rlm_radutmp: Logout entry for NAS

2008-06-02 Thread Percy Bloomfield Melgar
Hi, I have this erro message in radius.log Mon Jun 2 03:21:29 2008 : Error: rlm_radutmp: Logout entry for NAS Juniper port 3489661328 has wrong ID Many session has not save the stop query wen a user logout, I think that this error has relation whit this problem. I hope you can help me, thanks.

if passwd returns notfound - reject?

2008-06-02 Thread Wolfgang Burger
Good morning to all, I`m using the passwd module to add an atribute to the request. How can I configure the server to reject the request if the modeule returns notfound? One idea would be to add an default value to the attribute and check wether it has changed after the module was called.

Re: MSCHAP V2 + Plain Text

2008-06-02 Thread vijayakumar
Dear Ivan, Thanks for your prompt response. I want to integrate /etc/passwd file of fedora 8 to my Freeradius to use MSCHAP V2 . Will it be possible ??? If so what configuration changes to be made in configuration file ?? . how can I make NT hash of /etc/passwd Regards. VIJAY Ivan Kalik

Re: MSCHAP V2 + Plain Text

2008-06-02 Thread Nicolas Goutte
Am 02.06.2008 um 10:57 schrieb vijayakumar: Dear Ivan, Thanks for your prompt response. I want to integrate /etc/passwd file of fedora 8 to my Freeradius to use MSCHAP V2 . Will it be possible ??? If so what configuration changes to be made in configuration file ?? . how can I make

Re: Freeradius and OpenVpn

2008-06-02 Thread Ivan Kalik
For debugging, i enabled password logging in radius Do complete debug: radiusd -X Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: if passwd returns notfound - reject?

2008-06-02 Thread Wolfgang Burger
Thank you for your answer, Ivan. Am 02.06.2008 um 13:11 schrieb Ivan Kalik: Are passwords also coming from passwd module? No. If they are then there is no problem. If user is not found he won't have a password and will be rejected by default. Ivan Kalik Kalik Informatika ISP That's

Re: MSCHAP V2 + Plain Text

2008-06-02 Thread Ivan Kalik
You can't. Those passwords are already encrypted. Ivan Kalik Kalik Informatika ISP Dana 2/6/2008, vijayakumar [EMAIL PROTECTED] piše: Dear Ivan, Thanks for your prompt response. I want to integrate /etc/passwd  file of fedora 8  to my Freeradius to use MSCHAP V2 . Will it be possible

Re: if passwd returns notfound - reject?

2008-06-02 Thread Ivan Kalik
Are passwords also coming from passwd module? If they are then there is no problem. If user is not found he won't have a password and will be rejected by default. Ivan Kalik Kalik Informatika ISP Dana 2/6/2008, Wolfgang Burger [EMAIL PROTECTED] piše: Good morning to all, I`m using the passwd

Freeradius and OpenVpn

2008-06-02 Thread Sascha Kiefer
Hi, I set up a openvpn server with radius plugin. Everything seems to run. Now, i submit my username + password using the openvpn win client from openvpn.se . For debugging, i enabled password logging in radius Mon Jun 2 03:44:14 2008 : Auth: Login incorrect: [hugo/boss] (from client ds01 port

Is it possible to use FreeRadius Client with Microsoft IAS?

2008-06-02 Thread Knarkargott
Hi! I am new to both Linux and RADIUS, but I really want to learn about this. I have been trying to get the FreeRadius client to work with IAS for a while now but without success, so I really need some help with this. My test should be quite basic I think, but somehow I fail. My setup is as

looking into local db after Realm Default was found

2008-06-02 Thread Hans Bornemann
Hi, I don't know why my radius does the following: my freeradius-server (1.1.7) retrieves the username from the local db AFTER Found realm DEFAULT. Then the query was send to the correct radius. Thanks Hans Debug: ... Processing the authorize section of radiusd.conf modcall: entering

Re: looking into local db after Realm Default was found

2008-06-02 Thread Ivan Kalik
rlm_realm: Looking up realm dfn.de for User-Name = [EMAIL PROTECTED] rlm_realm: Found realm DEFAULT Realm dfn.de is not defined in proxy.conf. Realm DEFAULT is activated. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: if passwd returns notfound - reject?

2008-06-02 Thread Ivan Kalik
If you have a policy that users can gain access only from a registered mac address, revoke the certificates for all the users that didn't comply. In 2.0 you can reject them with unlang. Ivan Kalik Kalik Informatika ISP Dana 2/6/2008, Wolfgang Burger [EMAIL PROTECTED] piše: Thank you for your

Online users

2008-06-02 Thread Eduardo Cavalcanti
I want to list the online users, but I don't want to use a database such as mysql. Is there any alternative for me?? Is there any command to list the online users?? I tried radwho but it doesn't list any user... Any help? - List info/subscribe/unsubscribe? See

Re: if passwd returns notfound - reject? SOLVED

2008-06-02 Thread Wolfgang Burger
Thank you very much Ivan. Typical case of RTFM. ... module-name if (notfound) { reject } ... Thank you again and have a nice day. Wolfgang Burger Am 02.06.2008 um 14:49 schrieb Ivan Kalik: If you have a policy that users can gain access only from a registered mac address, revoke

Re: Online users

2008-06-02 Thread Ivan Kalik
Are you getting accounting packets from NAS? Ivan Kalik Kalik Informatika ISP Dana 2/6/2008, Eduardo Cavalcanti [EMAIL PROTECTED] piše: I want to list the online users, but I don't want to use a database such as mysql. Is there any alternative for me?? Is there any command to list the online

Re: looking into local db after Realm Default was found

2008-06-02 Thread Hans Bornemann
Yes, that is what I want: send all requests to the radius of dfn.de, except for tu-dortmund.de. whats wrong? proxy.conf: # realm NULL { type= radius authhost= LOCAL accthost= LOCAL } # # tu-dortmund.de lokal behandeln # realm tu-dortmund.de {

RE: looking into local db after Realm Default was found

2008-06-02 Thread Anders Holm
You don't have a realm that matches the domain name you're using to authenticate for : dfn.de //anders -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] g] On Behalf Of Hans Bornemann Sent: 02 June 2008 14:31 To: FreeRadius users mailing list Subject: Re: looking into

Re: looking into local db after Realm Default was found

2008-06-02 Thread Ivan Kalik
Yes, that is what I want: send all requests to the radius of dfn.de, except for tu-dortmund.de. whats wrong? Nothing then. Modules listed in authorize are executed and request is proxied. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

Saludos lista

2008-06-02 Thread Yurkis Isaac Ortiz ®
Saludos lista. Soy nuevo y necesito saber configurar mi freeradius quiero usar freeradius+portslave+ppp Estoy usando debian etch - Yurkis Isaac Ortiz ® Administrador de Red Oficina Territorial de Normalización Stgo de Cuba e_mail: [EMAIL

Re: Freeradius and OpenVpn

2008-06-02 Thread Percy Bloomfield Melgar
Are using mysq? Are you see if you check sentence say User-Password := boss not != for example. Some thing like that hapend to wen I set User-Password = pass the op must be ':=' I hope be useful, Percy Bloomfield Melgar 591 3-3597471, 591 700-72724 [EMAIL PROTECTED] [EMAIL PROTECTED] [EMAIL