Outer identity being used for LDAP group lookup in users file

2009-05-10 Thread Paul Dealy
In my users file I preform an Ldap-Group lookup and allocate vlan based on this. i.e. DEFAULT Ldap-Group != cn=DisabledRadiusUsers,ou=roles,ou=services,o=abc The issue I am having is if a user has an Outer Identity set, the Ldap-Group lookup is performed against this username not the Inner

Re: Wired 802.1x auth - Getting the IP address of the authed machine

2009-02-25 Thread Paul Dealy
I have accounting turned on, but I don't see the authed machines IP on that of the NAS. On Wed, Feb 25, 2009 at 8:47 PM, t...@kalik.net wrote: I have a wired 802.1x auth setup on cisco gear.  I would like to record the IP address of machines that connect and are authorized.  Is this possible?

Wired 802.1x auth - Getting the IP address of the authed machine

2009-02-24 Thread Paul Dealy
I have a wired 802.1x auth setup on cisco gear. I would like to record the IP address of machines that connect and are authorized. Is this possible? I currently see NAS-IP-Address and Client-IP-Address as the IP of the switch. The Calling-Station-Id is the correct mac address of the authorized

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread Paul Dealy
On Tue, Feb 17, 2009 at 9:50 AM, t...@kalik.net wrote: Am I correct in saying that the LDAP-attribute that is mapped to Tunnel-Private-Group-ID would need to be set to the value of the the VLAN I require? The LDAP-attribute that I wish to use curently contains values like ITISCP and ENISCP. I

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread Paul Dealy
On Tue, Feb 17, 2009 at 11:04 AM, t...@kalik.net wrote: Am I correct in saying that the LDAP-attribute that is mapped to Tunnel-Private-Group-ID would need to be set to the value of the the VLAN I require? The LDAP-attribute that I wish to use curently contains values like ITISCP and ENISCP. I

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread Paul Dealy
On Tue, Feb 17, 2009 at 11:44 AM, t...@kalik.net wrote: I'm using version 1.1.3 so, I moved the files entry below the ldap entry but my DEFAULT entry in the file: users does not match or return any value. You should upgrade. Did something else match in files? Post the debug. Stuck with this

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Paul Dealy
On Fri, Feb 13, 2009 at 6:37 PM, Michael Schwartzkopff mi...@multinet.de wrote: Am Freitag, 13. Februar 2009 07:17:17 schrieb Paul Dealy: I have a working radius server (ver 1.1.3). which I am using for 802.1x authentication of wired switch ports. I would like to dynamically assign users

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Paul Dealy
On Fri, Feb 13, 2009 at 9:12 PM, Michael Schwartzkopff mi...@multinet.de wrote: Am Freitag, 13. Februar 2009 11:00:10 schrieb Paul Dealy: On Fri, Feb 13, 2009 at 6:37 PM, Michael Schwartzkopff mi...@multinet.de wrote: Am Freitag, 13. Februar 2009 07:17:17 schrieb Paul Dealy: I have

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Paul Dealy
On Fri, Feb 13, 2009 at 10:16 PM, Michael Schwartzkopff mi...@multinet.de wrote: Am Freitag, 13. Februar 2009 11:54:29 schrieb Paul Dealy: On Fri, Feb 13, 2009 at 9:12 PM, Michael Schwartzkopff mi...@multinet.de wrote: Am Freitag, 13. Februar 2009 11:00:10 schrieb Paul Dealy: On Fri, Feb

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Paul Dealy
On Fri, Feb 13, 2009 at 11:22 PM, Michael Schwartzkopff mi...@multinet.de wrote: Am Freitag, 13. Februar 2009 12:36:09 schrieb Paul Dealy: On Fri, Feb 13, 2009 at 10:16 PM, Michael Schwartzkopff mi...@multinet.de wrote: Am Freitag, 13. Februar 2009 11:54:29 schrieb Paul Dealy: On Fri, Feb

Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-12 Thread Paul Dealy
I have a working radius server (ver 1.1.3). which I am using for 802.1x authentication of wired switch ports. I would like to dynamically assign users vlans. I have cisco gear and have achieved basic vlan allocation by configuring a Default entry in the users file. So the vlan allocation part