On 11 Oct 2011, at 13:34, Nataniel Klug wrote:
> Arran,
>
> Thanks for your answer. So to test the NAS what should I use?
> A ping packet in a shell script?
Yes. Or an SNMP request.
Arran Cudbard-Bell
a.cudba...@freeradius.org
Betelwiki, Betelwiki, Betelwiki.
@lists.freeradius.org
> [mailto:freeradius-users-
> bounces+listas.nata=cnett.com...@lists.freeradius.org] Em nome de
> Marinko Tarlac
> Enviada em: segunda-feira, 10 de outubro de 2011 17:59
> Para: FreeRadius users mailing list
> Assunto: Re: Trying to solve a Simultaneous-Use problem
On Tue, Oct 11, 2011 at 3:44 AM, Nataniel Klug wrote:
> Hello all,
>
> ** **
>
> I am trying to solve a problem about Simultaneous-Use, not
> in the code because it’s working, but inside my network layout. I have two
> different NAS the can authenticate the same
We discuss at least once per week about stalled sessions... Search
before you ask...
On 10/10/2011 10:49 PM, Arran Cudbard-Bell wrote:
So, my question is: how can I use Simultaneous-Use in
this scenario? Should I make a script that test if the NAS is online
every 10 seconds
> So, my question is: how can I use Simultaneous-Use in this
> scenario? Should I make a script that test if the NAS is online every 10
> seconds and if not list all clients connect and stop that connections? Should
> this work? Is there anyone with the same scenario that can sh
Hello,
After I've made your suggested change (inserted the Simultaneous-Use := 1
record into radgroupcheck table), the checkrad.pl script run, when I use
radtest to a user, who is listed by radwho. I've set the $debug, $snmpget,
$snmpwalk, $cmmty_string variables in the /usr/sbin/checkrad. After
Hello,
>Yes,
>
>Simulaneous-Use is a check item, not a reply.
Ok, I did this mistake, sorry. Now I've deleted the Simultaneous-Use := 1
record from radgroupreply (now this is empty), and inserted it into the
radgroupcheck.
mysql> select * from radgroupcheck;
++---+--+
Yes,
Simulaneous-Use is a check item, not a reply.
2010/2/12 Fojtán Balázs István
> Hello Fajar,
>
> >> mysql> select * from radgroupreply;
> >> ++---+--++---+
> >> | id | GroupName | Attribute ? ? ? ?| op | Value |
> >> ++---+--+-
Hello Fajar,
>> mysql> select * from radgroupreply;
>> ++---+--++---+
>> | id | GroupName | Attribute ? ? ? ?| op | Value |
>> ++---+--++---+
>> | ?1 | HZ ? ? ? ?| Simultaneous-Use | := | 1 ? ? |
>> ++---+-
Yes.
Fajar A. Nugraha wrote:
2010/2/11 Fojtán Balázs István :
mysql> select * from radgroupreply;
++---+--++---+
| id | GroupName | Attribute| op | Value |
++---+--++---+
| 1 | HZ| Simultaneous-Use | :=
2010/2/11 Fojtán Balázs István :
> mysql> select * from radgroupreply;
> ++---+--++---+
> | id | GroupName | Attribute | op | Value |
> ++---+--++---+
> | 1 | HZ | Simultaneous-Use | := | 1 |
> ++
Hello Fajar,
thanks for your rapid response!
>> simul_count_query = "SELECT COUNT(*) \
>> FROM ${acct_table1} \
>> WHERE username = '%{SQL-User-Name}' \
>> AND acctstoptime IS NULL"
>
>it uses ${acct_table1} (should be radacct by default). Have you
>enabled accounting?
>
Yes, the accounting is w
2010/2/11 Fojtán Balázs István :
> simul_count_query = "SELECT COUNT(*) \
> FROM ${acct_table1} \
> WHERE username = '%{SQL-User-Name}' \
> AND acctstoptime IS NULL"
it uses ${acct_table1} (should be radacct by default). Have you
enabled accounting?
