Re: can i set attribute after the proxy server authenticated the user information?

2002-12-23 Thread Alan DeKok
Huang Zhong [EMAIL PROTECTED] wrote: I added the following lines in the config file hints ... now, the result is: the customer's radius server successfully authenticated the request from freeradius server, but i lose the attributes added in the file hints. I'll bet money it's because you

can i set attribute after the proxy server authenticated the user information?

2002-12-22 Thread Huang Zhong
I've downloaded freeradius0.8.1 and installed it on a FreeBSD 4.4 pc. I added the following lines in the config file hints DEFAULT Suffix = @test1.vpdn, Strip-User-Name = No Hint = PPP, Service-Type = Framed-User, Framed-Protocol = PPP, cisco-avpair =

IPv6 + Proxy...

2002-12-20 Thread Tamer Demir
Hello, Is FreeRADIUS IPv6 compatible? And, after the authentication of the user I want to send (proxy) the authentication packets to another FreeRADIUS server, How can I do that? It is like proxying the packets to 2 other RADIUS server but one of them is its own. Regards, Tamer - List

Re: IPv6 + Proxy...

2002-12-20 Thread Alan DeKok
are welcome. And, after the authentication of the user I want to send (proxy) the authentication packets to another FreeRADIUS server, How can I do that? Why? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: IPv6 + Proxy...

2002-12-20 Thread Simon White
by using other small companies' NASes. And in order to solve the accounting conflict between the small companies the big company wants all the data about the authenticating users from all other small companies. Big company just will act as a referee. Is this somehow possible by using proxy option

Re: IPv6 + Proxy...

2002-12-20 Thread Tamer Demir
in an IPv6 Testbed to authenticate the users. And, after the authentication of the user I want to send (proxy) the authentication packets to another FreeRADIUS server, How can I do that? Why? I know it looks strange but, In an scenario like this: you are a big company and you have a contract

Re: IPv6 + Proxy...

2002-12-20 Thread Tamer Demir
possible by using proxy option in FreeRADIUS, if yes how? Either all your radius servers are proxies to the big company's radius server(s) or you use something like radrelay and just use the accounting information (which contains the detail you need) you don't need the actual packets that are sent

Re: IPv6 + Proxy...

2002-12-20 Thread Alan DeKok
to solve the accounting conflict between the small companies the big company wants all the data about the authenticating users from all other small companies. Big company just will act as a referee. Is this somehow possible by using proxy option in FreeRADIUS, if yes how? No. Use

Re: IPv6 + Proxy...

2002-12-20 Thread Simon White
companies. Big company just will act as a referee. Is this somehow possible by using proxy option in FreeRADIUS, if yes how? Either all your radius servers are proxies to the big company's radius server(s) or you use something like radrelay and just use the accounting information (which

Re: Proxy Config Using Auth Attributes

2002-12-10 Thread Chris Brotsos
At 05:42 PM 12/9/2002 -0500, you wrote: Is is possible to setup proxy radius not based so much on realms but based on Key/Value pairs in the authentication packets? For example, I have many resellers and I need to be able to proxy requests based on DNIS (CalledStationID) or even just the last 4

Proxy Config Using Auth Attributes

2002-12-09 Thread QCI Internet
Is is possible to setup proxy radius not based so much on realms but based on Key/Value pairs in the authentication packets? For example, I have many resellers and I need to be able to proxy requests based on DNIS (CalledStationID) or even just the last 4 digits of the DNIS. - List info

proxy configuration

2002-12-05 Thread maximo
Hi, everybody. I am trying to configure my radius server as proxy, but i have a dont know if it is possible write tacacs+ value in type option from proxy.conf file the, this beause we are in transition process and we need to do authentication any number users with tacacs+ and others ones

Re: proxy configuration

2002-12-05 Thread Alan DeKok
maximo [EMAIL PROTECTED] wrote: I am trying to configure my radius server as proxy, but i have a dont know if it is possible write tacacs+ value in type option from proxy.conf file the, this beause we are in transition process and we need to do authentication any number users with tacacs

Proxy configurations

2002-12-05 Thread troy white
I am new to cistron. How do i setup my sever to authenticate dial in users using command line. I use a PuTTY interface. Troy J. White C.E.O. D.A. JAZ Internet Technologies 727-321-8899 Powered by Verizon _ Sign up for FREE email from

