Re[2]: daily limit

2005-05-11 Thread avudz
Monday, May 9, 2005, 9:34:05 PM, you wrote: SE Hm... maybe you should set the SQL statements in your sqlcounter.conf file SE that can be usually found in /etc/raddb or SE /usr/local/etc/raddb depending on SE distribution... SE You can define the different counters for your vouchers that will

Re: Re[2]: daily limit

2005-05-11 Thread Marcin Jessa
You dont understand the way the counter works. As stated in the experimental.conf: # The 'reset' parameter defines when the counters are all # reset to zero. It can be hourly, daily, weekly, monthly or # never. It can also be user defined. It should be of the

Re[4]: daily limit

2005-05-11 Thread avudz
Hello Marcin, Wednesday, May 11, 2005, 2:54:09 PM, you wrote: MJ In your case you should change reset=never to reset=1h if you MJ want to reset the counter every hour. MJ But in that case it would not make sense to call it MJ Max-Hour-Session-Time since the counter would be reset after the MJ

difference between module authorize and authentication

2005-05-11 Thread dssd dsfdsfdsf
Good morningWhat is the difference between the module authorize and authentication in the file radiusd.conf if authorize don't return ok but authentication returns ok, eap-tls or peap works but ! it is not normal. When the module "authorize" don't return ok, is it possible to don't validate

Re: Counting number of open sessions in RADIUS

2005-05-11 Thread Florin Samareanu
this is kinda wrong, because radwho has one extra line on top, so the output of radwho |wc -l will count +1 the actual number of users :) On 5/10/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Quoting Sonali Karmarkar [EMAIL PROTECTED]: Hi I am using freeradius 0.9.3 with mysql on linux.

Re: Re[4]: daily limit

2005-05-11 Thread Marcin Jessa
Hi. As far as I know the sqlcounter will disallow furhter authentrication only if the user has used her time limit quota. The Session-Timeout Attribute will kick him out when loged in and the Max-XYZ-Session will be checked the next time a user wants to login. You would need an additional

Re[6]: daily limit

2005-05-11 Thread avudz
Hello Marcin, Wednesday, May 11, 2005, 4:06:52 PM, you wrote: MJ Hi. MJ As far as I know the sqlcounter will disallow furhter MJ authentrication only if the user has used her time limit quota. MJ The Session-Timeout Attribute will kick him out when loged in MJ and the Max-XYZ-Session will be

Re: Re[6]: daily limit

2005-05-11 Thread Chris Knipe
On Wed, May 11, 2005 at 04:31:49PM +0700, avudz wrote: Hello Marcin, Wednesday, May 11, 2005, 4:06:52 PM, you wrote: MJ Hi. MJ As far as I know the sqlcounter will disallow furhter MJ authentrication only if the user has used her time limit quota. MJ The Session-Timeout Attribute will

Re[8]: daily limit

2005-05-11 Thread avudz
Wednesday, May 11, 2005, 4:36:26 PM, you wrote: CK I'll second that idea. Definately would need some external maintenance CK on the database every night to expire accounts older than 24hrs... CK Alternatively, you *can* do some nifty sql query on the authentication query CK that compaires

Re: Re[8]: daily limit

2005-05-11 Thread Marcin Jessa
Hi. Yepp, that should work, i.e. mysql select * from radcheck; ++--+---+++ | id | UserName | Attribute | op | Value | ++--+---+++ | 5 | yazzy| User-Password | := | yazzy | | 6 |

Re: Re[8]: daily limit

2005-05-11 Thread Marcin Jessa
Errata. I meant radgroupcheck, not radgroupreply. On Wed, 11 May 2005 12:09:01 +0200 Marcin Jessa [EMAIL PROTECTED] wrote: Hi. Yepp, that should work, i.e. mysql select * from radcheck; ++--+---+++ | id | UserName | Attribute | op |

Re[10]: daily limit

2005-05-11 Thread avudz
Hello Marcin, Wednesday, May 11, 2005, 5:09:01 PM, you wrote: MJ Hi. MJ Yepp, that should work, i.e. mysql select * from radcheck; MJ ++--+---+++ MJ | id | UserName | Attribute | op | Value | MJ

