? Kinda ;like the way IPASS works. What I want to do is have all authentication requests for PREFIX/username@any_domain forwarded to another radius server who would then do the authentication. Thanx

Proxy problems -> seg fault in cvs 09

2001-11-09 Thread Richard Yeo
> OK, I've updated the code so that leaving out authhost or accthost > means LOCAL for that value. Very good, I didn't mean to complain about the inclusion of auth or accthost, although setting the default to LOCAL if the key is missing is a neat option, just so long as you don't now get a stri

aland help me !!! Proxy Accounting ????

2001-11-08 Thread Àî¹ú½®
I have two RADIUS servers , one is FR 3.0 and the other is another. Now FR 3.0 recieve authentication and accounting packet include username like "[EMAIL PROTECTED]" ,I want FR 3.0 forward the authentication and accounting request to another RADIUS server,and log the accounting packet to local

Re: proxy and without user@real issue

2001-11-01 Thread Chris Parker
At 01:41 AM 11/1/2001 -0800, Morgan M wrote: >Hi Guys, > >Two questions: > >1. Is it possible to proxy authentication and >accounting packets to a remote server if a user logs >in without a realm i.e. user logging in as only >"username" not "username@rea

proxy and without user@real issue

2001-11-01 Thread Morgan M
Hi Guys, Two questions: 1. Is it possible to proxy authentication and accounting packets to a remote server if a user logs in without a realm i.e. user logging in as only "username" not "username@realm"? I want to send all the authentication request to different server a

Re: Proxy forwarding depending on Called-Station-Id possible?

2001-10-15 Thread Christoph Haas
Hendrik van der Merwe wrote: > In the users file: > testuserCalled-Station-Id == "5552321", Proxy-To-Realm = "myrealm" > Fall-Through = No Thank you very much. Works like a charm. I love this mailing list. ;) Christoph - List info/su

Re: Proxy forwarding depending on Called-Station-Id possible?

2001-10-15 Thread Hendrik van der Merwe
> Does anyone know a way of making FreeRADIUS proxy-forward all > requests which come in on a specified Called-Station-Id? Our users > won't (probably) kill us if we forced them all to use the realm > syntax but it would make our server switch more transparent to them.

Proxy forwarding depending on Called-Station-Id possible?

2001-10-14 Thread Christoph Haas
ll any number (the router picks up the phone anyway) and then either enter "davis" for 'users' authentication or "davis@securid" which proxy-forwards his request to the RADIUS port of the ace server. The proxy.conf reads: > realm securid { >

Re: How to use acct_users for accounting proxy

2001-10-10 Thread aland
[EMAIL PROTECTED] wrote: > I work on the problem of missing accounting detail for two weeks. The NAS must send accounting packets for it to go into the detail file. > It seems that debug mode (-xx) is not useful for this case. If the NAS doesn't send accounting packets, then you won't s

How to use acct_users for accounting proxy

2001-10-10 Thread danielym
=== One proxy radius and One authentication/accounting radius server Two realms Proxy server is configured to ip address xxx.xxx.xxx.xxx:1812 proxy.conf, acct_users, naslist, clients are changed on proxy server. proxy.conf realms A { type = radius authhost= xxx.x

Re: Proxy and accounting

2001-10-08 Thread aland
"Daniel Yeung" <[EMAIL PROTECTED]> wrote: > I am configuring Freeradius-0.3 to replace my Merit radius on > Freebsd 4.3. I have one proxy freeradius and one normal > freeradius. No accounting log doesn't come out. That's probably because your NAS isn't s

Proxy and accounting

2001-10-08 Thread Daniel Yeung
Hi all I am configuring Freeradius-0.3 to replace my Merit radius on Freebsd 4.3. I have one proxy freeradius and one normal freeradius. No accounting log doesn't come out. I have no idea. How the proxy port works ? Many Thanks Daniel On my proxy radius Authen port is :

Re: Proxy and Accounting

2001-10-06 Thread aland
"Daniel Yeung" <[EMAIL PROTECTED]> wrote: > Recently, I replace my Merit radius to Freeradius. I downloaeded the > freeradius-devel-20010310 (freebsd port) from freebsd site and > installed on freebsd 4.3. That version is 6 months old. I'm a little surprised that the freebsd ports collection i

Proxy and Accounting

2001-10-06 Thread Daniel Yeung
Hi all Recently, I replace my Merit radius to Freeradius. I downloaeded the freeradius-devel-20010310 (freebsd port) from freebsd site and installed on freebsd 4.3. I setup one as radius proxy and another as normal radius server. The authentication works well. But no accounting log is found