> mysql> select * from radcheck;
> ++--
Hello all!
I have problem with the Simultaneous-Use on Freeradius + Mikrotik
environment.
I'm using freeradius 2.1.8 on Debian lenny with mysql support.
I've found a checklist in the wiki
(http://wiki.freeradius.org/index.php/FAQ#Simultaneous-Use_doesn.27t_work).
The second line of this is:
"2.
> On Monday 25 June 2007 11:42:08 Josh Howlett wrote:
> > I have a feeling that the answer is blindingly obvious, but I can't
> > figure it out...
> >
> > The 'users' file consists of:
> >
> > DEFAULT Auth-Type = Accept
> > Simultaneous-Use := 1
>
> Because Simultaneous-Use is in t
On Monday 25 June 2007 11:42:08 Josh Howlett wrote:
> I have a feeling that the answer is blindingly obvious, but I can't
> figure it out...
>
> The 'users' file consists of:
>
> DEFAULT Auth-Type = Accept
> Simultaneous-Use := 1
Simultaneous-Use is a check item, not a reply it
I have a feeling that the answer is blindingly obvious, but I can't
figure it out...
The 'users' file consists of:
DEFAULT Auth-Type = Accept
Simultaneous-Use := 1
In radiusd.conf I also have:
session {
sql
}
authorize {
radius-user-auth
}
'radius-user-auth' is
There is a line in (my)sql.conf:
# Remove stale session if checkrad does not see a double login
deletestalesessions = yes
that enables it. I don't know if there is such an entry in mssql.conf.
Ivan Kalik
Kalik Informatika ISP
Dana 12/4/2007, "satish patel" <[EMAIL PROTECTED]> piše:
No. Idle-Timeout will work if NAS doesn't realize that user is not
online any more. It doesn't help if stop packets are lost. Only
checkrad or such routines that check user status with NAS will help
there.
Ivan Kalik
Kalik Informatika ISP
Dana 12/4/2007, "satish patel" <[EMAIL PROTECTED]> piše:
for a temp fix I would make your perl script ping said ip before
checking for idle (perhaps a sleep timer) or you could simply have
each supposed active ip pinged every 1 - 2 minutes by a seperate perl
script.
Would you mind posting your checkrad.pl script, Im a perl hacker myself :)
On 4/12/07,
checkrad work only for simultaneous detection not fix my stop time entry in sql
it is possible to modify checkrad to fix sql stop time in radacct table ?
[EMAIL PROTECTED] wrote: If you are happy with reliability then fix checkrad
and it will clean
these random drops. That is the utility that r
I have faceing same problem when some time NAS send ACCT-STOP packet and packet
would be lost then user session would be open and next time whne user try to
login he/she got error multilogin so that i have implement checkrad.pl script
and check simultaneouse users through SNMP and it is working
If you are happy with reliability then fix checkrad and it will clean
these random drops. That is the utility that radiusd calls to check
stale entries and in sql.conf you can enable deletion of such entries.
Just make sure that such users are not listed as active by the hotspot.
If NAS thinks they
On 4/12/2007, "Milan Holub" <[EMAIL PROTECTED]> wrote:
>==> is Accounting-STOP reaching your radius?
>you can find out by running in debug mode: freeradius -X
>
>==> is the correct query run on your database? check accounting_ queries in
>your sql/mysql-dialup.conf
>* check your DB log files: eg.
On 4/12/2007, "[EMAIL PROTECTED]" <[EMAIL PROTECTED]> wrote:
>+ what cause of this problem ?
>Either NAS thinks that users are still connected or your RADIUS server is
>not receiving Stop packages. If NAS (NAS not radacct table) shows users
>as connected you can add Idle-Timeout of about 5 minutes
Dana 12/4/2007, "PD" <[EMAIL PROTECTED]> piše:
>snip
+ what cause of this problem ?
