radius process die

2007-02-28 Thread satish patel
Dear guys I have faceing some problem when i installed latest version of freeradius on RHEL and i start radiusd process after few min my radiusd process die and killed so why this happend and what is the best option to start radiusd ??? #radiusd --help <-- how to start radi

Re: disconnect users from radius

2007-02-28 Thread satish patel
Dear I got ans what to do with cisco router if u want to start PoD packet of disconnect basicaly it is IOS security feature so defult stop of disable so u have to start it with #aaa pod server command more document on this site : http://www.cisco.com/univercd/cc/td/do

clients.conf and nas table (was Re: installing FR on FBSD 6.2)

2007-02-28 Thread PD
On 3/1/2007, "Andrew D" <[EMAIL PROTECTED]> wrote: >> how and where to get the structure file ? >> > >Try looking in /usr/local/share/doc/freeradius/examples/ >docs for freeradius are in /usr/local/share/doc/freeradius/ > Thx Andrew.. I found it at /usr/local/share/doc/freeradius/examples/ Next qu

Re: How to remove accounting files in the Windows port of FreeRadius?

2007-02-28 Thread Foo JH
I've figured out the solution to my own problem... For the benefit of all, if i understand correctly, when the Windows port of FreeRadius runs, all the folders created are owned by the system process, and since it is created in 0666 mode, nobody can delete the files created within. To remove t

Re: installing FR on FBSD 6.2

2007-02-28 Thread Andrew D
PD wrote: > Dear all, > > I just do a fresh installation of FBSD 6.2 and FR 1.1.4 > > According to http://www.chillispot.org/forum/viewtopic.php?t=37... > -- > We still need to add a structure of database which FreeRadius is going to > use. In folder > /usr/src/freeradius-1.0.0-pre3/src/m

installing FR on FBSD 6.2

2007-02-28 Thread PD
Dear all, I just do a fresh installation of FBSD 6.2 and FR 1.1.4 According to http://www.chillispot.org/forum/viewtopic.php?t=37... -- We still need to add a structure of database which FreeRadius is going to use. In folder /usr/src/freeradius-1.0.0-pre3/src/modules/rlm_sql/drivers/rlm_s

Re: [SOLVED] CHAP Modification

2007-02-28 Thread ChristosH
Alan DeKok-4 wrote: > >> Also, is there a C function included in the libraries that will allow me >> to >> convert a hex string to binary? I'm worried I might get stuck in ASCII -> >> HEX -> BINARY conversions. > > Yes. see "bin2hex" and "hex2bin". See also rlm_pap in 1.1.4, which > does a

Re: Logging based on port request came in on

2007-02-28 Thread Phil Mayers
Walt Reynolds wrote: > Hello, > > I have freeradius 1.1.2 set up to listen on both ports 1812/1813 and > 1645/1646. This is simply to separate user and admin login. What I > would like to do is to add logging based on the port. I could add > %{NAS-Port-Type} to the Detail such as: > > deta

Logging based on port request came in on

2007-02-28 Thread Walt Reynolds
Hello, I have freeradius 1.1.2 set up to listen on both ports 1812/1813 and 1645/1646. This is simply to separate user and admin login. What I would like to do is to add logging based on the port. I could add %{NAS-Port-Type} to the Detail such as: detailfile = ${radacctdir}/%{NAS-Port-Ty

Re: disconnect users from radius

2007-02-28 Thread tnt
To kick a user of the Cisco router use: clear intreface virtual-access number You can see which number with: show users As far as I know Dialup Admin doesn't work with MSSQL, only MySQL and PostgreSQL. Ivan Kalik Kalik Informatika ISP http://www.kalik.co.yu Dana 28/2/2007, "satish patel" <[E

Re: disconnect users from radius

2007-02-28 Thread Kevin Bonner
On Wednesday 28 February 2007 10:40, satish patel wrote: > Dear all > > I have installed freeradius on RHEL with MSSQL server and it > is working fine but now i have facing problem regarding disconnecting of > users my NAS is cisco Router it is l2tp so what i do for this ??? problem >

Re: disconnect users from radius

2007-02-28 Thread Andrew D
satish patel wrote: > Dear all > > I have installed freeradius on RHEL with MSSQL server and > it is working fine but now i have facing problem regarding disconnecting > of users my NAS is cisco Router it is l2tp so what i do for this ??? > problem ?? > You have to do it at the

Re: eap-ttls proxy and ldap

2007-02-28 Thread basile
i try with a user in the users file : same probleme [EMAIL PROTECTED] and [EMAIL PROTECTED] dont work ( proxy a request with user-name = anonymous ) [EMAIL PROTECTED] and [EMAIL PROTECTED] works i have two differents versions of freeradius on the two server > hi > i try to proxy eap-ttls request

Re: [SOLVED] CHAP Modification

2007-02-28 Thread ChristosH
Alan DeKok-4 wrote: > > ChristosH wrote: >> It's a VALUE_PAIR type, so could I check and modify the password->length >> and >> password->strvalue in that function? > > Huh? Why? Do it elsewhere. > Well, that's part of my issue; where's the best place to check the password and convert it

Re: specify ip range in huntgroups (or similar functionality).