Proxy Realms configuration

2002-12-02 Thread Mike Varley
, instead of the text files. The advantages are twofold: a unified repository for all my user data (ISP, IP Pools, local usernames) and the other benefit is I could add/remove realms w/o sending a SIGHUP to the radius proxy. Before I go and change the core components within the freeradius library

Re: Proxy Realms configuration

2002-12-02 Thread Alan DeKok
a SIGHUP to the radius proxy. That sounds reasonable. Before I go and change the core components within the freeradius library, has anyone else implemented this type of system before, and have a better solution? Can I get this kind of behaviour through modules? (ie, do a DB lookup, and add

Re: Proxy Realms configuration

2002-12-02 Thread Mike Varley
benefit is I could add/remove realms w/o sending a SIGHUP to the radius proxy. That sounds reasonable. Before I go and change the core components within the freeradius library, has anyone else implemented this type of system before, and have a better solution? Can I get this kind

Re: Proxy Realms configuration

2002-12-02 Thread Alan DeKok
Mike Varley [EMAIL PROTECTED] wrote: Faster and more efficient aswell. How often is proxy information going to change, really? And SIGHUPing FreeRADIUS is not a costly affair. If everything is going well, proxy information won't change that often. If you want to have multiple fail-over

accounting acknowledgement radius proxy

2002-11-29 Thread arise
hi guys, i have the following setup: cistron radius - forwarding server (proxy) freeradius - remote server for certain realms + mysql accounting i have thousands of users on the freeradius server which is proxied by cistron radius. prior to upgrading to the current 0.8 release from the aug. 29

TACACS/PROXY gateway

2002-11-26 Thread Ing. Carlos M. Martinez
to proxy a tacacs request to a radius server in the free/open source software world ? There are commercial products that do this, but they're out the question. regards, Carlos Ing. Carlos M. Martinez Network Administrator ADINET - ANTEL Uruguay

Re: TACACS/PROXY gateway

2002-11-26 Thread Alan DeKok
Ing. Carlos M. Martinez [EMAIL PROTECTED] wrote: i have a fairly large all-Cisco equipment and we use freeRadius for accounting and user authentication (we used to have cistron, we migrated to FR 0.3 a while ago) Upgrade, PLEASE upgrade. Is there any way to proxy a tacacs request

Fw: MySQL-Proxy-Exec-Program-Wait

2002-11-11 Thread Mike Dain
I didn't get any responses...so I'm trying again... See message below. - Mike - Original Message - From: Mike Dain [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Wednesday, November 06, 2002 1:12 PM Subject: MySQL-Proxy-Exec-Program-Wait I'm using my server for both local

Re: Fw: MySQL-Proxy-Exec-Program-Wait

2002-11-11 Thread Alan DeKok
Mike Dain [EMAIL PROTECTED] wrote: Now I'm trying to add in an Exec-Program-Wait script. I don't care if it only runs for proxy users or if it runs for everyone, I just need to add in that attribute/value (Exec-Program-Wait/scriptname) to everyone that logs in. Can someone tell me how to add

Re: Fw: MySQL-Proxy-Exec-Program-Wait

2002-11-11 Thread Mike Dain
, November 11, 2002 3:55 PM Subject: Re: Fw: MySQL-Proxy-Exec-Program-Wait Mike Dain [EMAIL PROTECTED] wrote: Now I'm trying to add in an Exec-Program-Wait script. I don't care if it only runs for proxy users or if it runs for everyone, I just need to add in that attribute/value (Exec-Program

Re: Fw: MySQL-Proxy-Exec-Program-Wait

2002-11-11 Thread Alan DeKok
Mike Dain [EMAIL PROTECTED] wrote: I've tried adding: DEFAULT Exec-Program-Wait = /shell/example to the users file. sigh What's the point of writing documentation (what little there is), if it's not going to be read? What's the point of adding debugging, warning, and error

MySQL-Proxy-Exec-Program-Wait

2002-11-06 Thread Mike Dain
I'm using my server for both local authentication and proxy to another server. I'm using MySQL for authentication/accounting. I have all of the realms/secrets/etc. setup in the proxy.conf file, and everything seems to work ok. Accounting shows up in the radacct table for all of it. Now I'm

proxy (preprocess?)

