(RADIATOR) Re: Please help.

2001-12-17 Thread Sam Cheung


Dear Genius,
 
I am trying to config. a radiator (2.19-demo) allocating IP address dynamically

using DB1 to get the authentication info. from DB1 (an mysql server stored username

and password) and using DB2 (another mysql server) to log the dhcp client info.,

DHCP pool and leased IP, etc. using the database which created by a script called

mysqlCreate.sql. Can you give me some suggestion what to put down in the config.cfg?

Thanks so much for paying attention. Thanks a lot.





Best Regards,

Sam Cheung
 


Re: (RADIATOR) Sample or Example Radiator files for Connect.com vpdn

2001-12-17 Thread Hugh Irvine


Hello Darrin -

As far as I am aware, it is just a simple proxy server setup.

There are example configuration files in the "goodies" directory of the 
Radiator distribution.

regards

Hugh


On Tue, 18 Dec 2001 16:56, Adams, Darrin wrote:
> hi all,
>
> does anyone have any sample "user" and/or "config_file" for setting up
> Radiator in a Connect.com VPDN
> environment.
>
> so i can fast track an urgent customer install
>
> server is NT4 running Radiator 2.19
>
> thanks
> Darrin,
>
> Darrin Adams
> Senior Systems Consultant
> ph 02 9934 5777
> fax 02 9901 3149
> [EMAIL PROTECTED]
> Netbridge Systems Integration
> www.netbridge.com.au
>
>
>
>
> **
> This email may be confidential and/or privileged. Only the intended
> recipient may access or use it. Any dissemination, distribution or
> copying of this email is strictly prohibited. If you are not the
> intended recipient please notify us immediately by return email and
> then erase the email.
>
> We use virus scanning software but exclude all liability for viruses
> or similar in any attachment or message...,..,..,.
> **

-- 
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows 95/98/2000, NT, MacOS X.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.
===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



(RADIATOR) Sample or Example Radiator files for Connect.com vpdn

2001-12-17 Thread Adams, Darrin
Title: Sample or Example Radiator files for Connect.com vpdn





hi all,


does anyone have any sample "user" and/or "config_file" for setting up Radiator in a Connect.com VPDN
environment.


so i can fast track an urgent customer install


server is NT4 running Radiator 2.19


thanks 
Darrin,


Darrin Adams
Senior Systems Consultant
ph 02 9934 5777
fax 02 9901 3149
[EMAIL PROTECTED]
Netbridge Systems Integration
www.netbridge.com.au





**
This email may be confidential and/or privileged. Only the intended 
recipient may access or use it. Any dissemination, distribution or
copying of this email is strictly prohibited. If you are not the
intended recipient please notify us immediately by return email and
then erase the email.

We use virus scanning software but exclude all liability for viruses 
or similar in any attachment or message...,..,..,.
**



(RADIATOR) MySQL & Simultaneous-Use

2001-12-17 Thread Andy Dills





Andy Dills  301-682-9972
Xecunet, LLCwww.xecu.net

Dialup * Webhosting * E-Commerce * High-Speed Access

===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



Re: (RADIATOR) auth with flat/acct with mysql

2001-12-17 Thread Hugh Irvine


Hello Angel -

This is very easy to do:

# define AuthBy clauses


Identifier CheckFILE
Filename %D/.
.



Identifier SQLAccounting
DBSource 
DBUsername .
DBAuth .

# empty AuthSelect to disable authentication
AuthSelect

AccountingTable ACCOUNTING
AcctColumnDef .
...


