Re: Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Miquel van Smoorenburg
In article <[EMAIL PROTECTED]>, Christophe Boyanique <[EMAIL PROTECTED]> wrote: >On Tue, Apr 01, 2003 at 09:01:56AM +0200, Mike Janssen wrote: > >> Subject: Mike Janssen/ZND/CSS is out of the office. >> Date: Tue, 1 Apr 2003 09:01:56 +0200 > >I hope this is some kind of April Fools Day joke. Doubl

RE: freeRadiu, 802.1x and Cisco

2003-04-01 Thread Olivier PERROT
Thanks. I've seen the same info from somebody else who also used HP switchs but it's already "fixed" in the new dictionary file in (pre) version 0.9. So that's unfortunately not my problem ... I'll continue to investigate with my Cisco devices (Catalyst 2950) and let you know when/if I found someth

Re: check item problem

2003-04-01 Thread Brian Leung
Hi all, i don't know whether it have a bug or not? when i used checkval module and radiusCalledStationid, it is prefer. But, when i used radiusCheckItem: NAS-IP-Address := 202.14.68.51, it seems have problem. the NAS 202.14.68.50 still can pass the radius although i have the above restriction. You

Status to client...

2003-04-01 Thread Mike Cisar
Does anybody know if there are any "replacement" diallers or TCP/IP stacks for windows that actually report back the error code output by freeradius when a connection is denied. We've got a few customers that are becoming an increasing hassle support-wise, who we could easily silence if there was

Re: Framed-IP-Address Limit

2003-04-01 Thread Ador Dauz
if your RAS has a feature for Framed-IP-Pool just like Total Control its better to use it... At 06:26 PM 4/1/2003 -0500, you wrote: Gustavo Lozano <[EMAIL PROTECTED]> wrote: > If I put Framed-Ip-Address = 192.168.0.1+ in a profile, How can I limit > the Pool just to use the block until it reaches 1

Re: Framed-IP-Address Limit

2003-04-01 Thread Alan DeKok
Gustavo Lozano <[EMAIL PROTECTED]> wrote: > If I put Framed-Ip-Address = 192.168.0.1+ in a profile, How can I limit > the Pool just to use the block until it reaches 192.168.0.10 ? You can't. You've got to use rlm_ippool. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freera

priviliged nas?

2003-04-01 Thread Ray
freeRadius 0.8.1 MySQL auth/acct is there a way to setup a group to be (dis)allowed on a nas? (mainly for isdn accounts) - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Framed-IP-Address Limit

2003-04-01 Thread Gustavo Lozano
Hello. Dummy question: If I put Framed-Ip-Address = 192.168.0.1+ in a profile, How can I limit the Pool just to use the block until it reaches 192.168.0.10 ? I only want XX number of addresses to be assigned in every profile. Regards -- Gustavo Lozano <[EMAIL PROTECTED]> Noldata Corporation

Re: radzap

2003-04-01 Thread Alan DeKok
Oliver Zimmermann <[EMAIL PROTECTED]> wrote: > As far as I remember, someone patched this in the CVS. So I wait for the > next release. Yeah, the CVS head works. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radzap

2003-04-01 Thread Oliver Zimmermann
On Tue, 01 Apr 2003 12:24:10 -0500 "Alan DeKok" <[EMAIL PROTECTED]> wrote: > I'm also not sure if radzap works perfectly in 0.8.1. You may want > to try grabbing it from the CVS snapshot. Hello, on my 0.8.1-servers I use now the 0.7-radzap-binary again, which will do the job. With the 0.8.1

wanna know radwho script

2003-04-01 Thread Nazmul Haqe
hi! i wanna know how to create radwho script. can any one help me? S.M.Nazmul Haqe _ Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail - List info/subscribe/unsubscrib

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

Re: Something strange about logging

2003-04-01 Thread Alan DeKok
Degrande_Samuel <[EMAIL PROTECTED]> wrote: > Everything is working in debug mode (radiusd -X). > but it coredumps in 'normal mode'. ... > So at this point, radlog_dest is always RADLOG_FILES, and then it > executes > > log.vradlog:94 fopen(mainconfig.log_file, "a") > > mainconfig

Re: Cisco AIRONET mac address authentication

2003-04-01 Thread Jeffrey C. Ollie
On Tue, 2003-04-01 at 09:59, Seos wrote: > > I am seeing the Aironet trying to authenticate the laptop to the radius > server, but the authentication isn't succeeding. Somewhere I am going > wrong or missing something. Here's what I use: Auth-Type := Local, NAS-Port-Type := Wireless

Re: Is it possible to split authentication and authorization requestsbased on NAS IP?