Huntgroups

2005-05-11 Thread Marcin Jessa
Hi. I wonder how the huntgroups really work. Can I have a huntgroup with multiple NAS's stored in SQL and users belonging to that huntgroup? Then can each huntgroup have a different group defined in the radgroup/radcheck table ? What I want to do is to restrict certain users to only be able to

Re[11]: daily limit

2005-05-11 Thread avudz
Wednesday, May 11, 2005, 5:47:16 PM, you wrote: a Hello Marcin, a Wednesday, May 11, 2005, 5:09:01 PM, you wrote: MJ Hi. MJ Yepp, that should work, i.e. mysql select * from radcheck; MJ ++--+---+++ MJ | id | UserName | Attribute | op |

Re: Re[11]: daily limit

2005-05-11 Thread Marcin Jessa
Maybe the date format is incorrect? I am not sure what those silly americans use but afair it's of Month-Day-Year format - as logical as using bodyparts as the scale value for meassurements :) What does the debugging info say? On Wed, 11 May 2005 18:24:52 +0700 avudz [EMAIL PROTECTED] wrote:

Re[13]: daily limit

2005-05-11 Thread avudz
Hello Marcin, Wednesday, May 11, 2005, 6:32:36 PM, you wrote: MJ Maybe the date format is incorrect? MJ I am not sure what those silly americans use but afair it's MJ of Month-Day-Year format - as logical as using bodyparts as the MJ scale value for meassurements :) MJ What does the debugging

NAS compatibility

2005-05-11 Thread Sylvain Clerc
Hello, I have problems with Linksys wap54g and wrt54g to do radius authentication. the NAS sends the request of the client and when freeradius sends the Access-Challenge, it seems that the NAS doesn't send it to the client. Naturaly, the client sends another Access-Request and that's never

Re: Re[13]: daily limit

2005-05-11 Thread Marcin Jessa
Run your radiusd with -X flag, this will force it to foreground and give you more info. On Wed, 11 May 2005 18:40:38 +0700 avudz [EMAIL PROTECTED] wrote: Hello Marcin, Wednesday, May 11, 2005, 6:32:36 PM, you wrote: MJ Maybe the date format is incorrect? MJ I am not sure what those

Re: help

2005-05-11 Thread Marcin Jessa
On Wed, 11 May 2005 13:39:01 +0200 zze-BEN SAID Mehdi RD-CORE-ISS [EMAIL PROTECTED] wrote: Hi; I'm student and I'm new to freeRadius, actually I'm new to Radius! Hi. I used to be student and new to FreeRadius, then I started to read the docs and man pages. Then came google to make my life

Re: help

2005-05-11 Thread Ernesto Freyre Ramírez
Hi , I think your question is about the process of compiling and installing. This is like other linux software, with a previous configure stage with some parameters, If you want more help, I think you could to send me a email. If you wish to learn more about RADIUS itself, I think first

reply-message

2005-05-11 Thread Lucas Aimaretto
Hi all, I'm willing to send a reply-message when access-reject occurs. The thing is that, if authorize_check_query fails ( ie: user is not found) , then authorize_reply_query is not called. So, I do not know how to send back a Reply-Message Attribute if authorize_reply_query is not executed.

Re: help

2005-05-11 Thread Marcin Jessa
Don't you love it when you need to guess people's question? On Wed, 11 May 2005 09:03:54 -0500 Ernesto Freyre Ramírez [EMAIL PROTECTED] wrote: Hi , I think your question is about the process of compiling and installing. This is like other linux software, with a previous configure stage

RADIUS on Linux Network

2005-05-11 Thread Paulo C. Panaligan
Hello! My name is Paulo. I would like to set up a network using at least two different operating systems. My main choices are SUSE Linux and Windows XP (not Windows 2K). I am planning to set up a network that runs through a RADIUS server. I will install the server to SUSE Linux and having my

Re: help

2005-05-11 Thread ccarver
This is a good book for general RADIUS protocol information and some good freeradius specifics: http://www.oreilly.com/catalog/radius/index.html If you are running into a specific problem you need help with, then ask a specific question. -Chris Quoting zze-BEN SAID Mehdi RD-CORE-ISS [EMAIL

