RE: Calling-Station-Id Not Getting Updated in radacct table

2013-06-13 Thread Cholleti, Hanumantha
Thanks a lot Alan, that fixed the issue :-)... We tried this option before, but only tested with radclient and it doesn't update the calling-station-id. Here is the command we used: radclient 10.25.37.61 auto HANU -f acct_start_test1.txt The 'acct_start_test1.txt' file as the

Re: Calling-Station-Id Not Getting Updated in radacct table

2013-06-13 Thread Alan DeKok
On 2013-06-13, at 2:37 PM, "Cholleti, Hanumantha" wrote: > Similar to the above wimax configuration for authorize section, do we need to > enable any setting for accounting to fix the Calling-Station-Id attribute > that will populate the radacct correctly as string?

Calling-Station-Id Not Getting Updated in radacct table

2013-06-13 Thread Cholleti, Hanumantha
Hi We are on version 2.2.1 (github release). We noticed that Calling-Station-Id is not getting updated in radacct table if the NAS sends the Calling-Station-Id in octet format (ex: "\000\240\274/\370\260"). Based on the documentation below in default conf (sites-enabled/default) f

rlm_checkval: Could not find attribute named Calling-Station-Id in check pairs

2013-01-29 Thread Glassman, Stephen
through as the "calling-station-id" but it's not matching up on the checkval portion of things and I am not sure why. Here are the 2 entries that make me believe the data is coming through correctly: rlm_checkval: Item Name: Calling-Station-Id, Value: 00-26-bb-11-b9-9c rlm_checkval:

Re: Reject all calls from one or more Calling Station ID regardless of username or password

2012-11-21 Thread Bjørn Mork
Henrik Karlsson writes: > Hi guys, > I am a quite new user of the Free Radius Server and i have a problem. > I have an old Dial In system. > I want to reject all calls from one or more Calling Station ID regardless of > username or password. I have tried to edit the user

Reject all calls from one or more Calling Station ID regardless of username or password

2012-11-20 Thread Henrik Karlsson
Hi guys, I am a quite new user of the Free Radius Server and i have a problem. I have an old Dial In system. I want to reject all calls from one or more Calling Station ID regardless of username or password. I have tried to edit the user file like this USERNAME Calling-Station-Id == 404402704

Re: Pushing a policy for usergroup and calling station id from Free Radius Server

2012-09-30 Thread Fajar A. Nugraha
d := "guest", > LVL7-Wireless-Client-Policy-Dn := "policy1", > > > > Similarly for a usergroup say "usergroup1" I should send radius > attributes.. Also with client Mac which can be seen in radius request as > calling station id. > > Can we

Re: Pushing a policy for usergroup and calling station id from Free Radius Server

2012-09-30 Thread Subhani sk m
usergroup say "usergroup1" I should send radius attributes.. Also with client Mac which can be seen in radius request as calling station id. Can we do it from modifying config files instead of modifying sql database? Regards, Subhani On Sun, Sep 30, 2012 at 4:35 PM, Fajar A. Nugraha wrot

Re: Pushing a policy for usergroup and calling station id from Free Radius Server

2012-09-30 Thread Fajar A. Nugraha
s on what you mean by "push policy". If it's just "return some radius attribute"), then if you use database, simply put it on radgroupreply table. See the included documentation, or http://wiki.freeradius.org/modules/Rlm_sql > 2. how to push a policy for a specific Call

Pushing a policy for usergroup and calling station id from Free Radius Server

2012-09-30 Thread Subhani sk m
Hi, I am using free radius on Linux, Fedora 13. I am able to push policy for a user.. I need help on two scenarios given below. 1.how to push policy for a specific usergroup from free radius sever 2. how to push a policy for a specific Calling-Station-ID like 00:16:6F:A2:XX:XX [ no user

Re: freeradius, Calling-Station-Id

2012-09-06 Thread Alan DeKok
ZZ Wave wrote: > Help me please. Can't figure out how to authenticate my PBX calls only > by Calling-Station-Id attribute, without username. /etc/raddb/users is > useless here, right? You can still use it DEFAULT Calling-Station-Id = "12345", Auth-Type := Accept

Re: freeradius, Calling-Station-Id

2012-09-06 Thread Iliya Peregoudov
You can create another instance of rlm_files module that is using Calling-Station-Id as a key: # raddb/modules/callingids files callingids { key = "%{Calling-Station-Id}" usersfile = %{confdir}/callingids acctusersfile = %{confdir}/acct_callingids preproxy_usersfile =

