Re: Adding Vendor Specific Attribute to the Access-Accept

2011-05-02 Thread normal ozone
Sorry for the late reply. I found the reason why the attributes I added where not included in the reply list. Those attributes are used by the servers internally (Range: 1000-1199) They do not go to the reply attributes list. When I tried the attributes from other vendors like 3Com it worked.

Re: Mikrotik-Rate-Limit issue

2011-05-02 Thread speedlnx
The value for my test user is the follow: 512k/2048k 512k/2048k 192k/960k 8/8 1 128k/128k The mikrotik documentation say: "Mikrotik-Rate-Limit - Datarate limitation for clients. Format is: rx-rate[/tx-rate] [rx-burst-rate[/tx-burst-rate] [rx-burst-threshold[/tx-burst-threshold] [rx-burst-time[/

Re: Adding Vendor Specific Attribute to the Access-Accept

2011-05-02 Thread Alan DeKok
normal ozone wrote: > I found the reason why the attributes I added where not > included in the reply list. Those attributes are used by the servers > internally (Range: 1000-1199) > They do not go to the reply attributes list. This is documented, yes. > My new question is can you suggest an a

Re: Mikrotik-Rate-Limit issue

2011-05-02 Thread Alan DeKok
speedlnx wrote: > Hello, i'm migrating from freeradius 1.x to freeradius 2.1.10 on debian. > I've replicated all the configuration i have on the old radius to the new > and I import a dump of the mysql database on the new mysql server but i've > an issue when i try to authenticate my users: Edit

Renewal of certificats

2011-05-02 Thread Wegener, Norbert
Certificates tend to expire and have to be renewed on the freeradius server. This is annoying and I would like to automate the renewal process by e.g. using something like sscep. Although I got an initial certificate from an AD ca, renewal does not seem to work. Is there a tool out there to solv

Re: freeradius 2.1.10 WARNING: Internal sanity check failed

2011-05-02 Thread joanroldan
I have grabbed the 2.1.11 from git.freeradius.org, and unfortunally I get the same warning: Debug: WARNING: !! Debug: WARNING: !! EAP session for state 0xc729a88ac72ab1dd did not finish! Debug: WARNING: !! Please read http://wiki.

ERROR in the EAP/PEAP test of eapol_test

2011-05-02 Thread xuyu
Hi ! I meet a ERROR in the test of EAP/PEAP " radtest sqluser 123 localhost 1812 testing123 " is OK ,I just delete the # before 'eap' in radiusd.conf and default files. the test eapol_test -c peap.txt -s testing123 my peap.txt is network={ eap=PEAP eapol_flags=0 key_mgmt=IEE

EAP: method process -> ignore=FALSE methodState=MAY_CONT decision=FAIL

2011-05-02 Thread xuyu
Hi ! I meet a ERROR in the test of PEAP "eapol_test -c peap.txt -s testing123 my peap.txt is network={ eap=PEAP eapol_flags=0 key_mgmt=IEEE8021X identity="sqluser" password="123" ca_cert="/usr/local/freeradius/etc/raddb/certs/ca.pem" phase2="auth=MS

Re: Multiple MACs per Network

2011-05-02 Thread John Corps
wow i totally overlooked that, many thanks Aaran! I have it setup and working perfectly! Many many thanks again. The sql was wrong in your post, missing some quotes or something so the working code was, my complete authorize section: authorize { preprocess rewrite_calling_station_i

Re: ERROR in the EAP/PEAP test of eapol_test

2011-05-02 Thread Alan Buxey
Hi, >Hi ! I meet a ERROR in the test of EAP/PEAP >" radtest sqluser 123 localhost 1812 testing123 " is OK >�,I just delete the # before 'eap' in radiusd.conf and default files. >the test �eapol_test -c peap.txt -s testing123 you are using SQL as the user storage? you havent enabled

Re: Adding Vendor Specific Attribute to the Access-Accept

2011-05-02 Thread Alan Buxey
Hi, >I found the reason why the attributes I added where not >included in the reply list. Those attributes are used by the servers >internally (Range:  1000-1199) >They do not go to the reply attributes list. > >When I tried the attributes from other vendors like 3Com it worke