# define Realm(s) or Handler(s)


AuthByPolicy ContinueAlways
AuthBy SQLAccounting
AuthBy CheckFILE
.



regards

Hugh


On Tue, 18 Dec 2001 03:42, Angel Bustos wrote:
> Hi all,
>
> In my first instalation, I would have authentication with a flat text users
> File  but the accounting making online inserts in a MySQL db.
> I´ve read the ref.html and i´ve found examples of one or another 
> clauses; it seems that  example includes both authentication
> and accounting forcing  to an SQL authentication.
>
> Should I concatenate two   and  schemes?
> could you illustrate with some short example?
>
> thanks in advance!
> regards,
>
>
> Angel Bustos
> email: [EMAIL PROTECTED]
>
> ___
>_
>
> Conéctese Gratis a Internet desde http://www.brujula.net/gratis
> ===
> Archive at http://www.open.com.au/archives/radiator/
> Announcements on [EMAIL PROTECTED]
> To unsubscribe, email '[EMAIL PROTECTED]' with
> 'unsubscribe radiator' in the body of the message.

-- 
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows 95/98/2000, NT, MacOS X.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.
===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



Re: (RADIATOR) Multiple prefix

2001-12-17 Thread Hugh Irvine


Hello Rolando -

You would do this:


 :



 :




 :


regards

Hugh


On Tue, 18 Dec 2001 01:36, Rolando Riley wrote:
> Hi Hugh:
>   I am  still haveing problems with this handler .  This is how I am setting
> it:
>
> 
>
> 
>
> 
>
> 
>
>
> 
>
> 
>
>
>
>   Okay...  what is happening is that it is authenticating well "only" if 
> the user from IPASS or gric is this way:
>   [EMAIL PROTECTED]
>   [EMAIL PROTECTED]
>
>   But if the user try to auth like this it fails:
>   [EMAIL PROTECTED]
>   [EMAIL PROTECTED]
>
>
> Checking the debug trace I see that this users fall on the "REALM
> ayayai.com"  giving authentication rejects. I am thinking that this is
> happening because Realms has more priority than Handler?  How can I solve
> this situation?
>
> --
>
>
> Code:   Access-Request
> Identifier: 193
> Authentic:  <141>'zy<24><13>a<132>O<219><127><19>(<16><249>V
> Attributes:
> User-Name = "[EMAIL PROTECTED]"
> User-Password =
> "V<178><158>@<227><168><243><255><171>C<150><250><219><150><156>@"
> Client-Id = 200.24.140.2
> NAS-Port = 1292
> Acct-Session-Id = "84607095"
> USR-Interface-Index = 2548
> Service-Type = Framed-User
> Framed-Protocol = PPP
> Chassis-Call-Slot = 6
> Chassis-Call-Span = 1
> Chassis-Call-Channel = 12
> Calling-Station-Id = "2657832"
> Called-Station-Id = "055"
> NAS-Port-Type = Async
>
> Mon Dec 17 09:11:40 2001: DEBUG: Handling request with Handler
> 'Realm=ayayai.com'
> Mon Dec 17 09:11:40 2001: DEBUG:  Deleting session for
> [EMAIL PROTECTED], 200.24.140.2, 1
> 292
> Mon Dec 17 09:11:40 2001: DEBUG: Handling with Radius::AuthRADIUS
> Mon Dec 17 09:11:40 2001: DEBUG: Packet dump:
> *** Sending to 216.219.28.131 port 1645 
> Code:   Access-Request
> Identifier: 10
> Authentic:  <141>'zy<24><13>a<132>O<219><127><19>(<16><249>V
> Attributes:
> User-Name = "[EMAIL PROTECTED]"
> User-Password =
> "<241>/<190><159>e<4>\<248><199><181><31><146><234><18><159><131>"
> Client-Id = 200.24.140.2
> NAS-Port = 1292
> Acct-Session-Id = "84607095"
> USR-Interface-Index = 2548
> Service-Type = Framed-User
> Framed-Protocol = PPP
> Chassis-Call-Slot = 6
> Chassis-Call-Span = 1
> Chassis-Call-Channel = 12
> Calling-Station-Id = "2657832"
> Called-Station-Id = "055"
> NAS-Port-Type = Async
>
> Mon Dec 17 09:11:40 2001: DEBUG: Packet dump:
> *** Received from 216.219.28.131 port 1645 
> Code:   Access-Reject
> Identifier: 10
> Authentic:  <10><200><24><239><26>F2<142><152>sDAn<134><229><195>
> Attributes:
> Port-Message = "Request Denied"
>
> Mon Dec 17 09:11:40 2001: DEBUG: Received reply in AuthRADIUS for req 10
> from 216.219.28.131
>
> :1645
>
> Mon Dec 17 09:11:40 2001: DEBUG: Packet dump:
> *** Sending to 200.24.140.2 port 1645 
> Code:   Access-Reject
> Identifier: 193
> Authentic:  <141>'zy<24><13>a<132>O<219><127><19>(<16><249>V
> Attributes:
> Port-Message = "Request Denied"
>
> Mon Dec 17 09:11:44 2001: DEBUG: Packet dump:
>
>
>
>
>
>
>
>
>
> -Mensaje original-
> De: Hugh Irvine [mailto:[EMAIL PROTECTED]]
> Enviado el: Sunday, December 16, 2001 6:34 PM
> Para: Rolando Riley; [EMAIL PROTECTED]
> Asunto: Re: (RADIATOR) Multiple prefix
>
>
>
> Hello Rolando -
>
> On Sat, 15 Dec 2001 13:13, Rolando Riley wrote:
> > Hugh,
> >
> > How can I handle multiple prefix on the  same handler? I thought this
> > would work but it is not.
> > My prefix for gric are both   gric or fcc
> >
> > 
> > 
> > Synchronous
> > Host 216.219.28.10
> > Secret MySecret
> > AuthPort 7000
> > AcctPort 7001
> > 
> >
> >  AcctLogFileName %L/gric
> > 
>
> Your Handler should look like this:
>
> 
>   .
> 
>
>
> regards
>
> Hugh