Re: freeradius, Calling-Station-Id

2012-09-05 Thread Scott Lambert
On Wed, Sep 05, 2012 at 09:53:49PM +0400, ZZ Wave wrote: > Help me please. Can't figure out how to authenticate my PBX calls only by > Calling-Station-Id attribute, without username. /etc/raddb/users is useless > here, right? > > Here's "radiusd -X > debug

freeradius, Calling-Station-Id

2012-09-05 Thread ZZ Wave
Help me please. Can't figure out how to authenticate my PBX calls only by Calling-Station-Id attribute, without username. /etc/raddb/users is useless here, right? Here's "radiusd -X > debug.txt" output: http://pastebin.com/LfB9NZvf - List info/subscribe/unsubscribe? See ht

Re: Calling station ID

2012-07-27 Thread Khapare Joshi
; Acct-Output-Octets = 169755195 > Acct-Input-Octets = 52166343 > Acct-Output-Packets = 214098 > Acct-Input-Packets = 188732 > Calling-Station-Id = ".212" > > It could be the dictionary file (not sure) I copied from here : > htt

RE: Calling station ID

2012-07-13 Thread madal 30
Thanks Alan, It must be, The missing information on my log are : Acct-Status-Type = Alive Acct-Session-Time = 30600 Acct-Output-Octets = 169755195 Acct-Input-Octets = 52166343 Acct-Output-Packets = 214098 Acct-Input-Packets = 188732 Calling-Station-Id

Re: Calling station ID

2012-07-12 Thread alan buxey
Hi, >> The radius server can only process on what the NAS sends it. Look at >> the NAS and configure the NAS to send the correct/full >> Calling-Station-Id. >>  >Where I can Configure this (in which file ?) no file ont he RADIUS server - as per

RE: Calling station ID

2012-07-12 Thread madal 30
I setup vpn server(pptp) with freeradius to handle ippool and stuff. I tried to figure out where in my vpn server I have to alter is bugging me. perhas in radiusclient.conf ? > > In Freeradius? Nowhere. > > You have to alter the configuration of the device you are logging in to. > "192.168.1.

Re: Calling station ID

2012-07-12 Thread Sven Hartge
On 12.07.2012 12:57, madal 30 wrote: >> From: sav...@savage.za.org >> To: freeradius-users@lists.freeradius.org >> On Thu, Jul 12, 2012 at 12:29 PM, madal 30 wrote: >> > Calling-Station-Id = ".031" >> >> > How do I or where do i adjust thi

RE: Calling station ID

2012-07-12 Thread madal 30
Thanks Chris, > Date: Thu, 12 Jul 2012 12:38:17 +0200 > Subject: Re: Calling station ID > From: sav...@savage.za.org > To: freeradius-users@lists.freeradius.org > > On Thu, Jul 12, 2012 at 12:29 PM, madal 30 wrote: > > > Calling-Station-Id = ".031"

Re: Calling station ID

2012-07-12 Thread Chris Knipe
On Thu, Jul 12, 2012 at 12:29 PM, madal 30 wrote: > Calling-Station-Id = ".031" > How do I or where do i adjust this parameter sothat full IP address is > logged in calling-station-ID ? I looked at detail file in modules/detail > but could not find the parameter

Calling station ID

2012-07-12 Thread madal 30
I have enabled the detail log in my freeradius server. It logs everything which is cool. However, in Calling-Station-ID it only logs the last octes as : Acct-Session-Id = "4FEE219C619400"User-Name = "t...@test.com" Acct-Status-Type = StopServic

Re: no calling-station-id received

2012-01-09 Thread asgzl
Alan, Thank very much for the quick reply! I'll try the "run pppoe-server in kernel" solution then. -- View this message in context: http://freeradius.1045715.n5.nabble.com/no-calling-station-id-received-tp3291017p5131250.html Sent from the FreeRadius - User mailing list archiv

Re: no calling-station-id received

2012-01-09 Thread Alan DeKok
write unlang to get > calling-station-id send to sql? Many thanks It's impossible. Read what you wrote. The PPP system is NOT sending the MAC to RADIUS. So... RADIUS doesn't have the MAC. There is no amount of unlang you can write which will cause it to magically discover the M

