Re: Local Auth if Proxy Auth fails ---OR--- Proxy Auth if Local Auth fails

2011-10-11 Thread Яцко Эллад Геннадьевич (ngs)
Dear Alan! I am beginner in RADIUS. I guessed you talked about sites-available/default because Cisco does not use any realms when sends its packets to the RADIUS. I think it's needed expanding of my task boundaries :-) I want to make Cisco devices authenticate users when ther enter the

Re: Local Auth if Proxy Auth fails ---OR--- Proxy Auth if Local Auth fails

2011-10-11 Thread Alan DeKok
Яцко Эллад Геннадьевич (ngs) wrote: I am beginner in RADIUS. I guessed you talked about sites-available/default because Cisco does not use any realms when sends its packets to the RADIUS. I talked about realms because I wanted to talk about realms. I think it's needed expanding of my task

RE: Local Auth if Proxy Auth fails ---OR--- Proxy Auth if Local Auth fails

2011-10-11 Thread Sergio NNX
Are we in a bad mood? Date: Tue, 11 Oct 2011 08:46:28 +0200 From: al...@deployingradius.com To: freeradius-users@lists.freeradius.org Subject: Re: Local Auth if Proxy Auth fails ---OR--- Proxy Auth if Local Auth fails Яцко Эллад Геннадьевич (ngs) wrote: I am beginner in RADIUS. I

Re: Problems with my radrelay configuration?

2011-10-11 Thread tonimanel
Hi, After append inside modules section of radrelay.conf file this code: detail { detailfile = /var/log/freeradius/radacct/detail detailperm = 0600 dirperm = 0755 locking = no } When I lunch freeradius -X -n radrelay appear this: root@debian:/etc/freeradius# freeradius -X -n radrelay

Re: Local Auth if Proxy Auth fails ---OR--- Proxy Auth if Local Auth fails

2011-10-11 Thread Яцко Эллад Геннадьевич (ngs)
Am I ?! :-) I've just asked some questions.. Maybe stupid (I repeat again I am beginner in RADIUS).. And I still out of knowledge what to-do... Or more exactly: how does it work?... Kind regards, Ellad Yatsko Are we in a bad mood? - List info/subscribe/unsubscribe? See

Re: Problems with my radrelay configuration?

2011-10-11 Thread tonimanel
I have changed the line detailfil that was wrong. I have written this: detailfile = ${radacctdir}/%{Client-IP-Address}/detail-%Y%m%d And the output is: root@debian:/etc/freeradius# freeradius -X -n radrelay FreeRADIUS Version 2.1.10, for host i486-pc-linux-gnu, built on Nov 14 2010 at 20:41:03

Re: Local Auth if Proxy Auth fails ---OR--- Proxy Auth if Local Auth fails

2011-10-11 Thread Alan DeKok
Яцко Эллад Геннадьевич (ngs) wrote: I've just asked some questions.. Maybe stupid (I repeat again I am beginner in RADIUS).. And I still out of knowledge what to-do... Or more exactly: how does it work?... My original answer explained what to do. Follow instructions, or don't ask

Re: Problems with my radrelay configuration?

2011-10-11 Thread Alan DeKok
tonimanel wrote: After append inside modules section of radrelay.conf file this code: ... When I lunch freeradius -X -n radrelay appear this: ... Polling for detail file /var/log/freeradius/radacct/detail Detail listener /var/log/freeradius/radacct/detail state unopened signalled 0 waiting

Re: Problems with my radrelay configuration?

2011-10-11 Thread Alan DeKok
tonimanel wrote: I supposed this too (detail file not exist), so read process fails. So, I should to configure in radiusd.conf the server to write to the detail file. Then in radrelay.conf, the configuration is correct? Now radrelay is configurated to read detail file, ok? I think that this is

Re: [?? Probable Spam] Re: Local Auth if Proxy Auth fails ---OR--- Proxy Auth if Local Authfails

2011-10-11 Thread Яцко Эллад Геннадьевич (ngs)
Dear Alan! I ask you to be more indulgent, I didn't want to anger you. :-) Would you explain how will it work? I really need to understand what is happening, cause I want to do any thing sensibly. Suppose I have perform all your recommendations. Cisco sends Access-Acepts to RADIUS, It receives

RES: Trying to solve a Simultaneous-Use problem

2011-10-11 Thread Nataniel Klug
Marinko, I didn't know how to ask for stalled sessions and I searched for Sim-Use and found nothing useful... So, if you do not want to help, do not answer... -- -Mensagem original- De: freeradius-users-bounces+listas.nata=cnett.com...@lists.freeradius.org

Re: RES: Trying to solve a Simultaneous-Use problem

2011-10-11 Thread Arran Cudbard-Bell
On 11 Oct 2011, at 13:34, Nataniel Klug wrote: Arran, Thanks for your answer. So to test the NAS what should I use? A ping packet in a shell script? Yes. Or an SNMP request. Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki

Re: Problems with my radrelay configuration?

2011-10-11 Thread Alan DeKok
tonimanel wrote: Now, I have configured radiusd.conf with this code: ... That should read from the detail file... And radrelay.conf with this code: listen { ... identity = radrelay What's identity ? I *always* get worried when people do things which aren't necessary. It

Re: [?? Probable Spam] Re: Local Auth if Proxy Auth fails ---OR--- Proxy Auth if Local Authfails

2011-10-11 Thread Alan DeKok
Яцко Эллад Геннадьевич (ngs) wrote: Would you explain how will it work? I really need to understand what is happening, cause I want to do any thing sensibly. My original message explained what was going on. Suppose I have perform all your recommendations. Cisco sends Access-Acepts to

From inner to outer

2011-10-11 Thread Roland Hedberg
Hi! I have the following problem. A module I have written uses the inner tunnel User-Name to find information about the user from an outside source. This user information must be returned in the outer tunnel. Is this doable ? I can think of two ways of doing this: 1) The module while running in

Re: From inner to outer

2011-10-11 Thread Alan DeKok
Roland Hedberg wrote: I have the following problem. A module I have written uses the inner tunnel User-Name to find information about the user from an outside source. This user information must be returned in the outer tunnel. Is this doable ? Yes. I can think of two ways of doing this:

Re: From inner to outer

2011-10-11 Thread Phil Mayers
On 11/10/11 16:08, Roland Hedberg wrote: Hi! I have the following problem. A module I have written uses the inner tunnel User-Name to find information about the user from an outside source. This user information must be returned in the outer tunnel. Is this doable ? Sure. Set a variable in

Re: Problems with my radrelay configuration?

2011-10-11 Thread tonimanel
Thank you for your answer Alan. You have reason. I was probing some definitions inside of configuration, for this reason appears identity... Also I was very lost. I hope to gradually understanding the freeradius configuration because it's very difficult. Now, I am going to probe it with my

Locked account

2011-10-11 Thread Maurice James
How do I get freeradius to deny access based on the ldap attribute nsAccountLock = true? http://g.bfbcs.com/175/pc_Lt%20Lotz.png Description: pc_Lt Lotz image003.jpg- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html