Re: Usage (Traffic) Based RADIUS Accounting Question

2002-11-22 Thread Alan DeKok
Jason Lixfeld <[EMAIL PROTECTED]> wrote: > That poses a problem, obviously. If a user doesn't log off (or reboot > their router as the case would be) for 3 months, they could get a pretty > lofty bill which would not bode well. That's what "alive" packets are for. They're "interim update" mess

Max-Session-Time usage

2002-11-22 Thread Peter Santiago
I don't think Max-Session-Time is included in the sql tables for mysql, is it? So I have add it to the table then? Can anyone help out in providing a working example using Max-session-time? Thanks - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

rlm_sql_oracle

2002-11-22 Thread Gillou
What do I need to compile rlm_sql_oracle ? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Usage (Traffic) Based RADIUS Accounting Question

2002-11-22 Thread Jason Lixfeld
Suppose I have a user who is billed based on usage (or traffic) per month. If we're using RADIUS accounting to keep track of bytes|octets in/out, the accounting stop packets hold all that information. Suppose this user has a dedicated service and never logs off. If this user is online before the

HELP: radreply

2002-11-22 Thread Gian-Carlo Baldarelli
What kind of info do I need to insert in radreply table ( or where find info ) I act as a proxed server, so I need to give only user e password authorization. my config --- mysql> select * from radcheck; ++---+---

Re: EAP and synamic WEP keys

2002-11-22 Thread Artur Hecker
hi paul > I mean supplicants with non-cisco cards like D-Link, Linksys, etc... usually a card should work provided there are some recent drivers and you have the recent firmware installed. since EAPoL adds a new SNAP, you do need some support for it, it doesn't work automatically. > So from wh

Dynamic IP Addressing from MySQL

2002-11-22 Thread Ken Wolstencroft
I know this is not strictly a job for radius, but can FreeRadius dynamically assign ip addresses from mysql. This is a feature I have used previously in radiator and found it very useful. I have seen the Framed-IP-Address with a + (e.g. 192.168.1.1+), but I could not find any documentation. Thank

Re: proxying on Called-Station-Id instead of realm

2002-11-22 Thread Ken Wolstencroft
Thanks for that... Ken - Original Message - From: "Chris Parker" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, November 22, 2002 5:36 PM Subject: Re: proxying on Called-Station-Id instead of realm > At 05:32 PM 11/22/2002 +, kenw wrote: > >Hi Alan, > > > >I've got this t

dialup_admin

2002-11-22 Thread Gillou
What do I need to configure to make dialup_admin working ? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

help - misconfiguration ?? What does it mean ?

2002-11-22 Thread Gian-Carlo Baldarelli
Fri Nov 22 18:45:00 2002 : Error: rlm_sql_authorize: no rows returned from query (no such user) Fri Nov 22 18:45:00 2002 : Auth: Login OK: [giancarlo] (from nas easy@1 port 2070 cli 54942324) Fri Nov 22 18:47:07 2002 : Error: rlm_sql_authorize: no rows returned from query (no such user) Fri Nov 22

dialup_admin error

2002-11-22 Thread Leandro Machado
I´m running Apache 1.3.20 + PHP4 to support dialup_admin. When I try to execute i have the following: "Could not include SQL library functions. Aborting. " I cant find any reference to it on mail list, suggestions? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.htm

PARSE ERROR: /usr/include/unistd.h

2002-11-22 Thread Nikhil Chauhan
Hi all: While installing "freeradius-snapshot-20021122", I get the following message after doing "make". Any known problems here??? Thanks. === gmake[6]: Entering directory `/tmp/freeradius-snapshot-20021122/src/modules/rlm_u

Re: proxying on Called-Station-Id instead of realm

2002-11-22 Thread Chris Parker
At 05:32 PM 11/22/2002 +, kenw wrote: Hi Alan, I've got this to work, but only the access request is proxied. How would I go about getting the accounting to proxy aswell? Add the same to 'acct_users'. -Chris -- \\\|||/// \ StarNet Inc. \ Chris Parker \ ~ ~ /

