Re: IP-Assignment with sqlippool based on nas-ip-address

2009-02-02 Thread Sebastian Heil
] expand: /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d - /var/log/radius/radacct/10.98.6.95/auth-detail-20090202 [auth_log] /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands to /var/log/radius/radacct/10.98.6.95/auth-detail-20090202 [auth_log

Re: invalid Message-Authenticator! (Shared secret is incorrect.)

2009-02-02 Thread tnt
Could it be the problem?: radius server is in 10.10.10.0/24 and the nas is in the 192.168.1.1/27 the packets bridged, the nas can ping the radius server... can the different mask be a problem? No. Shared secret is wrong. Have you retyped it both on radius server and on the NAS? WARNING:

RE: chap authentication and freeradius

2009-02-02 Thread gf fg
Hi users!! Here i post my freeradius -X 0, for host i486-pc-linux-gnu, built on Nov 14 2008 at 11:57:03 Copyright (C) 1999-2008 The FreeRADIUS server project and contributors. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. You may redistribute copies

RE: chap authentication and freeradius

2009-02-02 Thread gf fg
THZ Users My problem was that i never configurated the file in site-enable called default!!! Very very thz From: litlle_cra...@hotmail.com To: freeradius-users@lists.freeradius.org Subject: RE: chap authentication and freeradius Date: Mon, 2 Feb 2009 13:26:10 -0200 Hi users!! Here i

Re: invalid Message-Authenticator! (Shared secret is incorrect.)

2009-02-02 Thread Hegedus Gabor
t...@kalik.net wrote: Could it be the problem?: radius server is in 10.10.10.0/24 and the nas is in the 192.168.1.1/27 the packets bridged, the nas can ping the radius server... can the different mask be a problem? No. Shared secret is wrong. Have you retyped it both on radius server

Re: invalid Message-Authenticator! (Shared secret is incorrect.)

2009-02-02 Thread Johan Meiring
Hegedus Gabor wrote: t...@kalik.net wrote: Could it be the problem?: radius server is in 10.10.10.0/24 and the nas is in the 192.168.1.1/27 the packets bridged, the nas can ping the radius server... can the different mask be a problem? No. Shared secret is wrong. Have you retyped it

radius web managment

2009-02-02 Thread Mr Little Crazzy
Someone has installed dialup admin or daloradius ?? I have installed diaul up admin , but my problem is that not list the user conecct. Which is the best ?? and someone has an install guide for install each of one _ Adelántate a

Re: [UKLAN] feature request

2009-02-02 Thread Alan DeKok
Hans-Peter Fuchs wrote: Hello Alan, freeradius-2.1.1 created the socket with 'radiusd' as owner and freeradius-2.1.3 throw error: Error: We do not own /var/run/radiusd/radius1.sock because it created it with owner root. This is a bug in 2.1.3 that will be fixed in 2.1.4. Alan DeKok.

Re: invalid Message-Authenticator! (Shared secret is incorrect.)

2009-02-02 Thread Alan DeKok
Hegedus Gabor wrote: Hi I have a problem: I get this message *invalid Message-Authenticator! (Shared secret is incorrect.) * But I checked the key and it equals. The shared secret is wrong. What is the problem? clients.conf: client 192.168.1.10 { secret = test

RE: radius web managment

2009-02-02 Thread Mr Little Crazzy
did you could configure Daloradius ?? Because i have this error when i try to login Database connection error Error Message: DB Error: connect failed Debug: [nativecode=Access denied for user 'root'@'localhost' (using password: NO)] ** mysql://root:@127.0.0.1/radius

Re: radius web managment

2009-02-02 Thread Marinko Tarlac
You need to learn basic things before you proceed with installation. Choose two words from your error message and google. You'll see that your username/pass combination is not correct for your database. This doesn't have anything with FR user list. Mr Little Crazzy wrote: did you could

RE: radius web managment

2009-02-02 Thread tnt
did you could configure Daloradius ?? Because i have this error when i try to login Database connection error Error Message: DB Error: connect failed Debug: [nativecode=Access denied for user 'root'@'localhost' (using password: NO)] ** mysql://root:@127.0.0.1/radius

Re: Cannot get value of config item with \

2009-02-02 Thread tnt
I'd like to check if a request that I received from a radius server will be proxied back to that same server resulting in a proxy loop. The way I see things there is no other way to find out to which server the request will be proxied to. Create a table proxy with information form proxy.conf.

