Re: FR2 - proxying inner tunnel

2008-02-18 Thread Dmitry Sergienko
Hi! Alan DeKok wrote: Dmitry Sergienko wrote: Please give me some tips how/where to fix this issue. I'm somewhat lost while debugging this EAP stuff with tunnelling and proxying ;) It's rather complicated after a while. I'm not sure how it can be easily debugged... Added some functions

Re: FR2 - proxying inner tunnel

2008-02-18 Thread Dmitry Sergienko
Hi! Dmitry Sergienko wrote: But during proxying handler-request-packet-src_ipaddr.ipaddr.ip4addr is zero: I'll try to debug deeper and figure out how to fix this correctly (and not to break anything else ;) At last it works. Patch is in attachment. I'm still not sure if this patch

Re: FR2 - proxying inner tunnel

2008-02-17 Thread Dmitry Sergienko
tips how/where to fix this issue. I'm somewhat lost while debugging this EAP stuff with tunnelling and proxying ;) -- Best wishes, Dmitry Sergienko (SDA104-RIPE) Trifle Co., Ltd. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FR2 - proxying inner tunnel

2008-02-15 Thread Dmitry Sergienko
Hi! Alan DeKok wrote: Dmitry Sergienko wrote: Config file is the same as default example proxy-inner-tunnel in 2.0.2 release with modified realm name only. I really don't understand. 1) default config Configuration from scratch. on Debian: cd freeradius-server-2.0.2 dpkg-buildpackage

Re: FR2 - proxying inner tunnel

2008-02-14 Thread Dmitry Sergienko
16:42:06 2008 : Auth: Login incorrect: [EMAIL PROTECTED]/via Auth-Type = EAP] (from client sw-local port 33 cli 00-a9-40-0f-83-a5) - -- Best wishes, Dmitry Sergienko (SDA104-RIPE) Trifle Co., Ltd. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FR2 - proxying inner tunnel

2008-02-12 Thread Dmitry Sergienko
100Mbps Full duplex request-check_items contain only Proxy-To-Realm AVPair. Dmitry Sergienko wrote: Thanks for committing patches. But I have to return to the question of proxying EAP-PEAP-MS-CHAPv2. I've spent several nights with gdb, radsniff and xsupplicant to figure out why authentication

Re: FR2 - proxying inner tunnel

2008-02-12 Thread Dmitry Sergienko
Hi! Alan DeKok wrote: Dmitry Sergienko wrote: Thanks for the tip. successfully_proxied_request() also needs patching: Fixed, thanks. Thanks for committing patches. But I have to return to the question of proxying EAP-PEAP-MS-CHAPv2. I've spent several nights with gdb, radsniff

Re: PEAP mschapv2 Proxy not working.

2008-02-06 Thread Dmitry Sergienko
request Waking up in 6 seconds... - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Best wishes, Dmitry Sergienko (SDA104-RIPE) Trifle Co., Ltd. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PEAP mschapv2 Proxy not working.

2008-02-06 Thread Dmitry Sergienko
= proxy-inner-tunnel } users file is empty at all. If this doesn't help please share your debug output. -- Best regards, Dmitry Sergienko - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

FR2 - proxying inner tunnel

2008-02-05 Thread Dmitry Sergienko
Tue Feb 5 14:56:01 2008 : Debug: There was no response configured: rejecting request 6 Tue Feb 5 14:56:01 2008 : Debug: Found Post-Auth-Type Reject Tue Feb 5 14:56:01 2008 : Debug: +- entering group REJECT -- Best wishes, Dmitry Sergienko (SDA104-RIPE) Trifle Co., Ltd. - List info

Re: FR2 - proxying inner tunnel

2008-02-05 Thread Dmitry Sergienko
Hi! Alan DeKok wrote: Dmitry Sergienko wrote: Does anyone here have working inner tunnel proxying with freeradius 2.0.x? Still having troubles with doing EAP-PEAP-MSCHAPv2 authorization. Switched to FreeRadius 2.0.1 from 1.1.7. I think the issue was introduced recently. Try editing src

Re: Terminate EAP-PEAP client connection at FreeRadius Proxy and proxy(forward) request as PAP

2008-02-01 Thread Dmitry Sergienko
also. -- Best wishes, Dmitry Sergienko (SDA104-RIPE) Trifle Co., Ltd. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html