How to describe Huntgroup Setting?

2005-02-24 Thread Masaru Yoshihama
Hi all. I have Trouble with Huntgroup Setting and report this ML few month ago. It probles can't solve yet, So I Try to test with new FreeRadius 1.0.2 and Report again with very simple construction. Of cousce, I already setup radiusd.conf/clients.conf and another necessary configuration. But

freeradius 1.0.2 + callback attributes

2005-02-24 Thread Victor M. Polukcht
Good day, freeradius-users. I have username sended to me as '[EMAIL PROTECTED]' How can i strip this callback_number before authentification, and send it as lcp:Callback-number attribute to Cisco NAS ? Or is there any other way to realize the callback function? Clients - are Microsoft Windows

Re: How to describe Huntgroup Setting?

2005-02-24 Thread Masaru Yoshihama
Hi Mitchell, Thank you for your reply. A NAS-IP-Address can only belong to one huntgroup. So 127.0.0.1 and 192.168.1.1 will only ever match the class1 huntgroup. This is essentially what huntgroups are for...to divide your NAS's into groups. According to the your advice, I can define below

Re: Bare Minimum Accounting Required

2005-02-24 Thread Peter Kolbe
Figured out need username and Nas-Port P - Original Message - From: Peter Kolbe To: freeradius-users@lists.freeradius.org Sent: Thursday, February 24, 2005 9:29 AM Subject: Bare Minimum Accounting Required Hi I am designing a perl script to read

RE: SQL Query to get total bandwidth used per user per month.

2005-02-24 Thread Hyperlink Admin
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Graeme Lee Sent: 24 February 2005 02:52 AM To: freeradius-users@lists.freeradius.org Subject: Re: SQL Query to get total bandwidth used per user per month. Hyperlink Admin wrote: Hi Guys, Ok, what I

Re: TTLS + PAP in LDAP for freeradius

2005-02-24 Thread Justin Guidroz
TTLS + PAP has worked for me out of the box with FreeRADIUS. The only changes I have made to the EAP settings is to point FreeRADIUS to my server certificates. The server does the rest. Justin On Thu, 24 Feb 2005 08:18:48 +0100, Rok Papez [EMAIL PROTECTED] wrote: Hello Chan Min Wai. Dne

Logging accounting data to MYSql

2005-02-24 Thread Alfred H. Dahl
Hello all, our PPPoE-servers log accounting data to the RADIUS-server, which in turn is stored in a mysql-database. The field in the database is int(12) - but data logged to the database is never larger than an unsigned_int_32 (2147483647/7FFF) If this is a limitation in the RADIUS-server,

Re: any check item available while doing EAP/TLS?

2005-02-24 Thread Dustin Doris
Hi, Dustin You are absolutely right. There are no matched profile in /etc/raddb/users file after NAS-IP-Address changed to 10.1.3.5. In my case, freeradius let user in. It solve after I add the following DEFAULT profile to /etc/raddb/users file. DEFAULT Auth-Type := Reject I

Re: freeradius 1.0.2 + callback attributes

2005-02-24 Thread Kostas Kalevras
On Thu, 24 Feb 2005, Victor M. Polukcht wrote: Good day, freeradius-users. I have username sended to me as '[EMAIL PROTECTED]' How can i strip this callback_number before authentification, and send it as lcp:Callback-number attribute to Cisco NAS ? Or is there any other way to realize the callback

FreeRadius eap-peap problém

2005-02-24 Thread Patrice PAPOT
Hi All, I use freeradius 1.0.2 in Eap-peap. My configuration hardware is: PDA -- AP Cisco --- Freeradius Not of error on the log but i have a popup on the PDA saying the certificate of the server has been emitted by a not recognized authority. I seek of the assistance for resoudre this

help

2005-02-24 Thread Patrick Rebert
help - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Securid authentication

2005-02-24 Thread Norbert Wegener
Asking google for securid freeradius I get 752 hits. Among them I have not yet found a meaningful answer to: Is it possible to do SecurID card authentication using freeradius. Are there any relevant pointers on how to setup such authentication? Thanks Norbert Wegener - List

RE: Securid authentication

2005-02-24 Thread Jeff Stout
There is no way directly in Free Radius, however there are a few Workarounds 1. PAM Securid take a look at http://lists.cistron.nl/pipermail/freeradius-users/2004-March/030077.html 2. Programmatically write a script to fork a process 3. Turn on the Radius Server on the RSA and Proxy

Re: Radrelay and coredumps...