Re: mschav2 can't get connected

2009-02-02 Thread Alan DeKok
saman saman wrote: Hi..Can anyone help me. I can't get client connect to radius server. any suggestion on how to fix it..appreciated. Here the radius output: ... EAP-Message = 0x0101000501 Your supplicant is sending an empty identity. This isn't permitted. Alan DeKok. - List

Re: Cannot get value of config item with \\

2009-02-02 Thread Matej Vadnjal
On Monday 02.02.2009 10:37:59 Alan DeKok wrote: Matej Vadnjal wrote: I'm having trouble getting the value of auth_pool of a realm. Realms are defined as regular expressions matched by suffix module against the domain portion of users username. Ok... *why* are you doing that? if

Re: invalid Message-Authenticator! (Shared secret is incorrect.)

2009-02-02 Thread Alan DeKok
Hegedus Gabor wrote: Could it be the problem?: radius server is in 10.10.10.0/24 and the nas is in the 192.168.1.1/27 the packets bridged, the nas can ping the radius server... can the different mask be a problem? Perhaps you should believe the answers on this list. and when I try

Re: IP-Assignment with sqlippool based on nas-ip-address

2009-02-02 Thread tnt
I'm afriad, but this won't work in my environment. I will need a different subnetmask. Can you explain why do you think 255.255.255.255 netmask won't work for you. Do you know how that netmask works? Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

Re: Cannot get value of config item with \\

2009-02-02 Thread Alan DeKok
Matej Vadnjal wrote: I'm having trouble getting the value of auth_pool of a realm. Realms are defined as regular expressions matched by suffix module against the domain portion of users username. Ok... *why* are you doing that? if (%{config:realm[%{Realm}].auth_pool} =~

RE: chap authentication and freeradius

2009-02-02 Thread tnt
+- entering group authorize {...} ++[preprocess] returns ok [chap] Setting 'Auth-Type := CHAP' ++[chap] returns ok ++[mschap] returns noop [suffix] No '@' in User-Name = ale, looking up realm NULL [suffix] No such realm NULL ++[suffix] returns noop [eap] No EAP-Message, not doing EAP ++[eap]

Re: radius web managment

2009-02-02 Thread orion
for me daloradius , if you can spend some monety you may go with radmanager ( ~ 99eur ) 2009/2/2 Mr Little Crazzy litlle_cra...@hotmail.com Someone has installed dialup admin or daloradius ?? I have installed diaul up admin , but my problem is that not list the user conecct. Which is the

invalid Message-Authenticator! (Shared secret is incorrect.)

2009-02-02 Thread Hegedus Gabor
Hi I have a problem: I get this message *invalid Message-Authenticator! (Shared secret is incorrect.) * But I checked the key and it equals. What is the problem? clients.conf: client 192.168.1.10 { secret = test shortname=blablabla } thx - List info/subscribe/unsubscribe? See

Re: chap authentication and freeradius

2009-02-02 Thread A . L . M . Buxey
Hi, What is wrong ??? well, the debug clearly shows these lines: [chap] login attempt by ale with CHAP password [chap] Cleartext-Password is required for authentication ++[chap] returns invalid Failed to authenticate the user. Login incorrect (rlm_chap: Clear text password not available):

Re: tag support in Free Radius

2009-02-02 Thread Alan DeKok
Marlon Duksa wrote: Hi - does anyone know how send taged attributes from FreeRadius. I'm including the tag number with a colon after the attribute but not sure if this is correct (the last two attributes): DEFAULT User-Name =~ ([a-z]+):([0-9]+)[^a-z]+([a-z]+):([0-9]+)$, Auth-Type :=

RE: chap authentication and freeradius

2009-02-02 Thread gf fg
yes that was my problem! I posted it! To: freeradius-users@lists.freeradius.org Subject: RE: chap authentication and freeradius Date: Mon, 2 Feb 2009 17:02:09 +0100 From: t...@kalik.net +- entering group authorize {...} ++[preprocess] returns ok [chap] Setting 'Auth-Type := CHAP'

Re: invalid Message-Authenticator! (Shared secret is incorrect.)

