Re: Fair usage package implementation

2009-05-09 Thread Ming-Ching Tiew
--- On Sat, 5/9/09, Ivan Kalik wrote: > > Yes. You can put if statement before update coa and make it > conditional. > Just like with updating any other list. > OK point gotten. Further to this I have added update coa into preacct, the conditional update coa has no error, but I get a WARNIN

Re: Is PEAP/EAP-MSCHAPv2 with certs a reasonable way to keep untrusted computers off the lan?

2009-05-09 Thread john
> Ah, you weren't mentioning AD. With AD you can exercise reasonable > control. And issuing and installing certificates should't be much of a > problem (read about domain member autoenrolement). You should go for AD > integration: Hi, Ivan. I mentioned AD but it was way back in the first email. To

Re: checking authorization in the duration of connection

2009-05-09 Thread Ivan Kalik
> Sorry for barging into the thread, but something just caught my > attention. We use Mikrotik throughout our network, and have found them > quite useful and with the right hardware, it performs pretty well in > our setup. > > But, there are guys in this forum who are quite frankly, way ahead > tha

Re: Re :checking authorization in the duration of connection

2009-05-09 Thread Ivan Kalik
> I mean if there is a windows vpn server as a NAS for radius server, could > I > set the session limit at the start of the session (at authentication) > and use methods explained in netexpertise article ? > No. Microsoft has no traffic limiting VSAs. And it doesn't support CoA/PoD. In Windows spe

Re: Fair usage package implementation

2009-05-09 Thread Ivan Kalik
> Is it site-available/originate-coa which is what > you are referring to ? I have read it many times. > > Ok, for example, there is a update coa { ..} which > we put it in somewhere in preacct ? > > But I want CoA packet to be sent only upon reaction to > certain conditions. I don't want it t

Re: Fair usage package implementation

2009-05-09 Thread Ming-Ching Tiew
--- On Sat, 5/9/09, Alan DeKok wrote: > From: Alan DeKok > Subject: Re: Fair usage package implementation > To: "FreeRadius users mailing list" > Date: Saturday, May 9, 2009, 12:41 PM > Ming-Ching Tiew wrote: > > Sorry I have quite an idiot here. I have been reading > everything > > radius

Re: Fair usage package implementation

2009-05-09 Thread Alan DeKok
Ming-Ching Tiew wrote: > Sorry I have quite an idiot here. I have been reading everything > radius 2.1.4, but I don't see how this is integrated into > the radiusd server. Am I missing anything ? Read doc/ChangeLog. Look for "coa". > Is this to say > that upon receiving accounting packets, s

Re: checking authorization in the duration of connection

2009-05-09 Thread Nyamul Hassan
Hi, Sorry for barging into the thread, but something just caught my attention. We use Mikrotik throughout our network, and have found them quite useful and with the right hardware, it performs pretty well in our setup. But, there are guys in this forum who are quite frankly, way ahead than myself

Re: Fair usage package implementation

2009-05-09 Thread Ming-Ching Tiew
--- On Fri, 5/8/09, Alan DeKok wrote: > From: Alan DeKok > Subject: Re: Fair usage package implementation > To: "FreeRadius users mailing list" > Date: Friday, May 8, 2009, 11:52 AM > Ming-Ching Tiew wrote: > > I wonder if how such a "package" can be implemented, > > > > > >1. Unli

Re: Re :checking authorization in the duration of connection

2009-05-09 Thread Eric
I mean if there is a windows vpn server as a NAS for radius server, could I set the session limit at the start of the session (at authentication) and use methods explained in netexpertise article ? > How about vpn windows as NAS? > Is that a joke? Windows server would be useless. It can't termin

Re: authentication failed because sqlcounter...

2009-05-09 Thread Nizar Zulmi
i am using freeradius 1.1.7, not that old rite??? i've tried using := operator and cleartext-password but still doesn't work..this bellow is my radcheck table.. ++--++++ | id | UserName | Attribute  | op | Value  | ++--+-

Re: authentication failed because sqlcounter...

2009-05-09 Thread Nizar Zulmi
i am using freeradius 1.1.7, not that old rite??? i've tried using := operator and cleartext-password but still doesn't work..this bellow is my radcheck table.. ++--++++ | id | UserName | Attribute  | op | Value  | ++--+-