2007-02-28 Thread tnt
It is possible with a huntgroups like: gear NAS-IP-Address > IPaddress1 , NAS-IP-Address < IPaddress2 Group == admin But I would assign admin group it's address pool and then restict access with access control lists. That should be the job for the firewall. Ivan Kalik Kalik Infor

eap-ttls proxy and ldap

2007-02-28 Thread basile
hi i try to proxy eap-ttls request from a freeradius server to another i use outer identity [EMAIL PROTECTED] and username [EMAIL PROTECTED] first server proxy to the second a request with anonymous as username so it don t work if i use outer identity [EMAIL PROTECTED] ( anoterdomain is local to

disconnect users from radius

2007-02-28 Thread satish patel
Dear all I have installed freeradius on RHEL with MSSQL server and it is working fine but now i have facing problem regarding disconnecting of users my NAS is cisco Router it is l2tp so what i do for this ??? problem ?? and i want to connect my dialupadmin with mssql ??

specify ip range in huntgroups (or similar functionality).

2007-02-28 Thread Jason Murray
Is it possible to specify a range of IP addresses in a huntgroups file? What I am trying to accomplish is: 1) AAA authentication to our Cisco devices using radius 2) Only allow people in a specific group to access the devices 3) Reject everyone else. I am using the following: huntgroups: ---

alternating authentication LDAP/mini Token

2007-02-28 Thread Jochen Schäfer
Hi List, I want to accomplish following task with freeradius: Users have two possibilities to authenticate 1. Authentication via username ldap password 2. Authentication via username mini Token What would be a possible solution? Do the normal authentication with username and password against ldap

FreeRadius 1.1.4 and rlm_krb5 and Active Directory

2007-02-28 Thread Kozlov Artem
Hi! I'm trying to configure freeradius with rlm_krb5 using mini howto from Enrik Berkhan http://archives.free.net.ph/message/20060104.153134.68c5be76.en.html , but i have some troubles. when i type radtest [EMAIL PROTECTED] userpass localhost 10 testing123 i got: Sending Access-R

sql set up - Fall-Through agains read_gr oups in sql.conf

2007-02-28 Thread tzieleniewski
Hi! How can I configure radius to always check the group table for a user without utilizing the Fall-Through parameter in the radreply table for a particular user?? I tried to use read_groups=yes in the sql.conf but it didn't help. Thanks in advanced -tomasz - List info/subscribe/unsubscrib

bypassing tls certificates

2007-02-28 Thread M. Onur ERGiN
Hi, [EMAIL PROTECTED] wrote: > Oh, by the way, may be this is a little off-topic but can I authenticate > windows xp users through peap without using a certificate? you COULD decide not to trust or check any certificate. nasty though. Radius says peap needs tls for windows xp authenticatio

Re: On IEEE 802.1x roaming

2007-02-28 Thread Alan DeKok
Josh Shamir wrote: > Now I need that the Supplicants can do "roaming" between the Access Points. > The IEEE 802.1X asserts that can be used two mechanisms to obtain roaming : > > - PMK Caching > - Pre Authentication > > I would to know how I could implement this mechanisms in my system. Are > req

On IEEE 802.1x roaming

2007-02-28 Thread Josh Shamir
Hello, I'm using FreeRADIUS with Coova Chilli in proxy mode with IEEE 802.1Xauthentication (PEAP auth. method to be more specific). In my network there are 6 Access Point that use TKIP as security protocol. Now I need that the Supplicants can do "roaming" between the Access Points. The IEEE 802.1X

Re: Add+cnadge attributes to proxy-reply with condition

2007-02-28 Thread Alan DeKok
Victor wrote: > proxy.conf: > > post_proxy_authorize = yes In the CVS head you can use postproxy_users file, which is a much better solution. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/uns

Re: group question

2007-02-28 Thread Alan DeKok
Matt Ashfield wrote: > Based on the WIKI FAQ, I found: > The following entry denies access to a group of users. The same restrictions > as above on location in the raddb/users file also apply: > > DEFAULT Group == "disabled", Auth-Type := Reject > Reply-Message = "Your account has been disabled"

Re: [SOLVED] CHAP Modification

2007-02-28 Thread Alan DeKok
ChristosH wrote: > Okay, in the radius.c file they call a function rad_chap_encode() that uses > the password attribute. > Is that what I'm looking for? Yes. > It's a VALUE_PAIR type, so could I check and modify the password->length and > password->strvalue in that function? Huh? Why? Do i

Add+cnadge attributes to proxy-reply with condition

2007-02-28 Thread Victor
Hello, I need to modify proxy-reply auth packet with condition. All i need - if proxy user enter UserName like 'username#554466' send UserName like 'username' to proxy (its already work) and check proxy-reply - if it consist av-pair Ascend-CBCP-Mode=CBCP-Any-Or-No changer this pair value to CBCP-