-- 
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows 95/98/2000, NT, MacOS X.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.
===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



Re: (RADIATOR) Suggestions

2001-12-17 Thread Hugh Irvine


Hello Steve -

On Tue, 18 Dec 2001 09:32, Steve Katen wrote:
> I want to start out by apologizing for sending this request rather than
> reading more into the documentation.  However, I have gone over the manual
> and have been reading some of the postings in the archives, and now I would
> like suggestions for my suspected model.
>
> I have radiator setup, and plan on storing all data in a mySQL
> database.  The structure of the mySQL database has been setup with the
> mysqlCreate.sql file.
>
> My ONLY focus is to proxy ALL Authentication packets to secondary radius
> servers.  I will need to determine the radius servers via
> Called-Station-Id.  The information that I have found in the goodies
> directory has been helpful, though I haven't found many answers to my
> questions.  If someone is currently running with this setup, I would love
> any advice you can provide on setting up the radius.cfg file.
>

It sounds like you should be using the AuthBy SQLRADIUS clause. Have a look 
at section 6.45 in the Radiator 2.19 reference manual ("doc/ref.html") as 
well as the example configuration file ("goodies/sqlradius.cfg").

regards

Hugh


-- 
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows 95/98/2000, NT, MacOS X.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.
===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



(RADIATOR) Re: problem with forking daemon and database connections

2001-12-17 Thread Mike McCauley

Hello Damir,

thanks for this. I can tell you have put a lot of effort into finding this 
problem.

We have rolled your code into the next release, but under the control of a 
new global parameter ForkClosesFDs which by default is off. If it does not 
break anyone, we will default it to on.

Cheers.