2005-02-24 Thread Terry J Fike Jr
What is gdb? (and what sort of package could i find it in) we don't have it on our boxes so i'll need to find it and install it then get you the info you need. -- Terry J Fike Jr System Administrator MTA Solutions 907-793-4100 [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See

Re: FreeRadius eap-peap problém

2005-02-24 Thread Alexandre Coninx
On Thu, Feb 24, 2005, Patrice PAPOT wrote: Hi All, I use freeradius 1.0.2 in Eap-peap. My configuration hardware is: PDA -- AP Cisco --- Freeradius Not of error on the log but i have a popup on the PDA saying the certificate of the server has been emitted by a not recognized authority.

Re: FreeRadius eap-peap problém

2005-02-24 Thread Zoltan Ori
On Thursday 24 February 2005 10:53, Patrice PAPOT wrote: I use freeradius 1.0.2 in Eap-peap. My configuration hardware is: PDA -- AP Cisco --- Freeradius Not of error on the log but i have a popup on the PDA saying the certificate of the server has been emitted by a not recognized authority.

Using freeradius to authenticate a watchguard firebox

2005-02-24 Thread Drew Weaver
Has anyone successfully gotten this to work, if so, can you contact me offlist? Thanks, -Drew

authentication saw web for wireless

2005-02-24 Thread Paulo Afonso Ribeiro Filho
Somebody knows as or what to use to make an authentication it saw web for wireless? Yours truly Paulo Afonso

Re: authentication saw web for wireless

2005-02-24 Thread Nelson Murilo
Several solutions, nocat i.e. (www.nocat.net) But you can use apache+mod-auth-pam and use virtually everyone authication solution. On Thu, Feb 24, 2005 at 03:05:56PM -0300, Paulo Afonso Ribeiro Filho wrote: Somebody knows as or what to use to make an authentication it saw web for wireless?

Re: pre-accounting/pre-proxy

2005-02-24 Thread Alan DeKok
Mitchell, Michael J [EMAIL PROTECTED] wrote: How do I get pre-proxy to cancel the proxy, but to send an Accounting ACK back to the client? I've looked high and low, but can't think of a way to do this. I don't think there's any easy way. We should really re-visit the server design, and

Re: How to define HAVE_THREAD_H ?

2005-02-24 Thread Alan DeKok
xuxu [EMAIL PROTECTED] wrote: How should I define the HAVE_THREAD_H ? in src,or Makefile ? You don't. If your system doesn't have threads.h, you will need to install it. If you don't know what it is, please read a Unix book. Don't ask here. Alan DeKok. - List

Re: Logging accounting data to MYSql

2005-02-24 Thread Alan DeKok
Alfred H. Dahl [EMAIL PROTECTED] wrote: The field in the database is int(12) - but data logged to the database is never larger than an unsigned_int_32 (2147483647/7FFF) If this is a limitation in the RADIUS-server, what do I do to work around it? It's a limitation of the client. The

Re: Radrelay and coredumps...

2005-02-24 Thread Alan DeKok
Terry J Fike Jr [EMAIL PROTECTED] wrote: What is gdb? (and what sort of package could i find it in) we don't have it on our boxes so i'll need to find it and install it then get you the info you need. It's a debugger. See the sun freeware package site. Alan DeKok. - List

How do I use Radius to make my network more secure?