Re: no calling-station-id received

2012-01-09 Thread asgzl
-station-id send to sql? Many thanks -- View this message in context: http://freeradius.1045715.n5.nabble.com/no-calling-station-id-received-tp3291017p5131233.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

RE: Authorising Clients by Calling Station ID Not IP

2011-11-12 Thread JennyBlunt
You are an asset to the community! I've just read through and it's fantastic - just what I and many others need for sure. Am going to have a play now :) -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authorising-Clients-by-Calling-Station-ID-Not-IP-tp48838

RE: Authorising Clients by Calling Station ID Not IP

2011-11-12 Thread Dirk van der Walt
... https://sourceforge.net/apps/trac/hotcakes/wiki/YfiTechDynamicClients https://sourceforge.net/apps/trac/hotcakes/wiki/YfiTechDynamicClients Cheers -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authorising-Clients-by-Calling-Station-ID-Not-IP-tp4883866p4986728.html Sen

RE: Authorising Clients by Calling Station ID Not IP

2011-11-10 Thread AaronB
That would be greatly appreciated, thanks! -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authorising-Clients-by-Calling-Station-ID-Not-IP-tp4883866p4981135.html Sent from the FreeRadius - User mailing list archive at Nabble.com.- List info/subscribe/unsubscribe? See

Re: Authorising Clients by Calling Station ID Not IP

2011-11-10 Thread JennyBlunt
Hi, not had much chance to do much recently. The aim's to take a peek this afternoon. Will report back after -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authorising-Clients-by-Calling-Station-ID-Not-IP-tp4883866p4981123.html Sent from the FreeRadius - User ma

Re: Authorising Clients by Calling Station ID Not IP

2011-11-10 Thread AaronB
;s and am interested to hear if you were successul in acheiving this. I look forward to hearing your results! -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authorising-Clients-by-Calling-Station-ID-Not-IP-tp4883866p4981116.html Sent from the FreeRadius - User mailing list

Re: Authorising Clients by Calling Station ID Not IP

2011-10-27 Thread JennyBlunt
Cool, thanks I'll download now and take a look J -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authorising-Clients-by-Calling-Station-ID-Not-IP-tp4883866p4943676.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subs

Re: Authorising Clients by Calling Station ID Not IP

2011-10-25 Thread Johan Meiring
ADIUS-Client-Virtual-Server = "dynamic_server" } ok } } } Notes: - "dynamic_server" is the spesific virtual server than handles the dynamic clients. - the rlm_raw packet MIGHT contain Calling-Station-Id (or do you mean Called-Station-Id??) as well. You will have

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Jennyanydots Napoleon Shoehorn
Fantastic news ;) !! We use some ddwrt, openwrt routers, coovap (ubuntu) and higher end Meraki / Ruckus stuff. Might be a pain to configure each. What about the idea of a common shared secret and then assigning a 'network' or huntgroup to each user. We could then block end users authenticating

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Arran Cudbard-Bell
On 24 Oct 2011, at 23:09, Jennyanydots Napoleon Shoehorn wrote: > This is very interesting, really appreciate the replies. > > Other than using a VPN, how do other wifi providers actually operate securely? They don't :) It's either VPN or same shared secret. If your equipment is running someth

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Jennyanydots Napoleon Shoehorn
This is very interesting, really appreciate the replies. Other than using a VPN, how do other wifi providers actually operate securely? J On 24 Oct 2011, at 21:04, Phil Mayers wrote: > On 10/24/2011 08:45 PM, JennyBlunt wrote: >> Hello Phil >> >> I guess we don't need a per NAS secret but thou

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Phil Mayers
On 10/24/2011 08:45 PM, JennyBlunt wrote: Hello Phil I guess we don't need a per NAS secret but thought it might help block any customers we don't need. We have a load of wifi hotspots on dynamic ips. We know all their nas Ok, that's about the hardest case I'm afraid. If you have the option

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Alan DeKok
Jennyanydots Napoleon Shoehorn wrote: > We started this conversation because we can't use the packet-src-ip > address. Hence the requirement for dynamic hosts? RADIUS works by using the source IP of the packet. If you want something else, set up SSH or SSL tunnels, and forward the RADIUS pack