>snip
Either NAS thinks that users are still connected or your RADIUS server is
not receiving Stop packages. If NAS (NAS not radacct table) shows users
as connected you can add Idle-Timeout of about 5 minutes in u
Operator should be :=. Check first that you have sql checking enabled in
radiusd.conf:
# Session database, used for checking Simultaneous-Use. Either the
radutmp
# or rlm_sql module can handle this.
# The rlm_sql module is *much* faster
session {
# radutmp
#
# See "Simul
On Thu, Apr 12, 2007 at 07:42:16AM +, PD wrote:
> I still have another problem...
> many of radacct table records are incompleted.
> We know the user already disconnected (even by click logout botton or
> just shut his/her computer down), but the information did not saved.
>
> At Radacct table
On 4/12/2007, "Milan Holub" <[EMAIL PROTECTED]> wrote:
.cut...
>==> I believe you have a typo in the tables:
>radgroupcheck: groupname=POSTPAID
>usergroup: groupname=POSPAID
I still have another problem...
many of radacct table records are incompleted.
We know the user already disconnected (even b
On 4/12/2007, "Milan Holub" <[EMAIL PROTECTED]> wrote:
>Hi,
>
>On Thu, Apr 12, 2007 at 07:14:48AM +, PD wrote:
>> Dear all,
>>
>> We has the problem regarding the above subject...
>> mysql> select * from radgroupcheck;
>> ++---+--++---+
>> | id | GroupName |
Hi,
On Thu, Apr 12, 2007 at 07:14:48AM +, PD wrote:
> Dear all,
>
> We has the problem regarding the above subject...
> mysql> select * from radgroupcheck;
> ++---+--++---+
> | id | GroupName | Attribute| op | Value |
> ++---+---
Dear all,
We has the problem regarding the above subject...
mysql> select * from radgroupcheck;
++---+--++---+
| id | GroupName | Attribute| op | Value |
++---+--++---+
| 1 | POSTPAID | Simultaneous-Use | == | 1
Hi, Everybody
Please I need your help!!
Why, When I work with enterasys or colubris NAS the
simultaneous-Use work perfectly, but with ARUBA NAS
not work.
I need add or configure another things?, or the
problem is from Aruba Manufacturer?, I need some
Specific characteristics (Which) from Aruba
"Jeremy Kenney" <[EMAIL PROTECTED]> wrote:
> Yes but what I want is for the radius server to check the accounting logs
> for a session already in progress and send a access reject if its already
> there
I responded to this yesterday. Do you read the list?
Read doc/Simultaneous-Use
Alan De
: freeradius-users@lists.freeradius.org
Subject: Re: Simultaneous-Use Problem
On 7/28/05, Jeremy Kenney <[EMAIL PROTECTED]> wrote:
> I have posted this twice now I was wondering if someone would be kind
enough
> to possibly answer it
>
> Hello,
>
> I am a very frustrated
currently want to use the same radius server to do
> dialup authentication. It currently is working to do this.
>
> We use freeradius with mysql. I am having problems with users dialing into
> the system more then once from more then one location at the sometime. I.E
> a simultaneou
freeradius with mysql. I am having problems with users dialing into
the system more then once from more then one location at the sometime. I.E
a simultaneous use problem. I cannot check against the NAS because we dont
have our own nases and are doing pass-thru radius authentication.
I need to do
Hi,
I need your help
I want to limit the number of times one user account can login;
I have next in the user file:
wireless User-Password == "wireless", Simultaneous-Use := 1 Aruba-User-Role = "STAFF"
But de user "wireless" can login more of one times
How can i solve this problem?
Do You Yahoo!?
La mejor conexión a Internet y 2GB extra a tu correo por $100 al mes. http://net.yahoo.com.mx
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Hi everybody.
I got a simple question about the Simultaneous-Use parameter.
We use freeradius for accounting of our ppp server. it work's fine at the
moment but from now on i want to restrict users to only one or two
simultanous logins.
So i implemented the Simultaneous-Use parameter to the "use
40 matches
Mail list logo