Re: help

2005-05-11 Thread Paulo C. Panaligan
is there anyone you know that can help me setup a network step by step from scratch? thx. Hello! My name is Paulo. I would like to set up a network using at least two different operating systems. My main choices are SUSE Linux and Windows XP (not Windows 2K). I am planning to set up a network

RE: RADIUS on Linux Network

2005-05-11 Thread Paulo C. Panaligan
thanks for replying. this is going to be my graduation project. I am trying to setup a network consisting of Linux and Windows XP. The server (RADIUS) is going to be installed on the linux having my Windows XP as my client. What materials do I need to have and how do I start it with?[EMAIL

RE: RADIUS on Linux Network

2005-05-11 Thread Paulo C. Panaligan
thanks for replying. this is going to be my graduation project.I am trying to setup a network consisting of Linux and Windows XP. The server (RADIUS) is going to be installed on the linux having my Windows XP as my client. I was going to set up three workstations running three different OS but

posgresql how to

2005-05-11 Thread avudz
Hello, anybody knows where can i download / read radius-postgre how to ? i think i better switch to postgre :-) -- Best regards, ./avd mailto:[EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RADIUS NETWORK

2005-05-11 Thread Paulo C. Panaligan
WHAT MATERIALS DO I NEED TO SETUP A RADIUS NETWORK ON LINUX?

RE: RADIUS NETWORK

2005-05-11 Thread mmiranda
-Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]On Behalf Of Paulo C. PanaliganSent: Wednesday, May 11, 2005 11:18 AMTo: freeradius-users@lists.freeradius.orgSubject: RADIUS NETWORK WHAT MATERIALS DO I NEED TO SETUP A RADIUS NETWORK ON LINUX? A radius

Re: (no subject)

2005-05-11 Thread Raghu
On 5/8/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Hello, I have a problem and I hope that You can help me, please!? version: 1.0.0 I want use (Free)RADIUS for AAA on IPv6. Only one router, one RADIUS server and one user. User(IPv6 address) connect with Telnet to Router(IPv6 address)

RE: RADIUS NETWORK

2005-05-11 Thread King, Michael
Before this get's too much further. You are experiencing a hard time because you have not done any research on your own, you are just asking for help. Especially when many howto's / write up's exist on the exact subject you are inquiring about. For people with no sense of humor

DialupAdmin/LDAP - General Questions

2005-05-11 Thread Mathieu Bénard
Hello I'd like to manage my LDAP users with DialupAdmin Radius interface, and here come a few questions. 1: It seems that DialupAdmin uses LDAPv2 protocol. Can it possibly use LDAPv3 ? 2: From what I read in the /lib/ldap/create_user.php3: $dn = 'uid=' . $login . ',' .

Re: reply-message

2005-05-11 Thread Alan DeKok
Lucas Aimaretto [EMAIL PROTECTED] wrote: I'm willing to send a reply-message when access-reject occurs. The thing is that, if authorize_check_query fails ( ie: user is not found) , then authorize_reply_query is not called. So, I do not know how to send back a Reply-Message Attribute if

RE: reply-message

2005-05-11 Thread Lucas Aimaretto
I'm willing to send a reply-message when access-reject occurs. The thing is that, if authorize_check_query fails ( ie: user is not found) then authorize_reply_query is not called. So, I do not know how to send back a Reply-Message Attribute if authorize_reply_query is not executed.

Re: Auth-Type = System and DSL Static IP

2005-05-11 Thread Dustin Doris
On Tue, 10 May 2005, Andrey wrote: Hi List, I have a question about Auth-Type = System. I have several accounts that need to be authenticated through System and it works great as long as the IP is assigned dynamically. As soon as I switch an account to static IP, it authenticates but does

Re: EAp/TSL authorization problem

2005-05-11 Thread Sergey Guriev
3 2005 22:39 Jim Seymour : Hmmm... I thought it meant simply that the User-Name was a match. Anyway . I changed it to User-Password and nothig has changed. Regards, Sergey. -- Sergey A. Guriev Organization: New Telephone Company e-mail: [EMAIL