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread JennyBlunt
radius server with IP assignment might be one option. > - > List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html > > > If you reply to this email, your message will be added to the discussion > below: > http://freeradius.1045715.n5.nabble.com/Authori

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Jennyanydots Napoleon Shoehorn
We started this conversation because we can't use the packet-src-ip address. Hence the requirement for dynamic hosts? On 24 Oct 2011, at 20:28, Fajar A. Nugraha wrote: > On Tue, Oct 25, 2011 at 2:06 AM, Jennyanydots Napoleon Shoehorn > wrote: >> In your opinion, are there better ways to deal wi

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Phil Mayers
On 10/24/2011 08:06 PM, Jennyanydots Napoleon Shoehorn wrote: The ultimate intention was to use the mac address of the nas and a nas specific shared secret. Do you really need a per-NAS secret? In your opinion, are there better ways to deal with dynamic clients? "It depends". Can you desc

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Fajar A. Nugraha
On Tue, Oct 25, 2011 at 2:06 AM, Jennyanydots Napoleon Shoehorn wrote: > In your opinion, are there better ways to deal with dynamic clients? Use Packet-Src-IP-Address -- Fajar - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Jennyanydots Napoleon Shoehorn
OH! I've looked too many lines of code over the last week. I have no idea how to patch but will investigate. Was thinking we might have to use nas-id instead. The ultimate intention was to use the mac address of the nas and a nas specific shared secret. In your opinion, are there better ways

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Phil Mayers
On 10/24/2011 07:02 PM, JennyBlunt wrote: If I put in default authorize section, the called-station-id is present. What I just don't understand is why it doesn't work in dynamic hosts and As per the comments in the "sample" dynamic-clients: # The request that is processed through this sectio

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread JennyBlunt
ord = "Y\270\306\323" NAS-Identifier = "simulator" NAS-Port-Type = Wireless-802.11 Service-Type = Login-User NAS-IP-Address = 192.168.0.1 Called-Station-Id = "00-00-00-11-00-10" Calling-Station-Id = &quo

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread Fajar A. Nugraha
On Mon, Oct 24, 2011 at 3:47 PM, JennyBlunt wrote: > Hi, > Huntgroup-Name := "%{sql:SELECT `groupname` FROM `radhuntgroup` WHERE > nasipaddress='%{NAS-IP-Address}'}" > > The mysql query then looks like this: > > SELECT `groupname` FROM `radhuntgroup` WHERE nasipaddress='' > > If I use packet-src-i

Re: Authorising Clients by Calling Station ID Not IP

2011-10-24 Thread JennyBlunt
this have something to do with the dynamic clients?? Jenny -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authorising-Clients-by-Calling-Station-ID-Not-IP-tp4883866p4931764.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubsc

Re: Authorising Clients by Calling Station ID Not IP

2011-10-23 Thread shiv
pname` FROM `radhuntgroup` WHERE UPPER(REPLACE(LEFT(`nasipaddress`,17),':',''))=UPPER(REPLACE(LEFT('%{Called-Station-Id}',17), '-', ''))}" -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authorising-Clients-by-Ca

Re: Authorising Clients by Calling Station ID Not IP

2011-10-22 Thread JennyBlunt
ng-Clients-by-Calling-Station-ID-Not-IP-tp4883866p4927984.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Rewriting wimax calling-station-id with perl

2011-10-07 Thread James T. Mugauri
Hi, All Thanks a bunch for this. I have tested both the ubuntu and CentOS/RedHat variants successfully on separate machines, integrated with postgresql. (The mysql was a typo incited by a previous install of freeradius-mysql). Ironically, i also managed to build deb packages from the 2.1.12 g

Re: Rewriting wimax calling-station-id with perl

2011-10-06 Thread Fajar A. Nugraha
On Thu, Oct 6, 2011 at 9:42 PM, James T. Mugauri wrote: > I am trying to install it on ubuntu 11.04 server. If there are rpm packages > suitable for CentOS 5.x prebuilt with wimax and mysql, i would take that! I've updated the package on https://launchpad.net/~freeradius/+archive/stable (the upda

Re: Rewriting wimax calling-station-id with perl

2011-10-06 Thread John Dennis
On 10/06/2011 10:42 AM, James T. Mugauri wrote: I am trying to install it on ubuntu 11.04 server. If there are rpm packages suitable for CentOS 5.x prebuilt with wimax and mysql, i would take that! Of course there are. In RHEL5 the package is called freeradius2 and is prebuilt with wimax an my

