Radius Guide

2004-09-21 Thread von dan
Hello, First time freeradius user.Any link to get radius start up and running. Dan Do you Yahoo!?vote.yahoo.com - Register online to vote today!

RE : Fail over mysql backend

2004-09-21 Thread EROS
I've tried to let the sql {} but it said rlm_sql_sql is not a valid sql driver or something like that. -Message d'origine- De : [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] De la part de Alan DeKok Envoyé : lundi 20 septembre 2004 21:11 À : [EMAIL PROTECTED] Objet : Re: RE : Fail over

Dialup Admin accounting issues.

2004-09-21 Thread Shannon Sariman
Hi All, I'm using FreeRadius-0.9.3 with MySQL and Dialup Admin configured on a Linux Red Hat 9.0 machine. How can I adjust the Subscription Analysis tables so that the daily limit hours reflect different User Group settings. For example, I have two groups, one called Dynamic and the other called

Expiration module

2004-09-21 Thread Van Deuren Joris
Title: Expiration module Hi, I would like to do the following: Using the unix shadow file for authentication. If a user password will expire send a message to the console telling him that he must change his password. If the user password has expired send a message to the console that his

Re: wrong 'statistic' in dialupadmin interface

2004-09-21 Thread Kostas Kalevras
On Tue, 21 Sep 2004, Flo4000 wrote: The SQL-String is OK! I get the result from sum(acctoctets). This seems good. But a user can not download 4344.00 MBs in 7,44 Minutes using a 56k Modem! This was my question! So check out the corresponding rows in the acounting table, any detail file you

Re: Dialup Admin accounting issues.

2004-09-21 Thread Kostas Kalevras
On Tue, 21 Sep 2004, Shannon Sariman wrote: Hi All, I'm using FreeRadius-0.9.3 with MySQL and Dialup Admin configured on a Linux Red Hat 9.0 machine. How can I adjust the Subscription Analysis tables so that the daily limit hours reflect different User Group settings. For example, I have

Re: Expiration module

2004-09-21 Thread Kostas Kalevras
On Tue, 21 Sep 2004, Van Deuren Joris wrote: Hi, I would like to do the following: Using the unix shadow file for authentication. If a user password will expire send a message to the console telling him that he must change his password. If the user password has expired send a message to

Problem with eap-tls, eap-peap

2004-09-21 Thread Guus Houtzager - Luna.nl
Hi, I'm trying to get eap-tls and eap-peap to work so I can use wpa on my access point and client, but I'm getting this error when I try to authenticate: /usr/sbin/freeradius: relocation error: /usr/lib/freeradius/rlm_eap_peap-1.0.0.so: undefined symbol: eaptls_process I'm running this on a

Re: another error in logs

2004-09-21 Thread Edgars
Alan, there is nothing wrong in debug mode, everythings goes flawesly.But in radius logs there are a plenty of these. Approximately every 10 seconds: Tue Sep 21 15:02:34 2004 : Auth: Login OK: [edgars/edgars] (from client edgara_tests port 1483 cli 1.1.1.2) Tue Sep 21 15:03:09 2004 : Error:

please help with this

2004-09-21 Thread jassim El-mansori
hi guys I'm using Freeradius as an authenticator point that a user has to authenticate against it and it works just like charm i need that user to browse the Internet i believe i can make use of SQUID I'm wondering if there is any other kind of application that does the same thing as SQUID

Re: Problem with eap-tls, eap-peap

2004-09-21 Thread Alan DeKok
Guus Houtzager - Luna.nl [EMAIL PROTECTED] wrote: I'm trying to get eap-tls and eap-peap to work so I can use wpa on my access point and client, but I'm getting this error when I try to authenticate: /usr/sbin/freeradius: relocation error: /usr/lib/freeradius/rlm_eap_peap-1.0.0.so: undefined

Re: gateway IP address

2004-09-21 Thread Alan DeKok
Milver S. Nisay [EMAIL PROTECTED] wrote: would it be possible for freeradius to specify the gateway IP address , for the dialup clients (after authenticating) ? http://www.freeradius.org/rfc/attributes.html Look for the word route Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Reg freeradius support with WPA

2004-09-21 Thread Alan DeKok
Phani Kumar [EMAIL PROTECTED] wrote: Can anyone suggest me how to reduce the authencation time? Run it in debug mode to see when it slows down, and where. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: another error in logs

