Accounting pakets on layer 2

2012-08-24 Thread Andreas Meyer
Hello! Excuse me please, if this is the wrong list for my question! If I have an AccessPoint working on layer 2 like the ALL0278, how are accounting pakets generated and sent to the radius-server on port 1813. Which application is responsible for generating those pakets? Thank you! Andreas -

Re: Accounting pakets on layer 2

2012-08-24 Thread Andreas Meyer
Hello! Michael Schwartzkopff mi...@schwartzkopff.org wrote: Hello! Excuse me please, if this is the wrong list for my question! If I have an AccessPoint working on layer 2 like the ALL0278, how are accounting pakets generated and sent to the radius-server on port 1813. Which

Re: Abwesenheit (was: Freeradius Installation Challenges)

2012-07-29 Thread Andreas Meyer
Klaus Klein k.kl...@gmx.de wrote: Am 29.07.2012 09:45, schrieb George Innocent: I'm using nano for the editors Take a copy of the backup of your original client.conf and start over with that. (You did save the original before you modified it, did you?) As already said, all you wanted

Re: radacct is not filled up

2012-07-17 Thread Andreas Meyer
Hello! Fajar A. Nugraha l...@fajar.net wrote: On Tue, Jul 17, 2012 at 5:59 AM, Andreas Meyer anme...@anup.de wrote: Hello! I authenticate a users against a mysql-db and everything is fine. Get entries in the radpostauth table but the radacct table stays emtpy, instead the logging

Re: radacct is not filled up

2012-07-17 Thread Andreas Meyer
Hello! Fajar A. Nugraha l...@fajar.net wrote: I wonder if it might have something to do with the buffered-sql in /usr/etc/raddb/sites-available. I made no changes to that file. Re-read the wiki page. If you HAVE read it correctly, you would've seen that you need to change something in

Re: radacct is not filled up

2012-07-17 Thread Andreas Meyer
Hello! Fajar A. Nugraha l...@fajar.net wrote: On Tue, Jul 17, 2012 at 4:08 PM, Andreas Meyer anme...@anup.de wrote: Hm, no luck with this one. I changed buffered.sql to log to sql, but it Did I EVER mention anything about buffered.sql? Was it EVER mentioned in the wiki page

Re: radacct is not filled up

2012-07-17 Thread Andreas Meyer
Fajar A. Nugraha l...@fajar.net wrote: On Tue, Jul 17, 2012 at 4:54 PM, Andreas Meyer anme...@anup.de wrote: I must say I am not sure, what information belongs to post-auth exactly and why. I promise I read the FAQ! FR is very configurable. It's one of those things where the hardest part

radacct is not filled up

2012-07-16 Thread Andreas Meyer
Hello! I authenticate a users against a mysql-db and everything is fine. Get entries in the radpostauth table but the radacct table stays emtpy, instead the logging is done in /usr/var/log/radius/radacct/192.168.1.254 # itx:/usr/var/log/radius/radacct/192.168.1.254 # ll insgesamt 284 -rw---

Re: working with vouchers

2012-07-09 Thread Andreas Meyer
Fajar A. Nugraha l...@fajar.net wrote: On Thu, Jul 5, 2012 at 11:05 PM, Andreas Meyer anme...@anup.de wrote: Is there a big picture somewhere available for the freeradius-server like it is for postfix for example? I want to understand the contiguities between proxiing, outer-tunnel

Re: working with vouchers

2012-07-09 Thread Andreas Meyer
Alan Buxey a.l.m.bu...@lboro.ac.uk wrote: Yrs, if you don't care about security and verification of server cert, then just username and password will work with PEAP. Some clients will throw up warning messages (that users ignore)..messages can be reduced by using a CA that is known by the

Re: working with vouchers

2012-07-05 Thread Andreas Meyer
Hi! alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, Hello! Without considering any security is it possible to hand out a voucher to a client with just the ESSID, the username and the password written down and this client can authenticate to the radiusserver over the authenticator?