Re: Rewriting wimax calling-station-id with perl

2011-10-06 Thread Fajar A. Nugraha
On Thu, Oct 6, 2011 at 9:42 PM, James T. Mugauri wrote: > Installing from source also dies when I make with the same libtool error on > my ubuntu server 11.04 install. I know i have to add 'rlm_wimax' to > src/modules/stable to have it compile, but the Make fails with or without > this entry. Addi

Re: Rewriting wimax calling-station-id with perl

2011-10-06 Thread James T. Mugauri
Hi, Apologies for the late response. Our mail system went down at a terrible time! From: Johan Meiring Subject: Re: Rewriting wimax calling-station-id with perl Which version of debian do you need packages for? I am trying to install it on ubuntu 11.04 server. If there are rpm

Re: Rewriting wimax calling-station-id with perl

2011-10-05 Thread Johan Meiring
On 2011/10/05 08:15 PM, James T Mugauri wrote: Hi, As you are undoubtedly aware, the ubuntu/debian package of freeradius comes without the wimax module (despite having the wimax module) installed. My own attempts to compile/install/build deb package for ubuntu always die with the infamous "undef

Re: Rewriting wimax calling-station-id with perl

2011-10-05 Thread Alan DeKok
James T Mugauri wrote: > > As you are undoubtedly aware, the ubuntu/debian package of freeradius > comes without the wimax module (despite having the wimax module) > installed. My own attempts to compile/install/build deb package for > ubuntu always die with the infamous "undefined reference to >

Re: Rewriting wimax calling-station-id with perl

2011-10-05 Thread James T Mugauri
mbols'" that apparently has even Alan opting to forsake libtool. Because many people would still like to implement mac authentication on a wimax network, I was wondering whether the c subroutine that does this in the module: /* * Fix Calling-Station-Id. Damn you, WiMAX!

Re: Calling-Station-ID not sent by pam_radius_auth.

2011-05-24 Thread Alan DeKok
lth0721 wrote: > I'd like to recall this because now I also met this problem. > I also need add Calling-Station-Id to accounting request > But I can't find how the account part in pam radius source code. > > Can anyone help to figure it out and tell me which codes I n

Re: Calling-Station-ID not sent by pam_radius_auth.

2011-05-24 Thread lth0721
Hi Guys, I'd like to recall this because now I also met this problem. I also need add Calling-Station-Id to accounting request But I can't find how the account part in pam radius source code. Can anyone help to figure it out and tell me which codes I need added in? hope hearing fro

Re: Calling-Station-Id problem

2011-03-14 Thread ziko
thank you guys. I will try. Thank you! From: Brian Candler To: FreeRadius users mailing list Sent: Mon, March 14, 2011 11:42:09 AM Subject: Re: Calling-Station-Id problem On Sun, Mar 13, 2011 at 04:37:06AM -0700, ziko wrote: >I tried both format toget

Re: Calling-Station-Id problem

2011-03-14 Thread Brian Candler
On Sun, Mar 13, 2011 at 04:37:06AM -0700, ziko wrote: >I tried both format together like this: >user1 Calling-Station-Id == 00-00-00-00-00 > user1 Calling-Station-Id == 00:00:00:00:00 >but no success. You could do a rewrite: if (Calling-Station-Id =~ /^([0-9a-f

Re: Calling-Station-Id problem

2011-03-14 Thread Suman Dash
You need to check the Calling-Station-Id format sent by the NAS. Start radius in debug more and send a auth request, the debug will show whether your NAS sends Calling-Station-Id or not . If it sends the Calling-Station-Id you can clearly see the format of the same. Best Regads Suman Dash On

Re: Calling-Station-Id problem

2011-03-13 Thread Alan DeKok
00:00:00:00 > How can i indicate calling-station-id for one user for both, wireless > and pppoe? In 2.1.11 (released real soon now), see raddb/policy.conf, rewrite.called_station_id. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Calling-Station-Id problem

2011-03-13 Thread ziko
ation-id for one user for both, wireless and pppoe? I tried both format together like this: user1 Calling-Station-Id == 00-00-00-00-00 user1 Calling-Station-Id == 00:00:00:00:00 but no success. I am using mikrotik and ubiquity products as NAS and ubiquity as clients. Please help me. Sorry f

