Re: Active Directory/freeradius/enterasys - combination

2009-10-13 Thread Alan DeKok
t.rob...@heidelberg.de wrote: ... > Sending Access-Challenge of id 191 to 172.16.255.101 port 49169 > EAP-Message = > 0x010700b519003082a52b18d9963104cec8ab3f3ddc453b55e1519bcf57d5178ca7fbc8 > 1d20727b3d75c92c438dbafd9a5544e5443ad544f16869af57ef84883eebc730362387c9 > e6357c18fcb15a8e862e2b6

Re: xsupplicant - freeradius EAP-TTLS PAP Access-Reject

2009-10-13 Thread Nagendra KS
Thanks Ivan, Commenting out DEFAULT has worked for me. Thanks, Nagendra. On Tue, Oct 13, 2009 at 8:52 PM, Ivan Kalik wrote: > > freeradius version: FreeRADIUS Version 1.0.1 > > That is seriously outdated. Upgrade. > > > Following is the output of freeRadius. > > > ... > > users: Matched DE

RE: raddebug before 2.1.4

2009-10-13 Thread ZHANG Gina
Got it. Thanks! Gina -Original Message- From: freeradius-users-bounces+gina.zhang=alcatel-lucent@lists.freeradius. org [mailto:freeradius-users-bounces+gina.zhang=alcatel-lucent@lists.fre eradius.org] On Behalf Of Alan DeKok Sent: Tuesday, October 13, 2009 3:05 PM To: FreeRadius

Re: Munin Graphs

2009-10-13 Thread Alan Buxey
Hi, > I've installed the freeradius_auth plugin > > added to plugins.conf > > [freeradius*] > user root > > But still I get the following error when the plugin is run... > > radmin: Failed connecting to /usr/local/var/run/radiusd/radiusd.sock: > Permission denied edit the munin/plugins/freer

Munin Graphs

2009-10-13 Thread Neville
Hi, I've installed the freeradius_auth plugin added to plugins.conf [freeradius*] user root But still I get the following error when the plugin is run... radmin: Failed connecting to /usr/local/var/run/radiusd/radiusd.sock: Permission denied Any ideas Running direct from root works fine, ju

Re: error on log radius

2009-10-13 Thread Alisson
thanks for the information, i tougth that was a error beacause I never got this message thank you 2009/10/13 Alan Buxey > Hi, > > i get this message > > > > Info: rlm_sql (sql): received Acct On/Off packet > > ??? your FR server received an accounting packet and > your system is configured to

Re: error on log radius

2009-10-13 Thread Alan Buxey
Hi, > i get this message > > Info: rlm_sql (sql): received Acct On/Off packet ??? your FR server received an accounting packet and your system is configured to use sql in the accounting section - whats the error? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.ht

RE: FreeRadius, Cisco WLC, configuration

2009-10-13 Thread James Taylor
Jalil, Refer to this page as it will be extremely helpful! http://www.cisco.com/en/US/products/ps6307/products_tech_note09186a0080870334.shtml James Taylor From: freeradius-users-bounces+jtaylor=fcip@lists.freeradius.org [mailto:freeradius-users-bounces+jtaylor=fcip@lists.freeradius.or

FreeRadius, Cisco WLC, configuration

2009-10-13 Thread Aziz, Jalil
Hello all, I need help with FreeRadius and Cisco's WLC. Anyone ever did this deployment before? Please help. Regards, Jalil - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: raddebug before 2.1.4

2009-10-13 Thread Alan DeKok
ZHANG Gina wrote: > Where to get a copy of raddebug? It's included in all recent versions of the server. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

error on log radius

2009-10-13 Thread Alisson
i get this message Info: rlm_sql (sql): received Acct On/Off packet -- Att. Alisson F. Gonçalves Sistemas de Informação - UFGD - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: raddebug before 2.1.4

2009-10-13 Thread ZHANG Gina
Where to get a copy of raddebug? Thanks, Gina -Original Message- From: freeradius-users-bounces+gina.zhang=alcatel-lucent@lists.freeradius. org [mailto:freeradius-users-bounces+gina.zhang=alcatel-lucent@lists.fre eradius.org] On Behalf Of Alan DeKok Sent: Tuesday, October 13, 200

wpa/wpa2 on logs

2009-10-13 Thread Sergio Belkin
Hi, Is there a way to log if a supplicant is using either wpa or wpa2? Thanks in advance! -- -- Open Kairos http://www.openkairos.com Watch More TV http://sebelk.blogspot.com Sergio Belkin - - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Freeradius + OpenLdap + WindowsXP(Wifi)

