Re: NAS ignoring Access-Accept

2007-05-21 Thread Wolfgang Rosenauer
[EMAIL PROTECTED] wrote: > debug radius > (This will activate debugging) > > show log > (To read logged requests/answers) > Hmm, got no output. I enabled "debug radius", made a dialin attempt (what failed) but haven't seen any radius log message on the Cisco with show log and also not on the rem

Re: Integrate freeradius v1.1.6 and openLADP v2.3.32 for authorization and authentication

2007-05-21 Thread Pshem Kowalczyk
Freeradius expects exactly one answer: rlm_ldap: object not found or got ambiguous search result kind regards Pshem On 22/05/07, xuebin gong <[EMAIL PROTECTED]> wrote: > Hi, All, > > I am user and want to integrate freeradius v1.1.6 and > openLADP v2.3.32 for authorization and > authentication. O

Re: NAS ignoring Access-Accept

2007-05-21 Thread Wolfgang Rosenauer
[EMAIL PROTECTED] wrote: > You are not sending any reply attributes to the NAS. Your client probably > needs things like Framed-IP-Address etc. from it. Or do you have DHCP on > the NAS? But I would expect Framed-IP-Address to be in the request then. Hmm, I don't think that the old server was send

Re: NAS ignoring Access-Accept

2007-05-21 Thread tnt
You are not sending any reply attributes to the NAS. Your client probably needs things like Framed-IP-Address etc. from it. Or do you have DHCP on the NAS? But I would expect Framed-IP-Address to be in the request then. Ivan Kalik Kalik Informatika ISP Dana 21/5/2007, "Wolfgang Rosenauer" <[EMAI

Re: NAS ignoring Access-Accept

2007-05-21 Thread Wolfgang Rosenauer
Hugh Messenger wrote: > Wolfgang Rosenauer <[EMAIL PROTECTED]> said: >> I ran radiusd -X and saw that freeradius sent an Access-Accept reply to >> the NAS' ip address and source port. > > Could you post the entire -X log for an example request? rad_recv: Access-Request packet from host 1.1.1.7:16

Re: Should I use FR 2.0.0 or 1.1.6?

2007-05-21 Thread Arran Cudbard-Bell
> I have four servers to upgrade - 3 currently run FR 1.0.1 and one is > already upgraded to 1.1.6. I am at an academic site, and the students > are currently taking their exams. As such, within the next few weeks > most of the staff/students will have left, and I can start to get on > with the up

Re: Should I use FR 2.0.0 or 1.1.6?

2007-05-21 Thread A . L . M . Buxey
Hi, > I have four servers to upgrade - 3 currently run FR 1.0.1 and one is > already upgraded to 1.1.6. I am at an academic site, and the students I would suggest that they were all on 1.1.6 at least now. > The question is, do I install FR 2.0.0 now (even as a pre-release) so > that upgrading to

Re: NAS ignoring Access-Accept

2007-05-21 Thread tnt
debug radius (This will activate debugging) show log (To read logged requests/answers) Ivan Kalik Kalik Informatika ISP Dana 21/5/2007, "Wolfgang Rosenauer" <[EMAIL PROTECTED]> piše: >[EMAIL PROTECTED] wrote: >> Run debug radius on Cisco. You are missing a key (shared secret) in >> radius-serv

Re: NAS ignoring Access-Accept

2007-05-21 Thread Wolfgang Rosenauer
[EMAIL PROTECTED] wrote: > Run debug radius on Cisco. You are missing a key (shared secret) in > radius-server host ... statement. See if that is the problem. The shared secret is in another config line which I've left out. radius-server key XX How can I get debug output on a Cisco? (I'm

Re: Dynamic VLAN - limiting switchs VLANs?

2007-05-21 Thread Arran Cudbard-Bell
Phil Mayers wrote: > Robert wrote: > >> Hello all, >> >> I currently have FR running and happily doing MAC authentication against >> a MYSQL DB. >> >> I can plug a computer into the switch, have the switch grab the MAC >> addy, pass it to FR, hit the DB and return what VLAN that MAC belongs >>

Integrate freeradius v1.1.6 and openLADP v2.3.32 for authorization and authentication

2007-05-21 Thread xuebin gong
Hi, All, I am user and want to integrate freeradius v1.1.6 and openLADP v2.3.32 for authorization and authentication. Our operating system is Fedora 5 Linux. (1)Install freeRadius-1.1.6 After following the instruction of installation in http://.freeradius.org, install freeRadius-1.1.6 on

Re: NAS ignoring Access-Accept

2007-05-21 Thread tnt
Run debug radius on Cisco. You are missing a key (shared secret) in radius-server host ... statement. See if that is the problem. Ivan Kalik Kalik Informatika ISP Dana 21/5/2007, "Wolfgang Rosenauer" <[EMAIL PROTECTED]> piše: >Hi, > >I'm not sure if I run into a Cisco or Freeradius issue here.

RE: NAS ignoring Access-Accept

2007-05-21 Thread Hugh Messenger
Wolfgang Rosenauer <[EMAIL PROTECTED]> said: > I ran radiusd -X and saw that freeradius sent an Access-Accept reply to > the NAS' ip address and source port. Could you post the entire -X log for an example request? > Thanks, > Wolfgang -- hugh - List info/subscribe/unsubscribe? See http:

NAS ignoring Access-Accept

2007-05-21 Thread Wolfgang Rosenauer
Hi, I'm not sure if I run into a Cisco or Freeradius issue here. I try to migrate from icradius to freeradius and everything worked in the new configuration when I tried with NTRadPing and so I'm switched the Cisco NAS to the new server. Unfortunately the NAS is ignoring the Access-Accept replies

Should I use FR 2.0.0 or 1.1.6?