2003-04-01 Thread Dustin Doris
Yes you can do that now. In your users file put. DEFAULT NAS-IP-Address == "1.1.1.1", Autz-Type := sql1 DEFAULT NAS-IP-Address == "2.2.2.2", Autz-Type := sql2 Then you can setup two different sql types. Then in authorization in radius.conf add autztype sql1 { sql1 }

Re: authentication and accounting using proxy feature

2003-04-01 Thread Franklin Trumpy
On Tue, 1 Apr 2003, Wisam Najim wrote: > I have configured the freeRADIUS to proxy requests to another remote > RADIUS (...) The problem is for every request the freeRADIUS that > proxies the request tries to authenticate the customer locally even if that > customer rquest is proxied (...) Under

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

FreeRADIUS dies

2003-04-01 Thread HOPPÁL Felicián
Hello,   I'm using FreeRADIUS 0.8.1 as production RADIUS server with Oracle 8.1.7 on Linux. It works fine, but sometimes it will get confused, then rejects _every_ login. There is no SQL or other error in the log files, the accounting works fine, but it sends Access-Reject for every Access-R

EAPTLS without certificates

2003-04-01 Thread Manuel Sánchez Cuenca
Hello, somebody know how to modify the source code of freeradius to configure the ssl context for not to use certificates. Thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Using LDAP and Realms with v0.81

2003-04-01 Thread Alan DeKok
"Ron Wahler" <[EMAIL PROTECTED]> wrote: > I guess my question here is how you create 2 ldap instances. Create a 'second' name for the ldap module: ldap ldap1 { ... } ldap ldap2 { ... } Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/u

RE: Using LDAP and Realms with v0.81

2003-04-01 Thread Ron Wahler
I guess my question here is how you create 2 ldap instances. Ron. -Original Message- From: Ron Wahler Sent: Tuesday, April 01, 2003 10:23 AM To: [EMAIL PROTECTED] Subject: RE: Using LDAP and Realms with v0.81 How do you tie ldap1 and ldap2 to the ldap module. Do you create Ldap1.a

RE: Using LDAP and Realms with v0.81

2003-04-01 Thread Ron Wahler
How do you tie ldap1 and ldap2 to the ldap module. Do you create Ldap1.attrmap Ldap2.attrmap And then include them both in the radiusd.conf file ? # Mapping of RADIUS dictionary attributes to LDAP # directory attributes. dictionary_mapping = ${raddbd

Re: radzap

2003-04-01 Thread Alan DeKok
Ross Reed <[EMAIL PROTECTED]> wrote: > I am trying to use radzap to clear an entry from the radutmp file. But > radzap requires a NAS, this is national dialup and we have no access to the > actual termserver. radzap needs to know about the NAS, but it doesn't require access to the NAS. I'm al

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

radzap

2003-04-01 Thread Ross Reed
Title: Message I am trying to use radzap to clear an entry from the radutmp file. But radzap requires a NAS, this is national dialup and we have no access to the actual termserver. Unless I am missing something, it seems you need this. Is there no other way to clear an entry, other than remo

Re: mixing acct_users / detail informations

2003-04-01 Thread Christophe Boyanique
> > But if I move "Realm := csd.sfr" on the first > > line it doesn't work (ie %{reply:Realm} is empty). > > Then use %{config:Realm}, as was mentioned in an earlier message. When moved on the first line the directive Realm = 'csd.sfr' or Realm := 'csd.sfr'; there is *nothing* in %{whatever:Rea

