Re: PEAP/TTLS and Client certificates

2010-12-04 Thread Alan DeKok
rdeboer wrote: I already enabled said option, the only problem is that this doesn't enforce the use of PEAP with a client certificate, as the TLS module is enabled and configured, it allows you to log in with just a client certificate using TLS. What I want is to enforce the use of not just

Re: Assign VLAN

2010-12-04 Thread Alan DeKok
Rangel, Luciano wrote: I Success authentication but the switch not assign vlan 200 to client port as log below: *Why the switch taking the VLAN 0?* Because the switch is ignoring the VLAN in the Access-Request. PS. I tested sending attribute with Cisco ACS and ran There's no magic

Meraki Access Points Login incorrect for SHA-Password

2010-12-04 Thread danodemano
Alright, I'm going to try my best to explain what's going on here. I have a Meraki wireless access point I am trying to get configured to work with RADIUS. I have my freeradius server up and running with two other access points just fine. However, I cannot get it to work right with the Meraki

Re: Meraki Access Points Login incorrect for SHA-Password

2010-12-04 Thread Alan Buxey
Hi, Sat Dec 4 09:21:54 2010 : Auth: Login OK: [testing] (from client Meraki port 0 via TLS tunnel) Sat Dec 4 09:21:54 2010 : Auth: Login OK: [testing] (from client Meraki port 0 cli 00-00-00-00-00-02) Sat Dec 4 09:22:24 2010 : Auth: Login incorrect: [test2] (from client Meraki port 0 via

Re: Meraki Access Points Login incorrect for SHA-Password

2010-12-04 Thread Alan DeKok
danodemano wrote: As requested, here is the debug output with one failed login from the Meraki AP and one successful login from radtest, both using the same username/password. Thanks! The entire point of the debug log is for you to *READ IT*. If this is too hard, paste the output into

Re: Meraki Access Points Login incorrect for SHA-Password

2010-12-04 Thread danodemano
That page (http://deployingradius.com/documents/protocols/compatibility.html) would have been very useful to have had going into this. I did read the debug log actually but I wasn't able to make heads or tails out of it. The page you gave though was extremely useful, since it shows that MS-CHAP

syntax to add mac addresses of users file

2010-12-04 Thread Viirydiianah Robles
hello! i have ubuntu 10.4 and freeradius-server-2.1.10 Recently i made some changes to the users file, to be able to register users via their MAC addresses in which use the following syntax : jesssi cleartext-password :=chispas service-type= framed-user, framed-protocol =ppp, #

Re: Need help Configuring Radius and Ldap

2010-12-04 Thread James Winter
The above log doesn't look like authentication; rather it's authorization. If you want your LDAP module instance to authenticate, too, call it from the 'authenticate' section? I do include ldap in my authenticate section of sites-enabled/default, do i need to include any other lines

Re: syntax to add mac addresses of users file

2010-12-04 Thread yzy-oui-fi
if it is for a chillispot or coova nas, then you should add 00-17-37-FA-B2-EB User-Password := password Le samedi 04 décembre 2010 à 13:35 -0600, Viirydiianah Robles a écrit : hello! i have ubuntu 10.4 and freeradius-server-2.1.10 Recently i made some changes to the users file, to be