Re: Version 1.1.6 - Mac Address Authentication/vlan tagging

2007-06-23 Thread Alan DeKok
Brian Ertel wrote: I wasn't able to find an answer to this on the archives. Now, here is the set up: Freeradius Ver. 1.1.6 on centOS V.5. I am testing a Cisco 2000 Series Wireless LAN Controller and am trying to figure out a way to put unknown users (via their MAC Address) into a limited

Re: terminating EAP tunnels, proxy and realms

2007-06-23 Thread Andreas Liebe
Hi Helmut, Is there a way to terminate the EAP regardless of the outer identity? why do you want this. The EAP Tunnel should terminate on the last RADIUS where the user belongs. On your RADIUS only the EAP-Tunnels for your users should be terminating. I do not want to terminate the EAP

Re: terminating EAP tunnels, proxy and realms

2007-06-23 Thread Arran Cudbard-Bell
Andreas Liebe wrote: Hi Helmut, Is there a way to terminate the EAP regardless of the outer identity? why do you want this. The EAP Tunnel should terminate on the last RADIUS where the user belongs. On your RADIUS only the EAP-Tunnels for your users should be terminating.

Re: terminating EAP tunnels, proxy and realms

2007-06-23 Thread Alan DeKok
Andreas Liebe wrote: I do not want to terminate the EAP tunnels for the foreign realms, but I have to terminate the local one (@tu-darmstadt.de and NULL) as I have to forward the requests to a set of internal radius servers not capable of speaking EAP. Set Proxy-To-Realm := LOCAL for the

Re: terminating EAP tunnels, proxy and realms

2007-06-23 Thread Arran Cudbard-Bell
Alan DeKok wrote: Andreas Liebe wrote: I do not want to terminate the EAP tunnels for the foreign realms, but I have to terminate the local one (@tu-darmstadt.de and NULL) as I have to forward the requests to a set of internal radius servers not capable of speaking EAP. Set

Re: EAP/TLS ,after access-challenge nothing happen

2007-06-23 Thread Giovanni Lovato
[EMAIL PROTECTED] ha scritto: http://wiki.freeradius.org/index.php/FAQ#PEAP_or_EAP-TLS_Doesn.27t_Work_with_a_Windows_machine Ivan Kalik Kalik Informatika ISP Dana 22/6/2007, stefek143 [EMAIL PROTECTED] piše: Hi I have a little problem with authenticate using EAP/TLS on freeradius.

Re: TTLS-PAP accounting bug

2007-06-23 Thread Alan DeKok
Sam Schultz wrote: I was just wondering if the bug from this post has been fixed since 1.1.6: No. It looks like the fix to make tunneled proxied MS-CHAP work broke this. i.e. a pairmove was turned into a pairadd. See src/modules/rlm_eap/types/rlm_eap_ttls/ttls.c: ... /*

Re: terminating EAP tunnels, proxy and realms

2007-06-23 Thread Arran Cudbard-Bell
Alan DeKok wrote: Arran Cudbard-Bell wrote: So the eap module extracts the attributes encoded in the eap message ? I can see that working for EAP GTC and EAP PAP but not MschapV2 ? It works for GTC, PAP, and MS-CHAPv2. The server can terminate PEAP, and proxy the inner

Probelms importing usage to rodopi

2007-06-23 Thread Jeff
Importing Accounting Detail to Rodopi 5.4 As anyone implememnted this and willing to share their configuration. I am having issues with what i come up with. First I have Freeradius only creating one detail file with no date extension, etc. Next I have a cron job run every

Re: terminating EAP tunnels, proxy and realms

2007-06-23 Thread Alan DeKok
Arran Cudbard-Bell wrote: So the eap module extracts the attributes encoded in the eap message ? I can see that working for EAP GTC and EAP PAP but not MschapV2 ? It works for GTC, PAP, and MS-CHAPv2. The server can terminate PEAP, and proxy the inner EAP-MSCHAPv2 session as plain

Exec-Program-Wait

2007-06-23 Thread Michael Alexeev
Hi all, I am having trouble with macro substitution in Exec-Program-Wait attribute. For some reason %C{User-Name} is expanded to localhost{User-Name} string instead of real user name. Here is an excerpt from the users config file: jsullivan User-Password == mypass

Re: Exec-Program-Wait

2007-06-23 Thread Alan DeKok
Michael Alexeev wrote: Hi all, I am having trouble with macro substitution in Exec-Program-Wait attribute. For some reason %C{User-Name} is expanded to localhost{User-Name} string instead of real user name. Because %C is documented as being the client name. What led you to believe