2002-11-04 Thread Mike Dain
I'm trying to setup my server to only allow proxying if a resellers account balance is good. Example: User connects to NAS NAS sends user/pass to my radius server My radius server checks the account balance of reseller if reseller account balance 0 send request to reseller radius

Re: proxy (preprocess?)

2002-11-04 Thread Kevin Bonner
Has anyone attempted this before? I'm using MySQL Freeradius. After looking at lots of config files, etc. I think that a preprocess addition might work. Does anyone know if the Realms/NAS tables work now? I could also write a script to check account balances and remove the Realms entry

Re: proxy (preprocess?)

2002-11-04 Thread Mike Dain
Thanks! It looks like that should work. I'm going to write some scripts up and see how it goes. I'll let everyone know the results. - Mike - Original Message - From: Kevin Bonner [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Monday, November 04, 2002 3:26 PM Subject: Re: proxy

Proxy Attributes

2002-10-22 Thread Darren Nay
Hey All, This may be a stupid question, but still, one to which I don't know the answer. :) If so, please forgive my ingnorance. I am trying to find a way to strip attributes sent from the NAS in the proxy authentication request in freeradius. I am able to modify the attributes that are sent

Proxy Radius

2002-10-09 Thread Mehdi Roomi
doesn't exist in FreeRadius, I want the user to be redirected to Previous nasty NT accounting server. Freeradius proxy always redirects the requests to NT accounting server before searching itself for this username! I want FreeRadius First search itself and if the username doesn't exist

Re: Proxy Radius

2002-10-09 Thread 3APA3A
accounting server. MR Freeradius proxy always redirects the requests to NT accounting server MR before searching itself for this username! MR I want FreeRadius First search itself and if the username doesn't exist , It MR redirect it to Next accounting Server. MR Additional Info: MR there is no seprator

Re: Proxy Radius

2002-10-09 Thread Mehdi Roomi
in FreeRadius, I want the user to be redirected to Previous nasty NT MR accounting server. MR Freeradius proxy always redirects the requests to NT accounting server MR before searching itself for this username! MR I want FreeRadius First search itself and if the username doesn't exist , It MR redirect

Re[2]: Proxy Radius

2002-10-09 Thread 3APA3A
and if the accounts doesn't MR exist in FreeRadius, I want the user to be redirected to Previous nasty NT MR accounting server. MR Freeradius proxy always redirects the requests to NT accounting server MR before searching itself for this username! MR I want FreeRadius First search itself

Re: Fw: Hints Proxy

2002-10-01 Thread angelos karageorgiou
27, 2002 2:57 PMSubject: Hints Proxy Hello all,I haven't used hints much in the past but I am wondering if it might bepossible to use them for proxying certain requests to a secondary radius.Or if there is possibly another way (besides hints) that this could beaccomplished.For example. We ha

Fw: Hints Proxy

2002-09-30 Thread Darren Nay
: Hints Proxy Hello all, I haven't used hints much in the past but I am wondering if it might be possible to use them for proxying certain requests to a secondary radius. Or if there is possibly another way (besides hints) that this could be accomplished. For example. We have a realm hosted

Re: Fw: Hints Proxy

2002-09-30 Thread Franklin Trumpy
| On Mon, 30 Sep 2002, Darren Nay wrote: Date: Mon, 30 Sep 2002 10:59:28 -0600 From: Darren Nay [EMAIL PROTECTED] Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Fw: Hints Proxy Can anyone tell me if this is a possibility?? Using hints, or otherwise. (refer to the forwarded

Re: Fw: Hints Proxy

2002-09-30 Thread Darren Nay
Franklin, Thanks for the suggestion. This just might work. :) I'll give it a try. Darren - Original Message - From: Franklin Trumpy [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Monday, September 30, 2002 12:44 PM Subject: Re: Fw: Hints Proxy Darren, I'm not exactly certain

Hints Proxy

2002-09-27 Thread Darren Nay
, and would like to proxy some of the requests for that realm to another radius, but have some still authenticating on the primary radius.. say for example, all of the users with a prxy- prefix (ie. [EMAIL PROTECTED]) would be sent to the secondary radius for authentication. A username without

Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Brandon Lehmann
Hi List, We are currently trying to get FreeRadius 0.7.1 to work with our VopRadius server. This is how it flows. Our users dial into the Qwest Network. The Qwest NAS sends a request to Qwest's radius proxy servers - Qwest proxy servers send a request to one of our proxy servers

