Postpaid configuration for all

2012-08-28 Thread Murat K
Dear All, I have all my users postpaid. How can I configure freeradius that all of them are postpaid? I heard there is a centralbase parameter that should be postpaid but I could not find how to do it. Best regards, Murat May the Force be with you. Han Solo (Star Wars) - List

Re: Postpaid configuration for all

2012-08-28 Thread Alan DeKok
Murat K wrote: I have all my users postpaid. How can I configure freeradius that all of them are postpaid? I heard there is a centralbase parameter that should be postpaid but I could not find how to do it. You will need to read the documentation and configure it. There is no

Re: Postpaid configuration for all

2012-08-28 Thread Fajar A. Nugraha
On Tue, Aug 28, 2012 at 1:20 PM, Murat K srvrmu...@gmail.com wrote: I have all my users postpaid. How can I configure freeradius that all of them are postpaid? Nothing I heard there is a centralbase parameter that should be postpaid Ask whomever you heard it from, because it's not true.

Re: Users on the multiple APs

2012-08-28 Thread Dagia Dorjsuren
I configured it using huntgroup with mysql in authorize section as below. update request {     Huntgroup-Name := %{sql:select groupname from radhuntgroup where nasipaddress=\%{NAS-IP-Address}\}     } but I have a question about reply message. How to configure that if the user's

Re: Postpaid configuration for all

2012-08-28 Thread Murat K
The gsm operator we are working with has their ggsn updated. Now they are requesting charging data postpaid in accept reply which is same for all. I know we can set sn_rulebase=postpaid in users file but firewall is also using it and it is risky to do it. Is there another way to do it? They do

Re: Users on the multiple APs

2012-08-28 Thread Fajar A. Nugraha
On Tue, Aug 28, 2012 at 1:54 PM, Dagia Dorjsuren dagmi...@yahoo.com wrote: but I have a question about reply message. How to configure that if the user's huntgroup is zone1 and that user login through zon2, the reply message will have to be You are not in zone2? Short answer: don't bother.

Re: Postpaid configuration for all

2012-08-28 Thread Fajar A. Nugraha
On Tue, Aug 28, 2012 at 2:02 PM, Murat K srvrmu...@gmail.com wrote: The gsm operator we are working with has their ggsn updated. Now they are requesting charging data postpaid in accept reply which is same for all. You need to understand basic concepts of radius. If you're asking what's the

Re: Postpaid configuration for all

2012-08-28 Thread Alan DeKok
Murat K wrote: The gsm operator we are working with has their ggsn updated. Now they are requesting charging data postpaid in accept reply which is same for all. I know we can set sn_rulebase=postpaid in users file but firewall is also using it and it is risky to do it. Is there another way

Radius server failure

2012-08-28 Thread Marko Eremija
Hi all! I had a problem with Radius server on Saturday, and after a lot of searching I have not found an appropriate answer on the Web. I will be submitting the log file that contains the problem that I have been working on. Aug 25 19:59:39 aai radiusd[12649]: TLS_accept: error in SSLv3

Re: Radius server failure

2012-08-28 Thread Alan DeKok
Marko Eremija wrote: Hi all! I had a problem with Radius server on Saturday, and after a lot of searching I have not found an appropriate answer on the Web. I will be submitting the log file that contains the problem that I have been working on. Aug 25 19:59:39 aai radiusd[12649]:

rlm_perl and dynamic_clients

2012-08-28 Thread Steven Eksteen
Hi, I was wondering how would I use Packet-Src-IP-Address using Perl for Dynamic Clients. I thought it might be part of the RAD_REQUEST hash. If some direction could be made as to setting FreeRADIUS-Client-Shortname, FreeRADIUS-Client-Secret, etc. too I would be very grateful. I already have Perl

brief window of opportunity to log in via windows

2012-08-28 Thread Brian Gold
Hi all, I've got freeradius 2.1.10 running PEAP/MS-CHAP. Everything seems to be working fine, but we've noticed a bit of an issue with our Windows clients. It seems that after selecting our SSID for the first time, they are prompted for their username password. Once those are entered they get

Re: brief window of opportunity to log in via windows

2012-08-28 Thread Phil Mayers
On 28/08/12 14:22, Brian Gold wrote: Hi all, I've got freeradius 2.1.10 running PEAP/MS-CHAP. Everything seems to be working fine, but we've noticed a bit of an issue with our Windows clients. It seems that after selecting our SSID for the first time, they are prompted for their username

Re: rlm_perl and dynamic_clients

2012-08-28 Thread Alan DeKok
Steven Eksteen wrote: I was wondering how would I use Packet-Src-IP-Address using Perl for Dynamic Clients. I thought it might be part of the RAD_REQUEST hash. It's not, but you can do: server dynamic_client_server { authorize { update request {