Re: no calling-station-id received

2010-12-03 Thread S Adrian
> > you run pppoe-server right? > 1. you can run pppoe-server in kernel mode to send calling-station-id to > radius > yup .. this was it .. Thanks :) There's a problem in gentoo's ippool.conf # ## If you prefer to allocate a random IP address every time, i # ## use thi

Re: no calling-station-id received

2010-12-03 Thread EasyHorpak.com
On 03/12/2553 22:59, S Adrian wrote: I'm receiving the calling station id now .. I somehow fscked up the sqlippool :| everybody seems to receive 10.67 ips :/ On Fri, Dec 3, 2010 at 5:50 PM, S Adrian <dex...@d3xt3r01.tk> wrote: > I don't seem to get a calling-sta

Re: no calling-station-id received

2010-12-03 Thread S Adrian
I'm receiving the calling station id now .. I somehow fscked up the sqlippool :| everybody seems to receive 10.67 ips :/ On Fri, Dec 3, 2010 at 5:50 PM, S Adrian wrote: > > I don't seem to get a calling-station-id packet when a username is > > trying to connect. > >

Re: no calling-station-id received

2010-12-03 Thread S Adrian
> I don't seem to get a calling-station-id packet when a username is > trying to connect. > Fix the client software so that it sends a Calling-Station-Id. clientsoftware being the pppd or rp-pppoe ? Would this also fix the second problem ? - List info/subscribe/unsubsc

Re: no calling-station-id received

2010-12-03 Thread Alan DeKok
S Adrian wrote: > I don't seem to get a calling-station-id packet when a username is > trying to connect. Fix the client software so that it sends a Calling-Station-Id. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

no calling-station-id received

2010-12-03 Thread S Adrian
Hey everybody I don't seem to get a calling-station-id packet when a username is trying to connect. I'm running gentoo and have the following package versions: net-dialup/ppp-2.4.5-r1 USE="activefilter atm dhcp eap-tls pam radius -gtk -ipv6" 0 kB net-dialup/rp-pppoe-3.

Re: Toggle Calling-Station-Id check item based on Framed-Protocol?

2010-10-15 Thread William Burnett
Thinking this over I may have thought of a solution, but if anyone can suggest something better let me know... I write another SQL module call it sql_ppp and change the query so that it omits any records with an attribute == Calling-Station-Id, and the use unlang to call that module when Service

Toggle Calling-Station-Id check item based on Framed-Protocol?

2010-10-15 Thread William Burnett
Hello all.. I'm trying to setup my Radius server so that it will map MAC addresses to TTLS user/pass for 802.1x. I have that part working fine. The problem is, the same user/pass pair I'm also using for the clients PPPoE authentication. I want the Calling-Station-Id to be verified w

Re: Calling-Station-Id Empty value

2010-10-13 Thread Alan DeKok
Moayad Mohammad wrote: > I am using freeradius with wichorus ASN-GW (WiMAX), I have problem with > Calling-Station-Id value > > The ASN-GW sent Calling-Station-Id in binary format like > this "\000&\031\001\000K" Horrible WiMAX specs... >

Calling-Station-Id Empty value

2010-10-13 Thread Moayad Mohammad
Dears, I am using freeradius with wichorus ASN-GW (WiMAX), I have problem with Calling-Station-Id value The ASN-GW sent Calling-Station-Id in binary format like this "\000&\031\001\000K" I checked the debug radius -X result and I found the AAA g

Re: Calling-Station-Id and Called-Station-Id values

2010-06-17 Thread Alan DeKok
Omer Faruk Sen wrote: > First of all thank you for your reply Alan. Is this feature also valid > for 1.1.8 for some certain reasons I have to use 1.1.8 Upgrade. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Calling-Station-Id and Called-Station-Id values

2010-06-17 Thread Omer Faruk Sen
Hi, First of all thank you for your reply Alan. Is this feature also valid for 1.1.8 for some certain reasons I have to use 1.1.8 Regards. On Thu, Jun 17, 2010 at 9:06 AM, Alan DeKok wrote: > Omer Faruk Sen wrote: >> How can I make  Calling-Station-Id and Called-Station-Id to