Re: Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Chris Parker
At 09:51 AM 9/20/2002 -0400, Brandon Lehmann wrote: Hi List, We are currently trying to get FreeRadius 0.7.1 to work with our VopRadius server. This is how it flows. Our users dial into the Qwest Network. The Qwest NAS sends a request to Qwest's radius proxy servers - Qwest

Re: Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Alan DeKok
to be in the 'clients' file are the machines which send packets to the server. The only reason that this would happen is because our proxy server is NOT sending back a Proxy-State [33] attribute. How can I make sure that FreeRadius sends this attr back? Look at the output of debugging mode? Also, try

Re: Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Franklin Trumpy
On Fri, 20 Sep 2002, Brandon Lehmann wrote: The only reason that this would happen is because our proxy server is NOT sending back a Proxy-State [33] attribute. How can I make sure that FreeRadius sends this attr back? If I can't get it to do this, can someone please advise a software

Re: Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Chris Parker
At 01:31 PM 9/20/2002 -0500, Franklin Trumpy wrote: On Fri, 20 Sep 2002, Brandon Lehmann wrote: The only reason that this would happen is because our proxy server is NOT sending back a Proxy-State [33] attribute. How can I make sure that FreeRadius sends this attr back? If I can't get

RE: Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Brandon Lehmann
rlm_realm: Proxying request from user test to realm DEFAULT rlm_realm: Adding Realm = DEFAULT rlm_realm: Preparing to proxy accounting request to realm DEFAULT modcall[preacct]: module suffix returns ok modcall: group preacct returns ok modcall: entering group accounting radius_xlat: '/usr/local

RE: Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Chris Parker
-Ascend-Disconnect-Cause = 43 X-Ascend-Connect-Progress = 101 X-Ascend-Data-Rate = 26400 X-Ascend-PreSession-Time = 27 X-Ascend-Xmit-Rate = 38000 Qwest isn't sending you a Proxy-State attribute. Kindly ask them how you are supposed to return one if they aren't

RE: Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Brandon Lehmann
43420 800-644-6638 [EMAIL PROTECTED] www.nwonline.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Chris Parker Sent: Friday, September 20, 2002 3:36 PM To: [EMAIL PROTECTED] Subject: RE: Question regarding Proxy-State [33] Attribute At 03

RE: Question regarding Proxy-State [33] Attribute

2002-09-20 Thread Brandon Lehmann
; Stephen Goff Subject: RE: Worldteq - Status of Realm Activation: IP Change Brandon, Please try again. Your realm was pointing (test server only) to another company that previously owned this realm... Proxy-state will not be sent in your dialtests. Proxy-state will be implemented with our

Problems to use as proxy

2002-09-05 Thread Wolfgang Bremer
Hi, I'm trying to configure the freeradius (Version 0.5) to proxy requests to a remote server. I'm getting a message 'No request found for proxy reply from server XXX' Has anybody got the same problem? Here is some debug output: Server#/usr/local/sbin/radiusd -x Starting - reading

Re: Problems to use as proxy

2002-09-05 Thread Alan DeKok
Wolfgang Bremer [EMAIL PROTECTED] wrote: I'm trying to configure the freeradius (Version 0.5) to proxy requests to a remote server. Please don't post problems or bug reports with old versions of the server. There are MANY bugs fixed in newer releases, see: http

Re: [FreeRadius] Random port for proxy requests?

2002-08-26 Thread Chris Parker
are not trying to proxy the requests from your systems to anywhere else. If you want to proxy from your systems, the situation becomes more complex as you need to keep some sort of state so that proxy replies are returned to the system that originally sent them. Or you need to start playing with different

Re: [FreeRadius] Re: [FreeRadius] Re: Random port for proxy requests?

2002-08-25 Thread Xavier Mertens
It's LVS (http://www.linuxvirtualserver.org) What do you recommand to load-balance RADIUS traffic? Any suggestion? Xavier -- http://www.rootshell.be echo '16i[q]sa[ln0=aln100%Pln100/snlbx]sb20293A2058554E494Csnlbxq'|dc On Fri, 23 Aug 2002, Alan DeKok wrote: Xavier Mertens [EMAIL PROTECTED]

Re: [FreeRadius] Re: [FreeRadius] Re: Random port for proxy requests?

