Ippool giving gateway addresses

2011-10-17 Thread Alejandro Gandara
Hi List, I have two doubts which I couldn't resolv properly. I'll be so pleased if someone could give me a hand. 1º There is any way to configure ippool to give a gateway for each configured pool? 2º How I could check the bind addresses in db.* files? 3º Radiuis-Framed-Routing is used to

Re: Problems with my radrelay configuration?

2011-10-17 Thread tonimanel
Any body can help me? Please!! I need to get a good configuration! Thanks! -- View this message in context: http://freeradius.1045715.n5.nabble.com/Problems-with-my-radrelay-configuration-tp4876089p4909025.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List

Re: Problems with my radrelay configuration?

2011-10-17 Thread Fajar A. Nugraha
On Mon, Oct 17, 2011 at 2:50 PM, tonimanel antoniofernan...@fabergames.com wrote: Any body can help me? Please!! I need to get a good configuration! Step back for a moment. You want to run when you can't even walk. Try answering these questions: (1) Do you REALLY understand what this

Re: EAP Testing - Newbie

2011-10-17 Thread Alan Buxey
hi, ...please dont send eapol_test output - send the output from radiusd -X from the log sent it looks like the client isnt get a response from the server (note the 3 default timeouts at the end) alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Configuring FreeRADIUS to use ntlm_auth for MS-CHAP

2011-10-17 Thread Alan Buxey
Hi, Thanks for that. I had left some previous versions of files in the modules directory not knowing that they are still active. Moving them to another location progressed me to the following error: yes, FreeRADIUS will read ALL files in sites-enabled/ and ALL files in modules/ directory.

RE: EAP Testing - Newbie

2011-10-17 Thread Sergio NNX
/%{Client-IP-Address}/auth-detail-%Y%m%d.log expands to ../var/log/radius/radacct/127.0.0.1/auth-detail-20111017.log ++[auth_log] returns ok [pap] WARNING! No known good password found for the user. Authentication may fail because of this. ++[pap] returns noop ++[mschap] returns noop ++[files

Re: Ippool giving gateway addresses

2011-10-17 Thread Alejandro Gandara
2011/10/17 Fajar A. Nugraha l...@fajar.net On Mon, Oct 17, 2011 at 2:18 PM, Alejandro Gandara agand...@optaresolutions.com wrote: Hi List, I have two doubts which I couldn't resolv properly. I'll be so pleased if someone could give me a hand. 1º There is any way to configure

Re: Ippool giving gateway addresses

2011-10-17 Thread Fajar A. Nugraha
On Mon, Oct 17, 2011 at 4:21 PM, Alejandro Gandara agand...@optaresolutions.com wrote: 2º How I could check the bind addresses in db.* files? try http://wiki.freeradius.org/Rlm_ippool_tool I'd recommend you use rlm_sqlippool instead though. When I use this tool I got users identified by

how to configure

2011-10-17 Thread Harish Mandowara
Dear all, How to configure freeradius server with netgear WNR3500L access point with these three entities. Authentication server (Freeradius)- Access Pint(Netgear)Mobile Terminal (My PC). -- Warm Regards Harish Mandowara -- This message has been scanned for viruses and

Re: EAP Testing - Newbie

2011-10-17 Thread Alan Buxey
hi, your radiusd -X output was not all there... it just stopped. need to see it all to see where/when the fail is occuring. alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: EAP Testing - Newbie

2011-10-17 Thread Sergio NNX
Hi Alan, Thanks for your reply. That's all ... after the following lines: EAP-Message = 0x737420526f6f742043412028 Message-Authenticator = 0x State =

Problem with F5 BigIP accouting : hexadecimal attribute

2011-10-17 Thread Vincent, Fabien
Dear all, I'm using Radius for authenticating admin users on different network equipments. group authorize {...} works fine with rlm_ldap and group management. But I have some problem for accounting on F5 BigIP LTM / GTM. In fact, my radius accounting server is receiving

Re: Problems with my radrelay configuration?

2011-10-17 Thread tonimanel
Thank you for your answer. I am going to follow this guide. I think that there are some points that maybe it isn't necessary for the objective. I can tell you that: 1.- I thought that the achieve of this configuration was to have two services with authentication and accounting data synchronized.

Re: Problems with my radrelay configuration?

2011-10-17 Thread Fajar A. Nugraha
On Mon, Oct 17, 2011 at 6:42 PM, tonimanel antoniofernan...@fabergames.com wrote: Thank you for your answer. I am going to follow this guide. I think that there are some points that maybe it isn't necessary for the objective. I can tell you that: 1.- I thought that the achieve of this

Re: Problems with my radrelay configuration?

2011-10-17 Thread tonimanel
Thanks again with your answer. When you speak about an external mechanism to synchronize user data for authentication, this means that for example, I should to do a mysql replica with this table? I want to get to synchronize both concepts, authentication and accounting data because I want to get

Re: Ippool giving gateway addresses

2011-10-17 Thread Alejandro Gandara
2011/10/17 Fajar A. Nugraha l...@fajar.net On Mon, Oct 17, 2011 at 4:21 PM, Alejandro Gandara agand...@optaresolutions.com wrote: 2º How I could check the bind addresses in db.* files? try http://wiki.freeradius.org/Rlm_ippool_tool I'd recommend you use rlm_sqlippool instead though.