Re: Proxy & Reply Attributes

2001-09-25 Thread aland
Philippe Joyez <[EMAIL PROTECTED]> wrote: > I mean, when the freeradius server is configured for proxying, returned > attributes are those from the final radius server...I would like to > return only those configured in my freeradius one. Right now, no, it's not possible. It would be a nice fe

Proxy & Reply Attributes

2001-09-25 Thread Philippe Joyez
Hi all, Is it possible to use proxy functionnality just for authentication part? I mean, when the freeradius server is configured for proxying, returned attributes are those from the final radius server...I would like to return only those configured in my freeradius one. TIA, Philippe

Re: Proxy Setup.

2001-09-24 Thread aland
"Mustafa N. Deeb" <[EMAIL PROTECTED]> wrote: > I want the Freeradius to append some settings in addition to the > settings coming from the one in the backend > Depending on the profile the user have in usergroup in MYSQL. I don't think that works right now.

Proxy Setup.

2001-09-22 Thread Mustafa N. Deeb
, since in a proxy setup you can't pass Tunnel Attributes. 2- I'm using usernames similar to this, 151000 , in hints, can I do this DEFAULT Prefix="151*". Best Regards - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Proxy to Cistron Questions

2001-09-19 Thread VISP Systems Administration
does the remote sever know about the >originating NAS or is the request rewritten so the proxy is acting like a >NAS? There are two variables. Client-IP-Address, and NAS-IP-Address. The NAS-IP-Address follows all the way through to your radius server from the proxy; however, the Client

Proxy to Cistron Questions

2001-09-18 Thread Dave
proxy is acting like a NAS? 2) If the proxy looks like a NAS to the remote server then I would assume that the remote server needs a client entry/secret for the proxy and not the NAS..is this correct? 3) If the remote server knows about the originating NAS (if #2 is false) then the remote server needs

Re: 128bit Proxy-State Attribute

2001-09-05 Thread Joe Modjeski
> At 01:28 PM 9/5/2001 -0500, you wrote: >>At 11:20 AM 9/5/2001 -0700, [EMAIL PROTECTED] wrote: >>>Hello all, >>> >>>I am curious if anyone has tested freeradius with a 128bit proxy >>>attribute. >>> Our upstream proxy requires us to be a

Re: 128bit Proxy-State Attribute

2001-09-05 Thread VISP Systems Administration
At 01:28 PM 9/5/2001 -0500, you wrote: >At 11:20 AM 9/5/2001 -0700, [EMAIL PROTECTED] wrote: >>Hello all, >> >>I am curious if anyone has tested freeradius with a 128bit proxy attribute. >> Our upstream proxy requires us to be able to take and respond to the radius >

Re: 128bit Proxy-State Attribute

2001-09-05 Thread Chris Parker
At 11:20 AM 9/5/2001 -0700, [EMAIL PROTECTED] wrote: >Hello all, > >I am curious if anyone has tested freeradius with a 128bit proxy attribute. > Our upstream proxy requires us to be able to take and respond to the radius >requests with a 128bit proxy-state attribute. > >C

128bit Proxy-State Attribute

2001-09-05 Thread jmodjeski
Hello all, I am curious if anyone has tested freeradius with a 128bit proxy attribute. Our upstream proxy requires us to be able to take and respond to the radius requests with a 128bit proxy-state attribute. Currently we are using Cistron 1.6.4 and this hasn't had any problems but I

Re: Proxy and DNIS

2001-08-29 Thread aland
"Garrick T. Brooks" <[EMAIL PROTECTED]> wrote: > Is there a way to decide which radius server to proxy to based upon the > DNIS value? Yes. DEFAULT Some-Attribute == "some-value", Proxy-To-Realm = "realm" Fall-Through = No Alan DeKok. -

Proxy and DNIS

2001-08-29 Thread Garrick T. Brooks
Hello, I have set up FreeRadius as a proxy server and all seems to be working well. Is there a way to decide which radius server to proxy to based upon the DNIS value? Thanks, Garrick Brooks [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Proxy & failover

2001-08-28 Thread aland
VISP Systems Administration <[EMAIL PROTECTED]> wrote: > If there is a pending "wish list" out there, I'll add my vote for this > option. =) So submit a bug report, as a "wishlist". Source code patches, or suggestions for how it would be implemented are welcomed, too. Alan DeKok. - Li