On Wed, 5 Dec 2001 11:07, Damir Dzeko wrote:
> Hello Mike,
>
> I had a strange and hard to trace problem with Radiator server
> that was connected to Oracle database (for maintaining session
> database and accounting) and had a handler (for IPASS requests)
> that would fork.
>
> Every time the server forked our radiusd would lose it's connection
> to database. That resulted in errors like:
>
>ORA-03113: end-of-file on communication channel
> (DBD ERROR: OCIStmtExecute)
>
> in the middle of a query execution. The problem was hard to trace
> because the reason for failure was not in the broken query but
> somewhere else.
>
> After many hours of work I discovered that closing a few file
> descriptors just after the daemon forked a child (in the child
> process) would prevent it from happening.
>
> Here are those few lines of code that do the job for me:
>
> use IO::Handle;
>
> in file radiusd.pl, sub safeFork:
>
> elsif (defined $pid)
> {
>   # Child.
>
>   # 
>   #
>   # close kid's file descriptors ;>>>
>   # (this will teach the kid to stay out of
>   # parent's database business)
>   #
>   if (1) {
>   my ($io) = new IO::Handle;
>   for (my $i = 3; $i < 20; $i++) {
> $io->fdopen($i, 'r') && $io->close;
>   }
>   }
>   # 
>
>   return 1;
> }
>
> Greetings,
>
> --damir;

-- 
I am travelling at the moment, and there may be delays in our correspondence.
Mike McCauley, Open System Consultants, [EMAIL PROTECTED], www.open.com.au
===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



(RADIATOR) Suggestions

2001-12-17 Thread Steve Katen

I want to start out by apologizing for sending this request rather than 
reading more into the documentation.  However, I have gone over the manual 
and have been reading some of the postings in the archives, and now I would 
like suggestions for my suspected model.

I have radiator setup, and plan on storing all data in a mySQL 
database.  The structure of the mySQL database has been setup with the 
mysqlCreate.sql file.

My ONLY focus is to proxy ALL Authentication packets to secondary radius 
servers.  I will need to determine the radius servers via 
Called-Station-Id.  The information that I have found in the goodies 
directory has been helpful, though I haven't found many answers to my 
questions.  If someone is currently running with this setup, I would love 
any advice you can provide on setting up the radius.cfg file.

Thanks!

katen


===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



RE: (RADIATOR) Multiple prefix

2001-12-17 Thread Mike McCauley



--  Forwarded Message  --

Subject: BOUNCE [EMAIL PROTECTED]:Non-member submission from ["Ricardo 
J. Sousa" <[EMAIL PROTECTED]>]
Date: Mon, 17 Dec 2001 08:19:52 -0600
From: [EMAIL PROTECTED]
To: [EMAIL PROTECTED]

>From [EMAIL PROTECTED] Mon Dec 17 08:19:52 2001
Received: from relay-1.net4b.pt (relay-out.net4b.pt [195.245.176.1])
by server1.open.com.au (8.11.0/8.11.0) with SMTP id fBHEJp301158
for <[EMAIL PROTECTED]>; Mon, 17 Dec 2001 08:19:51 -0600
Received: (qmail 18750 invoked from network); 17 Dec 2001 15:58:35 +
Received: from unknown (HELO smtp-1.net4b.pt) ([10.0.7.1]) (envelope-sender
 <[EMAIL PROTECTED]>) by relay-1.lx.esp (qmail-ldap-1.03) with SMTP
  for <[EMAIL PROTECTED]>; 17 Dec 2001 15:58:35 +
Received: (qmail 7754 invoked from network); 17 Dec 2001 15:58:35 +
Received: from unknown (HELO slash.meganet.pt) ([194.38.131.251])
 (envelope-sender <[EMAIL PROTECTED]>) by smtp-1.lx.esp (qmail-ldap-1.03)
 with SMTP
  for <[EMAIL PROTECTED]>; 17 Dec 2001 15:58:35 +
Subject: RE: (RADIATOR) Multiple prefix
From: "Ricardo J. Sousa" <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
In-Reply-To: <[EMAIL PROTECTED]>
References: <[EMAIL PROTECTED]>
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
X-Mailer: Evolution/1.0.0.99+cvs.2001.12.16.08.57 (Preview Release)
Date: 17 Dec 2001 16:00:13 +
Message-Id: <[EMAIL PROTECTED]>
Mime-Version: 1.0

On Mon, 2001-12-17 at 14:36, Rolando Riley wrote:
> Hi Hugh:
>   I am  still haveing problems with this handler .  This is how I am setting
> it:
>
> 
>
> 
>
> 
>
> 
>
>
> 
>
> 

Perhaps you could try,


.
.
.



