Re: linelog and rlm_eap

2011-03-11 Thread Alan DeKok
Kolbjørn Barmen wrote: What I meant to ask for, is some way of having more usefull information from failed logins. Today we're using ldap backend, and the only error message that comes in the log is rlm_ldap: User not found, regardless of what the real cause is. There may be *multiple* real

Re: linelog and rlm_eap

2011-03-11 Thread Kolbjørn Barmen
On Fri, 11 Mar 2011, Alan DeKok wrote: Kolbjørn Barmen wrote: What I meant to ask for, is some way of having more usefull information from failed logins. Today we're using ldap backend, and the only error message that comes in the log is rlm_ldap: User not found, regardless of what the

Re: Virtual Server

2011-03-11 Thread Rob Yamry
Thanks Phil. That worked great. On Mar 10, 2011 10:53 AM, Phil Mayers p.may...@imperial.ac.uk wrote: On 10/03/11 16:46, Rob Yamry wrote: Im running FreeRadius 2.1.8 to allow wireless access and that is working great. I now want to have the vpn auth against the freeradius server for access, but

Re: linelog and rlm_eap

2011-03-11 Thread Alan DeKok
Kolbjørn Barmen wrote: I cannot remember to have seen multiple causes in play at once, but if that is the case, why not all of them? What I typically see is only one issue being the cause of a Reject. Of course there may be more, so that if you sort out one issue, it will just fail at the next

RE: FR 2.1.7 Exits for no reason

2011-03-11 Thread McNutt, Justin M.
Well, at the very least, I'm going to START there and see what happens. It's maddening, since it goes for weeks with no problems, and then suddenly two or three will die within hours. :( --J -Original Message- From: freeradius-users-bounces+mcnuttj=missouri.edu@lists.freeradius

Re: Access Accept vs Tunneled reply

2011-03-11 Thread Alan Buxey
Hi, I am trying to work out where I would be putting attributes for Access Accept. add them at the post-auth stage...or add them in the inner-tunnel and copy inner-tunnel to the reply.. thats 2 standard ways alan - List info/subscribe/unsubscribe? See

RE: Access Accept vs Tunneled reply

2011-03-11 Thread David Peterson
These values are unique per user. Is there an elegant way to copy this to the post-auth section? David -Original Message- From: Alan Buxey [mailto:a.l.m.bu...@lboro.ac.uk] Sent: Friday, March 11, 2011 8:36 AM To: David Peterson-WirelessConnections; FreeRadius users mailing list

Re: Access Accept vs Tunneled reply

2011-03-11 Thread Alexander Clouter
David Peterson dav...@wirelessconnections.net wrote: These values are unique per user. Is there an elegant way to copy this to the post-auth section? The following might help? http://lists.freeradius.org/mailman/htdig/freeradius-users/2011-January/msg00353.html Cheers -- Alexander Clouter

Proxy Request to Virtual Server using EAP

2011-03-11 Thread joao...@gmail.com
Hello Guys I need a help to use proxy request to virtual_server using EAP-TTLS and EAP-PEAP I have the following scenario: I have a Radius Sever (version 2.1.10), this server on a Linux Debian 6 This server must authenticate users of my wireless network. But my network is interconnected with

RE: Access Accept vs Tunneled reply

2011-03-11 Thread David Peterson
I am wondering if it's a misconfiguration of a group reply. I have those attributes listed as a group-reply. Would putting the attributes in the normal vs the group reply put them in a different portion of the response? David -Original Message- From:

RE: Access Accept vs Tunneled reply

2011-03-11 Thread David Peterson
Please correct my assumption if I am off I have been working on getting reply attributes sent out to define VLAN's etc on a WiMax NAS. I see the following in radiusd -X: (3495) [ttls] Got tunneled reply code 2 WiMAX-VLAN-ID := 192 WiMAX-Classifer-Direction = Bi-Directional

Re: CHAP-Challenge Question

2011-03-11 Thread Jeremiah
Yes. Unless the user entered the wrong password. Or, the NAS does the CHAP algorithm incorrectly. Thanks .. we were able to track down an issue with the way the NAS was getting the password. Jeremiah - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Access Accept vs Tunneled reply

2011-03-11 Thread Alan DeKok
David Peterson wrote: Please correct my assumption if I am off I have been working on getting reply attributes sent out to define VLAN's etc on a WiMax NAS. I see the following in radiusd -X: (3495) [ttls] Got tunneled reply code 2 These are the attributes *inside* of the tunnel.

RE: Access Accept vs Tunneled reply

2011-03-11 Thread David Peterson
I have set: use_tunneled_reply = no copy_request_to_tunnel = no Set for both TTLS and PEAP sections. Should I be setting those to yes? David -Original Message- From: freeradius-users-bounces+david.peterson=acc-corp@lists.freeradius.org

RE: Access Accept vs Tunneled reply

2011-03-11 Thread David Peterson
Perhaps I have broken my install. I see that I have in my radiusd.conf file the following: $INCLUDE ${confdir}/modules/ # Extensible Authentication Protocol # # For all EAP related authentications. # Now in another file, because it is very large.

Re: Access Accept vs Tunneled reply

2011-03-11 Thread Alexander Clouter
David Peterson dav...@wirelessconnections.net wrote: I am wondering if it's a misconfiguration of a group reply. I have those attributes listed as a group-reply. Would putting the attributes in the normal vs the group reply put them in a different portion of the response? As you have

RE: Access Accept vs Tunneled reply

2011-03-11 Thread David Peterson
Progress at last guys! Thanks for all the help!Now seeing this both outside the tunnel as well as in the pcap. Now to make my attribute conform with the NAS. (175) ++[wimax] returns updated Sending Access-Accept of id 103 to 172.16.4.2 port 1812 WiMAX-VLAN-ID = 192

Dictionary question`

2011-03-11 Thread David Peterson
I have to define a TLV which has a description of: TLV ID 1 for Classifier ID Description An identifier of the classifier that uniquely identifies the classifier in the scope of the Packet Flow Descriptor irrespective of whether or not the classifier is an uplink or downlink classifier.

Re: Help migrating from 1.1.7 to 2.1.10 - clear text password being lost

2011-03-11 Thread John . Hayward
Hi Radius Fans, I am trying to move our current environment from 1.1.7 to 2.1.10 and are having a problem getting things to work. We have a Novell NDSLdap server which provides clear text passwords for Novell users. We are using peap-mschapv2. What might be causing the request-config to

Trying to get my sql configuration right.

2011-03-11 Thread John . Hayward
Hi Radius People, I am getting the message from sql authentication: !!! !!! Please update your configuration so that the known good !!! !!! clear text password is in Cleartext-Password, and not in