Re: proxying on Called-Station-Id instead of realm

2002-11-22 Thread kenw
Hi Alan, I've got this to work, but only the access request is proxied. How would I go about getting the accounting to proxy aswell? All the best and thanks again, Ken Alan DeKok wrote: kenw <[EMAIL PROTECTED]> wrote: Is it possible with FreeRadius to proxy based on Called-Station-Id instea

Re: EAP and synamic WEP keys

2002-11-22 Thread Paul Khavkine
Artur Hecker wrote: > hi > > > We are probably getting a Cisco Aironet 350 AP. > > it works with this one. > > >>From what i have gathered from the list about Aironet, the 350 suports EAP-TLS > > but i'm not sure how the WEP keing works. > > an AP never supports or doesn't support a particular EAP

Re: EAP and synamic WEP keys

2002-11-22 Thread Artur Hecker
hi We are probably getting a Cisco Aironet 350 AP. it works with this one. From what i have gathered from the list about Aironet, the 350 suports EAP-TLS but i'm not sure how the WEP keing works. an AP never supports or doesn't support a particular EAP type (like EAP/TLS, etc.), that's w

Re: EAP and synamic WEP keys

2002-11-22 Thread Paul Khavkine
Artur Hecker wrote: > it works with TLS and can work only with TLS. install and compile the > newer version. it's still experimental but it works. please note that > there is still no standard to do so, you have to have hardware is > capable of supporting MS-MPPE-Key-* attributes > We are probabl

Re: EAP and synamic WEP keys

2002-11-22 Thread Artur Hecker
it works with TLS and can work only with TLS. install and compile the newer version. it's still experimental but it works. please note that there is still no standard to do so, you have to have hardware is capable of supporting MS-MPPE-Key-* attributes MD5 doesn't exchange any key material and

Re: proxying on Called-Station-Id instead of realm

2002-11-22 Thread kenw
Ah, on a closer look the user file I expect... Thanks again, Ken kenw wrote: Thanks Alan, Which file would I put this, proxy.conf? Thanks, Ken Alan DeKok wrote: kenw <[EMAIL PROTECTED]> wrote: Is it possible with FreeRadius to proxy based on Called-Station-Id instead of realm. A large s

Re: proxying on Called-Station-Id instead of realm

2002-11-22 Thread kenw
Thanks Alan, Which file would I put this, proxy.conf? Thanks, Ken Alan DeKok wrote: kenw <[EMAIL PROTECTED]> wrote: Is it possible with FreeRadius to proxy based on Called-Station-Id instead of realm. A large section of our users do not use realms as part of the username, but dial-in to di

insert to mssql failed

2002-11-22 Thread novelss
Dear all I have problem in insert to mssql field in mssql. Why when i telnet to cisco with users config from NasPortType Async or Virtual, that field insert to field in mssql success but if i connect with NasPortType ISDN..that field can't insert to field in mssql??? please help me... - Li

Re: proxying on Called-Station-Id instead of realm

2002-11-22 Thread Alan DeKok
kenw <[EMAIL PROTECTED]> wrote: > Is it possible with FreeRadius to proxy based on Called-Station-Id > instead of realm. A large section of our users do not use realms as part > of the username, but dial-in to different numbers. Sure. DEFAULT Called-Station-Id == "foo", Proxy-To-Realm := "bar

EAP and synamic WEP keys

2002-11-22 Thread Paul Khavkine
Hi folks. What's the status of dynamic WEP keys in FR ? Anyone got it to work with EAP/TLS ? Also does EAP/MD5 support dynamic WEP keys ? Thanx Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius 0.8 and mysql