.
.
.



.
.
.


I guess that would be more like what you want.

According to the manual
[...]
 Mixing Handlers and Realms in the same configuration file is
permissible but may lead to hard to understand handler selections, and
difficult to understand behaviour.
[...]
(on Section 6.16).


RJS
--
"Liberty is the Mother, not the Daughter of Order" - Proudhon
Sys. Adm.   eServices/Consultadoria
PGP Fingerprint: 5C 53 4B CC 90 6D 2E E7  60 54 6B 39 35 E9 28 C5
Key available in a pgp key server near you

---

-- 
Mike McCauley   [EMAIL PROTECTED]
Open System Consultants Pty. LtdUnix, Perl, Motif, C++, WWW
24 Bateman St Hampton, VIC 3188 Australia   http://www.open.com.au
Phone +61 3 9598-0985   Fax   +61 3 9598-0955

Radiator: the most portable, flexible and configurable RADIUS server 
anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, 
Platypus, Freeside, TACACS+, PAM, external, Active Directory etc etc 
on Unix, Win95/8, 2000, NT, MacOS 9, MacOS X
===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



(RADIATOR) auth with flat/acct with mysql

2001-12-17 Thread Angel Bustos


Hi all, 

In my first instalation, I would have authentication with a flat text users 
File  but the accounting making online inserts in a MySQL db.
I´ve read the ref.html and i´ve found examples of one or another  
clauses; it seems that  example includes both authentication and 
accounting forcing  to an SQL authentication. 

Should I concatenate two   and  schemes?
could you illustrate with some short example? 

thanks in advance!
regards, 


Angel Bustos
email: [EMAIL PROTECTED] 

 

Conéctese Gratis a Internet desde http://www.brujula.net/gratis
===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



Re: (RADIATOR) Radiator going down after Oracle SQL Timeout

2001-12-17 Thread Mariano Absatz

Hi John,

Thanx for your excellent advise... the point with this specific setup is 
that:

1) I don't have access to the oracle server (we are contractors and only have 
access to the Radius servers "on demand" and I don't even have a unix login 
on the Oracle server).

2) The authentication process is far more complicated that "username/password 
+ a bunch of attributes" and involves port limit checks, dynamic services 
(where some reply-attributes are bound to a service, not to a user, and some 
others are inferred from the servicem, not the user), dynamic IP address 
pools and the like.

3) Since the service is "re-sold" by my client to serveral other customers, 
they want to enforce all of this dynamic checks.

Oracle falls down relatively rarely and performance is, at least, quite 
adequate (when it's working, obviously). I shortened the back-off time to one 
minute (they have a kind of "cold/warm oracle stand-by", so, when it goes 
down, it comes up back quite fast.

My question was oriented to why Radiator was falling down in those cases 
(rather than simply backing off and not authenticating for a while).

As the time it took for me to get a login to the servers was rather long 
('cause my customer didn't think it was critical, since the service WAS up 
all of the time) I couldn't see the "supervise" logs (because they are 
autorotated and autoerased automatically). This logs capture all of the 
standard output and standard error from Radiator timestamping it. I increased 
the size and number of logs, so I will be able to see them the next time it 
happens (I hope).


El 15 Dec 2001 a las 18:43, John Coy escribió:

