May I only use rlm_ldap to authenticate against Active Directory? (without samba + winbind + ntlm_auth)

2010-03-01 Thread Tong Anh Quan
Hi all, Can someone give me a confirmation? Details below: - In modules/ldap, I configures: server = 10.128.28.3 identity = cn=anonbinduser,dc=domain,dc=com password = xx basedn = dc=domain,dc=com filter = (sAMAccountName=%{%{Stripped-User-Name}:-%{User-Name}}) - In

Re: May I only use rlm_ldap to authenticate against Active Directory? (without samba + winbind + ntlm_auth)

2010-03-01 Thread Phil Mayers
On 03/01/2010 09:14 AM, Tong Anh Quan wrote: Hi all, Can someone give me a confirmation? Details below: - In modules/ldap, I configures: - In modules/pap, I changed the auto_header option to yes. - In eap.conf, + Set the default_eap_type = mschapv2 in peap section No, sorry. You cannot

Conflicting packets

2010-03-01 Thread rihad
Hi, We have FreeRADIUS 2.1.3 servicing four Cisco NASses, which in turn service hundreds of PPPoE clients. rlm_perl with a custom written script is used for authorization/accounting, performing at about 10 auth requests/sec on a Dell PowerEdge 2950 box. At times, when a NAS is rebooted,

Re: Conflicting packets

2010-03-01 Thread Alan DeKok
rihad wrote: We have FreeRADIUS 2.1.3 servicing four Cisco NASses, which in turn service hundreds of PPPoE clients. rlm_perl with a custom written script is used for authorization/accounting, performing at about 10 auth requests/sec on a Dell PowerEdge 2950 box. That is *incredibly* slow.

Re: Conflicting packets

2010-03-01 Thread rihad
Alan DeKok wrote: However, if you want to work around the problem, set max_requests to something like 128000. The server will use more RAM, but it will make progress. But I'm not seeing this line at times requiring operator interference: Info: WARNING: Please check the configuration file.

Re: Conflicting packets

2010-03-01 Thread Alan Buxey
Hi, Some current settings: max_request_time = 6 cleanup_delay = 10 max_requests = 1024 max_servers = 5 #threads are used not enough threads around to do heavy work. i'd suggest that you you increase the max_servers (and start_servers and max_spare_servers) to eg 128 you may then need to

RE: duplicate sessions

2010-03-01 Thread Santiago Balaguer García
I think you need to analyse more the accounting request because the MAC and IP address would be different. Check the attributes framedipaddress and calledstationid in Accountig request. Date: Sun, 28 Feb 2010 20:56:16 +0400 From: na...@ultel.net To: freeradius-users@lists.freeradius.org

Re: Conflicting packets

2010-03-01 Thread Alan DeKok
rihad wrote: But I'm not seeing this line at times requiring operator interference: Info: WARNING: Please check the configuration file. The value for 'max_requests' is probably set too low. I'm only seeing the Received conflicting packet lines. Well... then changing max_requests likely

Re: duplicate sessions

2010-03-01 Thread Ramon J. Castillo
As a random thought . Aren't these interim accounting messages hence Radius (40) Acct-Status-Type = '3' From: Santiago Balaguer García santiago...@hotmail.com To: Lista de correo RADIUS freeradius-users@lists.freeradius.org Sent: Mon, March 1, 2010 3:53:47

simultaneous-use doc

2010-03-01 Thread J Brandon Polley
I am trying to understand the simultaneous-use docI am having trouble with a part that says:Note that you need to add the Simultaneous-Use parameter to the check item (first line), not the reply item, using the ':=' operator.I am not sure where to add the Simultaneous-Use parameter. Does it go

Re: simultaneous-use doc

2010-03-01 Thread Alan DeKok
J Brandon Polley wrote: I am trying to understand the simultaneous-use doc I am having trouble with a part that says: Note that you need to add the Simultaneous-Use parameter to the check item (first line), not the reply item, using the ':=' operator. I am not sure where to add the

LDAP groups and attributes

2010-03-01 Thread Jethro Carr
hi all, I have setup a FreeRadius server which is authenticating against an OpenLDAP database. It's all working very nicely and I have it setup with radius attributes being stored inside the LDAP database for each user. However, what would be nice, would be to have the ability to store radius

Re: LDAP groups and attributes

2010-03-01 Thread John Dennis
On 03/01/2010 03:55 PM, Jethro Carr wrote: hi all, I have setup a FreeRadius server which is authenticating against an OpenLDAP database. It's all working very nicely and I have it setup with radius attributes being stored inside the LDAP database for each user. However, what would be nice,

Can a wpa_supplicant talk to a Free Radius server without a NAS in between?

2010-03-01 Thread rchinnapu
Hi, My requirement is to test scalability of my Server software that hosts Free Radius Server. I want to see how many wpa supplicant requests it can handle via EAP-TLS. 1. Can a wpa_supplicant talk to a Free Radius server without a NAS in between? I just want to see how many requests my Free

WPA supplicant

2010-03-01 Thread R C
hi, is there any wpa supplicant out there that can generate multiple seperate sessions at the same time? i have wpa_supplicant, but it will generate only 1 session per interface. I need to generate 1000's of such wpa client requests going to the free radius server. Any help is appreciated.

Cisco Not counted traffic

2010-03-01 Thread Andrew Paternoster
HI List Has anyone have any hints how to not count peering traffic for a customer? E.G. not count traffic to and from other customers on the same network. I thought you could do this with a profile from Cisco but i cannot find the info about it anymore. Thanks Andrew Paternoster Senior