Re: proxy question

2011-06-03 Thread Alan DeKok
Doty, Seth wrote: > Currently I have a wireless setup that terminates the outer tunnel > locally then queries AD to get group/user data. This happens for the > realm named after the domain,the default realm, and NULL realm and works > perfectly. What I need to do now is add a new realm (testrealm

Re: Renaming during Machine Authentication

2011-06-03 Thread Alan DeKok
mjonesmcne wrote: > Here is the rest of the debug ... > [eap] EAP/mschapv2 > [eap] processing type mschapv2 > [mschapv2] # Executing group from file /etc/raddb/sites-enabled/inner-tunnel > [mschapv2] +- entering group MS-CHAP {...} > [mschap] No Cleartext-Password configured. Cannot create LM-Pass

Re: Can't get checkrad to be called

2011-06-03 Thread Dan Brisson
Just finished setting up the latest Freeradius - 2.1.10. Checkrad is working. I've replicated the settings from 2.1.7 so I have to think something has changed from 2.1.7 to 2.1.10. I'm running on CentOS with 2.1.7 installed from Yum. My 2.1.10 was built from source on RHEL5. I ultimately

Re: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Jason Frawley
it appears I wont be able to easily upgrade because of the fact its windows based and was downloaded from freeradius.net and their site is not exactly working again but when I was able to get to parts of the page it looks as if they only released one version, so I have and extra rack mount computer

Re: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Gary Gatten
Yeah, that version may help ;). Lots has changed since then, if you can upgrade I would. Else. If you run it in debug mode does it spew what info you want? Maybe you can somehow wrap it with a "tee" process and then massage that output as you wish. From: Jason Frawley [mailto:jfrawle...@gma

Re: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Fajar A. Nugraha
On Sat, Jun 4, 2011 at 5:48 AM, Jason Frawley wrote: > it may help to note-  I am using windows version of FreeRadius ver 1.1.7 r2 The usual reponse would be "upgrade". > > On Fri, Jun 3, 2011 at 3:45 PM, Jason Frawley wrote: >> >> - ADD what information logged (look at radiusd.conf, look for m

Re: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Jason Frawley
it may help to note- I am using windows version of FreeRadius ver 1.1.7 r2 On Fri, Jun 3, 2011 at 3:45 PM, Jason Frawley wrote: > - ADD what information logged (look at radiusd.conf, look for msg) -- > unable to find msg in radiusd.conf file > - log to a NEW file, with another format altogether

Re: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Jason Frawley
- ADD what information logged (look at radiusd.conf, look for msg) -- unable to find msg in radiusd.conf file - log to a NEW file, with another format altogether (see linelog module) -- unable to find anything on linelog module with option one I do see where I can create the detail logs, and they a

Re: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Fajar A. Nugraha
On Sat, Jun 4, 2011 at 2:46 AM, Jason Frawley wrote: > There may be some confusion, I am currently logging auth and accounting > information in seperate folders that are labeled by client ip addresses, but > those are the detail auth logs, I am working with just the radius.log file. > Below is a s

proxy question

2011-06-03 Thread Doty, Seth
Currently I have a wireless setup that terminates the outer tunnel locally then queries AD to get group/user data. This happens for the realm named after the domain,the default realm, and NULL realm and works perfectly. What I need to do now is add a new realm (testrealm)that terminates the eap t

Re: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Jason Frawley
There may be some confusion, I am currently logging auth and accounting information in seperate folders that are labeled by client ip addresses, but those are the detail auth logs, I am working with just the radius.log file. Below is a sample of what I get in the radius log file, notice the from cl

Re: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Fajar A. Nugraha
On Sat, Jun 4, 2011 at 2:19 AM, Jason Frawley wrote: > Sorry I meant to say log the client ip and not the subnet in which its in > eg.  log shows request from 207.32.194.0/23 but I need it to show the > actual ip in which the request came from.  Eg.  207.32.194.4 There was a post sometime ago