Re: Mac Auth - Timeout Connecting WiFi

2011-05-02 Thread John Corps
I am still racking my brains over this...I am pointing more and more at the AP but not sure why for some reason it works on a test ubuntu server and not my debian server...I have been testing it based on ethernet mac auth using the radius section on a switch and the debian server and ubuntu server

Re: Multiple MACs per Network

2011-05-02 Thread Arran Cudbard-Bell
Yeah I missed out a bunch of things, well done for figuring it out . Would you mind dumping out the schema of your table, and I can add it and the below snippet to the wiki for future users? Thanks, Arran On May 2, 2011, at 6:51 AM, John Corps wrote: > wow i totally overlooked that, many thanks

Help with freeradius 2.1 with Mikrotik parameter

2011-05-02 Thread Michell
Hello people, I just did an installation with debian squeeze freeradius / freeradius-mysql 2.1.10 + dfsg-2. He had previously debian Etch with freeradius 1.1.1-3 installed and running normally. I made corrections to the layout settings in the current package, the service starts normally. But wh

Re: Help with freeradius 2.1 with Mikrotik parameter

2011-05-02 Thread Michell
Sorry ... yet answered this same question yesterday. Re: Mikrotik-Rate-Limit issue -> http://lists.freeradius.org/pipermail/freeradius-users/2011-May/msg8.html I added the $INCLUDE dictionary.mikrotik and resolved this error. Thanks! 2011/5/2 Michell > Hello people, > > I just did an inst

Freeradius, bind addresses, and multihoming

2011-05-02 Thread Gary T. Giesen
I've compiled freeradius with the --with-udpfromto directive. Everything works as expected when I bind to all IPs: listen { ipaddr = * port = 1812 type = auth } listen { ipaddr = * port = 1813 type = acct } However, if I specify multiple IPs to bind to

Re: Freeradius, bind addresses, and multihoming

2011-05-02 Thread Tanjil Ahmed
Dear All why radius is not bind auto MAC from user in first time use?like mikrotik user manager have this option... is there any way? Thanks in Advance On Tue, May 3, 2011 at 3:20 AM, Gary T. Giesen wrote: > I've compiled freeradius with the --with-udpfromto directive. > Everything works

ldap server connection timeout

2011-05-02 Thread Daniel Davidson
My new wireless network tested great, but now that I have rolled it out to the entire building, I get error messages like: Mon May 2 15:15:06 2011 : Error: rlm_ldap: ldap_search() failed: Timed out while waiting for server to respond. Please increase the timeout. And when these trigger, near

Re: Mikrotik-Rate-Limit issue

2011-05-02 Thread speedlnx
Thank you. It works now! -- View this message in context: http://freeradius.1045715.n5.nabble.com/Mikrotik-Rate-Limit-issue-tp4363178p4365873.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Radius proxy implementation

2011-05-02 Thread d...@hotmail.com
Hello... I am new to freeradius and I am hoping someone can give me some help with a little project. The architecture is as follows: RADIUS SERVER -freeRadius-Radius client The radius client is sending Authentications and accounting requests to freeRadius. For

Re: Radius proxy implementation

2011-05-02 Thread Fajar A. Nugraha
On Tue, May 3, 2011 at 9:45 AM, d...@hotmail.com wrote: > Hello... > > I am new to freeradius and I am hoping someone can give me some help with a > little project.  The architecture is as follows: > > RADIUS SERVER -freeRadius-Radius client > > The radius client is

Re: Radius proxy implementation

2011-05-02 Thread d...@hotmail.com
Thanks for your quick reply... In order to store the accounting information, do I need to execute an external script? With my little knowledge of freeRadius at the moment, I have a vague idea on how to forward the packets, but I have no clue yet on how to do the mysql part you mentioned. Could

Re: Radius proxy implementation

2011-05-02 Thread Fajar A. Nugraha
On Tue, May 3, 2011 at 10:08 AM, d...@hotmail.com wrote: > Thanks for your quick reply... > > In order to store the accounting information, do I need to execute an > external script? No > > With my little knowledge of freeRadius at the moment, I have a vague idea on > how to forward the packets,