Pb configuring EAP/MD5 auth with Orinoco AP1000

2002-04-06 Thread Guillaume DURAND
I read in the archive that the same problem was reported a few months ago : I try to configure authentification with freeRadius for an ORINOCO AP1000, with a client on winXP. EAP auth goes correcly (Access-Challenge sent) but there is no answer from the wireless side, and the client gets no acces

Re: Blocking multiple logins.

2002-04-06 Thread Stephan Viljoen
Hi , this might not be the most correct way of doing it but it worked fine for me. Each user should get an entry Simultaneous-Use := 1 . I think you can setup a group as well , and then you can just tell each user to belong to that group. You also need to add all your Access servers in the raddb/

Re: Using Radius for Mac Auth. with Wireless Internet.

2002-04-06 Thread Stephan Viljoen
Title: Message How secure is it Mac Authentication. I mean, is there no way for someone to emulate a Authorized Mac. with software or something to get onto the network?     - Original Message - From: Stephan Viljoen To: [EMAIL PROTECTED] Sent: Friday, April 05, 200

RE: Using Radius for Mac Auth. with Wireless Internet.

2002-04-06 Thread Veli-Matti Riepula
>How secure is it Mac Authentication. I mean, is there no way for someone to emulate a Authorized Mac. with software or >something to get onto the network? Practically it provides low security, anyone who knows a valid MAC address can connect. Most network cards (wired or wireless) provide MAC sp

Re: dial_up admin question

2002-04-06 Thread Kostas Kalevras
On Sat, 6 Apr 2002, Peter Santiago wrote: > I'm using a mysql database. I created a user via dial_up admin... somehow > after the user disconnects, under dial_up admin's online menu, the user is > still connected. Connection status is still counting the time... How do I > solve this? Do I nee

Re: LDAP Authentication

2002-04-06 Thread Kostas Kalevras
On Fri, 5 Apr 2002, Rob Payne wrote: > Based upon the number of people who have this working, either I am > trying to do something entirely crazed, or I am missing something very > basic! Please bear with me. 8^) > > I have an existing FreeRadius implementation that I am attempting to > migrate

Re: Blocking multiple logins.

2002-04-06 Thread Kostas Kalevras
On Fri, 5 Apr 2002, Aqeel Anwar wrote: > Hi everyone. > On my network I am using three cisco access servers. I > want to blcok multiple login of same user ID on these > access servers i.e. if a user ID 'xyz' login on Access > server 1 then the user id 'xyz' should not login for > second time on s

Re: rlm_counter && mysql ...

2002-04-06 Thread Kostas Kalevras
On Thu, 4 Apr 2002, Do-Risika RAFIEFERANTSIARONJY wrote: > > Hi all, > > I remember to have seen an rlm_counter patch, with mysql support, a few > months ago. Is someone thinking to include it in the next release one > day ? It would be very interesting for me. > > My purpose is to have a centere

Re: IP POOL

2002-04-06 Thread Kostas Kalevras
On Tue, 2 Apr 2002, Jacobo [iso-8859-1] González Simón wrote: > Hi all, > > I´m testing freeradius and ldap( with radtest utility, i have not > another ras server that one is running whith another radius ), and it > seems to work fine. Now the problem: > > I had read in users file this: > > # > #

Re: Using Radius for Mac Auth. with Wireless Internet.

2002-04-06 Thread Stephan Viljoen
Ye , that's what I thought . Thanks for the conformation though. Is there any other way in making this more secure? - Original Message - From: "Veli-Matti Riepula" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Saturday, April 06, 2002 12:59 PM Subject: RE: Using Radius for Mac Auth.

Re: Dialup-Admin

2002-04-06 Thread Kostas Kalevras
On Tue, 2 Apr 2002, Jason M. Weber wrote: > When I change the following line in accounting.php: > > $link = @da_sql_pconnect($config) or die... > > to > > $link = mysql_pconnect(localhost, ,) or die... > > I can connect to the db and the accounting page works just fine. A problem > with my config

Re: LDAP module binding to wrong IP adress..

2002-04-06 Thread Kostas Kalevras
On Thu, 4 Apr 2002, Erling Paulsen wrote: > Hello listusers, > > I run v.0.5 with 2 realms forwarded to Merit based RADIUS servers and DEFAULT > no relmed requests to an Active Directory box. It runs on FreeBSD 4.5 in a > chrooteed environment. > > All well, bells and trumpets, and then.. now I r

RE: Using Radius for Mac Auth. with Wireless Internet.

2002-04-06 Thread Veli-Matti Riepula
> Ye , that's what I thought . Thanks for the conformation though. Is there > any other way in making this more secure? Nokia has a hybrid WEP/MAC authentication using RADIUS, where the user's personal WEP key is delivered to the AP as a reply-item from a RADIUS server. The user must have corre

Re: freeradius and mysql

2002-04-06 Thread Artur Hecker
tywe wrote: > > That did it!! My accounting is working just fine! And now I even see it > updating the mysql tables! Thanks a TON! > > Frank > does it write any radutmp, radwtmp, sradutmp files, etc.? can you use radwho? in which sequence did you send your Accounting messages? First an ON or

Re: Using Radius for Mac Auth. with Wireless Internet.

2002-04-06 Thread Stephan Viljoen
Ta for the the help. - Original Message - From: "Veli-Matti Riepula" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Saturday, April 06, 2002 2:30 PM Subject: RE: Using Radius for Mac Auth. with Wireless Internet. > > > Ye , that's what I thought . Thanks for the conformation though.

Re: Unusual authentication problems... groups not applied

2002-04-06 Thread Alan DeKok
"Mike Cisar" <[EMAIL PROTECTED]> wrote: > If I log in with the "username" flavor everything works properly and I > am either denied access, or assigned the proper attributes as defined > above. BUT if I try to log in as "[EMAIL PROTECTED]" the group > lines are ignored and for example if my group

Re: Blocking multiple logins.

2002-04-06 Thread Mohsin Khan
A-o-a I havent used Cisco as Access server but , it could be done by limiting number of chanels used by a login, it is one for normal login and 2 for multi login users. To get it more easy you can put a chcek in you radius, can create an attribute that will help i think, what radius are you usi

RE: Configuring Free Radius to do MAC Address Authentication

2002-04-06 Thread David Petruzzella
I'm kind of new at this and I was wondering if anyone can help me out configuring free radius for mac address authentication. I have it compiled. But I don't how to set it up so I can use it to Authenticate the mac addresses of my wireless network. I couldn't find any documentation on the

Re: Freeradius not working under firewall

2002-04-06 Thread Mojahedul Hoque Abul Hasanat
On Sun, Apr 07, 2002 at 11:37:14AM +0600, Dr. Muhammad Masroor Ali wrote: > ... > rules we have put something like allow packets to ports 1645 and > 1646 tcp + udp only from NAS IP. But, as soon as firewall is > activated, users start getting invalid login. All outgoing ports > are open. No need

Freeradius not working under firewall

2002-04-06 Thread Dr. Muhammad Masroor Ali
Hi All, Our radius server (freeradius 0.4 in RH 7.1) was working just fine untill we installed firewall. In our firewall (ipchains) rules we have put something like allow packets to ports 1645 and 1646 tcp + udp only from NAS IP. But, as soon as firewall is activated, users start getting invalid l