Re: VLAN and SSID

2006-03-30 Thread Antonio Matera
Hi to all, I have modified my users file: user1    Auth-Type := EAP, Cisco-AVPair := "ssid=SSID1"    Tunnel-Medium-Type = IEEE-802,    Tunnel-Private-Group-Id = 2,    Tunnel-Type = VLAN user2    Auth-Type := EAP, Cisco-AVPair := "ssid=SSID2"   

FC5

2006-03-30 Thread Sam Sein Muan Tie
hi all Got a bug from freeradius of FC5, i ended up using FC4 and radiusd. dont have the server no more but here's some debug information for those who might be able to help out on Redhat Fedora Core 5 Module: Loaded radutmpradutmp: filename = "/var/log/radius/radutmp"radutmp: username

Re: Freeradius authentication agains Domino

2006-03-30 Thread Christoffer Dahl Petersen
tor, 30 03 2006 kl. 00:49 -0500, skrev Alan DeKok: If the domino server supplies a clear-text password, yes. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Hi Alan! Thanks for the quick reply!! Sorry for my ignorance, but how can I

Two times authorization and/or both proxying and serving

2006-03-30 Thread Mark Supersonik
Sorry I forgot the subject !!! Here it goes again! Hi friends! I speak from the tongue of an engineering student in a research group trying to implement a RADIUS proxy system. My doubt is: can a freeradius server do first an authorization of a request throught a DB (i.e MySQL) and proxy then

Mac address help

2006-03-30 Thread Mordor Networks
HelloI have pppoe-server with freeradius and mysql backend working pretty good , thus i still want to know if it is possible to use mac adders with user name and password ?thanks in advanced - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Different user attributes based on NAS-IP-Address?AlsoSuffixwildcards available?

2006-03-30 Thread John Mylchreest
I think you missed the question then. This is a single username, but the return being selective based on NAS. For example: Radreply will reply with an IP of 1.2.0.1 if NAS=1 else it will respond with IP of 1.1.0.1 if NAS=2, else it will respond with an IP of 1.3.0.1 The radcheck would be at

Problem with FreeRadius EAP/TLS and 3com OfficeConnect Wireless AP

2006-03-30 Thread Eugenio Pasquariello
Hi, we have installed freeradius in conjunction with a 3com OfficeConnect Wireless AP, with WPA encryption. Our system is a Slackware Linux with kernel ver. 2.4.28. The 3Com OfficeConnect Wireless 11g Access Point model is 3CRWE454G72. We've installed the version 1.1.1 of Freeradius, and we

Re: VLAN and SSID

2006-03-30 Thread James J J Hooper
--On 30 March 2006 09:56 +0200 Antonio Matera [EMAIL PROTECTED] wrote: In my log after the MAC address there isn't any information on the SSID.   In the log i haven't information on the SSID  but in my aP configuration I have the radius-server vsa send accounting:

RE: == error

2006-03-30 Thread Cris Boisvert
I have the Default hints file.. (never needed to change anything in it) Is their something I can change to not have those errors occur? Thanx -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Wednesday, March 29, 2006 5:37 PM To:

Re: Problem with FreeRadius EAP/TLS and 3com OfficeConnect Wireless AP

2006-03-30 Thread Alan DeKok
Eugenio Pasquariello [EMAIL PROTECTED] wrote: The client start the EAP transaction, start TLS and receive the server certifcate, we have used WinXp as client and then WIN requests to the user the client certificate. After the choice of the certificate, the client remain blocked. You do

Re: Freeradius authentication agains Domino

2006-03-30 Thread Alan DeKok
Christoffer Dahl Petersen [EMAIL PROTECTED] wrote: Sorry for my ignorance, but how can I verify if the domino server supply the passwords in clear-text? Ask it? Read the domino documentation? I don't run domino, so I can't help you there. Alan DeKok. - List info/subscribe/unsubscribe?

Re: VLAN and SSID

2006-03-30 Thread Antonio Matera
hi, ok, now the authentication request works (the problem was that if I restart the AP I lost this configuration. How can I save it using the web configuration?) Now the log is the following: rad_recv: Access-Request packet from host 192.168.9.104:1645, id=19, length=166 User-Name =

frontend for freeradius???

2006-03-30 Thread Pelusa Vali
hi list, i have a question, are there any freeradius frontend to administer users, but which don't assume i have ldap or mysql?? my users are only in users file, i reviewed dialup_admin and php radius accounting tool, but both assume i have mysql or ldap, i just want some program with graphical

Freeradius Expiration Date

2006-03-30 Thread Atkins, Dwane P
I have looked into the db_mysql.sql and found that their was start and stop dates in the radacct. If I can get freeradius to use the radcheck table, does this mean it will automatically see the radacct table and use input from this table as well? Thanks Dwane Dwane Atkins TN

Re: Freeradius Expiration Date

2006-03-30 Thread Alan DeKok
Atkins, Dwane P [EMAIL PROTECTED] wrote: I have looked into the db_mysql.sql and found that their was start and stop dates in the radacct. If I can get freeradius to use the radcheck table, does this mean it will automatically see the radacct table and use input from this table as well?

