Hi!
Alan DeKok wrote:
Dmitry Sergienko wrote:
Please give me some tips how/where to fix this issue. I'm somewhat lost
while debugging this EAP stuff with tunnelling and proxying ;)
It's rather complicated after a while. I'm not sure how it can be
easily debugged...
Added some functions
Hi!
Dmitry Sergienko wrote:
But during proxying handler-request-packet-src_ipaddr.ipaddr.ip4addr
is zero:
I'll try to debug deeper and figure out how to fix this correctly (and
not to break anything else ;)
At last it works. Patch is in attachment.
I'm still not sure if this patch
tips how/where to fix this issue. I'm somewhat lost while debugging this EAP stuff with tunnelling
and proxying ;)
--
Best wishes,
Dmitry Sergienko (SDA104-RIPE)
Trifle Co., Ltd.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Hi!
Alan DeKok wrote:
Dmitry Sergienko wrote:
Config file is the same as default example proxy-inner-tunnel in 2.0.2
release with modified realm name only.
I really don't understand.
1) default config
Configuration from scratch.
on Debian:
cd freeradius-server-2.0.2
dpkg-buildpackage
16:42:06 2008 : Auth: Login incorrect: [EMAIL PROTECTED]/via Auth-Type = EAP] (from client sw-local port 33
cli 00-a9-40-0f-83-a5)
-
--
Best wishes,
Dmitry Sergienko (SDA104-RIPE)
Trifle Co., Ltd.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
100Mbps Full
duplex
request-check_items contain only Proxy-To-Realm AVPair.
Dmitry Sergienko wrote:
Thanks for committing patches.
But I have to return to the question of proxying EAP-PEAP-MS-CHAPv2.
I've spent several nights with gdb, radsniff and xsupplicant to figure
out why authentication
Hi!
Alan DeKok wrote:
Dmitry Sergienko wrote:
Thanks for the tip.
successfully_proxied_request() also needs patching:
Fixed, thanks.
Thanks for committing patches.
But I have to return to the question of proxying EAP-PEAP-MS-CHAPv2. I've spent several
nights with gdb, radsniff
request
Waking up in 6 seconds...
-
List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html
--
Best wishes,
Dmitry Sergienko (SDA104-RIPE)
Trifle Co., Ltd.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
= proxy-inner-tunnel
}
users file is empty at all.
If this doesn't help please share your debug output.
--
Best regards,
Dmitry Sergienko
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Tue Feb 5 14:56:01 2008 : Debug: There was no response configured: rejecting
request 6
Tue Feb 5 14:56:01 2008 : Debug: Found Post-Auth-Type Reject
Tue Feb 5 14:56:01 2008 : Debug: +- entering group REJECT
--
Best wishes,
Dmitry Sergienko (SDA104-RIPE)
Trifle Co., Ltd.
-
List info
Hi!
Alan DeKok wrote:
Dmitry Sergienko wrote:
Does anyone here have working inner tunnel proxying with freeradius 2.0.x?
Still having troubles with doing EAP-PEAP-MSCHAPv2 authorization.
Switched to FreeRadius 2.0.1 from 1.1.7.
I think the issue was introduced recently. Try editing
src
also.
--
Best wishes,
Dmitry Sergienko (SDA104-RIPE)
Trifle Co., Ltd.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
12 matches
Mail list logo