RE: Inner tunnel post auth question

2013-05-13 Thread Franks Andy (RLZ) IT Systems Engineer
[mailto:freeradius-users-bounces+andy.franks=sath.nhs...@lists.freeradius.org] On Behalf Of Alan DeKok Sent: 11 May 2013 14:26 To: FreeRadius users mailing list Subject: Re: Inner tunnel post auth question Franks Andy (RLZ) IT Systems Engineer wrote: My FR version is 2.1.10+dfsg-3build2_amd64

Re: Inner tunnel post auth question

2013-05-11 Thread Alan DeKok
Franks Andy (RLZ) IT Systems Engineer wrote: My FR version is 2.1.10+dfsg-3build2_amd64. Unless there’s a nice package for Ubuntu 12.04 server then I’ll be compiling from source then I think. Yes. Upgrading would be good. so yes, the “use_tunneled reply” bit is there. Is that what’s

Inner tunnel post auth question

2013-05-10 Thread Franks Andy (RLZ) IT Systems Engineer
Hi, This may have come up before but I can't find any solutions : I'm using a NAS which always performs EAP/MSCHAP2 authentication, so I've stripped the sites-enabled/default right down to pretty much just include the eap stuff for authorisation/authentication, and am doing all the rest inside

Re: Inner tunnel post auth question

2013-05-10 Thread Alex Sharaz
Andy, What version of FreeRadius are you using? I *think* that unless you are using the git source for 2.2.1, post-auth reject is broken. There was some stuff I was doing a few months ago that got fixed in 2.2.1 … but I'm getting old and can't remember all the details :-( On 10 May 2013, at

Re: Inner tunnel post auth question

2013-05-10 Thread Phil Mayers
On 10/05/13 13:53, Franks Andy (RLZ) IT Systems Engineer wrote: Hi, This may have come up before but I can’t find any solutions : I’m using a NAS which alwaysperformsEAP/MSCHAP2authentication, so I’ve stripped the sites-enabled/default right down to pretty much just include the eap stuff

RE: Inner tunnel post auth question

2013-05-10 Thread Franks Andy (RLZ) IT Systems Engineer
: Re: Inner tunnel post auth question Andy, What version of FreeRadius are you using? I *think* that unless you are using the git source for 2.2.1, post-auth reject is broken. There was some stuff I was doing a few months ago that got fixed in 2.2.1 ... but I'm getting old and can't remember

Re: Help with FreeRadius + Switch + Mac Based Auth - question

2008-06-05 Thread Alan DeKok
Daniel Machado Grilo wrote: Do I need to have supplicants even so i want to authenticate with the mac-address, or could it be that this switch doesn't support this, and the normal behaviour should be that the switch asks RADIUS to have access showing the machine credentials (MAC Address)!?

Help with FreeRadius + Switch + Mac Based Auth - question

2008-06-03 Thread Daniel Machado Grilo
Hi, I'm hopping that you can help me, because i'm trying this for a lot of time I'm testing an SMC6248M switch to check if radius support is fine, so I configured a freeradius server in one fedora 8. I've made some tests adding clients to clients.conf and making requests via radtest to ensure

Re: post-auth question, prevent exec if attribute == foo

2006-04-04 Thread Duane Cox
change NAS-IP-Address before relayingDoes anyone have any insight to this? - Original Message - From: Duane Cox To: FreeRadius users mailing list Sent: Monday, April 03, 2006 4:44 PM Subject: post-auth question, prevent exec if attribute == foo Hello List: I'm using the post-auth

Auth question

2006-02-07 Thread Nick Marino
Can anyone tell me why I am getting trashed passwords when attempting to authenticate? Login incorrect: [nickm/d\313f`\247+4\203\360/\367] Nick Marino - IT Solutions - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Auth question

2006-02-07 Thread mnisay
: Auth question Can anyone tell me why I am getting trashed passwords when attempting to authenticate? Login incorrect: [nickm/d\313f`\247+4\203\360/\367] Nick Marino - IT Solutions - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- No virus found

Re: Auth question

2006-02-07 Thread Lewis Bergman
Can anyone tell me why I am getting trashed passwords when attempting to authenticate? Login incorrect: [nickm/d\313f`\247+4\203\360/\367] Looks like your secrets in clients.conf don't match what your NAS has. -- Lewis Bergman Texas Communications 4309 Maple St. Abilene, TX 79602-8044 Off.