Re: Proxy & failover

2001-08-27 Thread VISP Systems Administration
of our clients have multiple radius servers and would > > like automatic failover from the proxy server should one of their > > servers fail. > > No, the code can't do that right now. > > Alan DeKok. > >- >List info/subscribe/unsubscribe? See http://www.freerad

Re: Proxy & failover

2001-08-27 Thread aland
Eddie Stassen <[EMAIL PROTECTED]> wrote: > Is there a way of specifying multiple remote servers per realm in > proxy.conf? Some of our clients have multiple radius servers and would > like automatic failover from the proxy server should one of their > servers fail. No, the

Proxy & failover

2001-08-27 Thread Eddie Stassen
Hi, Is there a way of specifying multiple remote servers per realm in proxy.conf? Some of our clients have multiple radius servers and would like automatic failover from the proxy server should one of their servers fail. Thanks, Eddie - List info/subscribe/unsubscribe? See http

Re: Conditional proxy

2001-08-24 Thread aland
Eddie Stassen <[EMAIL PROTECTED]> wrote: > This works in that case where you only have one realm, but in my case I > have multiple realms, some with conditions attached, some unconditional. > e.g. > > realm1 : NAS-Port-Type==Async > realm2 : NAS-Port-Type==Async > realm3 : No conditions OK, if

Re: Conditional proxy

2001-08-23 Thread Eddie Stassen
[EMAIL PROTECTED] wrote: > > Eddie Stassen <[EMAIL PROTECTED]> wrote: > > I would like to know if there is a way of proxying users only if certain > > conditions are met iow 'check items' for proxied requests. In my > > application I need to proxy certain

Re: Conditional proxy

2001-08-23 Thread aland
Eddie Stassen <[EMAIL PROTECTED]> wrote: > I would like to know if there is a way of proxying users only if certain > conditions are met iow 'check items' for proxied requests. In my > application I need to proxy certain realms only if for example > NAS-Port-Type==Asy

Conditional proxy

2001-08-23 Thread Eddie Stassen
I would like to know if there is a way of proxying users only if certain conditions are met iow 'check items' for proxied requests. In my application I need to proxy certain realms only if for example NAS-Port-Type==Async. Any suggestions? Thanks, Eddie - List info/subscribe/unsubs

Re: update and proxy

2001-08-22 Thread aland
<[EMAIL PROTECTED]> wrote: > the description of the product says when proxying it can add attributes to > request > how is that done ? Hmm.. not that easily, I think. The current format of the 'users' file is set up to add attributes to the reply, not the forwarded pr

Re: update and proxy

2001-08-22 Thread Chris Parker
At 03:45 AM 8/22/2001 -0400, you wrote: >Hellow > >i am new to this newgroup and hope i dont ask any question that allready >has been asked >i have searched the archive but did not find the answer >neither on the help files > >the description of the product says when proxying it can add attributes

update and proxy

2001-08-22 Thread radius
Hellow i am new to this newgroup and hope i dont ask any question that allready has been asked i have searched the archive but did not find the answer neither on the help files the description of the product says when proxying it can add attributes to request how is that done ? what do i need t

Re: Username & realm & proxy

2001-08-15 Thread aland
[EMAIL PROTECTED] wrote: > Would it be possible with freeradius to > add some information to the suffix eg. realm of the > username an then proxy the request to an other radius? Perhaps, but I haven't tried doing it myself. > following situation > we have mutliple NAS, &

Username & realm & proxy

2001-08-15 Thread Jörg Feldmann
Hello my name is Jörg Would it be possible with freeradius to add some information to the suffix eg. realm of the username an then proxy the request to an other radius? following situation we have mutliple NAS, it would be very nice if we could based of from which NAS the user is commming, add

Re: Rejected Proxy not Logging

2001-08-14 Thread VISP Systems Administration
d on all logging, to no avail. Still no logs. This would be useful > > to have, it worked on Cistron based proxy servers. > > > > Perhaps I am simply overlooking something (most likely). > > Nope. The code doesn't call the log routine for proxy rejects. > >

Re: Rejected Proxy not Logging

2001-08-13 Thread aland
ould be useful > to have, it worked on Cistron based proxy servers. > > Perhaps I am simply overlooking something (most likely). Nope. The code doesn't call the log routine for proxy rejects. I've just added a patch to fix that, thanks. Alan Dekok. - List info/subscrib

<    1   2   3   4   5   6   >