2002-08-25 Thread Alan DeKok
Xavier Mertens [EMAIL PROTECTED] wrote: It's LVS (http://www.linuxvirtualserver.org) What do you recommand to load-balance RADIUS traffic? Any suggestion? No, sorry. I would probably recommend using a custom version of FreeRADIUS, as it knows about the RADIUS protocol. The LVS

Re: [FreeRadius] Random port for proxy requests?

2002-08-25 Thread Tabor J. Wells
On Sun, Aug 25, 2002 at 12:09:10PM +0200, Xavier Mertens [EMAIL PROTECTED] is thought to have said: It's LVS (http://www.linuxvirtualserver.org) What do you recommand to load-balance RADIUS traffic? Any suggestion? I've used Alteon products (now owned by Nortel) to load balance my RADIUS

Random port for proxy requests?

2002-08-22 Thread Xavier
Hi, I just installed a FreeRadius, works fine! Seems to be a very strong implementation of the RADIUS protocol. But, I already have a question. :) My radiusd is used as a proxy and send request to a load-balancer (LVS). But all packets are forwarded with the same source port (8002) and the LVS

Freeradius proxy server configuration

2002-08-14 Thread Zhang, Defu
Title: Freeradius proxy server configuration I set up two freeradius servers to test the proxy feature. In one machine (A), I installed radius server and a radius client testing program. In another machine (B), I installed radius server only. I configured server A and B by editing

Re: accounting-start proxy error

2002-08-13 Thread Josh . Howlett
= RADIUS User-Name = x Proxy-State = 120 Freeradius gets the following back from MS IAS: rad_recv: Accouting-Response packet from xxx.xxx.xxx.xxx:, id=22, length=25 Proxy-State = 0x313230 And sends it on to the NAS: Sending Accouting-Response of id 120

Re: accounting-start proxy error

2002-08-11 Thread Alan DeKok
[EMAIL PROTECTED] wrote: It works fine for authentication request/accept and accounting-stop, but my NAS complains about the accounting-start messages: Then it's most likely a problem with the attributes in the accounting start packet. WARNING: Identifier does not match - ignoring

How to Configure Proxy server

2002-07-29 Thread Sachin Jain
Hi, I want to know how to configure a proxy server. My requests come from one host to a radius server which I want to forward to another server. I added the entry for the host in proxy.conf specifying the realm as xx.yy.com and gave the address of the remote server as auth-host. However my

Re: proxy accounting

2002-07-25 Thread Alan DeKok
Igor Chen [EMAIL PROTECTED] wrote: I tried to configure proxying accounting requests to another radius server (NAS --A--B), but it just doesn't send anything. Autorization and authetification works perfectly. Debugging mode says... ? Alan DeKok. - List info/subscribe/unsubscribe? See

Proxy problem

2002-07-24 Thread Ionut Muntean
Hi, Does anyone know what is wrong when you receive the following message? Proxy: No request found for proxy reply from server - ID X 10x, -- Ionut Muntean - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

ignore proxy from certain IP

2002-07-18 Thread Kevin Bonner
I've read docs mailing lists, and played with a test server, but I still cannot figure this out. How can I tell FR to not proxy an accounting packet if it came from a specific IP? I have added an entry into proxy.conf where the accthost is LOCAL, and setup an entry in acct_users to proxy

accounting proxy question

2002-07-15 Thread Kevin Bonner
I'm trying to get freeradius 0.6 to bypass the proxy settings and handle the packet locally if an accounting packet comes from a certain IP. Here's what I've got so far, but it still tries to proxy to the NULL realm accthost when I send an accounting packet. Any help would be appreciated

Re: FreeRADIUS Proxy and MS IAS

2002-07-11 Thread Dimitar Peikov
be bugs in tunnelling code, which was fixed in 0.6. If you're running an earlier version, you should upgrade. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Unfortunately I made proxy request but only PAP authentication succeed. When using CHAP

Re: FreeRADIUS Proxy and MS IAS

2002-07-11 Thread Alan DeKok
Dimitar Peikov [EMAIL PROTECTED] wrote: Unfortunately I made proxy request but only PAP authentication succeed. When using CHAP complain is about bad password! Read the FAQ on CHAP versus PAP. The same issues apply to IAS. Alan DeKok. - List info/subscribe/unsubscribe? See http

