O'Reillys Radius Book - Worth buying

2007-04-15 Thread Jacob Jarick
Hi, Im just getting started with freeradius (trying to nut out dynamic vlans atm) and I was wondering if this book would be a worth while purchase. I had a great experience with O'reillys bind and perl cookbook books. Have any FR users used this book and if so your comments would be appreciated.

Re: Howto compile 1.1.6 on Fedora 6

2007-04-15 Thread Jacob Jarick
I should be more specific, I will compile all specially needed apps after doing a norm installation. Generic stuff like X etc, I dont care about unless it doesnt work. On 4/16/07, Jacob Jarick <[EMAIL PROTECTED]> wrote: > I personally hate rpms and will compile all apps so no, I try rpms as > a l

RE: Multiple REALMS, multiple SQL

2007-04-15 Thread Andrea Cerrito
Great, it does the trick :) It was simplier than I thought. Another question: is it safe to write into the same sql server\database\table by 2 radius servers authenticating the same realm? -- Andrea Cerrito - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Howto compile 1.1.6 on Fedora 6

2007-04-15 Thread Jacob Jarick
I personally hate rpms and will compile all apps so no, I try rpms as a last resort and Im not surprised when they fail with a big list of dependancies. I will look into it though and test on the next machine and report back. On 4/16/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > Hi, > > Than

Re: Howto compile 1.1.6 on Fedora 6

2007-04-15 Thread A . L . M . Buxey
Hi, > Thanks to the people who helped me figure this out (big thanks to > Alan), this works perfectly on a fresh Fedora system. > > Download, compile and install openssl > > download freeradius 1.1.6 > unpack in usr/src > cd freeradius-1.1.6 > > ./configure --prefix=/usr > --with-openssl-include

Requesting help with FR + Dynamic vlans

2007-04-15 Thread Jacob Jarick
Hi, here is the current scenario: * school with wireless access * allready uses radius (soon to be freeradius) * freeradius auth's via a win2k3 Active Directory Server * teachers need to be able to log into WAP's a,b,c etc and be automatically assigned to the teachers vlan * priv students need to

Re: The server will carry local authentication first, despite ofproxying or not, is this correct?

2007-04-15 Thread Alan DeKok
LinHai wrote: >> The server will not perform authentication before proxying. Read the >> debug log you posted to the list. > But in debug log, rlm_sql (sql) , I found 4 sql query has been carried. > These sql query should not be performed > for optimizing reason, I think. No. One of the p

Re: assigning vlan based on NAS and LDAP field?

2007-04-15 Thread Jacob Jarick
Jerry, I hate to be a pain but what you have implemented atm is my next task with freeradius. Would you mind linking any howtos you use, thanks. Also how do u get freeradius to find a users group then report it back to the cisco / ap so it can decide what vlan the client belongs on. Many thanks

Re: Re: The server will carry local authentication first, despite ofproxying or not, is this correct?

2007-04-15 Thread LinHai
Hi, >The server will not perform authentication before proxying. Read the >debug log you posted to the list. But in debug log, rlm_sql (sql) , I found 4 sql query has been carried. These sql query should not be performed for optimizing reason, I think. >The server *will* process the request t

Howto compile 1.1.6 on Fedora 6

2007-04-15 Thread Jacob Jarick
Thanks to the people who helped me figure this out (big thanks to Alan), this works perfectly on a fresh Fedora system. Download, compile and install openssl download freeradius 1.1.6 unpack in usr/src cd freeradius-1.1.6 ./configure --prefix=/usr --with-openssl-includes=/usr/local/ssl/include -

Re: The server will carry local authentication first, despite of proxying or not, is this correct?

2007-04-15 Thread Alan DeKok
LinHai wrote: >In radiusd.c, function "int rad_respond(REQUEST *request, RAD_REQUEST_FUNP > fun)", I found such problem: > If a AUTHENTICATION_REQUEST or ACCOUNTING_REQUEST packet is received, the > server will first carry the operation > (ex. authentication) itself, then send proxy request

The server will carry local authentication first, despite of proxying or not, is this correct?

2007-04-15 Thread LinHai
Hi all: In radiusd.c, function "int rad_respond(REQUEST *request, RAD_REQUEST_FUNP fun)", I found such problem: If a AUTHENTICATION_REQUEST or ACCOUNTING_REQUEST packet is received, the server will first carry the operation (ex. authentication) itself, then send proxy request to home server

unsubscribe

2007-04-15 Thread Bin Chen
unsubscribe - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Using Client-Ip-Address attribute in preprocess files

2007-04-15 Thread Arran Cudbard-Bell
[EMAIL PROTECTED] wrote: > Hi, > > Trying to use Client-Ip-Address is huntgroups and hints doesn't seem to work, if this because the Client-Ip-Address is written to the request packet at the end of pre-process and not the beginning ? Or is there more strangeness afoot

Re: Using Client-Ip-Address attribute in preprocess files

2007-04-15 Thread A . L . M . Buxey
Hi, > >> Trying to use Client-Ip-Address is huntgroups and hints doesn't seem to > >> work, > >> if this because the Client-Ip-Address is written to the request packet > >> at the end of pre-process > >> and not the beginning ? Or is there more strangeness afoot ? are you sure you want Client-I

Re: Using Client-Ip-Address attribute in preprocess files

2007-04-15 Thread Arran Cudbard-Bell
Alan DeKok wrote: > Arran Cudbard-Bell wrote: > >> Hi, >> >> Trying to use Client-Ip-Address is huntgroups and hints doesn't seem to >> work, >> if this because the Client-Ip-Address is written to the request packet >> at the end of pre-process >> and not the beginning ? Or is there more stran

Re: access-accept with exception

2007-04-15 Thread Phil Mayers
Wael ELLOUZE wrote: > Hello, > My freeradius verify the login, password and all other attributes. > > My question is : Is it possible to access-accept all authentication that > come with the attribute called-station-id= and how to do this exception Yes, if you are using PAP: DEFAULT Callin

PAM Radius Authentication

2007-04-15 Thread daniel
Hi, I have been trying to set up the pam_radius_auth pam module to authenticate my users through my freeradius server. The radius server is working fine as I can get and Access-Accept packet with radtest and also my wireless hotspot authenticates fine through it. The problem I have is that p

Re: Multiple REALMS, multiple SQL

2007-04-15 Thread Alan DeKok
Andrea Cerrito wrote: > How can I let the proxy write in a db just the realm DEF and GHI and ignore > the realm ABC? Do *conditional* logging to SQL. See Acct-Type, which lets you conditionally call a module. > I think it can be done in the post-proxy section of the radius.conf... But > how?

Re: WEP only client

2007-04-15 Thread George Embrey
Ian Truelsen wrote: >I have a client whose wifi adaptor (Linksys WUSB11) can only do wep key >encryption and I was wondering whether it would be possible to use >eap-tls or something similar given the restrictions. What is the most >secure system that can be used with this type of adaptor? > > I