Conditional Dynamic VLAN

2011-09-05 Thread joao...@gmail.com
Hello Guys, I need the following in a wireless environment, using 802.1X authentication based on LDAP, need to do dynamic VLAN assignment. Need to consult an LDAP attribute, and from this attribute to determine which VLAN to send to my wireless controler. I need something like this: ... if (

Authentication probation for VLAN

2011-08-25 Thread joao...@gmail.com
Hello, I am using freeradius to authenticate to multiple databases, some in other LDAP in SQL. I am doing authentication and wireless networks, where I have multiple SSIDs for wireless networks, and each one logs in a database. All these databases are in the same Radius server, which

Re: Authentication probation for VLAN

2011-08-25 Thread joao...@gmail.com
. 2011/8/25 Arran Cudbard-Bell a.cudba...@freeradius.org On 25 Aug 2011, at 21:43, Alexander Clouter wrote: joao...@gmail.com joao...@gmail.com wrote: This model is funcionaç, however have a problem (very serious), Radius does not know from which SSID the client is trying

Adding default Realms in users without Realms

2011-08-24 Thread joao...@gmail.com
Hello everybody I have a doubt and I'm not finding answers on the Internet. I have a freeradius server operating normally, it is a proxy for several Realms, with each Realm leads the user to a different authentication database, so far okay. What I need now is to get users coming to the radius

Re: Adding default Realms in users without Realms

2011-08-24 Thread joao...@gmail.com
do this manipulation Realm users through the file? Thank you. 2011/8/24 Arran Cudbard-Bell a.cudba...@freeradius.org: On 24 Aug 2011, at 20:42, joao...@gmail.com wrote: Hello everybody I have a doubt and I'm not finding answers on the Internet. I have a freeradius server operating normally

Re: Adding default Realms in users without Realms

2011-08-24 Thread joao...@gmail.com
OK Thanks for the tips, helped me a lot. 2011/8/24 Arran Cudbard-Bell a.cudba...@freeradius.org: On 24 Aug 2011, at 20:42, joao...@gmail.com wrote: Hello everybody I have a doubt and I'm not finding answers on the Internet. I have a freeradius server operating normally, it is a proxy

Re: radwho shows only the last user logged.

2011-03-28 Thread joao...@gmail.com
ok, how would that be? how do I not use the freeradius NAS-Port as the key? acct_unique is a module? acct_unique { key = User-Name, Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port } I just remove the the NAS-Port-up of the keys? John 2011/3/25 Alan Buxey

Re: radwho shows only the last user logged.

2011-03-26 Thread joao...@gmail.com
ok, how would that be? how do I not use the freeradius NAS-Port as the key? acct_unique is a module? acct_unique { key = User-Name, Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port } I just remove the the NAS-Port-up of the keys? John 2011/3/25 Alan Buxey

radwho shows only the last user logged.

2011-03-25 Thread joao...@gmail.com
Hello guys, I have a question. I'm using freeradius 2.1.10 on debian squezze. I am using multiple databases for authentication, in an LDAP, and SQL in another. Each using a different Realm. Regarding the authentication, everything is working normally. But when I try to check the server how

Re: radwho shows only the last user logged.

2011-03-25 Thread joao...@gmail.com
OK Alan, First thanks for listening. Actually my NAS is sending the same port for all my users, but the door that she is sending is NAS-Port = 29. How can I configure it? is the radius or the NAS? If the radius, how do I setup? Thanks. 2011/3/25 Alan DeKok al...@deployingradius.com joao

Re: radwho shows only the last user logged.

2011-03-25 Thread joao...@gmail.com
My NAS is cisco is a wireless controller. Any suggestions for settings? And I'm also keeping my sessions in SQL. Att. 2011/3/25 Alan DeKok al...@deployingradius.com joao...@gmail.com wrote: Actually my NAS is sending the same port for all my users, but the door that she is sending is NAS

Re: Freeradius Ldap

2011-03-21 Thread joao...@gmail.com
Maicon, como vi o Pereira no seu nome, deduzo que você seja do Brasil, portanto irei responder sua pergunta em português. 1º Sim o freeradius se integra perfeitamente com o LDAP 2º Que base LDAP vc esta utilizando? OpenLDAP, Active Directory??? 3° Como esta a configuração de seu arquivo ldap?

Re: Freeradius 2 + MySQL + MD5 hash don't work

2011-03-18 Thread joao...@gmail.com
Okay folks, I appreciate the help. Already managed to solve. Basically there were two details, the first was as the supplicant was trying to authenticate, it was either use MSCHAPv2, but the passwords were encrypted at the base with MD5, just like CHAP authentication would not work . By forcing

Freeradius 2 + MySQL + MD5 hash don't work

2011-03-17 Thread joao...@gmail.com
Hello, Someone already has implemented two freeradius with mysql I'm using version 2.1.10 of freeradius on a debian 6 If I try a plaintext based authentication, everything works. But if I try to do an authentication with an MD5 password, I get the message seguite: *[pap] ERROR: You set

Re: Freeradius 2 + MySQL + MD5 hash don't work

2011-03-17 Thread joao...@gmail.com
handler ++[eap] returns reject Failed to authenticate the user. 2011/3/17 Phil Mayers p.may...@imperial.ac.uk On 03/17/2011 08:01 PM, joao...@gmail.com wrote: *[pap] ERROR: You set 'Auth-Type = PAP' for a request that does not contain a User-Password attribute!* This is very clear

Proxy Request to Virtual Server using EAP

2011-03-14 Thread joao...@gmail.com
Hello Guys I need a help to use proxy request to virtual_server using EAP-TTLS and EAP-PEAP I have the following scenario: I have a Radius Sever (version 2.1.10), this server on a Linux Debian 6 This server must authenticate users of my wireless network. But my network is interconnected with

Proxy Request to Virtual Server using EAP

2011-03-11 Thread joao...@gmail.com
Hello Guys I need a help to use proxy request to virtual_server using EAP-TTLS and EAP-PEAP I have the following scenario: I have a Radius Sever (version 2.1.10), this server on a Linux Debian 6 This server must authenticate users of my wireless network. But my network is interconnected with