2009-10-13 Thread Garber, Neal
> Have any idea ? Where can i find the solution ? > When i trying connect freeradius server with wireless over > access point i get this error: > Tue Oct 13 12:00:45 2009 : Debug: rlm_eap_peap: Had sent TLV failure. > User was rejcted rejected earlier in this session. The error you're lookin

Freeradius + OpenLdap + WindowsXP(Wifi)

2009-10-13 Thread Kleber Larroyd
Freeradius 1.1.7 Openldap Windows XP SP2 (WPA-TKIP / Protected EAP (PEAP)) Have any idea ? Where can i find the solution ? When i trying connect freeradius server with wireless over access point i get this error: Tue Oct 13 12:00:45 2009 : Debug: Finished request 7 Tue Oct 13 12:00:45 2009 :

Re: Odd proxy authentication failures

2009-10-13 Thread Michael Schlies
I don't suppose anyone has any ideas on this issue I posted, do they? If I missed something in the documentation for relaying, etc. it would be greatly appreciated if someone could point it out to me. Michael Schlies - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: raddebug before 2.1.4

2009-10-13 Thread Alan DeKok
marco perugini wrote: > hi list! my simple question is: is there a way to use the > powerfull/wonderfull raddebug script with version 2.1.1? or the only way > is to start the server with -x option? It can't be used with 2.1.1. There are other changes inside of the server to work with raddebug.

Re: Authenticating access via caller-id or username/password

2009-10-13 Thread John Ward
Hi There, the authentication will take place based only on the calling station id. in one scenario: the users use usernames and passwords. in the second scenario, a device is authenticated on the calling-station-id as it has no username or password. the device is put into a different part of the

raddebug before 2.1.4

2009-10-13 Thread marco perugini
hi list! my simple question is: is there a way to use the powerfull/wonderfull raddebug script with version 2.1.1? or the only way is to start the server with -x option? thanks and regards, marco -- 4IT S.r.l. Marco Perugini | system adm

Re: xsupplicant - freeradius EAP-TTLS PAP Access-Reject

2009-10-13 Thread Ivan Kalik
> freeradius version: FreeRADIUS Version 1.0.1 That is seriously outdated. Upgrade. > Following is the output of freeRadius. > ... > users: Matched DEFAULT at 164 > users: Matched test...@mynet.net at 235 > modcall[authorize]: module "files" returns ok for request 5 > modcall: group aut

xsupplicant - freeradius EAP-TTLS PAP Access-Reject

2009-10-13 Thread Nagendra KS
Hi All, Supplicant tries authentication with EAP-TTLS, TLS tunnel is established properly but Radius sends Access-Reject. Following are the xsupplicant.conf, eap.conf and radius output. radiusd.conf is not changed. It would be great if anyone could help in solving this issue or identify it. Tha

RE: Improving Auth-Rate

2009-10-13 Thread ZHANG Gina
Hi, When you have 100 auths/sec rate, what protocol are you using? Thanks, Gina -Original Message- From: freeradius-users-bounces+gina.zhang=alcatel-lucent@lists.freeradius.org [mailto:freeradius-users-bounces+gina.zhang=alcatel-lucent@lists.freeradius.org] On Behalf Of Micha

Re: Active Directory/freeradius/enterasys - combination

2009-10-13 Thread Ivan Kalik
> Now I need a username/password auth against AD. > Ntlm-auth works very well. > > If I activate ldap in /etc/raddb/modules: > The server don't do ldap. > > What is my mistake ? > > First the server should do a ntlm-auth and then check an ldap-group in > AD. How does that ldap-group check look lik

Re: perl_rlm and differences FR 1 and 2

2009-10-13 Thread John Dennis
On 10/13/2009 01:57 AM, Alan DeKok wrote: David Jones wrote: Thanks to some handy hints in here, I've had some success with rlm_perl. But (and there is always a but) I've been happily developing against 2.x but have just discovered I need to actually use 1.x because of RHEL. You can ins

Re: Authenticating access via caller-id or username/password

2009-10-13 Thread Ivan Kalik
> I now have to authenticate users based on username and password in one > instance That's easy, but ... > and solely calling-station-id in another. ... what does that mean? Each user can call from a specific callerID? Each user can call from a specific list of callerIDs? Every user can call fro

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-13 Thread Alisson
Hi, I still have the problems, I changed some variables, but the problem continues 2009/10/9 Marinko Tarlac > This is not database list but here what you can do: > - install sysbench and do some tests with your current settings > - tunning-primer.sh (http://www.day32.com/MySQL/tuning-primer.