> > 
> > Hello Mariano -
> > 
> > What you describe below sounds to me like a problem with the DBD-Oracle
> >  module. I would suggest that you try to use the "restartWrapper"
> > program that  we provide in the distribution ("goodies/restartWrapper")
> > instead of  "supervise" (at least for debugging this problem). The
> > restartWrapper program  can be set up with a delay before restarting,
> > and it can also be configured  to email a designated email address with
> > the exit status and any error  messages that were written to stderr. We
> > should then be able to see what is  causing Radiator to die.
> > 
> > regards
> >
> 
> Hugh's answer is a good one, although you mentioned you're already using a 
> daemon-restart tool.
> 
> I'm replying because I am running about the same configuration you are -- 
> two RADIUS daemons (one for auth the other for accounting) and using an 
> Oracle database for the back-end.  Here's my approach for handling the 
> database being offline.
> 
> 1) Check to see why your database is offline =)  If it's going down often 
> enough you might want to spend some time troubleshooting that.  (ok, so 
> that's obvious, but I thought I'd state it anyhow just in case :-)
> 
> 2) Export your Oracle password file to a flat-file equivalent on a regular 
> basis.  My export simulates a traditional UNIX shadow file.  
> 
> This will allow you to use the  to chain together a couple of 
>  clauses.  The first clause will query your SQL server, the second 
> will query the flat file if the SQL server is unavailable.  An example cut 
> out of my "auth.cfg" file:
> 
> #
> # The  statement allows me to bundle the SQL 
> # authentication with the UNIX-style authentication in case the
> # SQL server is down.  SQL authentication is preferred and takes
> # precedence.
> #
> 
> Identifier  ANCI-AuthSQLorUNIXPasswd
> AuthByPolicyContinueWhileIgnore
> 
> AuthBy  ANCI-AuthSQLPasswd
> AuthBy  UNIX
> 
> 
> 
> Identifier  ANCI-AuthSQLPasswd
> 
> ... all your SQL auth stuff here ...
> 
> 
> 
> Identifier  UNIX
> Filename/usr/local/etc/shadow
> GroupFilename   /usr/local/etc/group
> 
> 
> This gives you a bit of redundancy in case your Oracle database goes 
> offline.  Be sure your export routine does not clobber the file with empty 
> data if it cannot read from the database (or else you're back where you 
> started).
> 
> Hope that helps.
> 
> John
> Arkansas.Net


--
Mariano Absatz
El Baby
--
Nobody has ever, ever, EVER learned all of WordPerfect. 


===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



Re: (RADIATOR) assign ip from radius to AS5300 NAS

2001-12-17 Thread Mariano Absatz

Hi Manoj,

usually, if you send "Framed-IP-Address" + "Framed-IP-Netmask" attributes in 
the "Access-Accept" packet, the NAS will use the IP address instead of 
assigning one of its own.

In the authentication for e-mail users you should (after the standard 
user/password authentication) use an  (see 
http://www.open.com.au/radiator/ref.html#pgfId=406580) and use a SQL database 
for holding your IP address pools (or DHCP if you have a DHCP server 
available).

Obviously, the IP addresses in the Radiator database should not conflict with 
the ones assigned by your NAS.

A more simple arrangement would be possible if your NAS supports any kind of 
selection of IP address pool based on some Radius attribute. You should check 
your NAS documentation and/or provider and set that attribute in the "Access-
Accept" packet.

El 17 Dec 2001 a las 11:20, Manoj Agrawal escribió:

> 
> Hi!
> We are an ISP. We have two types of account one for internet account
> and another one is for email only account. Both users dial the same
> number to access our network. I want to assign IPs address to email
> only users from Radiator radius to AS5300 NAS so that I can block
> those IPs only to our email servers. But, for Internet users I am
> assigning IPs from AS5300 NAS and it works fine. So, how can I assign
> IPs from radius to AS5300 NAS.
> Regards,
> manoj
> 
> 
> 
> --
> Best regards,
>  Manoj  mailto:[EMAIL PROTECTED]
> 

--
Mariano Absatz
El Baby
--
I thought I wanted a career, turns out I just wanted pay checks.


===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.



RE: (RADIATOR) Multiple prefix

2001-12-17 Thread Rolando Riley

Hi Hugh:
I am  still haveing problems with this handler .  This is how I am setting
it:


 :



 :




 :




Okay...  what is happening is that it is authenticating well "only" if  the
user from IPASS or gric is this way:
[EMAIL PROTECTED]
[EMAIL PROTECTED]

But if the user try to auth like this it fails:
[EMAIL PROTECTED]
[EMAIL PROTECTED]


Checking the debug trace I see that this users fall on the "REALM
ayayai.com"  giving authentication rejects. I am thinking that this is
happening because Realms has more priority than Handler?  How can I solve
this situation?