Re: rlm_perl and dynamic_clients

2012-08-28 Thread Steven Eksteen
Thank you. Much appreciated On Tue, Aug 28, 2012 at 4:14 PM, Alan DeKok al...@deployingradius.com wrote: Steven Eksteen wrote: I was wondering how would I use Packet-Src-IP-Address using Perl for Dynamic Clients. I thought it might be part of the RAD_REQUEST hash. It's not, but you can

RE: Radius server failure

2012-08-28 Thread Marko Eremija
Thanks, this helpa a lot. -Original Message- From: freeradius-users-bounces+marko.eremija=amres.ac...@lists.freeradius.org [mailto:freeradius-users-bounces+marko.eremija=amres.ac.rs@lists.freeradius. org] On Behalf Of Alan DeKok Sent: Tuesday, August 28, 2012 12:37 PM To: FreeRadius users

VMware View 5.1 smsotp authentication with multiple realms [WAS: Re: Yeah, it works !!]

2012-08-28 Thread Thomas Glanzmann
Hello Joël, jodan@otpradius:~/work/smsotpd$ ./pap_challenge_request.pl Enter username: dsp1A00113 Enter password: server response type = Access-Challenge (11) Enter otp: 89003 server response type = Access-Accept (2) Yeah, it works  !! The step 1 is achieved :o) that is good to hear.

Bug/Enhancement request: Race condition with short-term accounting (FreeRadius 2.1.10)

2012-08-28 Thread Matthias Nagel
Hello everybody, if two accounting messages for the same session are sent by the authenticator very quickly, the messages may be processed by the radius server in the wrong order. This results into two sessions being accounted instead of one. The second phantom session stays open for ever,

request_dequeue problems (recent 3.0, when home-server stalls)

2012-08-28 Thread Brian Julin
I'm currently hunting a problem that causes a recent checkout of FR3.0 to abort but which does not seem to be affecting an older revision (April 8th or so) of FR3.0 on another box. I do have a couple small in-house patches applied but they should probably not be relevant. The issue seems to

Re: Bug/Enhancement request: Race condition with short-term accounting (FreeRadius 2.1.10)

2012-08-28 Thread Alan DeKok
Matthias Nagel wrote: if two accounting messages for the same session are sent by the authenticator very quickly, the messages may be processed by the radius server in the wrong order. This results into two sessions being accounted instead of one. The second phantom session stays open for

Re: request_dequeue problems (recent 3.0, when home-server stalls)

2012-08-28 Thread Alan DeKok
Brian Julin wrote: I'm currently hunting a problem that causes a recent checkout of FR3.0 to abort but which does not seem to be affecting an older revision (April 8th or so) of FR3.0 on another box. I do have a couple small in-house patches applied but they should probably not be relevant.

Re: Bug/Enhancement request: Race condition with short-term accounting (FreeRadius 2.1.10)

2012-08-28 Thread Fajar A. Nugraha
On Wed, Aug 29, 2012 at 4:11 AM, Alan DeKok al...@deployingradius.com wrote: Matthias Nagel wrote: 5) Thread #2 terminates first and the accounting stop message is written to the PostgreSQL database. The SQL UPDATE statement fails, because there is no entry for this session that could be

Re: Bug/Enhancement request: Race condition with short-term accounting (FreeRadius 2.1.10)

2012-08-28 Thread Matthias Nagel
Hello, Am Dienstag 28 August 2012, 23:11:57 schrieb Alan DeKok: Matthias Nagel wrote: if two accounting messages for the same session are sent by the authenticator very quickly, the messages may be processed by the radius server in the wrong order. This results into two sessions being

Re: Bug/Enhancement request: Race condition with short-term accounting (FreeRadius 2.1.10)

2012-08-28 Thread Arran Cudbard-Bell
Yes yes RADIUS vendors should go die in a big fiery pit somewhere. 1) Verify your NAS supports the Class attribute correctly (http://www.ietf.org/rfc/rfc2865.txt 5.25) 2) Implement the policies in raddb/policy.d/accounting (master:HEAD) 3) Submit patch to add unique index constraint on

Re: Bug/Enhancement request: Race condition with short-term accounting (FreeRadius 2.1.10)

2012-08-28 Thread Arran Cudbard-Bell
On 28 Aug 2012, at 23:05, Matthias Nagel matthias.h.na...@gmail.com wrote: Hello, Am Dienstag 28 August 2012, 23:11:57 schrieb Alan DeKok: Matthias Nagel wrote: if two accounting messages for the same session are sent by the authenticator very quickly, the messages may be processed by