Managing IpPools

2003-04-01 Thread Gustavo Lozano
Hello Docs!! I need to manage IpPools from the Radius server instead allocating the Pools in the NAS boxes. The thing is that I need to doit using freeradius :) Any suggestion? Regards! -- Gustavo Lozano <[EMAIL PROTECTED]> Noldata Corporation - List info/subscribe/unsubscribe? See http:/

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

Re: Cisco AIRONET mac address authentication

2003-04-01 Thread Alan DeKok
Seos <[EMAIL PROTECTED]> wrote: > I am seeing the Aironet trying to authenticate the laptop to the radius > server, but the authentication isn't succeeding. Somewhere I am going > wrong or missing something. > > any thoughts? Run the server in debugging mode as suggested in the FAQ, the README

Re: mixing acct_users / detail informations

2003-04-01 Thread Alan DeKok
Christophe Boyanique <[EMAIL PROTECTED]> wrote: > 1/ radiusd screams that "WARNING! Check item Realm ?found in reply item > list for user "DEFAULT". ?This attribute MUST go on the first line with > the other check items". Yes, Realm is a 'check', or 'config' item. > But if I move "Realm := csd.

Cisco AIRONET mac address authentication

2003-04-01 Thread Seos
Hi all, hoping this'll be a simple question. I am attempting to use freeradius to authenticate mac addresses connecting to my network from wireless laptops via Cisco Aironet access points . I have an aironet device ip address entered in the clients.conf file, and an entry for a wireless laptop

Re: mixing acct_users / detail informations

2003-04-01 Thread Christophe Boyanique
On Mon, Mar 31, 2003 at 11:48:25AM -0500, Alan DeKok wrote: > Try: > detailfile = /radacct/%{%{config:Acct-Type}:-NOREALM}_%Y%m%d.log > > Acct-Type is a server configuration directive, and never goes into > the reply. I made some new experiences and I found a way to do what I want. This is

Is it possible to split authentication and authorizationrequests based on NAS IP?

2003-04-01 Thread Deramus, Chris
Title: Is it possible to split authentication and authorization requests based on NAS IP? I will try to make this as simple to understand as possible. Basically in our production environment we are trying to use our FreeRADIUS server to do authentication for both VPN users (stored in radcheck)

Nokia RADIUS Client Password Issue

2003-04-01 Thread Scott Van Outer
I am working with a Nokia network device (IP650) that is serving as a RADIUS client.  I am running FreeRADIUS on a SuSE Linux server.  When the remote user makes a login they hit the Nokia device which then forwards the login to the RADIUS server.  In debug mode I can see the User-Password

RE: Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Casey Boone
Can someone please unsubscribe this gentleman until the 13th? Or perhaps leave him subscribed but prevent him from posting? Casey > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > Mike Janssen > Sent: Tuesday, April 01, 2003 9:06 AM > To: [EMAIL P

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

Re: Problem Installing FreeRadius

2003-04-01 Thread Degrande_Samuel
According to [EMAIL PROTECTED] (Tue, 01 Apr 2003 09:31:13 -0500): > I am having a problem installing FreeRadius on Solaris 8, SPARC based. > Please see the log message below for further information. > > If you can provide some suggestions, I would appreciate it. > > Thank you. > Milan Raval > >

strange accounting garbage

2003-04-01 Thread Ray
using: FreeRadius 0.8.1 w/ MySQL NAS: USR total contol hub we have a number of people with AcctSessionTime of 2147483647 (max signed 32 bit int?) with start/stop times maxing at less then 4 hours (all within the same 4 hours) some example start/end times are 2003-03-01 23:28:41 to 2003-03-02 00

Something strange about logging

2003-04-01 Thread Degrande_Samuel
Hello, this is my first message on that list. I just compiled freeradius-snapshot-20030324 on sparc-solaris9 Before to really install thing, I'm used to test applications in a specific directory. I mean that I configured that way : ./configure --prefix= --exec-prefix=/usr --libdir=/usr/lib/radius

