How to Change Source Port for

2010-11-12 Thread Stefan A.
I'm using copy-acct-to-home-server . Freeradius sends any acct request using the source port of 1814 My client sent me a trace, where wireshark is claiming duplicate requests. We have to handle 1000+ Requests per second. Is it possible to change the source port settings to get a new source port

Re: How to Change Source Port for

2010-11-12 Thread Alan Buxey
Hi, Freeradius sends any acct request using the source port of 1814 My client sent me a trace, where wireshark is claiming duplicate requests. We have to handle 1000+ Requests per second. Is it possible to change the source port settings to get a new source port for every request? you

Re: freeradius and Cisco VPN IPSEC profiles authentication

2010-11-12 Thread Alan DeKok
Jevos, Peter wrote: Hi Alan, , thanks , I’ve read it but it’s too complicated and I’m missing more examples of configurations The raddb directory *does* come with examples. If anybody help me with the syntax and code location with this issue: Sorry, but: 1) the unlang documentation

Radius Client password not accepted

2010-11-12 Thread Azam Zia
Hi, I am using free radius for communication between asterisk voip server and database. I have everything setup on same machine which has Centos 5.4. My problem is that when i send request from client to server the radius password is not accepted, also when i see radius packets in wireshark

Radreply Attributs full lists

2010-11-12 Thread morocon
Hi every one, Could someone point me to the place i could find the entire list of available attribut that could be send to a user via radreply (or radgroupreply)? i- have been digging a while and only found WISPR-Bandwidth-Max-Down and frame things. i'm pretty sure there is more than that.

Re: Radreply Attributs full lists

2010-11-12 Thread Alan DeKok
morocon wrote: Hi every one, Could someone point me to the place i could find the entire list of available attribut that could be send to a user via radreply (or radgroupreply)? See the dictionary files. There are nearly 5K attributes defined. But most of those are irrelevant.

Re: Radius Client password not accepted

2010-11-12 Thread Alan DeKok
Azam Zia wrote: I am using free radius for communication between asterisk voip server and database. I have everything setup on same machine which has Centos 5.4. My problem is that when i send request from client to server the radius password is not accepted, What does that mean? also

Output from Exec-Program-Wait in users file

2010-11-12 Thread Craig Campbell
Hi, am migrating from an ancient radius install to FreeRADIUS Version 2.1.8 The system uses a custom authentication binary which we access from the users file via, DEFAULT NAS-IP-Address == 192.168.1.100, Auth-Type := Accept, Simultaneous-Use := 1 Exec-Program-Wait =

Re: Logging ntlm authentication

2010-11-12 Thread schilling
Thanks. Could you please share the perl scripts and the corresponding configuration in radiusd.conf like authorize and post-auth section related to these logs? Schilling On Wed, Nov 10, 2010 at 10:04 PM, Garber, Neal neal.gar...@iberdrolausa.com wrote: Could you please summarize what you

Re: Output from Exec-Program-Wait in users file

2010-11-12 Thread Craig Campbell
__ Information from ESET Smart Security, version of virus signature database 5612 (2010) __ The message was checked by ESET Smart Security. http://www.eset.com __ Information from ESET Smart Security, version of virus signature database 5614 (20101112

RE: freeradius and Cisco VPN IPSEC profiles authentication

2010-11-12 Thread Jevos, Peter
Thank you phill, that's great help, but it still doesn't work as it should. Now I don't know how should I adjust the users file : ) I used if ((NAS-IP-Address == 1.1.1.1) %{mschap:NT-Domain} = vipdomainuser)) { update control { Auth-Type := ntlm_auth_vip

Re: freeradius and Cisco VPN IPSEC profiles authentication

2010-11-12 Thread Alan DeKok
Jevos, Peter wrote: Thank you phill, that's great help, but it still doesn't work as it should. Now I don't know how should I adjust the users file : ) You don't. The messages on this list should make it *very* clear that updating the authorize section is all that is necessary. With this

RE: freeradius and Cisco VPN IPSEC profiles authentication

2010-11-12 Thread Jevos, Peter
As a hint, if you don't implement a rule for a different NT-Domain, then the rules for that different NT-Domain won't be applied. Because they don't exist. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Thank you Alan , it makes sense. But it

Re: freeradius and Cisco VPN IPSEC profiles authentication

2010-11-12 Thread Alan DeKok
Jevos, Peter wrote: Thank you Alan , it makes sense. But it doesn't solve my problem (1) Edit your responses. It shows consideration for other people (2) pick one problem at a time. Changing the problem midway in a conversation makes it look like you don't care about the solution to the