Re: frontend for freeradius???

2006-03-30 Thread Guy Fraser
On Thu, 2006-30-03 at 16:40 +0100, Pelusa Vali wrote: hi list, i have a question, are there any freeradius frontend to administer users, but which don't assume i have ldap or mysql?? my users are only in users file, i reviewed dialup_admin and php radius accounting tool, but both assume i

Re: frontend for freeradius???

2006-03-30 Thread Guy Fraser
On Thu, 2006-30-03 at 16:40 +0100, Pelusa Vali wrote: hi list, i have a question, are there any freeradius frontend to administer users, but which don't assume i have ldap or mysql?? my users are only in users file, i reviewed dialup_admin and php radius accounting tool, but both assume i

Re: Freeradius Expiration Date

2006-03-30 Thread Guy Fraser
On Thu, 2006-30-03 at 10:09 -0600, Atkins, Dwane P wrote: I have looked into the db_mysql.sql and found that their was start and stop dates in the radacct. If I can get freeradius to use the radcheck table, does this mean it will automatically see the radacct table and use input from this

Re: Two times authorization and/or both proxying and serving

2006-03-30 Thread Alan DeKok
Mark Supersonik [EMAIL PROTECTED] wrote: My doubt is: can a freeradius server do first an authorization of a request throught a DB (i.e MySQL) and proxy then if so or reject it (if all isn't in rule)? Yes. We want only to accept access if each one of the two servers

Re: == error

2006-03-30 Thread Alan DeKok
Cris Boisvert [EMAIL PROTECTED] wrote: I have the Default hints file.. (never needed to change anything in it) Is their something I can change to not have those errors occur? If you're not using those entries, delete them. Alan DeKok. - List info/subscribe/unsubscribe? See

Telephony-Summit Announcment

2006-03-30 Thread Peter Nixon
Hi Guys I will be giving the keynote speech on AAA for fun and profit at the Free Software/Open Source Telephony-Summit 2006. Hope to see some of you there. -Peter Free Software/Open Source Telephony-Summit 2006 Tuesday, May 2nd 2006

run-time variable

2006-03-30 Thread Duane Cox
Is there such a runtime variable that I could use that would be a specific identification for a radius server? Even a hostname would be suffice. Thanks Duane Cox - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

VSA and other attributes in Access-Accept

2006-03-30 Thread Mohammed Petiwala
Hi: First thanks to the freeRADIUS team - this is one of the most flexibile and powerful AAA available...I've 2 questions: 1. I've set up my clients to authenticate using EAP-TTLS with MSCHAPv2 as the inner authentication protocol. This works fine with the wpa_suppicant with intel 2200b/g

no sql log for proxied Accounting

2006-03-30 Thread Ryan Melendez
Hello, I'm trying to configure freeradius to only sql log Accounting packets that are not proxied. I see the note in the config file that reads accounting requests which are proxied are also logged in the detail file. That is fine, but I can't have it log to sql. In general I would only like

Re: dialup admin ippool administraton

2006-03-30 Thread Alan DeKok
Olaf =?ISO-8859-1?Q?Sch=E4fer?= [EMAIL PROTECTED] wrote: This module sounds interesting - something I haven't take into my considerations keeping the dynamic ippool data in the sql-db, too. And it's obvious to do it this way using a primary and a backup server. But the configuration

Re: multiple attribute instaces and radius variables (xlat)

2006-03-30 Thread Alan DeKok
Andriy Gapon [EMAIL PROTECTED] wrote: Is it possible to add something like %{Attr-Name[*]} that would expand to all values of an attribute and something like %{Attr-Name[#]} that would expand to number of attribute instances ? This works in the CVS head. I'm not sure why it isn't in 1.1.1.

Re: Different user attributes based on NAS-IP-Address?AlsoSuffixwildcards available?

2006-03-30 Thread Alan DeKok
John Mylchreest [EMAIL PROTECTED] wrote: This is a single username, but the return being selective based on NAS. For example: Radreply will reply with an IP of 1.2.0.1 if NAS=1 else it will respond with IP of 1.1.0.1 if NAS=2, else it will respond with an IP of 1.3.0.1 I'm not sure

Re: frontend for freeradius???

2006-03-30 Thread Alan DeKok
Guy Fraser [EMAIL PROTECTED] wrote: Since the users file can handle multiple alternate configurations for DEFAULT and or user entries, it will require careful planning. I would suggest avoiding the users file. It causes *way* too many problems. Instead, design something that will be

We need help

2006-03-30 Thread Sam Sein Muan Tie
dear all, we, well shoudnt say we, i got stucked to this project of building a radius server for stopping some user NFS mount from MAC/IP spoofing on linux . We are hoping for wired dot1.x for radius server. [EMAIL PROTECTED] raddb]# rpm -qa |grep freeradius freeradius-mysql-1.0.4-1.FC4.1

Re: PsionTeklogix 9150

2006-03-30 Thread Magnus Willigens
tried to get it working with handhelds of seriestype 7035... they just do leap (cisco) but the first series of the basestations are build with orinocco cards. == so this does not work. with xp clients md5 worked fine. tried tls and peap: the authentification worked but it does not share ip (no