Query regarding Grouping devices and users for login Access

2007-12-01 Thread ajay raut
Hi, I am trying one test setup in my LAB on RADIUS. As i am new to all the feature of Radius, I need one information on Radius feature urgentlySo any information regarding this will be very helpful for me. The Query is... assume a scenario..there is an organisation having

Re: rlm_passwd and EAP-MD5

2007-12-01 Thread Kolbjørn Barmen
On Fri, 30 Nov 2007, Phil Mayers wrote: But is this for real? I need to restart the server if someone changes their password in the file that is configured with rlm_passwd? Yes If so, that's not just a minor annoyance :P Then use an SQL database. I see. HUP does not work

Re: rlm_passwd and EAP-MD5

2007-12-01 Thread Kolbjørn Barmen
On Fri, 30 Nov 2007, [EMAIL PROTECTED] wrote: Hi, But is this for real? I need to restart the server if someone changes their password in the file that is configured with rlm_passwd? If so, that's not just a minor annoyance :P there are other modules which provide non-restart

Re: Query regarding Grouping devices and users for login Access

2007-12-01 Thread tnt
Group devices into huntgroups and users in SQL groups. Add Huntgroup-Name == locationx as a radcheck item for a group containing users from locationx. Ivan Kalik Kalik Informatika ISP Dana 1/12/2007, ajay raut [EMAIL PROTECTED] piše: Hi, I am trying one test setup in my LAB on RADIUS. As i

Re: rlm_passwd and EAP-MD5

2007-12-01 Thread Alan DeKok
Kolbjørn Barmen wrote: HUP does not work reliably, and cannot be made to, for architectural reasons. However, Alan has recently added code to the CVS HEAD which will reload *certain* portions of the server (just users files I believe) safely on HUP. Well, that's not a big difference from

Re: LDAP Authentication: filter problem

2007-12-01 Thread Alan DeKok
Carlos Parada wrote: ... filter = ((uid=%{User-Name})(radiusServiceInfo=%{Service-Info})) The problem is that when Service-Info doesn't come in the Radius packet (because is not mandatory for me), it doesn't work, See doc/variables.txt for how to deal with attributes that don't exist, and

Re: Packets in Accounting ?

2007-12-01 Thread Alan DeKok
Edvin Seferovic wrote: what happened to the Acct-Input/Output-Packets in Accounting. MySQL schema doesn’t have those fields anymore. Any special reason ? Were they ever in the schema? I don't see them in 1.1.x. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Newbie: What does this mean (Wrong NAS port ID)?

2007-12-01 Thread Alan DeKok
Piero Giobbi wrote: Im using freeradius 1.1.7 with Proxim AP4000 and it works. But i get this in my syslog. /Error: rlm_radutmp: Logout entry for NAS ap-serverummet port 9 has wrong ID/ It just means that the server missed a logout packet for that port. Alan DeKok. - List

RE: Packets in Accounting ?

2007-12-01 Thread Edvin Seferovic
I found this in an older sql.conf file of mine : accounting_update_query = UPDATE ${acct_table1} SET FramedIPAddress = '%{Framed-IP-Address}', AcctSessionTime = '%{Acct-Ses sion-Time}', AcctInputOctets = '%{Acct-Input-Octets}', AcctOutputOctets = '%{Acct-Output-Octets}', AcctOutputPackets

Re: Query regarding Grouping devices and users for login Access

2007-12-01 Thread Alan DeKok
ajay raut wrote: Organisation needs a configuration previlleges to be grouped regionwise means the devices which are local to a particular location the local adminstrator can configure it but they will not have any access previlleges to other devices.. Put the devices into groups.

Re: Packets in Accounting ?

2007-12-01 Thread Alan DeKok
Edvin Seferovic wrote: I found this in an older sql.conf file of mine : shrug It's always possible that there were local changes... I suppose, the packets were in the schema, but I cannot confirm that for version 1.0 since the FTP server of freeradius doesn't respond :( Hmm... OK.

Re: rlm_passwd and EAP-MD5

2007-12-01 Thread Kolbjørn Barmen
On Sat, 1 Dec 2007, Alan DeKok wrote: Well, that's not a big difference from my point of view, since restarting the server is done quite quickly anyhow. I'm more surpriced that I have to do anything, I would expcet that one can change passwords in a passwd-file without having to restart