RE: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Jason Frawley
Sorry I meant to say log the client ip and not the subnet in which its in eg. log shows request from 207.32.194.0/23 but I need it to show the actual ip in which the request came from. Eg. 207.32.194.4 On Jun 3, 2011 10:57 AM, "Gary Gatten" wrote: > > Huh? It sounds like you already have i

RE: Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Gary Gatten
Huh? It sounds like you already have it reporting the NAS IP. Are you saying you want it to report the "client" IP? Doesn't it already to that in radiusd.log? From: freeradius-users-bounces+ggatten=waddell@lists.freeradius.org [mailto:freeradius-users-bou

Log NAS IP rather than Shortname - PLEASE

2011-06-03 Thread Jason Frawley
I have about 50 routers that are accessing my radius server and I setup the clients.conf with CIDR and left shortnames blank so now it logs the ip address and cidr. What I really need it to do is just report the ip in which the requests came from rather than the shortname... thoughts? Jason Fraw

Re: how apply policy on my ldap users

2011-06-03 Thread motaibi
Please guys i need some help ?? no reply on my post above UP UP UP -- View this message in context: http://freeradius.1045715.n5.nabble.com/how-apply-policy-on-my-ldap-users-tp4449095p4451928.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubs

Re: Renaming during Machine Authentication

2011-06-03 Thread mjonesmcne
Here is the rest of the debug Waking up in 3.3 seconds. rad_recv: Access-Request packet from host 10.152.0.100 port 32819, id=114, length=198 User-Name = "host/TEST-11501.hpsd48.ab.ca" NAS-IP-Address = 10.152.0.100 NAS-Port = 1 NAS-Identifier = "10.152.0.100"

Re: Renaming during Machine Authentication

2011-06-03 Thread mjonesmcne
Here is my debug now I might have to break it up into 2 posts though because of the size FreeRADIUS Version 2.1.10, for host i686-pc-linux-gnu, built on Mar 23 2011 at 11:28:44 Copyright (C) 1999-2009 The FreeRADIUS server project and contributors. There is NO warranty; not even for MERCHANTABILI

Re: Error: User-Name is not the same as MS-CHAP name

2011-06-03 Thread Phil Mayers
On 03/06/11 15:09, Johan Meiring wrote: On 2011/06/03 02:15 PM, Phil Mayers wrote: I'm not downloading a torrent of copyrighted software to fix someone else's problem. As long as you dont get a key, it is legal. This is getting farcical... Not picking on any one specific person here, but

Re: Mac authenticaion failure

2011-06-03 Thread Phil Mayers
On 26/05/11 15:48, pcunha wrote: Hi Everyone, I tried to set up Mac Authentication per the the doc at freeradius.org. Be specific. Which doc? The doc on the wiki: http://wiki.freeradius.org/Mac%20Auth ...contains several examples. Which are you following? - List info/subscribe/unsubscri

Re: Error: User-Name is not the same as MS-CHAP name

2011-06-03 Thread Alan DeKok
Johan Meiring wrote: > As long as you dont get a key, it is legal. No. This list is not the place to discuss non-FreeRADIUS software. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Error: User-Name is not the same as MS-CHAP name

2011-06-03 Thread Johan Meiring
On 2011/06/03 02:15 PM, Phil Mayers wrote: I'm not downloading a torrent of copyrighted software to fix someone else's problem. As long as you dont get a key, it is legal. -- Johan Meiring Cape PC Services CC Tel: (021) 883-8271 Fax: (021) 886-7782 Before acting on thi

Re: Can't get checkrad to be called

2011-06-03 Thread Dan Brisson
On 6/3/2011 9:21 AM, George Chelidze wrote: On 06/03/2011 02:35 PM, Dan Brisson wrote: It really seems like this line in the radutmp "modules" file is not being executed: check_with_nas = yes But from radiusd -X, it does seem to be: It's a configuration option not a command to be executed

Re: Can't get checkrad to be called

2011-06-03 Thread George Chelidze
On 06/03/2011 02:35 PM, Dan Brisson wrote: It really seems like this line in the radutmp "modules" file is not being executed: check_with_nas = yes But from radiusd -X, it does seem to be: It's a configuration option not a command to be executed check_with_nas = yes So, it's there Can y