2007-05-21 Thread John Horne
Hi, I expect the freeradius developers will hate me for asking this, but is there an estimate of when the final version of FR 2.0.0 will be released? I have four servers to upgrade - 3 currently run FR 1.0.1 and one is already upgraded to 1.1.6. I am at an academic site, and the students are curr

Re: Dynamic VLAN - limiting switchs VLANs?

2007-05-21 Thread Phil Mayers
Robert wrote: > Hello all, > > I currently have FR running and happily doing MAC authentication against > a MYSQL DB. > > I can plug a computer into the switch, have the switch grab the MAC > addy, pass it to FR, hit the DB and return what VLAN that MAC belongs > to, and then have the switch con

Re: Dynamic VLAN - limiting switchs VLANs?

2007-05-21 Thread A . L . M . Buxey
Hi, > What I need is a way FR can not only match the MAC to a VLAN, but also > to cross reference that result to the VLANs that are available from the > requesting switch. either use larger queries or use an extrenal perl or php script to do the work in your DB you'd need to add a few more colu

DialupAdmin Question.

2007-05-21 Thread Joseph Sullivan
Hello Group, I am trying to use Dialup Admin on Free Radius 1.1.6. I have the admin.conf file all setup, it will add, remove users from the MySQL db, but it will not do the radius check by clicking on Check Server. It outputs this: Monday, 21 May 2007, 09:10:14 MDT Server: 127.0.0.1:1812 (

Dynamic VLAN - limiting switchs VLANs?

2007-05-21 Thread Robert
Hello all, I currently have FR running and happily doing MAC authentication against a MYSQL DB. I can plug a computer into the switch, have the switch grab the MAC addy, pass it to FR, hit the DB and return what VLAN that MAC belongs to, and then have the switch configure to port to the correct

Re: Freeradius-Proxied-To, radrelay and 2.0

2007-05-21 Thread Alan Dekok
Milan Holub wrote: > I wonder whether there is any use for Freeradius-Proxied-To attribute > with freeradius 2.0. It should be there for backwards compatibility, but there are likely better ways of achieving the same result. > Now when I'm relaying some accounting packets to my freeradius serve

Freeradius-Proxied-To, radrelay and 2.0

2007-05-21 Thread Milan Holub
Hi Alan/others, I wonder whether there is any use for Freeradius-Proxied-To attribute with freeradius 2.0. In freeradius 1.X the attribute was used to stop proxy for relayed packets. Now when I'm relaying some accounting packets to my freeradius server using radrelay binary from 1.1.6 and there

Re: Problem in installing FreeRadius

2007-05-21 Thread Alan Dekok
saurabh agarwal wrote: ... > So when i did make install, it gave the following error:- ... > libtool: link: unable to infer tagged configuration > libtool: link: specify a tag with `--tag' ... > I tried searching a lot but couldnt find anything. Please do provide me > with your valuable inputs

Re: Wiki

2007-05-21 Thread Doug Hardie
On May 21, 2007, at 00:23, Alan Dekok wrote: > Doug Hardie wrote: >> I would be glad to. Is there a plan? Is there a listing of the >> various pages? I couldn't find either. > > There's no plan. There's no listing of various pages, > unfortunately. Well, then I can't botch it up too bad.

Re: Freeradius-Users Digest, Vol 25, Issue 99

2007-05-21 Thread [EMAIL PROTECTED]
Ich bin am 21. Mai nicht im Haus und kann Ihre Nachricht erst am Dienstag den 22. Mai bearbeiten. In dringenden Fällen wenden Sie sich bitte an Herrn René Böhm (E-Mail: [EMAIL PROTECTED]). Mit freundlichen Grüßen Tobias Drollinger - List info/subscribe/unsubscribe? See http://www.freeradius

Problem in installing FreeRadius

2007-05-21 Thread saurabh agarwal
Hi, Im the first time user of FreeRadius (as a part of Jradius). To use Jradius, first it is required to configure and install FreeRadius as follows:- -configure -make -make install So when i did make install, it gave the following error:- gmake[5]: Entering director

Re: Problem in runnning radius server

2007-05-21 Thread Alan Dekok
prajakta choudhari wrote: ... > rlm_eap: Failed to link EAP-Type/tls: file not found > radiusd.conf[10]: eap: Module instantiation failed. > radiusd.conf[1959] Unknown module "eap". > radiusd.conf[1906] Failed to parse authenticate > section. You do not have OpenSSL installed on your system. In

Re: Wiki

2007-05-21 Thread Alan Dekok
Doug Hardie wrote: > I would be glad to. Is there a plan? Is there a listing of the > various pages? I couldn't find either. There's no plan. There's no listing of various pages, unfortunately. I suggest looking at: http://wiki.freeradius.org/Special:Deadendpages http://wiki.freeradiu

Re: Very critical: Memory leak in freeradius-1.1.6

2007-05-21 Thread Alan Dekok
nikitha george wrote: > On 5/20/07, Alan DeKok <[EMAIL PROTECTED]> wrote: If valgrind doesn't say that the memory is lost, then the memory is > very likely still being used. i.e. It's likely needed for something. > > something..? Did you read my earlier explanations? > Why do radiusd nee

Problem in runnning radius server

2007-05-21 Thread prajakta choudhari
Hi all: I have just started to configure the Radius Server. I have downloaded and installed the latest freeradius and openssl software. I am trying to configure EAP-TLS authentication and currently using the default certificates in raddb/certs directory. eap.conf is as follows: eap {