FreeRADIUS Proxy and MS IAS

2002-07-10 Thread Dimitar Peikov
Hi, Did someone tryed to proxy to MS IAS on 2K Server? I've got bad success about that and need some help, or example on this. If I point directly from NAS to either FreeRADIUS ot MS IAS authentication goes alright but when try to proxy MS IAS via FreeRADIUS I get errors on MS Event viewer

Re: FreeRADIUS Proxy and MS IAS

2002-07-10 Thread Alan DeKok
Dimitar Peikov [EMAIL PROTECTED] wrote: If I point directly from NAS to either FreeRADIUS ot MS IAS authentication goes alright but when try to proxy MS IAS via FreeRADIUS I get errors on MS Event viewer. Which are...? Alan DeKok. - List info/subscribe/unsubscribe? See http

Re: FreeRADIUS Proxy and MS IAS

2002-07-10 Thread Dimitar Peikov
On Wed, 10 Jul 2002 12:00:18 -0400 Alan DeKok [EMAIL PROTECTED] wrote: Dimitar Peikov [EMAIL PROTECTED] wrote: If I point directly from NAS to either FreeRADIUS ot MS IAS authentication goes alright but when try to proxy MS IAS via FreeRADIUS I get errors on MS Event viewer. Which

Re: FreeRADIUS Proxy and MS IAS

2002-07-10 Thread Alan DeKok
Dimitar Peikov [EMAIL PROTECTED] wrote: In this case NAS is MS RAS on 2k Server. This is explanation of error event 'A malformed request was received from= client . The data is the packet.' OK, it may be bugs in tunnelling code, which was fixed in 0.6. If you're running an earlier

accounting on a proxy

2002-07-02 Thread Josh . Howlett
Hi, Is it possible to ocnfigure a Freeradius proxy to log details of accounting packets that it is proxying? thanks, josh. Josh Howlett, Networking and Digital Communications Group, Information Systems Computing, University of Bristol. email: [EMAIL PROTECTED] | phone: +44 (0)117 928 7850

Re: accounting on a proxy

2002-07-02 Thread Chris Parker
At 10:59 AM 7/2/2002 +0100, [EMAIL PROTECTED] wrote: Hi, Is it possible to ocnfigure a Freeradius proxy to log details of accounting packets that it is proxying? Yes. Simply add the appropriate module to the 'accounting' block of the server's config. -Chris

authorization after proxy access-accept (lastest CVS)

2002-06-27 Thread Bobi
Hi list, I'm wondering how sql authorization pass to be ignored when my proxy access-request is accepted. Now after successfull proxy accept my sql authorization module tries to authorize the user once more: rad_recv: Access-Accept packet from host xx.xx.xx.xx:1812, id=12, length=63

Proxy Authentication Override

2002-06-27 Thread Eric Dean
We have a proxied customer that uses DNIS as part of their authentication sequence; however Qwest and UUNET do not supply DNIS as part of their tests. Is there a way to create a user [EMAIL PROTECTED] and have him locally authenticate against a users file while allowing everything else to proxy

Re: Proxy radius based on dialled number

2002-06-26 Thread James Taylor
or anyone have any idea how I can set a realm for an accounting packet by the Called-Station-Id? Thanks, James. On Wed, 19 Jun 2002 21:53, Chris Parker wrote: At 01:31 PM 6/19/2002 +0800, James Taylor wrote: Hi all, I wish to set up freeradius to act as a radius proxy but instead of using

Re: Proxy radius based on dialled number

2002-06-26 Thread Alan DeKok
James Taylor [EMAIL PROTECTED] wrote: However now I have a problem with accounting packets. They seem to always be proxied off to the default realm no matter what. I guess this is because the users file is not processed for accounting packets. Do you or anyone have any idea how I can set

Re: Proxy radius based on dialled number

2002-06-26 Thread Chris Parker
is not processed for accounting packets. Do you or anyone have any idea how I can set a realm for an accounting packet by the Called-Station-Id? There is an equivalent to the 'users' file used for accounting that is called 'acct_users'. If you add the same Proxy-To-Realm configs to that you should get