Re: Error: User-Name is not the same as MS-CHAP name

2011-06-03 Thread Phil Mayers
On 03/06/11 13:10, Paul Harris wrote: On 02/06/11 14:47, Francois Gaudreault wrote: Did you have a chance to look at it? Ironically I'm having trouble finding a windows XP install CD... I have a link to a torrent, just send me a email at pau...@mail.com Or not. I'm not downloading a

RE: Error: User-Name is not the same as MS-CHAP name

2011-06-03 Thread Paul Harris
On 02/06/11 14:47, Francois Gaudreault wrote: >>> >> Did you have a chance to look at it? >Ironically I'm having trouble finding a windows XP install CD... I have a link to a torrent, just send me a email at pau...@mail.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/li

Re: Mac authenticaion failure

2011-06-03 Thread Stanisław Kamiński
What hardware are you using? On 2011-05-26 16:48, pcunha wrote: Hi Everyone, I tried to set up Mac Authentication per the the doc at freeradius.org. The client connects but the users don't. The folowing is the output from the debug mode in freeradius. Thanks for your help. eady to process

Re: Can't get checkrad to be called

2011-06-03 Thread Dan Brisson
No different with only using sql in session { }. It really seems like this line in the radutmp "modules" file is not being executed: check_with_nas = yes But from radiusd -X, it does seem to be: Module: Checking session {...} for more modules to load Module: Linked to module rlm_ra

Re: Can't get checkrad to be called

2011-06-03 Thread Dan Brisson
George, Sorry, I had commented out the simul_verify_query as a troubleshooting step but actually do have it uncommented at this point, but it still won't work. I checked radiusd.conf and found this: # The program to execute to do concurrency checks. checkrad = ${sbindir}/checkrad Re: radut

Re: Freeradius not releasing IPs from pool

2011-06-03 Thread George Chelidze
On 06/01/2011 04:02 PM, Angel L. Mateo wrote: Hello, I have a problem with my pools in freeradius. The problems is that it is not releasing IPs from the pools. At least, not all of them, so after a while my users can't connect because the pool is full. Several quick questions: 1. Are you sure

Re: FreeRadius Support for WiMAX Sub-TLVs of Sub-TLVs

2011-06-03 Thread Johan Meiring
On 2011/06/03 10:07 AM, Alan DeKok wrote: Martin wrote: Did this and it is 3.0.0, but on on the official site there is nothing mention regarding 3.0 version. When is going to be official released 3.0? Perhaps this summer. What hemisphere are you in? :-) -- Johan Meiring Cape PC Serv

Re: FreeRadius Support for WiMAX Sub-TLVs of Sub-TLVs

2011-06-03 Thread Alan DeKok
Martin wrote: > Did this and it is 3.0.0, but on on the official site there is nothing > mention regarding 3.0 version. When is going to be official released > 3.0? Perhaps this summer. > Some people are reticent to install it in production if it is not > official released. The 3.0 pre-relea

Re: Can't get checkrad to be called

2011-06-03 Thread George Chelidze
On 06/03/2011 03:59 AM, Dan Brisson wrote: # simul_verify_query = "SELECT radacctid, acctsessionid, username, \ # nasipaddress, nasportid, framedipaddress, \ # callingstationid, framedprotocol \ # FROM ${acct_table1} \ # WHERE username = '%{SQL-User-Name}' \ # AND acctstoptime IS NULL" as your

Re: Error: User-Name is not the same as MS-CHAP name

2011-06-03 Thread Phil Mayers
On 06/02/2011 10:39 PM, Fajar A. Nugraha wrote: On Thu, Jun 2, 2011 at 9:01 PM, Phil Mayers wrote: On 02/06/11 14:47, Francois Gaudreault wrote: Did you have a chance to look at it? Ironically I'm having trouble finding a windows XP install CD... This might help: Not really. - List in