New VM daloradius for freeradius2 is out - just for your information.

2011-08-12 Thread aceror
Hi all! just post from Liran Tal (Daloradius) "Hey everyone, The daloRADIUS Virtual Machine and User Guide which I have been working on for so long are finally available on the daloradius.com blog." I just try it. Working for now!! Lets see tomorrow. I still missing paypal, or visa module But

Re: Home servers in SQL for CoA Proxy

2011-08-12 Thread Alan DeKok
Francois Gaudreault wrote: > Is there a way to list the home servers (so the access switches) into a > sql table (like nas table) intead of proxy.conf? No, sorry. > My goal here is to > proxy the CoA to the NAS without having to manually list all the devices > in proxy.conf, and use Proxy-To-R

Home servers in SQL for CoA Proxy

2011-08-12 Thread Francois Gaudreault
Hi, Is there a way to list the home servers (so the access switches) into a sql table (like nas table) intead of proxy.conf? My goal here is to proxy the CoA to the NAS without having to manually list all the devices in proxy.conf, and use Proxy-To-Realm = %{NAS-IP-Address}. Thanks -- Fran

Re: Freeradius + MySQL + WiFi PEAP authorisation only to a group of users

2011-08-12 Thread Alan DeKok
Lumir Lindovsky wrote: > How do I give access to wifi users who authenticate with username & pass > over PEAP only to a group of users? See the FAQ. You can create a group, and limit them based on group membership. You can use SQL-Group. See doc/rlm_sql Alan DeKok. - List info/subscribe/un

Re: Questions about status counters

2011-08-12 Thread Alan DeKok
Tamás Becz wrote: > 1) Is there some documentation on the values I got there? I of course see > dictionary.freeradius, and the names are pretty self-explanatory, but we all > know devil is in the details :) The values are taken from the SNMP MIBs for RADIUS. See doc/rfc/ > 2) If I understand

Re: Questions about status counters

2011-08-12 Thread Arran Cudbard-Bell
Here might be a start... https://github.com/alandekok/freeradius-server/tree/master/scripts/snmp-proxy -Arran On 12 Aug 2011, at 14:54, Tamás Becz wrote: > Hi, > > I'm trying to collect some statistics about my freeradius servers with > nagios. Before I've been doing this with some perl code

Questions about status counters

2011-08-12 Thread Tamás Becz
Hi, I'm trying to collect some statistics about my freeradius servers with nagios. Before I've been doing this with some perl code digging through the logs, and doing stats (plus generating gnuplot graphs out etc) but I'd rather have something more flexible, so I tought I'd put together some sm

Re: Config for TLS, TTLS and PEAP and subject validation

2011-08-12 Thread Daniel Bertolo
Hi Alan Am 11.08.11 23:13, schrieb Alan DeKok: > The TLS-Client-Cert-Subject is empty. You will need to check for EAP-TLS: > > if ((EAP-Type == EAP-TLS) && \ > (%{TLS-Client-Cert-Subject}" !~ /\/O=MyCompany\//)) { > ... Thank you very much. This works great. Reg

Re: freeradius 2.1.7 PEAP mschapv2 invalid parameter

2011-08-12 Thread Eugene Vihman
The problem persists with escaped username (it's Administrator in UTF-8 in russian): Found Auth-Type = EAP +- entering group authenticate {...} [eap] Request found, released from the list [eap] EAP/mschapv2 [eap] processing type mschapv2 [mschapv2] +- entering group MS-CHAP {...} [mschap] Told to

Re: Freeradius capable of url-redirect

2011-08-12 Thread Arran Cudbard-Bell
On 12 Aug 2011, at 11:28, helloFreeRadius wrote: > have you found the way to conf url-redirect? thank u > Yes... By sending the correct AVP to the NAS... Again with the seriously wanting to block posing from nabble... gr Arran Cudbard-Bell a.cudba...@freeradius.org RADIUS - Half the com

Re: Freeradius capable of url-redirect

2011-08-12 Thread helloFreeRadius
have you found the way to conf url-redirect? thank u -- View this message in context: http://freeradius.1045715.n5.nabble.com/Freeradius-capable-of-url-redirect-tp2807977p4692634.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http:/

Re: freeradius 2.1.7 PEAP mschapv2 invalid parameter

2011-08-12 Thread Alan Buxey
hi, in your debug output you can see the command parts being issued for the authentication, you could try manually cutting and pasting those bits and doing your own manual authentication i'm seeing 'strange' characters in your User-Name - you might be best to ensure that the ntlm_auth command