Prevent certain ip ranges from accounting

2006-10-07 Thread Van Der Westhuizen, Eldridge \(Mr\) \(Summerstrand Campus North\)
Hi I'm busy setting up a community network. I'm using freeradius and mysql to authenticate users and do accounting. After the users authenticated to the freeradius system, i only want to do accounting for any internet services. All the free community services, like local chatting within the

Re: Adding proxying to our EAP setup

2006-10-07 Thread Phil Mayers
Dave Mussulman wrote: passwords for local accounts. I'd like to change from maintaining my own sql copy/user database to RADIUS proxying to someone else's server. What's the recommended way to configure failover proxying/realms when there's no realm-ish identifier? When user logs in, I want

Re: Prevent certain ip ranges from accounting

2006-10-07 Thread Phil Mayers
Van Der Westhuizen, Eldridge (Mr) (Summerstrand Campus North) wrote: for any/ internet/ services. All the free community services, like /local/ chatting within the community network, local voice over ip, etc, should not be billed. All of this traffic will flow between the local network on a

Re: Proxy question

2006-10-07 Thread Phil Mayers
Roberto Greiner wrote: You've marked that realm as something that shouldn't be proxied. Why do you expect it to be proxied? Actually I don't wan't it to be proxied, only that it removes the realm part to handle it locally. But it's comparing the full entry (with realm) against the

Re: two or more ippool

2006-10-07 Thread Phil Mayers
Roberto Gonzalez Azevedo wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thanks for reply. I can't subdivide in two groups ... I need 1 group, with several pools ... Can't be done. Sorry - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Proxy question

2006-10-07 Thread Phil Mayers
Roberto Greiner wrote: Alan DeKok wrote: Roberto Greiner [EMAIL PROTECTED] wrote: Show the *full* log. rad_recv: Access-Request packet from host E.F.G.H:4126, id=4, length=62 User-Name = [EMAIL PROTECTED] Is this the log from the home server? If so, why? You

Re: Proxy question

2006-10-07 Thread Alan DeKok
Roberto Greiner [EMAIL PROTECTED] wrote: Actually I don't wan't it to be proxied So when you originally said you wanted it to be proxied... If you want people to be able to help you, tell them what you really want to do. Alan DeKok. -- http://deployingradius.com - The web site of

Re: Prevent certain ip ranges from accounting

2006-10-07 Thread James Wakefield
Phil Mayers wrote: If you're assigning fixed IPs, you might look at netflow. Packets like ipfm and similar can be used to monitor traffic by IP from a port mirror. All depends on your network architecture. You can also use netflow with dynamic IPs, if you script up something to match the

Re: two or more ippool

2006-10-07 Thread Peter Nixon
On Sat 07 Oct 2006 14:17, Phil Mayers wrote: Roberto Gonzalez Azevedo wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thanks for reply. I can't subdivide in two groups ... I need 1 group, with several pools ... Can't be done. Sorry As explained to Roberto on IRC this IS

Compatibility issue with Nortel?

2006-10-07 Thread Juan Pablo Espino
Hello, I have beeen experimenting some problems connecting a nortel router 1430 with freeradius (v1.0.1, using mysql). When I try telnet I couldn't get the command line, although the authentication process is ok. Then I added the specific vendor attributes as a new dictionary file. It looks as

Re: Compatibility issue with Nortel?

2006-10-07 Thread Alan DeKok
Juan Pablo Espino [EMAIL PROTECTED] wrote: Then I added the specific vendor attributes as a new dictionary file. Why? See dictionary.bay, that attribute is already there. Probably I have something wrong with the configuration because it seems the values of the new attributes are not

Re: Compatibility issue with Nortel?

2006-10-07 Thread Juan Pablo Espino
Hi, thanks for the response. Then I added the specific vendor attributes as a new dictionary file. Why? See dictionary.bay, that attribute is already there. I didn't know that :-) Probably I have something wrong with the configuration because it seems the values of the new attributes

EAP-TLS Certificate problems.

2006-10-07 Thread Brian vb
Hi, I'm trying to get Freeradius up and running on a WinXP box (win haters. be nice ;) ) I have downloaded, installed, and configured the Freeradius version from www.freeradius.net. The server starts seemingly without errors. However when I try to connect with my XP laptop I get a certificate