Re: Problem with F5 BigIP accouting : hexadecimal attribute

2011-10-17 Thread Suman Dash
NAS-IP-Address = *[IP address unknown, not corresponding to NAS interfaces] * Did you added your F5 IP address to NAS Table ? Regards Suman * On Mon, Oct 17, 2011 at 4:56 PM, Vincent, Fabien fabien.vinc...@coreye.frwrote: Dear all, ** ** I’m using Radius for authenticating admin users

Re: Multiple NAS freeradius

2011-10-17 Thread Alejandro Gandara
2011/10/4 Arran Cudbard-Bell a.cudba...@freeradius.org On 4 Oct 2011, at 13:32, Alejandro Gandara wrote: Hi list, Im using freeradius 2.1.10 with ldap and I have a doubt. Im testing radius with two NAS , first one an openvpn service and the other one is a switch Procurve. My question

RE: Problem with F5 BigIP accouting : hexadecimal attribute

2011-10-17 Thread Vincent, Fabien
NAS-IP-Address = [IP address unknown, not corresponding to NAS interfaces] * Did you added your F5 IP address to NAS Table ? Yes I have added the F5 IP address, authorize works fine using the SQL NAS Table, but the IP returned by the F5 Accounting packet isn't a valid Self IPs of the

Re: Problem with F5 BigIP accouting : hexadecimal attribute

2011-10-17 Thread Alan DeKok
Vincent, Fabien wrote:\ /Yes I have added the F5 IP address, authorize works fine using the SQL NAS Table, but the IP returned by the F5 Accounting packet isn’t a valid Self IPs of the corresponding F5…/ The NAS-IP-Address attribute can be ANYTHING. It has little or no correspondence to the

setup freeradius to generateng COA

2011-10-17 Thread Alex rsm
Hi, I am trying to setup freeradius to generateng COA after receiving Access-Request packets. Is there any document on how to configure this setting? It seems I am sending Accounting packet to authorization port: After sending ... echo User-Name=test,User-Password=abc123 |

Re: Problem with F5 BigIP accouting : hexadecimal attribute

2011-10-17 Thread Phil Mayers
On 17/10/11 12:26, Vincent, Fabien wrote: F5-Attr-14 = /[Hexa decimal output starting with 0x …]/ This happens when an unknown attribute is found. The attribute is assumed to be type octets and is rendered at hex. */++ ATTRIBUTE F5-Attr-14 14 octets/* This won't help at all. This is

Re: setup freeradius to generateng COA

2011-10-17 Thread Alan Buxey
Hi, look in sites-available read the 'coa' virtual server enable it (link it from sites-enabled or copy) - then run the server. CoA , be default is on port 3799 ... alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Problem with F5 BigIP accouting : hexadecimal attribute

2011-10-17 Thread Vincent, Fabien
Thanks for your replies/help. I set in the dictionary.f5 the following value : ATTRIBUTE F5-Acct 14 string First for the F5 NAS-IP-Address, it's equal to 127.1.1.1, which I suspect a strange behavior of the F5 syslog-ng / audit forwarder. But this is not a

Re: Problem with F5 BigIP accouting : hexadecimal attribute

2011-10-17 Thread Len Conrad
Thanks, but I won't transfer until closer to the expiration date, so please lock it up again. also wanted to make sure somebody was on watch, hadn't been in contact since Don died. Len -- Original Message -- From: Phil Mayers p.may...@imperial.ac.uk

Re: Problem with F5 BigIP accouting : hexadecimal attribute

2011-10-17 Thread Alan Buxey
Hi, add that to the following: VENDOR F5 3375 BEGIN-VENDOR F5 ATTRIBUTE F5-LTM-User-Role 1 integer ATTRIBUTE F5-LTM-User-Role-Universal 2 integer# enable/disable ATTRIBUTE F5-LTM-User-Partition3 string

Framed-IP-Address null value

2011-10-17 Thread Alejandro Gandara
Hello all! Im testing freeradius in a preproduction machine. I've configured It with freeradius + Ldap. At this moment I only need read from ldap these attributes: user, password and Framed-IP-Address to assing an IP to an specific User. The problem cames when i use this: in

Re: Framed-IP-Address null value

2011-10-17 Thread Alan DeKok
Alejandro Gandara wrote: The problem cames when i use this: .. update reply { Framed-IP-Address := %{Client-IP-Address} } That is completely and totally wrong. You are telling the end user that he can use the IP address assigned to the NAS. But if

Re: Framed-IP-Address null value

2011-10-17 Thread Alejandro Gandara
2011/10/17 Alan DeKok al...@deployingradius.com Alejandro Gandara wrote: The problem cames when i use this: .. update reply { Framed-IP-Address := %{Client-IP-Address} } Sorry I meantFramed-IP-Address := %{Framed-IP-Address} That is

Re: Framed-IP-Address null value

2011-10-17 Thread Fajar A. Nugraha
On Mon, Oct 17, 2011 at 11:26 PM, Alejandro Gandara agand...@optaresolutions.com wrote: 2011/10/17 Alan DeKok al...@deployingradius.com Alejandro Gandara wrote: The problem cames when i use this: ..  update reply {                         Framed-IP-Address := %{Client-IP-Address}    

Re: Framed-IP-Address null value

2011-10-17 Thread Alan Buxey
Hi, �update reply { � � � � � � � � � � � � Framed-IP-Address := %{Client-IP-Address} � � � � � � � � } Sorry I meant� � Framed-IP-Address := %{Framed-IP-Address} which, in your debug evaluated to NULL. are you sure its set/known at that point? alan - List