Re: Proxy radius based on dialled number

2002-06-26 Thread James Taylor
that is called 'acct_users'. If you add the same Proxy-To-Realm configs to that you should get the behaviour you are looking for. -Chris -- \\\|||/// \ StarNet Inc. \ Chris Parker \ ~ ~ / \ WX *is* Wireless!\ Director, Engineering

Can proxy query multiple

2002-06-21 Thread Shawn Barnhart
Can freeradius proxy search multiple radius servers? I'd like to be able to have the NAS access the proxy and have the proxy access more than one radius server to authenticate the user without the use of realms or other identifiers supplied by the end user for identification. It's not clear

Re: a strange proxy problem

2002-06-18 Thread Alan DeKok
Kenneth Lee [EMAIL PROTECTED] wrote: oh, I have seen from the proxy radius with debug mode, sending a MTU=576 to RAS, however, I have not set any value for MTU in my configuration, why would this happen? I don't know. is it the source of my problem? thanks very much! Probably, yes

Proxy radius based on dialled number

2002-06-18 Thread James Taylor
Hi all, I wish to set up freeradius to act as a radius proxy but instead of using the user@domain style username for different realms I wish to use the dialled number (Called-Station-Id) to determine which radius server the request is sent to. So two people on two different systems can use

RE: Proxy Client Source IP and Realm

2002-06-14 Thread Gelson Dias Santos
Title: RE: Proxy Client Source IP and Realm Hello people, Just found this message on the archive, and I think I need something similar: You want to do: DEFAULT Called-Station-Id == 1234, Proxy-To-Realm := company.com Fall-Through = Yes DEFAULT Called-Station-Id == 2345, Proxy

Re: Proxy Client Source IP and Realm

2002-06-14 Thread Alan DeKok
Gelson Dias Santos [EMAIL PROTECTED] wrote: If I do the above, will the realm information be changed somehow? I mean, if a dial-up client connects to station 1234 and logs in as [EMAIL PROTECTED], will freeradius proxy it to the servers defined for company.com, but without changing

Proxy-To-Realm and accounting{}

2002-06-13 Thread Franklin Trumpy
, the preacct{} block is called, followed by the accounting{} block. accounting{} is skipped if preacct{} sets Proxy-To-Realm. Unless I'm mistaken, rlm_realm will add a Proxy-To-Realm attribute during preacct{}, which, if doc/module_interfaces is correct, should prevent accounting{} from handling

Re: Proxy Value 33

2002-06-12 Thread Enesha Fairluck
the problem: dballew@radtest02:/export/home/dballew echo [EMAIL PROTECTED], Password=abc, NAS-Port=10, NAS-Identifier=RadTest, Proxy-State=0xab00ef | /etc/radclient/bin/radclient -r 1 -t 5 -d /etc/radclient/etc/raddb 64.218.97.97:1645 01 cosi71sunfl radclient: no response from server The request comes

RE: Proxy Value 33

2002-06-12 Thread Eric Dean
This is a timedout authentication...not an issue with attribute 33. If you are seeing the requests but they aren't seeing the responses then you have a network problem...often attributed to a radius proxy having multiple IP addresses. Does your server have more than one IP address? If so

Re: Proxy Value 33

2002-06-12 Thread Chris Parker
to them, This is what they sent me to prove the problem: dballew@radtest02:/export/home/dballew echo [EMAIL PROTECTED], Password=abc, NAS-Port=10, NAS-Identifier=RadTest, Proxy-State=0xab00ef | /etc/radclient/bin/radclient -r 1 -t 5 -d /etc/radclient/etc/raddb 64.218.97.97:1645 01 cosi71sunfl

Re: Proxy Value 33

2002-06-12 Thread Enesha Fairluck
This is what I see when I have it in debug: Shouldn't I see that Proxy-State in the Access-Request? Waking up in 6 seconds... rad_recv: Access-Request packet from host 63.150.70.42:55330, id=250, length=151 User-Name = tbullock CHAP-Password

Re: Proxy Value 33

2002-06-12 Thread Alan DeKok
Enesha Fairluck [EMAIL PROTECTED] wrote: This is what I see when I have it in debug: Shouldn't I see that Proxy-State in the Access-Request? If the NAS sends one, yes. If the NAS doesn't send one, no. The issue from your earlier emails seemed to be that the *reply* didn't have a Proxy