2005-02-24 Thread CKramer
We currently have all Cisco network equipment, and a 2003 Active Directory environment. With my current budget constraints, I built a debian server to run Freeradius. I want my radius box to use LDAP to hit against our user accounts in AD. I also want to make sure that we use any and all

Re: calling a stored procedure

2005-02-24 Thread Max Ahston
this is an example of what can be done in postgresql: authorize_check_query = SELECT * FROM radius_check('%{SQL-User-Name}', '%{Client-IP-Address}') HAVING id IS NOT NULL the function returns the correct number of cols as needed. should be similiar for oracle. Maybe a little late

Re: SQL back-end interface

2005-02-24 Thread Max Ahston
Is it possible to pass ALL auth. request attributes to the stored procedure (in some kind of attr/value comma-separated list) which verifies username/password and returns accept/reject/challenge status code and output attribute's list, that have to be added to the response. The preffered

launching extenral programs

2005-02-24 Thread shabanip
is there any way to run an external program for authetication, authorization and accouting? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

my radiusd stops working under high load

2005-02-24 Thread shabanip
what would be the potential causes? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

tunning radiusd

2005-02-24 Thread shabanip
how can i tune radius for best performance (request/sec)? thanks, Payam Shabanian - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

user-defined attributes

2005-02-24 Thread shabanip
can i define or get unstanderds attributes in freeradius? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Radrelay and coredumps...

2005-02-24 Thread Terry J Fike Jr
argh...i pulled the package down from sunfreeware.com and this is my outupt... this is on a sol 9 box, runing 1.0.2 radrelay # ./gdb ./radrelay /opt/var/log/radius/radacct/12.21.213.86/core GNU gdb 6.0 Copyright 2003 Free Software Foundation, Inc. GDB is free software, covered by the GNU General

PEAP, Odyssey, Cisco 1200 fails with: No SSL info available. Waiting for more SSL data.

2005-02-24 Thread Mike Ingle
Hello, I am trying to set up FreeRADIUS 1.0.2 with OpenSSL 0.9.7e to do PEAP authentication. The wireless device is a Cisco 1200 (IOS) and the client is Odyssey 3.03.0.1194 I have followed the HOWTOs to configure both sides using WPA, TKIP, PEAP, generating the test keys, etc. The authentication

RE: Dialup Admin ?

2005-02-24 Thread Joel Eddy
In my dialup admin in user info I can see fields for Name, Mail, Department, Home Phone, Work Phone Mobile Phone and Home Address. I can make changes in all of them except Home Address. I loaded the userinfo table with the address and I can see through the sql debug display that it checks the

PPTP + RADIUS+LDAP

2005-02-24 Thread Anderson Alves de Albuquerque
I have freeradius with LDAP to do users authentication, now I need to use VPN (pptp) connect freeradius to do users authetication. Is this possible? I am doing the steps in http://poptop.sourceforge.net/dox/radius_mysql.html, but I have problems with authentication. Does someone known

Re: TTLS + PAP in LDAP for freeradius

2005-02-24 Thread Chan Min Wai
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Rok Papez wrote: Hello Chan Min Wai. Dne etrtek 24 februar 2005 07:28 je Chan Min Wai napisal(a): Anyone have a good documentation on this part? I have some documentation (system set-up instructions). If it's any good for you, you'll

Re: DEFAULT profile in postgresql database?

2005-02-24 Thread Vincent Chen
I do have the following configuration in postgresql.conf default_user_profile = DEFAULT query_on_not_found = yes Do I need other options? In /etc/raddb/users, I have this profile: Presario 2135AD EAP-Type := EAP-TLS, NAS-IP-Address == 10.1.3.5 In postgresql database, I

Re: Radius+Nocat

2005-02-24 Thread Chan Min Wai
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thomas MARCHESSEAU wrote: HI all, Nocat rocks with Freeradius. I just have pb with RADIUS.pm Try this one, and let me know if its ok for you . Btw , Chilli woks nice too. Regards Thomas MARCHESSEAU However, I'm using chillispot at the

Problem in authenticating winXP supplicant using freeradius server

2005-02-24 Thread Prashant Agrawal
I have configured the freeradius server for PEAP authentication of my WinXP SP1 supplicant. I am using a properity AP which has connexant radio's port authentication application. I have set correct values of the secret and radius server which can be verfied from the radiusd dump. On the