2009-02-02 Thread tnt
I think the problem is in the AP(nas), not in the radius. Sorry, no more questions about it . I think the CISCO 861 router(new) has something problem. I would seriously doubt that. Your server would be much bigger suspect. It can't find openSSL either. Ivan Kalik Kalik Informatika ISP - List

Re: Installation Problem

2009-02-02 Thread Alan DeKok
Marcelo Freitas wrote: Hello everybody, I searched the archive but I couldn't find any other topic similar. Can someone help me with the installation of FreeRadius 2.1.3 on my Slackware box ? ... /home/other/freeradius-server-2.1.3/src/main/modules.c:1037: undefined reference to

radmanager

2009-02-02 Thread Mike Strider
Orion, do you have a link to radmanager? Thanks .. Mike - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

mschav2 can't get connected

2009-02-02 Thread saman saman
Hi..Can anyone help me. I can't get client connect to radius server.any suggestion on how to fix it..appreciated.Here the radius output:Going to the next request Waking up in 4.9 seconds. User-Name = john NAS-IP-Address = 0.0.0.0 Framed-MTU = 1488

Re: radius web managment

2009-02-02 Thread Phil Meech
I doubt you've configured the database connection for daloradius. In it's management folder, I think there's a file called daloradius.conf (if not search for it) edit it with your database login details and radius DB name. I think its all self explanatory in the file. 2009/2/2 Mr Little Crazzy

Re: invalid Message-Authenticator! (Shared secret is incorrect.)

2009-02-02 Thread Hegedus Gabor
Alan DeKok wrote: Hegedus Gabor wrote: Hi I have a problem: I get this message *invalid Message-Authenticator! (Shared secret is incorrect.) * But I checked the key and it equals. The shared secret is wrong. What is the problem? clients.conf: client 192.168.1.10 { secret

Re: IP-Assignment with sqlippool based on nas-ip-address

2009-02-02 Thread tnt
That should happen only if IP allocation has expired (see lease-duration in sqlippool.conf). There is another allocate-find query that issues random IPs. Hmmm, maybe there is another problem in my config. I tried two requests within ten seconds. Attached you'll find the debug. During the

Re: Cannot get value of config item with \\

2009-02-02 Thread Alan DeKok
Matej Vadnjal wrote: On Monday 02.02.2009 10:37:59 Alan DeKok wrote: I'd like to check if a request that I received from a radius server will be proxied back to that same server resulting in a proxy loop. Hmm... if a server proxies requests to you that it *should* have handled itself, it is

Re: radmanager

2009-02-02 Thread Gunza
Anybody have Radius Manager copy of download link. If you have please send me. Thanks, Gunza --- On Mon, 2/2/09, Mike Strider mstri...@atmc.net wrote: From: Mike Strider mstri...@atmc.net Subject: radmanager To: 'FreeRadius users mailing list' freeradius-users@lists.freeradius.org Date: Monday,

Re: Cannot get value of config item with \\

2009-02-02 Thread Matej Vadnjal
On Monday 02.02.2009 12:37:09 Alan DeKok wrote: Hmm... if a server proxies requests to you that it *should* have handled itself, it is seriously broken. It also happens when users mistype their user names. Suppose you have a user: u...@a.orga.tld. orgA has a radius server that proxies

Re: Certificate Provisioning for EAP-TLS Networks

2009-02-02 Thread Anders Holm
There are other solutions around as well to distribute and manage client side certificates. Not cheap, but they do exist. //anders - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Cannot get value of config item with \\

2009-02-02 Thread Alan DeKok
Matej Vadnjal wrote: Great. I did not know about %{home_server:ipaddr}. However there are still two issues: - %{client:ipaddr} does not expand to anything on my end but Client-IP-Address works. If %{client:ipaddr} doesn't work, it's because there's no ipaddr entry in the relevant