Re: Calling-Station-Id and Called-Station-Id values

2010-06-16 Thread Alan DeKok
Omer Faruk Sen wrote: > How can I make Calling-Station-Id and Called-Station-Id to be see in > accounting if one of them is empty in detail log file. What I mean if > one of the field (Calling-Station-Id or Called-Station-Id ) doesn't > supplied by NAS I want it to be seen li

Calling-Station-Id and Called-Station-Id values

2010-06-16 Thread Omer Faruk Sen
Hi, How can I make Calling-Station-Id and Called-Station-Id to be see in accounting if one of them is empty in detail log file. What I mean if one of the field (Calling-Station-Id or Called-Station-Id ) doesn't supplied by NAS I want it to be seen like : Calling-Station-Id = "xx

Re: Log IP address (Calling-Station-Id?) of failed authentication attempts

2010-05-09 Thread Matt Hite
code and looked at it). It appears the functionality to log client IP (Calling-Station-Id) is already there -- you only need "auth = yes" in radiusd.conf enabled. Enabling "auth_badpass = yes" and/or "auth_goodpass = yes" and msg_goodpass/msg_badpass to include %{Callin

Re: Log IP address (Calling-Station-Id?) of failed authentication attempts

2010-05-09 Thread Alan DeKok
Matt Hite wrote: > It looks like I can possibly enable auth_badpass and auth_goodpass in > radiusd.conf and then set: > > msg_goodpass = "%{Calling-Station-Id}" > msg_badpass = "%{Calling-Station-Id}" Yes. > Is this going about it the right way? Yes.

Log IP address (Calling-Station-Id?) of failed authentication attempts

2010-05-08 Thread Matt Hite
.sv4 port 0) It looks like I can possibly enable auth_badpass and auth_goodpass in radiusd.conf and then set: msg_goodpass = "%{Calling-Station-Id}" msg_badpass = "%{Calling-Station-Id}" Is this going about it the right way? Also, I really don't want the failed passwords to

Re: Set Calling-Station-Id after first authorization

2010-02-13 Thread EasyHorpak.com
? } else { mysql_query("INSERT into radcheck (UserName, Attribute, op, Value) values ('$argv[1]', 'Calling-Station-Id', '==', '$argv[2]')"); } ?> I rarely write any php, so any improvement in the code is highly app

Re: Set Calling-Station-Id after first authorization

2010-02-13 Thread Kledi Andoni
After a bit of work, I was able to solve it by running a php script in the preacct process. I added the external program with exec: exec 1stlogin { wait = yes program = "/usr/bin/php /root/1stlogin.php %{User-Name} %{Calling-Stati

Re: Set Calling-Station-Id after first authorization

2010-02-12 Thread EasyHorpak.com
Kledi Andoni wrote: Hello, I need a way to set the Calling-Station-Id attribute automatically for each user after the first authorization request. In this way the user will be allowed to authorize only from that mac address in the future. I am using freeradius 1.1.7 with mysql. I do not

Set Calling-Station-Id after first authorization

2010-02-12 Thread Kledi Andoni
Hello, I need a way to set the Calling-Station-Id attribute automatically for each user after the first authorization request. In this way the user will be allowed to authorize only from that mac address in the future. I am using freeradius 1.1.7 with mysql. I do not have the expertise to

Re: Calling-Station-Id

2010-01-08 Thread Alan Buxey
Hi, > I had the checkval line commented out. I just uncommented it and that's > it. > I also went further but commenting all of the modules that I did not > need in the authorize section as well as in the preacct section. so > things like the suffix, mschap, chap, etc I commented out so that > fre

Re: Calling-Station-Id

2010-01-08 Thread Bjørn Mork
r the operator. >> > >> >> > >> |312|t...@internet.quimefa.cu|Calling-Station-Id | += | "72061490" >> > >> |298|t...@internet.quimefa.cu|MD5-Password | := | password >> > >> |313|t...@internet.quimefa.cu|Calling-Station-Id |

Re: Calling-Station-Id

2010-01-07 Thread Osmany
On Thu, 2010-01-07 at 09:06 -0500, Osmany wrote: > On Thu, 2010-01-07 at 08:42 -0500, Michel Bulgado wrote: > > Bjørn Mork wrote: > > > Michel Bulgado writes: > > > > > > > > >> Try this way, remember the operator. > > >> > > &g

