Re: COA default configuration...Need help to test radclient

2010-05-14 Thread Alan DeKok
Eric Martell wrote: > I followed the direction of how to setup COA in the freeradius. > Uncommented from client.conf coa_server = localhost-coa > > When I ran the sample radclient, I am not seeing any response back. ... > Do I have to do anything more than any default configuration? In 2.1.8,

Re: autthentication error

2010-05-14 Thread Alan DeKok
shirkavand wrote: > i have followed this tutorial(because this is what i need exacty to do) > but it does not worked either. I'm astonished at a few things here. One, the Wiki contains instructions for building on Debian. What's wrong with them? Two, the tutorial has you do a *lot* of wo

Re: autthentication error

2010-05-14 Thread shirkavand
hi, i have followed this tutorial(because this is what i need exacty to do) but it does not worked either. http://www.wains.be/index.php/2009/09/13/wpa2-freeradius-eap-tls/ Cheers - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: autthentication error

2010-05-14 Thread shirkavand
HI there, Ok i have tryed to add ssl support to freeradius in my ubuntu 9.10. As i mentioned before i have installed freeradius using apt-get. The thing is that every tutorial i followed did not woked, and after hours of trying...i read that freeradius over ubuntu does not have ssl support for som

Authentication with existing MySQL database

2010-05-14 Thread Quentin Smith
Hello all, I've set up and configured freeradius to properly authenticate users using the MySQL database schema specified on the freeradius.org website. However, since we already have a different database set up with users' passwords that is updated by scripts when users change their passwords or

EAP-TLS and MAC Authentication

2010-05-14 Thread John McDonnell
First a little information on our setup. When I first started working here, the wireless network had been in place for a year already and was rather small, only 3 access points and ~90 laptops. My boss set it up as static WEP (I don't know why WEP instead of WPA) and used the AP's (Cisco 1121 se

Re: A question about disconnections

2010-05-14 Thread Alan DeKok
Nick Warr wrote: > We have a central radius server, and a few point to point connections > where we have our point to multipoint connections (base stations) each > base stations is a NAS, which for the most part works just fine. Our > problem happens if something interrupts the point to point conne

Re: Configuration trouble (2.1.8 for use with WiMAX)

2010-05-14 Thread Alan DeKok
Sumedh Sathaye wrote: > Thanks for pointing out what I am doing wrong. Being a newbie to the > whole field of AAA, can you give me a few pointers where/what I can read > up to configure EAP for the TLS method (rather than MD5)? I appreciate > your help. See the Wiki && my web page: deployingradi

Re: autthentication error

2010-05-14 Thread shirkavand
Hi there, Thanks for the fast reply. I did not build myself freeradius, i have installed Freeradius on ubuntu 9.10 using sudo apt-get install freeradius* But maybe this does not installed openSSL support so I am going to check if i have dev packages and ssl support properly installed, and come

Re: Configuration trouble (2.1.8 for use with WiMAX)

2010-05-14 Thread Sumedh Sathaye
Hi Alan, Thanks for pointing out what I am doing wrong. Being a newbie to the whole field of AAA, can you give me a few pointers where/what I can read up to configure EAP for the TLS method (rather than MD5)? I appreciate your help. Best Regards, Sumedh Sathaye |> | From: | |

Re: Freeradius privilege separation

2010-05-14 Thread Alan DeKok
Michał Dopierała wrote: > Thanks for response! > > So, users file can look like this: Yes. > users= > > mdopierala Packet-Src-IP-Address == 192.168.1.1, Crypt-Password = > "some_hash" It's NOT a hash. It's a password. > Thi

Re: Freeradius privilege separation

2010-05-14 Thread Michał Dopierała
Thanks for response! So, users file can look like this: users= mdopierala Packet-Src-IP-Address == 192.168.1.1, Crypt-Password = "some_hash" Service-Type = "Administrative-User", Cisco-AVPair="shell:p

A question about disconnections

2010-05-14 Thread Nick Warr
We're a WISP using freeradius to do our AAA, and are in the process of updating our backend to the latest version of freeradius (probably 2.1.8), and we've been able to resolve a lot of issues with our current setup, except for a few (possibly vital) problems. The one we haven't been able to f

Re: Pending release of 2.1.9

2010-05-14 Thread Alan DeKok
Johan Meiring wrote: > You made a modification to dynamic clients a while ago where you could > get hold of the whole packet inside dynamic clients. Ah... yes. The rlm_raw won't go into 2.1.x. It's a new feature, and doesn't belong there. I'm not sure it will go into 2.2.x, either. It's