RE: freeRadiu, 802.1x and Cisco

2003-04-01 Thread Terry Green
I found with my HP switch, I needed to change the type of the Tunnel-Private-Group-ID to String in the dictionary.tunnel file. > -Original Message- > From: Olivier PERROT [mailto:[EMAIL PROTECTED] > Sent: Tuesday, April 01, 2003 4:49 AM > To: [EMAIL PROTECTED] > Subject: freeRadiu, 802.1x

Problem Installing FreeRadius

2003-04-01 Thread Milan_Raval
I am having a problem installing FreeRadius on Solaris 8, SPARC based. Please see the log message below for further information. If you can provide some suggestions, I would appreciate it. Thank you. Milan Raval gmake[2]: Entering directory `/tmp/freeradius-0.8.1/libltdl' /bin/sh ./libtool --mo

Re: check item problem

2003-04-01 Thread Dustin Doris
Do you see how the Called-Station-Id is not coming in with the auth request? > The following is the whole debug when i used "compare_check_items", > > Listening on IP address *, ports 1645/udp and 1646/udp, with proxy on > 1647/udp. > Ready to process requests. > rad_recv: Access-Request packet fr

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

Re: freeradius and mysql on solaris

2003-04-01 Thread Chris Brotsos
At 02:13 AM 4/1/2003, you wrote: i'm having problems compiling freeradius v0.8.1 on a solaris 9 machine with mysql support and any help would be greatly appreciated. here's some more details on the setup. solaris 9 (12/02) freeradius v0.8.1 mysql 3.23.53 (from sunfreeware.com) mysql base dir is at

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

Re: Encryption...

2003-04-01 Thread Artur Hecker
hi > When you use edit the clients list in Radius there is a key or > password "test123" per clients, what does this really do? you should perhaps simply download and read the current RADIUS RFC, would you? > I understand that it can provide a simple auth for the NASes, > but d

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

Unknown `--run' option in ./configure output

2003-04-01 Thread Christian Loos
Hi after I started ./configure --localstatedir=/var --sysconfdir=/etc I receive the error in the output about the missing file [..] creating src/include/autoconf.h configuring in libltdl running /bin/sh ./configure --localstatedir=/var --sysconfdir=/etc --enable-ltdl-install -- cache-file

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

freeRadiu, 802.1x and Cisco

2003-04-01 Thread Olivier PERROT
Hi all, I'am trying to setup authentication and automatic VLAN attribution between freeRadius box and a Cisco switch ... without success until now. The deal is to allow mobile users to be on the same VLAN even if they aren't using the same port and/or switch all over the campus. Authentication i

Re: radiusCheckItem and radiusReplyItem

2003-04-01 Thread Brian Leung
hi Kostas, the checkval module seems work. Thank you so much Regards, Brian - Original Message - From: "Kostas Kalevras" <[EMAIL PROTECTED]> To: "freeradius" <[EMAIL PROTECTED]> Sent: Monday, March 31, 2003 11:18 PM Subject: Re: radiusCheckItem and radiusReplyItem > On Mon, 31 Mar 2003

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik

Re: Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Christophe Boyanique
On Tue, Apr 01, 2003 at 09:01:56AM +0200, Mike Janssen wrote: > Subject: Mike Janssen/ZND/CSS is out of the office. > Date: Tue, 1 Apr 2003 09:01:56 +0200 I hope this is some kind of April Fools Day joke. Doubled mailing-list traffic during two weeks may drive someone insane... -- Christophe.

freeradius and mysql on solaris

2003-04-01 Thread bofh
i'm having problems compiling freeradius v0.8.1 on a solaris 9 machine with mysql support and any help would be greatly appreciated. here's some more details on the setup. solaris 9 (12/02) freeradius v0.8.1 mysql 3.23.53 (from sunfreeware.com) mysql base dir is at /usr/local/mysql with includes

Mike Janssen/ZND/CSS is out of the office.

2003-04-01 Thread Mike Janssen
I will be out of the office starting 01-04-2003 and will not return until 13-04-2003. I will respond to your message when I return. _ De informatie, verzonden met dit e-mailbericht, is uitsluitend bedoeld voor de geadresseerde. Gebruik