Re: EAp/TSL authorization problem

2005-05-11 Thread Sergey Guriev
3 2005 22:39 Jim Seymour : Sergey Guriev [EMAIL PROTECTED] wrote: Hmmm... I thought it meant simply that the User-Name was a match. And, also I see that in the Radius.log --- Thu May 12 08:28:14 2005 : Info: rlm_eap_tls: Length Included Thu May 12 08:28:14 2005 : Error:

OpenLDAP / FreeRADIUS / Cisco 5350 problem

2005-05-11 Thread Douglas G. Phillips
I'm running into an issue here, and I can't seem to find the forest for the trees. I'm probably overlooking something obvious, and am not searching correctly for the problem. Our LDAP server is using crypted passwords at the moment. The router is a cisco 5350. RADIUS is FreeRADIUS 1.0.1-2 on

Re: OpenLDAP / FreeRADIUS / Cisco 5350 problem

2005-05-11 Thread Vladimir Vuksan
Douglas G. Phillips wrote: Here is a sample of the password that is being passed: User-Password = \240d\351E\3737\025\022\0227,(rest removed) This may imply that your shared secret is incorrect. Please verify that RADIUS shared secret on Cisco 5350 and shared secret for that particular IP in

Re: OpenLDAP / FreeRADIUS / Cisco 5350 problem

2005-05-11 Thread Alan DeKok
Douglas G. Phillips [EMAIL PROTECTED] wrote: Our LDAP server is using crypted passwords at the moment. RADIUS clients can use PAP. Nothing else. The problem is this: If I pass the radtest client a clear-text password, authentication is successful. If either I pass the client an encrypted

Re: OpenLDAP / FreeRADIUS / Cisco 5350 problem

2005-05-11 Thread Julien freeradius
Hello Douglas, The password that you try to resend is not the encrypted password it s an ascii representation of your encrypted password. I assume that you need to activate the chap (or pap with a encryption_scheme = crypt) module to be able to authenticate this request. I don't know about

Re: DialupAdmin/LDAP - General Questions

2005-05-11 Thread Chris Carver
Mathieu Bénard wrote: Hello I'd like to manage my LDAP users with DialupAdmin Radius interface, and here come a few questions. 1: It seems that DialupAdmin uses LDAPv2 protocol. Can it possibly use LDAPv3 ? Absolutely. I'm using it right now. 2: From what I read in the

Re: RADIUS NETWORK

2005-05-11 Thread Jim Seymour
Paulo C. Panaligan [EMAIL PROTECTED] wrote: WHAT MATERIALS DO I NEED TO SETUP A RADIUS NETWORK ON LINUX? Paulo, you're not getting any useful answers because you're violating every rule in the book on how to go about asking for help. Briefly: You're asking a group of people, this mailing

RE: RADIUS NETWORK

2005-05-11 Thread mmiranda
[EMAIL PROTECTED] wrote: Paulo C. Panaligan [EMAIL PROTECTED] wrote: WHAT MATERIALS DO I NEED TO SETUP A RADIUS NETWORK ON LINUX? Paulo, you're not getting any useful answers because you're violating every rule in the book on how to go about asking for help. I believe you'd be

Re: HuntGroup + MySQL

2005-05-11 Thread Dustin Doris
On Wed, 11 May 2005, Julien freeradius wrote: Hello, I would like to set freeradius to send a PPP like configuration if the request come from a nas and a VPN style configuration if coming from another NAS. More or less like that : huntgroups file: PPPNAS-IP-Address == 192.168.2.1

Windows/Linux

2005-05-11 Thread Paulo C. Panaligan
Hello, Thanks for replying back. I was just wondering can I setup a secured connection between two computers running Linux as my server and Windows XP as my client connected from a school LAN connection to a wireless router through a radius server? I have some of the resources for you check out:

Re: OpenLDAP / FreeRADIUS / Cisco 5350 problem

2005-05-11 Thread Alexei Chetroi
On Wed, May 11, 2005 at 05:28:27PM -0500, Douglas G. Phillips wrote: Date: Wed, 11 May 2005 17:28:27 -0500 From: Douglas G. Phillips [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Subject: OpenLDAP / FreeRADIUS / Cisco 5350 problem I'm running into an issue here, and I can't