Re: Accounting and anonymous outer identity in EAP-TTLS

2005-10-28 Thread Damjan
> > Shouldn't the := operator in "user" replace the User-Name = "anonymous", > > or it doesn't because files is before sql in the authorize section, and > > my users are in the MySQL database? > > Yes, and it shouldn't matter that the users are in SQL. > > I suspect that something else is add

Re: FreeRADIUS - 802.1x WPA-TKIP, WPA2-AES settings

2005-10-28 Thread Damjan
> add to it: forward the DHCPDISCOVER to the DS if no internal table entry > for this MAC is found. yapp, that would be even very easy to integrate. > > but i don't think that _any_ AP does that. Well, an AP that does 802.1x + chillispot is all you need :) You get the accounting, bandwidth shapp

Upgrading Realms

2005-10-28 Thread Jeffrey Froman
Hi, I have a working installation of freeradius 0.9, and I am attempting to migrate my configuration to freeradius-1.0.4 on a newer server. Authentication for the local domain is working fine, but there is a problem with way realms are being handled. In huntgroups, I have the following: MyH

RE: return ALL the AVPs for a username that belongs multiple groups

2005-10-28 Thread Lenir
Here's the rest of my config. Notice, that username 3000 belongs to group Dialin and Dialin2. The user can register fine, however in this case the Access-Accept packet only returns the AVPs related to group Dialin (I'm guessing is because it's the first one that it matches). mysql> select * from r

rlm_sql module won't compile under Solaris 10

2005-10-28 Thread M.McNeil
Hello, I'm trying to get FreeRadius 1.0.5 to compile with MySQL / RLM_SQL, under Solaris 10. Configure works just fine, however, after running "make", I get the following: gmake[7]: Entering directory `/export/home/freeradius-1.0.5/src/modules/rlm_sql' Making static in drivers... gmake[8]:

Re: Accounting and anonymous outer identity in EAP-TTLS

2005-10-28 Thread Alan DeKok
Damjan <[EMAIL PROTECTED]> wrote: > Shouldn't the := operator in "user" replace the User-Name = "anonymous", > or it doesn't because files is before sql in the authorize section, and > my users are in the MySQL database? Yes, and it shouldn't matter that the users are in SQL. I suspect that s

Accounting and anonymous outer identity in EAP-TTLS

2005-10-28 Thread Damjan
I've been searching the mail list about this, but haven't found a definitive sollution. The scenario, I'm using WPA2 access points, they are setup to authorize users against my freeradius server. The freeradius server is setup to use a MySQL database, and eap-ttls is configured (and that works ok)

Re: Problem installing freeradius 1.0.1 or 1.05 on 64 bit platform

2005-10-28 Thread Alan DeKok
"Ashwin Gobind" <[EMAIL PROTECTED]> wrote: > I am attempting to install freeradius on a 64 bit platform with Suse > Linux 9. > > However I get the following error during make. What maybe the problem ? ... > /usr/lib/libgdbm.so: could not read symbols: Invalid operation > collect2: ld returned 1 ex

controling bandwidth

2005-10-28 Thread Alex M
Hi, How can I control bandwidth for specific users? And how can I block all ports except one, for their connection?   Thanks! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius, 802.1x, PEAP for wlan

2005-10-28 Thread Alan DeKok
Juan Mauel Lopez Villalobos <[EMAIL PROTECTED]> wrote: > is there a way of not using ntlm_auth-samba-ldap if I only have ldap? If your LDAP server gives FreeRADIUS clear-text passwords, yes, it will work. > how works "ntlm_auth --request-nt-key --username=%{St > ripped-User-Name:-%{User-Name:-N

Re: return ALL the AVPs for a username that belongs multiple groups

2005-10-28 Thread Alan DeKok
"Lenir" <[EMAIL PROTECTED]> wrote: > Radius replies with the AVPs of the first group that it > matches that the user belongs to. Instead of returning all the AVPs for all > the groups that the user belongs to. The example you posted didn't include groups or reply AVP's. > So I guess the questi

Re: PEAP MS_CHAP V2: problem with tunnel attributes on enterasys V2 switch

2005-10-28 Thread Zoltan Ori
On Friday 28 October 2005 10:40, [EMAIL PROTECTED] wrote: > I am new to this list and would like to know if someone out there > has been successfull in implementing eap-PEAP user authentication > and VLAN assignment with freeradius and Enterasys V2 switches ? > The V2 switches (and all Enterasys

RE: Problem using "Calling-Station-Id"-Attribute in radcheck

2005-10-28 Thread Alex M
Im about to try to do the same but to log the MAC addresses…. Im newbie to freerad, but some times depends on swiches and routers that you have on your netror, your MAC addrs gets hashed along the way ( I saw that on MS IAS)…. So check in logs if you can see the Mac of the user first, altho

PEAP MS_CHAP V2: problem with tunnel attributes on enterasys V2 switch

2005-10-28 Thread slapeyre
Hello, I am new to this list and would like to know if someone out there has been successfull in implementing eap-PEAP user authentication and VLAN assignment with freeradius and Enterasys V2 switches ? It wasn´t a problem to configure EAP-PEAP with freeradius server (running on suze) and Enter

RE: Problem using "Calling-Station-Id"-Attribute in radcheck

2005-10-28 Thread Guy Davies
In what format does your NAS send the calling-station-id?  Mine uses 00-00-00-00-00-00.  Maybe you're simply not matching the format?   Rgds,   Guy From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of kdr akmSent: 28 October 2005 15:16To: freeradius-users@lists.freeradius.orgSu

Problem installing freeradius 1.0.1 or 1.05 on 64 bit platform

2005-10-28 Thread Ashwin Gobind
Good day I am attempting to install freeradius on a 64 bit platform with Suse Linux 9. However I get the following error during make. What maybe the problem ? /usr/software/freeradius-1.0.1/libtool --mode=link gcc -release 1.0.1 \ -module -export-dynamic -g -O2 -D_REENTRANT -D_POSIX_PTHREAD_S

Problem using "Calling-Station-Id"-Attribute in radcheck

2005-10-28 Thread kdr akm
Hello,I´m using  freeradius-1.0.1-0.FC2.i386.rpm and freeradius-mysql-1.0.1-0.FC2.i386.rpm  with Mysql  for Authentication for my lan client .   Now, I want also to check the MAC-Address of this  Lan Client.Therefore I added the "Calling-Station-Id"-Attribute to the radchecktable.mysql> select * f

Can someone guide to configuring pgsql-voip docs

2005-10-28 Thread maruna
I read through the list archives but I still reading for almost a week now no success yet.   What I a looking for is a document on how to enter my rate table i.e. tariff for the prepaid VoIP and to which table of the radius db?   I have a successfully running radius server with pgsql-vo

Re: Testing accounting

2005-10-28 Thread Roy
Hi, On Fri, 2005-10-28 at 10:06 +0200, Sébastien Cantos wrote: > I've got 2 radius servers in HA mode behind a load balancer. My load > balancer needs to test the 2 radius servers to make sure they are > responding. I need to send some payload to the accounting port to test this. > Can someone tel

Testing accounting

2005-10-28 Thread S�bastien Cantos
Hi, I've got 2 radius servers in HA mode behind a load balancer. My load balancer needs to test the 2 radius servers to make sure they are responding. I need to send some payload to the accounting port to test this. Can someone tell me which payload I could send to test the accounting port ? Reg