2004-09-21 Thread Alan DeKok
Edgars [EMAIL PROTECTED] wrote: there is nothing wrong in debug mode, everythings goes flawesly. sigh That's not the point. The question I asked was: Is it *slow*. The response of the server should be nearly instantaneous, even in debugging mode. If you see pauses in the debug messages,

Re: Authenticating but no access

2004-09-21 Thread Alan DeKok
Saunders, Shawn [EMAIL PROTECTED] wrote: I have Freeradius 1.0 port on FreeBSD 4.10. I'm using it to authenticate our VPN connections from a PIX 525. The radius server is located inside of our internal network, and it is authenticating (per the logs) fine, Debug mode will show you more

Re: Problem with eap-tls, eap-peap

2004-09-21 Thread Guus Houtzager - Luna.nl
On Tue, 2004-09-21 at 16:24, Alan DeKok wrote: Guus Houtzager - Luna.nl [EMAIL PROTECTED] wrote: I'm trying to get eap-tls and eap-peap to work so I can use wpa on my access point and client, but I'm getting this error when I try to authenticate: /usr/sbin/freeradius: relocation error:

RE: VPN to PIX Authenticating but no access

2004-09-21 Thread Michael Markstaller
I can only tell about the VPN3000 and IOS ezvpn but it should be similar: The only thing that is needed is an appropriate services type (006) and Framed-Routing=Listen. PIX is nasty sometimes, try with service-type Administrative first and then lock down further. But when the connection succeeds,

RE: Multiple Accounting Stop packet and rlm_sql (on Mysql)

2004-09-21 Thread Michael Markstaller
and a second thing, if you have multiple radius-servers running remove Client-IP from rlm_unique so that AcctUniqueId is consitent over the machines. but I just made AcctUniqueId a primary key in the DB, works also for me.. Michael -Original Message- From: [EMAIL PROTECTED]

Re: Problem with eap-tls, eap-peap

2004-09-21 Thread Alan DeKok
Guus Houtzager - Luna.nl [EMAIL PROTECTED] wrote: Is the rlm_eap_tls module on your system? This is with freeradius 1.0.1, exact same relocation error. At this point, I'd say to do: $ ./configure --disable-shared Alan DeKok. - List info/subscribe/unsubscribe? See

group attributes not in access-accept

2004-09-21 Thread Scott A. H. Phillips
Hi all, Recently set up FreeRADIUS 1.0.0 with MySQL. The server auths correctly but the reply and check items from group memberships are not returned with the Access-Accept packet. In fact, no attribute-value pairs are returned at all, just a vanilla Access-Accept. What is required for check

ip pools question

2004-09-21 Thread Evren Yurtesen
Hello, I want to use the freeradius ip pools. I just wonder something though ever ip pool name I define should be included in the accounting and post-auth sections? Its kind of confusing, whats the point of defining the Pool-Name attribute in users file and then define the same name in

freeradius WPA support

2004-09-21 Thread pkumar
Hi, I have configured freeradius with WPA support using Redhat9.1 Using Windowss Xp machine i could successfully authenticate. The problem is that it takes nearly 5-6 minutes to authenticate. Can anyone suggest me how to reduce the authencation time? Phani - List

Re: ip pools question

2004-09-21 Thread Paul Hampson
On Wed, Sep 22, 2004 at 04:20:23AM -0700, Evren Yurtesen wrote: Hello, I want to use the freeradius ip pools. I just wonder something though ever ip pool name I define should be included in the accounting and post-auth sections? Its kind of confusing, whats the point of defining the

Re: VPN to PIX Authenticating but no access

2004-09-21 Thread wang hao
i user pix 515e and user vpn client is good .this my config : aaa-server 1.1.1.1 protocol radius aaa-server 1.1.1.1 (inside) host radius cisco timeout 10 crypto map outside_map client authentication 1.1.1.1 On Tue, 21 Sep 2004 18:55:22 +0200, Michael Markstaller [EMAIL PROTECTED] wrote:

Re: Problem with eap-tls, eap-peap

2004-09-21 Thread wang hao
chown -R root:root ./freeradius-1.0.0 cd freeradius-1.0.0 ./configure \ --prefix=/usr/local/radius \ --with-openssl-includes=/usr/local/ssl/include \ --with-openssl-libraries=/usr/local/ssl/lib \ --without-rlm_krb5 make make install this runing redhat linux AS3 On Tue, 21 Sep 2004 09:54:07