--


Code:   Access-Request
Identifier: 193
Authentic:  <141>'zy<24><13>a<132>O<219><127><19>(<16><249>V
Attributes:
User-Name = "[EMAIL PROTECTED]"
User-Password =
"V<178><158>@<227><168><243><255><171>C<150><250><219><150><156>@"
Client-Id = 200.24.140.2
NAS-Port = 1292
Acct-Session-Id = "84607095"
USR-Interface-Index = 2548
Service-Type = Framed-User
Framed-Protocol = PPP
Chassis-Call-Slot = 6
Chassis-Call-Span = 1
Chassis-Call-Channel = 12
Calling-Station-Id = "2657832"
Called-Station-Id = "055"
NAS-Port-Type = Async

Mon Dec 17 09:11:40 2001: DEBUG: Handling request with Handler
'Realm=ayayai.com'
Mon Dec 17 09:11:40 2001: DEBUG:  Deleting session for [EMAIL PROTECTED],
200.24.140.2, 1
292
Mon Dec 17 09:11:40 2001: DEBUG: Handling with Radius::AuthRADIUS
Mon Dec 17 09:11:40 2001: DEBUG: Packet dump:
*** Sending to 216.219.28.131 port 1645 
Code:   Access-Request
Identifier: 10
Authentic:  <141>'zy<24><13>a<132>O<219><127><19>(<16><249>V
Attributes:
User-Name = "[EMAIL PROTECTED]"
User-Password =
"<241>/<190><159>e<4>\<248><199><181><31><146><234><18><159><131>"
Client-Id = 200.24.140.2
NAS-Port = 1292
Acct-Session-Id = "84607095"
USR-Interface-Index = 2548
Service-Type = Framed-User
Framed-Protocol = PPP
Chassis-Call-Slot = 6
Chassis-Call-Span = 1
Chassis-Call-Channel = 12
Calling-Station-Id = "2657832"
Called-Station-Id = "055"
NAS-Port-Type = Async

Mon Dec 17 09:11:40 2001: DEBUG: Packet dump:
*** Received from 216.219.28.131 port 1645 
Code:   Access-Reject
Identifier: 10
Authentic:  <10><200><24><239><26>F2<142><152>sDAn<134><229><195>
Attributes:
Port-Message = "Request Denied"

Mon Dec 17 09:11:40 2001: DEBUG: Received reply in AuthRADIUS for req 10
from 216.219.28.131
:1645

Mon Dec 17 09:11:40 2001: DEBUG: Packet dump:
*** Sending to 200.24.140.2 port 1645 
Code:   Access-Reject
Identifier: 193
Authentic:  <141>'zy<24><13>a<132>O<219><127><19>(<16><249>V
Attributes:
Port-Message = "Request Denied"

Mon Dec 17 09:11:44 2001: DEBUG: Packet dump:









-Mensaje original-
De: Hugh Irvine [mailto:[EMAIL PROTECTED]]
Enviado el: Sunday, December 16, 2001 6:34 PM
Para: Rolando Riley; [EMAIL PROTECTED]
Asunto: Re: (RADIATOR) Multiple prefix



Hello Rolando -

On Sat, 15 Dec 2001 13:13, Rolando Riley wrote:
> Hugh,
>
>   How can I handle multiple prefix on the  same handler? I thought this
> would work but it is not.
> My prefix for gric are both   gric or fcc
>
> 
> 
> Synchronous
> Host 216.219.28.10
> Secret MySecret
> AuthPort 7000
> AcctPort 7001
> 
>
>  AcctLogFileName %L/gric
> 
>

Your Handler should look like this:


.



regards

Hugh


--
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows 95/98/2000, NT, MacOS X.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.

===
Archive at http://www.open.com.au/archives/radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.