Re: configuration freeradius with mysql

2010-05-14 Thread David Seira
Have you decommented the "$INCLUDE sql.conf" line in radiusd.conf? I had the same problem when I compiled freeradius-2.1.8. If I compiled freeradius without libmysqlclient15-dev package the problem appeared. Try it. 2010/5/14 dorra aa > hi > i installed mysql. > > and i modify in /etc/freera

Re: Pending release of 2.1.9

2010-05-14 Thread Johan Meiring
On 2010/05/14 11:08 AM, Johan Meiring wrote: Its dynamic clients. Alan, I just saw you were cc-ed on the mail sent to this list. Not intentional. I know you hate it. I always use "reply-to-all" as a habit. It then replied to you as well. Apologies -- Johan Meiring Cape PC Service

Re: Diameter roaming

2010-05-14 Thread Alan DeKok
VU VAN HUNG wrote: > I means roaming between 2 client with 1 AAA Server in network (ex: > wireless mesh network). Is roaming with Diameter faster than with Radius? What did I say? > I'm sure that Diameter do authentication and accounting. > Check it out, > http://www.ibm.com/developerworks/wire

Re: Diameter roaming

2010-05-14 Thread Bjørn Mork
VU VAN HUNG writes: > Do anyones know why Diameter support faster roaming than RADIUS ? Higher marketing budgets > I've read some references but I dont understand. In my experience, that often means that the claim just is not true. Anyway, I believe you'd better ask whoever made that claim.

configuration freeradius with mysql

2010-05-14 Thread dorra aa
hi i installed mysql. and i modify in /etc/freeradius/sql.conf: readclients=yes also, i decommented in /etc/freeradius/radiusd.conf: accounting { sql} authorize {... sql} i run again freeradius -X: but it seems failed because of sql: this is the output [...] sql: postauth_query = "INSERT i

Re: Diameter roaming

2010-05-14 Thread VU VAN HUNG
Alan DeKok wrote: VU VAN HUNG wrote: Do anyones know why Diameter support faster roaming than RADIUS ? It doesn't. I means roaming between 2 client with 1 AAA Server in network (ex: wireless mesh network). Is roaming with Diameter faster than with Radius? I've read some refer

Re: Diameter roaming

2010-05-14 Thread Alan DeKok
VU VAN HUNG wrote: > Do anyones know why Diameter support faster roaming than RADIUS ? It doesn't. > I've read some references but I dont understand. Diameter is useful if you have an ISP / phone company with 10 million users, and $5-10 million to spend on a Diameter infrastructure. And eve

Diameter roaming

2010-05-14 Thread VU VAN HUNG
Hi all, Do anyones know why Diameter support faster roaming than RADIUS ? I've read some references but I dont understand. Hung, - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Pending release of 2.1.9

2010-05-14 Thread Johan Meiring
On 2010/05/14 10:35 AM, Alan DeKok wrote: Johan Meiring wrote: The "dynamic clients' code runs modules before the packet is decoded... but that's only because it doesn't *receive* the packet. So any "raw" access to the packet will return nothing. What are you doing with the module? I ca

Re: Pending release of 2.1.9

2010-05-14 Thread Alan DeKok
Johan Meiring wrote: > I compiled the server and can confirm it runs ok on my develepment machine. OK. > On another note, every time a new release comes out, I manually add > rlm_raw and recompile. > > I updated rlm_raw to work with FR2 a while ago and have been running it > successfully in pr

Re: Pending release of 2.1.9

2010-05-14 Thread Johan Meiring
On 2010/05/14 07:46 AM, Alan DeKok wrote: Johan Meiring wrote: There is a log of warnings though. Small subset says this. - dpkg-shlibdeps: warning: symbol radlog used by debian/freeradius/usr/lib/freeradius/rlm_checkval-2.1.9.so found in n

Re: Freeradius privilege separation

2010-05-14 Thread Alan DeKok
Michał Dopierała wrote: > It is possible in freeradius to have one user who has full privilege > level to one equipment (one cisco router privilege lvl15), and limited > privilege level to other equipment (other router with smaller privilege > e.g. lvl10 which will be configured on router)? Yes.

Re: Deny connection to users

2010-05-14 Thread Alan DeKok
Hermidio A. Rodriguez Chavez wrote: > It's posible to when a user disconnect from the directive > Session-Timeout deny connect again in the following 30 Min? You will need to track that information in a database. Remember: FreeRADIUS isn't a database, and doesn't store data. It doesn't store