Re: working with vouchers

2012-07-05 Thread Andreas Meyer
Fajar A. Nugraha l...@fajar.net wrote: On Thu, Jul 5, 2012 at 3:43 PM, Andreas Meyer anme...@anup.de wrote: Without considering any security is it possible to hand out a voucher to a client with just the ESSID, the username and the password written down and this client can authenticate

a question about the connection to the server

2012-07-04 Thread Andreas Meyer
Hello! If some machine is in the same subnet as the radiusd and the AP, how do I prevent it from sniffing the secret for authentication to the server? Regards Andreas - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Authenication with certifiactes

2012-07-03 Thread Andreas Meyer
Hello! alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, I have no luck with this. I read in some articles to make an AP with Radius-Authentication, one should create cerificates with 'make all' in the certs-directory after editing the ca.cnf and server.cnf and copy the ca.pem to the

Re: Authenication with certifiactes

2012-07-03 Thread Andreas Meyer
of the openSUSE I use and that made it. With the NetworkManager I had this compatibilityproblems described for Windows OIDs. The NetworkManager didn't like the server. Andreas Meyer wrote: Found Auth-Type = EAP +- entering group authenticate {...} [eap] Request found, released from the list [eap

Authenication with certifiactes

2012-07-02 Thread Andreas Meyer
Hello! # radiusd -v radiusd: FreeRADIUS Version 2.1.9, for host i686-pc-linux-gnu I could need some help with authenticating users per certificate to a freeradius server. I created the certificates and copied the ca.pem the testing supplicant. Startet freeradius with radius -X and a local

Re: Authenication with certifiactes

2012-07-02 Thread Andreas Meyer
Hello! alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, 1) you are getting an access-accept - which suggest the client is using the values you mention - that is 'miles' with 'davis45' as the password - hence you are using PEAP or PAP or somesuch and not EAP-TLS certificate I have no luck

Re: A question about port 1646

2004-11-16 Thread Andreas Meyer
Alan DeKok [EMAIL PROTECTED] wrote: Andreas Meyer [EMAIL PROTECTED] wrote: I wanted to use ports 1812 and 1813. If I set port=0 in radiusd.conf, radacct wants to connect to 1646 although I edited /etc/services to use 1813 for radius-acct. I suggest finding out why that's happening

Re: A question about port 1646

2004-11-16 Thread Andreas Meyer
now. -- Andreas Meyer We only do well the things we like doing. - Colette - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: A question about port 1646

2004-11-16 Thread Andreas Meyer
. And it seems that radacct is compiled to use port 1646. My god, excuse my ignorance! I am wondering if I can use freeradius to protect a subnetwork when clients connect to a radiusclient over ethernet or WLAN. -- Andreas Meyer We only do well the things we like doing. - Colette - List info

A question about port 1646

2004-11-15 Thread Andreas Meyer
2.4.20-4GB-athlon (3). Welcome to SuSE Linux 8.2 (i586) - Kernel 2.4.20-4GB-athlon (4). gamma login: gamma login: Why is that so? I tried changing the ports in /etc/services without success. Is there another way to tell freeradius to take port 1813 for accounting? Thank you! -- Andreas Meyer

Re: A question about port 1646

2004-11-15 Thread Andreas Meyer
with port radius-acct 1646/tcp 1646/udp with no luck. sigh... :( Any way to tell radacct to look for port 1813 or should I start radiusd with the old ports? But how? -- Andreas Meyer We only do well the things we like doing. - Colette - List info/subscribe/unsubscribe? See http

Re: A question about port 1646

2004-11-15 Thread Andreas Meyer
Alan DeKok [EMAIL PROTECTED] wrote: Andreas Meyer [EMAIL PROTECTED] wrote: If I enable accounting in acct_users DEFAULT Acct-Status-Type == Start DEFAULT Acct-Status-Type == Stop That doesn't enable accounting. It doesn't do anything. Accounting is enabled by default. ah