Re: Proxy Value 33

2002-06-12 Thread Enesha Fairluck
: Re: Proxy Value 33 Enesha Fairluck [EMAIL PROTECTED] wrote: This is what I see when I have it in debug: Shouldn't I see that Proxy-State in the Access-Request? If the NAS sends one, yes. If the NAS doesn't send one, no. The issue from your earlier emails seemed to be that the *reply

Re: Proxy Value 33

2002-06-11 Thread Chris Parker
At 10:42 AM 6/11/2002 -0400, Enesha Fairluck wrote: Hey guys:) I have another problem maybe some of you can help me with. I just got off the phone with the people at our reseller...They say that when we send the accept, reject or accounting packets, we are supposed to be sending proxy

Re: Proxy Value 33

2002-06-11 Thread Enesha Fairluck
Thank you for all your help! :) --E - Original Message - From: Chris Parker [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Tuesday, June 11, 2002 10:49 AM Subject: Re: Proxy Value 33 At 10:42 AM 6/11/2002 -0400, Enesha Fairluck wrote: Hey guys:) I have another problem maybe

RE: Proxy Value 33

2002-06-11 Thread Eric Dean
Been there..run the latest CVS -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Enesha Fairluck Sent: Tuesday, June 11, 2002 10:42 AM To: [EMAIL PROTECTED] Subject: Proxy Value 33 Hey guys:) I have another problem maybe some of you can

RE: Proxy Client Source IP and Realm

2002-06-10 Thread Chris Parker
At 01:32 PM 6/8/2002 -0400, Eric Dean wrote: I got no bytes on this and I already google'd the hell out of the subject matter...any ideas? http://www.mail-archive.com/freeradius-users@lists.cistron.nl/msg05238.html -Chris -- \\\|||/// \ StarNet Inc. \ Chris Parker

RE: Proxy Client Source IP and Realm

2002-06-10 Thread Chris Parker
want to do: DEFAULT Called-Station-Id == 1234, Proxy-To-Realm := company.com Fall-Through = Yes DEFAULT Called-Station-Id == 2345, Proxy-To-Realm := else.net Fall-Through = Yes -Chris -- \\\|||/// \ StarNet Inc. \ Chris Parker

RE: Proxy Client Source IP and Realm

2002-06-08 Thread Eric Dean
I got no bytes on this and I already google'd the hell out of the subject matter...any ideas? -Original Message-From: Eric Dean [mailto:[EMAIL PROTECTED]]Sent: Friday, June 07, 2002 3:40 PMTo: [EMAIL PROTECTED]Subject: Proxy Client Source IP and Realm The features page

Proxy Client Source IP and Realm

2002-06-07 Thread Eric Dean
The features page says that freeradius can "Proxy or replicate the request to another RADIUS server, based on any criteria, not just '@realm'." http://www.freeradius.org/features.html Can someone shoot me an example whereby I can proxy using theClient IP address of an upst

Proxy-To-Realm FreeRadius 0.5

2002-06-06 Thread agp933
Is there any detail doc about how to config Proxy-To-Realm ? I think the doc proxy is not enough to understand everying relate to radius proxy funtion in FreeRadius. May I know How to config my FR 0.5 act as check users file before do proxy? How to config suffix or prefix proxy

Re: Removal of Proxy-State

2002-06-05 Thread Chris A. Kalin
Why did this fix get removed from the June 4th CVS snapshot? auth.c is version 1.103 in those snapshots. Chris - Original Message - From: Alan DeKok [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Friday, May 31, 2002 12:06 PM Subject: Re: Removal of Proxy-State eric [EMAIL PROTECTED

Re: Removal of Proxy-State

2002-06-05 Thread Alan DeKok
Chris A. Kalin [EMAIL PROTECTED] wrote: Why did this fix get removed from the June 4th CVS snapshot? auth.c is version 1.103 in those snapshots. Uhh... weird. I guess it wasn't committed. I'll do so now. Alan DeKok. - List info/subscribe/unsubscribe? See

Proxy requests on criteria other than realms?

2002-06-05 Thread steve bernacki
Greetings: I'm looking to be able to proxy RADIUS requests based on criteria OTHER than a 'realm' in a username. Specifically, I'd like to proxy /some/ requests based on the NAS-IP-Address. Is this possible to do with the latest version of FreeRADIUS, or is it at least possible to write

<    1   2   3   4   5   >