Re: error discarding packet

2009-12-24 Thread Alan DeKok
Gary Gatten wrote: I missed the start of this thread, but seems some frustration is building. Q: How do I fix this problem? A: Here's how Q: How do I fix this problem? A: Here's how Q: But it's still not fixed, how do I fix it? A: sigh I understand the frustration of but it doesn't

Re: error discarding packet

2009-12-24 Thread Marinko Tarlac
I had the same problem several times. Once the problem was in external script which was to slow and radius had problems with it. Second time I had a problem with SATA disk because it wasn't recognized correctly and IO performance was terrible... Third time the problem was in slow mysql and few

Access-Request / Mandatory Attributes

2009-12-24 Thread rsg
Hi, I find that FreeRadius server allows access even without either of the mandatory attributes i.e. NAS-Identifier or NAS-IP-Address in the Access Request packet. Is this a deviation from RFC 2865 ? .An Access-Request SHOULD contain a User-Name attribute. It MUST contain either a

Re: Access-Request / Mandatory Attributes

2009-12-24 Thread Alan DeKok
rsg wrote: I find that FreeRadius server allows access even without either of the mandatory attributes i.e. NAS-Identifier or NAS-IP-Address in the Access Request packet. Is this a deviation from RFC 2865 ? No. .An Access-Request SHOULD contain a User-Name attribute. It MUST

Re: Access-Request / Mandatory Attributes

2009-12-24 Thread rsg
Thanks for your prompt response Alan. .An Access-Request SHOULD contain a User-Name attribute. It MUST contain either a NAS-IP-Address attribute or a NAS-Identifier attribute (or both). Can someone clarify this please? It is a requirement on *client* implementations. It has no

Re: Access-Request / Mandatory Attributes

2009-12-24 Thread Alan DeKok
rsg wrote: What do you suggest that a RADIUS server do if it receives a non-compliant packet? Discard it? Reject it? ... Yes, i came across a different vendor that Rejects requests without either of those mandatory attributes. Throw that product in the garbage, and get a real RADIUS

RE: MAC authentication bypass --- How am I supposedto?edit?theusers file to include multiple MAC addresses??

2009-12-24 Thread Difan Zhao
Hey guys, So I finally started configuring this MAC auth bypass thing... I am editing the raddb/policy.conf to include the rewrite_calling_station_id function/module however when I am trying to run the radiusd -X I got this error: /etc/raddb/policy.conf[72]: Parse error in condition at:

Re: MAC authentication bypass --- How am I supposedto?edit?theusers file to include multiple MAC addresses??

2009-12-24 Thread Arran Cudbard-Bell
Difan Zhao wrote: Hey guys, So I finally started configuring this *MAC auth bypass* thing... I am editing the *raddb/policy.conf* to include the *rewrite_calling_station_id* function/module however when I am trying to run the *radiusd –X* I got this error: /etc/raddb/policy.conf[72]:

RE: MAC authentication bypass --- How am I supposedto?edit?theusersfile to include multiple MAC addresses??

2009-12-24 Thread Difan Zhao
Lol Thank you Arran... You found the problem! Now it's good. Thanks again! Guest-tek, Difan Zhao difan.z...@guest-tek.com www.guest-tek.com Office: 403-509-1010 ext 3048 Cell: 403-689-7514 -Original Message- From: freeradius-users-bounces+difan.zhao=guest-tek@lists.freeradius.org