Configuring L2tp forwarding based on suffix?

2007-08-28 Thread Garry Glendown
uot;vpdn:ip-addresses=10.221.1.34" Cisco-AVPair = "vpdn:l2tp-tunnel-password=secret" just the "reject" seems to point towards something that's still missing ... what is it??? Loggfile also still says the auth is unsuccessful: Tue Aug 28 22:33:14 2007 : Auth: Login inc

Re: Return values for rlm_exec scripts

2007-01-10 Thread Garry Glendown
Thor Spruyt wrote: >>> Session-Timeout := `%{exec:/bin/echo 200}` > I use exec_program_wait, try having a look at that. ... which doesn't return a value if I'm not mistaken ... !? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Return values for rlm_exec scripts

2007-01-09 Thread Garry Glendown
Garry Glendown wrote: > Hi, > > I'm trying to configure dynamic values in the users-file, which works > fine using the rlm_expr module. Anyway, due to some more complicated > expressions that can not be formed using rlm_expr, I tried to set up an > external script that

Return values for rlm_exec scripts

2007-01-08 Thread Garry Glendown
Hi, I'm trying to configure dynamic values in the users-file, which works fine using the rlm_expr module. Anyway, due to some more complicated expressions that can not be formed using rlm_expr, I tried to set up an external script that will return the value I need ... only problem is: I can't

auto-expiring accounts w/ FreeRadius

2006-03-02 Thread Garry Glendown
Hi, I've been asked to set up an authentication system with automatically expiring user access ... so, once the user first loggs in, and a certain time (like e.g. 24 hours) goes by, the account is supposed to be deleted. I recon based on MySQL authentication this should be possible with FreeR

Stripping part of the login before authentication?

2006-02-05 Thread Garry Glendown
Hi, we have multiple ways of getting connections, all in the format [EMAIL PROTECTED] Is it possible to define something in FreeRadius to just compare the part before the "#" and authenticate based on that? Tnx,-gg - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/u

Fallback ?

2004-11-08 Thread Garry Glendown
Question - in order to get some basic fallback running, I was thinking about setting up some kind of mechanism where one FreeRadius was operating in proxy mode, querying our two radius servers, and in case both failed to answer, would deliver some kind of fallback authentication (like, always O

Checking users file before activation ...

2004-11-04 Thread Garry Glendown
Hi, we are doing our users file administration through another front end, which enters both automatic as well as manually edited entries to the users file. Every now and then, we have the problem that a typo in manual entries either stops freeradius itself, or disables the wrong entry. Neither

OT: L2TP from Max to Cisco ...

2004-09-08 Thread Garry Glendown
Hi, I'm trying to configure our Max2000 access router to forward all incoming connections to a Cisco router via L2TP ... the connection itself seems to be forwarded (i.e., Cisco debug shows an L2TP tunnel being opened), but I don't get any auth requests from either the Max or the Cisco router .

OT: L2TP from Lucent/Ascend Max?

2004-06-30 Thread Garry Glendown
Sorry, slightly off topic, but my google search didn't turn up anything helpful ... I'm wondering, is it possible to set up a Max 2000/4000 series dialup router to send certain (or, if not certain, all) dialups to another router via l2tp instead of doing auth and stuff itself? I want to/need t

Re: Only first Cisco-AVPair entry posted to cisco

2004-05-27 Thread Garry Glendown
sy sy wrote: I set multi Cisco-AVPair in users file,but only first is posted to Cisco router . Why ? How did you assign the additional entries? Can you post your radius entries? The second and following entries should have the "+="-assignment ... -gg - List info/subscribe/unsubscribe? See http

Overwriting default entries

2004-05-16 Thread Garry Glendown
Given: PPPoE dialup connections to our Cisco router, which authenticates through FreeRadius 0.93, working fine as such. Default-entry w/fall-through adds some config settings. When I do a "show int viX conf", I get the entries displayed that I configured through the default entry: interface Vi

Re: Problem with L2TP/Cisco and FreeRadius ...

2004-05-10 Thread Garry Glendown
Sorry, the last mail was meant for Michael directly ... forgot to edit the address ... :( -garry - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problem with L2TP/Cisco and FreeRadius ...

2004-05-10 Thread Garry Glendown
Hallo, We have the same setup wit FreeRADIUS (0.9.3 and 1.0-pre working fine.. obviously even with the same realm ;) Was ein Zufall ;) "Login incorrect" is not caused by the Cisco LAC ! it's caused by your local setup somehow. I don't get these entries.. Hm ... egal, tut nicht weh ... Lt. MK-Netz

Problem with L2TP/Cisco and FreeRadius ...

2004-05-09 Thread Garry Glendown
Hello, I'm trying to get a Cisco running with FreeRadius ... please note - FreeRadius as such is already working fine with other Dialup-routers (ascend max w/ ISDN/Modem dialup) ... We set up DSL dialup through a Cisco router. DSL is done through a L2TP tunnel, which in itself worked fine, too