Re: [radius] Re: Auth question

2006-02-07 Thread Nick Marino
Nick Marino - IT Solutions - Original Message - From: Lewis Bergman [EMAIL PROTECTED] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tuesday, February 07, 2006 5:56 AM Subject: [radius] Re: Auth question Can anyone tell me why I am getting trashed

Re: [radius] Re: Auth question

2006-02-07 Thread futhwo
07, 2006 5:56 AM Subject: [radius] Re: Auth question Can anyone tell me why I am getting trashed passwords when attempting to authenticate? Login incorrect: [nickm/d\313f`\247+4\203\360/\367] Looks like your secrets in clients.conf don't match what your NAS has. No the secret in my

Re: [radius] Re: Auth question

2006-02-07 Thread Nick Marino
Nick Marino - IT Solutions - Original Message - From: futhwo [EMAIL PROTECTED] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tuesday, February 07, 2006 9:57 AM Subject: Re: [radius] Re: Auth question Maybe you are not loading the right dictionary

Re: [radius] Re: Auth question

2006-02-07 Thread Alan DeKok
Nick Marino [EMAIL PROTECTED] wrote: that could be possible, the only one that is being included is the compat and freeradius and other than whats in the main dictionary file itself. The dictionaries have nothing to do with the passwords or shared secrets. When I try to include the ascend

Re: [radius] Re: Auth question

2006-02-07 Thread Alan DeKok
Nick Marino [EMAIL PROTECTED] wrote: Only when NAS send the request to FR does it generate that garbled password. Then the shared secret is wrong. Or, there's a bug in the server that mangles the password only for that NAS. Which is more likely? Alan DeKok. - List

Re: [radius] Re: Auth question

2006-02-07 Thread Nick Marino
Nick Marino - IT Solutions - Original Message - From: Alan DeKok [EMAIL PROTECTED] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tuesday, February 07, 2006 11:49 AM Subject: Re: [radius] Re: Auth question Nick Marino [EMAIL PROTECTED] wrote

Re: [radius] Re: Auth question

2006-02-07 Thread Nick Marino
Nick Marino - IT Solutions - Original Message - From: Alan DeKok [EMAIL PROTECTED] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tuesday, February 07, 2006 11:50 AM Subject: Re: [radius] Re: Auth question Nick Marino [EMAIL PROTECTED] wrote: Only when

Re: [radius] Re: Auth question

2006-02-07 Thread Alan DeKok
Nick Marino [EMAIL PROTECTED] wrote: Its more likely that the password is wrong but, I am sure that they are the same. If the password is wrong, then you'll see the wrong password, rather than ranbom binary nonsense. Shared secret has been the same in the nas for 3 years now and it has

Re: [radius] Re: Auth question

2006-02-07 Thread Andrew Browning
@lists.freeradius.org Sent: Tuesday, February 07, 2006 11:50 AM Subject: Re: [radius] Re: Auth question Nick Marino [EMAIL PROTECTED] wrote: Only when NAS send the request to FR does it generate that garbled password. Then the shared secret is wrong. Or, there's a bug in the server

Re: [radius] Re: Auth question

2006-02-07 Thread Nick Marino
] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tuesday, February 07, 2006 1:56 PM Subject: Re: [radius] Re: Auth question The only files I know of that use the secret password are clients.conf and proxy.conf. Make sure your clients.conf has an entry for your NAS

Re: mac address auth question

2005-10-21 Thread kdr akm
Hi Mr N White Thanks for replying and i do what u said but it not success this is my /etc/raddb/users file if u can take a look to see if i do it right plz and notice me if there's something wrong :

mac address auth question

2005-10-19 Thread kdr akm
Hi, i'm using freeradius 1.0.5.i make a pppoe server with rp-pppoe and freeradius without mysqland i make auth by username and password all i need to add to my configuration a check if mac address and if valid accept ( a mac address authentication but without mysql ) so how cani make this think