Re: acct_postgresql+auth_ldap

2009-10-13 Thread José Johnny RANDRIAMAMPIONONA
understood 2009/10/13 Rakotomandimby Mihamina > 10/09/2009 04:05 PM, José Johnny RANDRIAMAMPIONONA:: > >> Thank u guys! >> > > Please keep us in touch. > and if you kept some history of what you've done, > I am interested in. > > -- > Architecte Informatique chez Blueline/Gulfsat: > Admin

RE: NAS ? What is the best option

2009-10-13 Thread Santiago Balaguer García
Hi, I am using MikroTik and I am vry satisfied. However, it is not a easy device to configura and understand all its different configurations. I do not understand why you have to ue POD packets. If you do correctly the configurations and you have you want to offer your users, I think you

Authenticating access via caller-id or username/password

2009-10-13 Thread John Ward
Good Day, I've an interesting question. I currently authenticate users via caller-id for a static ip delivery system. I have had to change the "sql_user_name" to the "calling-station-id" attribute so that i can match the entries to so called usernames in the MYSQL database This is working and wo

dynamic crl fetching

2009-10-13 Thread console23
Hello, is or will there be a feature called "dynamic crl fetching" in FreeRADIUS 2.x ? Strongswan for example is able to fetch actual crls via http and ldap. In the wiki i only could get information about defining local stored pem files. regards, Simon - List info/subscribe/unsubscribe? See htt

Re: over 30 radiusd processes

2009-10-13 Thread Craig Campbell
.freeradius.org/list/users.html __ Information from ESET Smart Security, version of virus signature database 4501 (20091012) __ The message was checked by ESET Smart Security. http://www.eset.com __ Information from ESET Smart Security, version of virus signature dat

Active Directory/freeradius/enterasys - combination

2009-10-13 Thread T.Robers
auth-detail-%Y%m%d -> /var/log/radius/radacct/172.16.255.101/auth-detail-20091013 [auth_log] /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands to /var/log/radius/radacct/172.16.255.101/auth-detail-20091013 [auth_log] expand: %t -> Tue Oct 13 11:59:35 2009 ++[auth_log

Re: Improving Auth-Rate

2009-10-13 Thread Ivan Kalik
> I m trying to improve the auth rate. > the auth-rate i m getting now is 3 i.e number of mobile units that can > authenticate per minute is 3. > So how can i increase it to 5 or something? > Which part of the code should i focus on? What modules are you using? Chances are that problem comes from

Re: Improving Auth-Rate

2009-10-13 Thread Michael Schwartzkopff
Am Dienstag, 13. Oktober 2009 12:18:24 schrieb kachin Agarwal: > Hi, > I m trying to improve the auth rate. > the auth-rate i m getting now is 3 i.e number of mobile units that can > authenticate per minute is 3. So how can i increase it to 5 or something? > Which part of the code should i focus on

Re: Improving Auth-Rate

2009-10-13 Thread kachin Agarwal
Hi, I m trying to improve the auth rate. the auth-rate i m getting now is 3 i.e number of mobile units that can authenticate per minute is 3. So how can i increase it to 5 or something? Which part of the code should i focus on? Thanx From cricket scores to your friends. Try the Yahoo

Re: Improving Auth-Rate..

2009-10-13 Thread Alan DeKok
kachin Agarwal wrote: > hi, >If i want to improve the auth-rate which part of the code should i > focus on? Improving it from... what? Why do you want to improve it? "Hi, I want to fix the server so it's better. How do I do that" That question is nearly content-free. Alan DeKok. -

Re: NAS ? What is the best option

2009-10-13 Thread Ivan Kalik
> I know that this list is not connected with any hardware vendor but I > see that every couple days someone cries here NAS problems... > > I use Mikrotik and I'm not satisfied (duplicated packets, does not > support POD correctly , etc) > > Also, yesterday I see that Cisco can be pain in the

Improving Auth-Rate..

2009-10-13 Thread kachin Agarwal
hi,    If i want to improve the auth-rate which part of the code should i focus on? Keep up with people you care about with Yahoo! India Mail. Learn how. http://in.overview.mail.yahoo.com/connectmore- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html