Re: Calling-Station-Id

2010-01-07 Thread Bjørn Mork
"Ben Wiechman" writes: > Try removing the radreply entry with auth-type := accept. Won't that > allow the user in regardless of the check items? It should not be in the radreply table in any case so that should certainly be removed. But I don't think it makes any difference. The radcheck looku

Re: Calling-Station-Id

2010-01-07 Thread Osmany
On Thu, 2010-01-07 at 08:42 -0500, Michel Bulgado wrote: > Bjørn Mork wrote: > > Michel Bulgado writes: > > > > > >> Try this way, remember the operator. > >> > >> |312|t...@internet.quimefa.cu|Calling-Station-Id | += | "7206

RE: Calling-Station-Id

2010-01-07 Thread Ben Wiechman
> > > This time I used: > > > > |298|t...@internet.quimefa.cu|MD5-Password | := | password > > |313|t...@internet.quimefa.cu|Calling-Station-Id | =~ | 6480342|55 > > > > and it still accepts the user from regardless of the phone number it'

Re: Calling-Station-Id

2010-01-07 Thread Bjørn Mork
Osmany writes: > This time I used: > > |298|t...@internet.quimefa.cu|MD5-Password | := | password > |313|t...@internet.quimefa.cu|Calling-Station-Id | =~ | 6480342|55 > > and it still accepts the user from regardless of the phone number it's using. > this

Re: Calling-Station-Id

2010-01-07 Thread Michel Bulgado
Bjørn Mork wrote: Michel Bulgado writes: Try this way, remember the operator. |312|t...@internet.quimefa.cu|Calling-Station-Id | += | "72061490" |298|t...@internet.quimefa.cu|MD5-Password | := | password |313|t...@internet.quimefa.cu|Calling-Station-Id | += |

Re: Calling-Station-Id

2010-01-07 Thread Osmany
On Thu, 2010-01-07 at 11:32 +0100, Bjørn Mork wrote: > Michel Bulgado writes: > > > Try this way, remember the operator. > > > > |312|t...@internet.quimefa.cu|Calling-Station-Id | += | "72061490" > > |298|t...@internet.quimefa.cu|MD5-P

Re: Calling-Station-Id

2010-01-07 Thread Bjørn Mork
Michel Bulgado writes: > Try this way, remember the operator. > > |312|t...@internet.quimefa.cu|Calling-Station-Id | += | "72061490" > |298|t...@internet.quimefa.cu|MD5-Password | := | password > |313|t...@internet.quimefa.cu|Calling-Station-Id | += | "7206

Re: Calling-Station-Id

2010-01-06 Thread Michel Bulgado
another phone number (another Calling-Station-Id) to the user test, so that the user can connect from only one phone number or the other. I tried using the += operator and the user can connect from any phone number. So my configuration works only if the user has only one Calling-Station-Id attribute

Re: Calling-Station-Id

2010-01-06 Thread Osmany
On Wed, 2010-01-06 at 17:05 +0100, Bjørn Mork wrote: > Osmany writes: > > >> If you would like this test user connect from another phone number, > >> simply add another entry in the same table, just as you did before. > >> > > > > Add another entry

Re: Calling-Station-Id

2010-01-06 Thread Bjørn Mork
Osmany writes: >> If you would like this test user connect from another phone number, >> simply add another entry in the same table, just as you did before. >> > > Add another entry with the Calling-Station-Id attribute? Let's see if I > understand. After I add

Re: Calling-Station-Id

2010-01-06 Thread Osmany
orking, now I want to add another phone number (another > > Calling-Station-Id) to the user test, so that the user can connect from > > only one phone number or the other. I tried using the += operator and the > > user can connect from any phone number. So my configuration works o

Re: Calling-Station-Id

2010-01-06 Thread Michel Bulgado
osm...@oc.quimefa.cu wrote: On Tue, 05 Jan 2010 20:05:07 -0500, mic...@casa.co.cu wrote: Osmany escribió: Hi, I have Freeradius configured using a mysql backend. I want users to be able to connect only if their Calling-Station-Id is the same as the attribute I specify in the

Re: Calling-Station-Id

2010-01-06 Thread osmany
On Tue, 05 Jan 2010 20:05:07 -0500, mic...@casa.co.cu wrote: > Osmany escribió: > >> Hi, >> >> I have Freeradius configured using a mysql backend. I want users to be >> able to connect only if their Calling-Station-Id is the same as the >> attribute I specify

  1   2   3   4   >