2002-11-22 Thread Alan DeKok
"Chhai Thach" <[EMAIL PROTECTED]> wrote: > I have been testing freeradius 0.8 but I can't seem to get the mysql > authentication going. When I run it in debug mode, this is what I get: ... > What seems to be wrong? Help appreciated. Thanks. Nothing is wrong. There are no warning or error messa

proxying on Called-Station-Id instead of realm

2002-11-22 Thread kenw
Hi, Is it possible with FreeRadius to proxy based on Called-Station-Id instead of realm. A large section of our users do not use realms as part of the username, but dial-in to different numbers. I operate two layers of radius servers (currently radiator), but I am looking at the possibilties o

Re: EAP/TLS testing: SSL_set_my_callback

2002-11-22 Thread Nikhil Chauhan
Hi Artur: My "freeradius-0.7.1/src/modules/rlm_eap/types/rlm_eap_tls/Makefile" looks like the following: === # Generated automatically from Makefile.in by configure. TARGET = rlm_eap_tls SRCS= rlm_eap_tls.c eap_tls.c cb.c tls.c mppe_key

Re: Wireless LAN with Freeradius...

2002-11-22 Thread david tran
Hi All, I am successfully running my home wireless network with Freeradius server using EAP-TLS. The setup process is not difficult at all thank to Raymond McKay. Raymond has written a very detailed instruction on how to setup Wireless LAN using Freeradius server in conjunction with EAP-TLS.

Re: Wireless LAN with Freeradius...

2002-11-22 Thread Owen Squires
I'm certainly open to any others also! Wireless APs (it turns out) are a very inconsistent breed. My intent was, and still is, to do MAC address (only) authentication. Not with EAP, WAP, etc added on... To that end I've got a Cisco AP 350, Symbol AP4131, 3Com AP8000 an Orinoco AP1000 in house t

Wireless LAN with Freeradius...

2002-11-22 Thread Tamer Demir
Hi all, Could you please write your freeradius experiences in 802.11 Wireless LAN. Can we setup freeradius to allow certain MAC addresses? and Is there need for a third party software in the Wireless clients? Regards, Tamer - List info/subscribe/unsubscribe? See http://www.freeradius.org/l

Re: EAP/TLS testing: SSL_set_my_callback

2002-11-22 Thread Artur Hecker
hi Nikhil in my case i have: radius:/usr/local/lib# ldd rlm_eap_tls-0.8-pre.so libnsl.so.1 => /lib/libnsl.so.1 (0x400df000) libresolv.so.2 => /lib/libresolv.so.2 (0x400f3000) libpthread.so.0 => /lib/libpthread.so.0 (0x40104000) libc.so.6 => /lib/libc.so.6 (0x40118

How to implement Radius on a NAS (round robin...?)

2002-11-22 Thread Joost
Hi, Not a specific FR question but for a NAS that should authenticate against a FR server. I'm working on a NAS with RADIUS support. You can configure a 1st, 2nd, 3th and 4th radius server. The NAS should first try the 1st one and if it fails after X seconds it should go to the second or somethin

Re: freeradius 0.8 & checkrad

2002-11-22 Thread Andrea Gabellini
I have the same problem, and I solved it putting nastype in clients.conf. At 05.57 22/11/02, you wrote: hello guys, i've recently upgraded to freeradius 0.8. everything went well except checkrad. it was not being invoked by the server to verify simultaneous logins on the NAS. do i miss somethi

Operator question + freeradius 0.8

2002-11-22 Thread Alessandro Maioli
Hi to all! I need to reject any access where there aren't information about NAS port number. By mean of users.conf i've implemented the next rule: DEFAULT NAS-Port !* 0, Auth-Type := Reject Fall-Through = No I've made few test with RadPing but it seem doesn't work at all. In debug mode I

Exec-Program-Wait & Solaris & crash

2002-11-22 Thread Bondar Tamas
Hi All, I'm trying to use freeradius v0.8 for external authentication with Exec-Program-Wait. The server crashes after a couple of failed authentications. My OS is Solaris 5 (updating is not an option for me right now). Is this considered as a known bug, or it should work and I just misconfigured