RE: wireshart shows wrong information

2013-04-29 Thread Juan Pablo L.
To: freeradius-users@lists.freeradius.org Subject: RE: wireshart shows wrong information Date: Fri, 26 Apr 2013 14:22:20 + i realise now that i may have not been very clear in my explanation of the problem, that problem is that all values for the fields are the wrong values, for example

Re: wireshart shows wrong information

2013-04-29 Thread A . L . M . Buxey
Hi, Hi Alan, i m sorry i m sorry if i m not being clear enough, but please consider the example from my last reply: ...you've written this 3 or 4 times. its clear. we see what you are saying but you are not taking the answers given to you. alan - List info/subscribe/unsubscribe? See

RE: wireshart shows wrong information

2013-04-28 Thread Juan Pablo L.
@lists.freeradius.org Subject: RE: wireshart shows wrong information Date: Fri, 26 Apr 2013 14:22:20 + i realise now that i may have not been very clear in my explanation of the problem, that problem is that all values for the fields are the wrong values, for example, this is my code: pairadd

Re: wireshart shows wrong information

2013-04-28 Thread Alan DeKok
Juan Pablo L. wrote: Alan, can you please extend a little bot more ... what do you mean that you see the correct value i see value f3 08 48 12 when i m actually expecting 0001 . i really dont see where it is actually correct. ... thanks!!! In the debug log *I* see, it has the

Re: wireshart shows wrong information

2013-04-28 Thread Peter Lambrechtsen
On Mon, Apr 29, 2013 at 12:14 AM, Alan DeKok al...@deployingradius.com wrote: Juan Pablo L. wrote: Alan, can you please extend a little bot more ... what do you mean that you see the correct value i see value f3 08 48 12 when i m actually expecting 0001 . i really dont see where

RE: wireshart shows wrong information

2013-04-26 Thread Juan Pablo L.
wrong information Date: Thu, 25 Apr 2013 21:00:51 + i m sorry i accidentally press the wrong combination of keys and the mail left resuming my message below . this is the data that tcpdump show as being transmitted for this attribute: type = 1a length = 1a vendor = 00 00 15 9f

Re: wireshart shows wrong information

2013-04-26 Thread Alan DeKok
Juan Pablo L. wrote: i realise now that i may have not been very clear in my explanation of the problem, that problem is that all values for the fields are the wrong values, for example, this is my code: pairadd(request-reply-vps,pairmake(3GPP2-Prepaid-Acct-Quota-QuotaIDentifier,1,

wireshart shows wrong information

2013-04-25 Thread Juan Pablo L.
Hi, i m implementing a module in which i m using some TLV for which i modified the dictionary.3gpp2 as very well suggested in a different thread, but i see that the data for those TLV fields are not encoded properly or at least that is what wireshark is showing even thou debugging freeradius it

RE: wireshart shows wrong information

2013-04-25 Thread Juan Pablo L.
will be appreciated. From: jpablolorenze...@hotmail.com To: freeradius-users@lists.freeradius.org Subject: wireshart shows wrong information Date: Thu, 25 Apr 2013 20:53:58 + Hi, i m implementing a module in which i m using some TLV for which i modified the dictionary.3gpp2 as very well

Re: wireshart shows wrong information

2013-04-25 Thread Arran Cudbard-Bell
On 25 Apr 2013, at 16:53, Juan Pablo L. jpablolorenze...@hotmail.com wrote: Hi, i m implementing a module in which i m using some TLV for which i modified the dictionary.3gpp2 as very well suggested in a different thread, but i see that the data for those TLV fields are not encoded properly

Re: wireshart shows wrong information

2013-04-25 Thread Alan DeKok
debugging freeradius it shows that the data being sent is the correct it differs from the data captured using tcpdump ... Can you post that information, or is it secret? here is my dictionary entry: That seems like it should work. and for that i m writing the following code: pairadd

Re: wireshart shows wrong information

2013-04-25 Thread Alan DeKok
Juan Pablo L. wrote: i m sorry i accidentally press the wrong combination of keys and the mail left resuming my message below . Thanks. i dont see where i m doing wrong ... any help will be appreciated. It looks correct to me. Maybe wireshark is wrong. Alan DeKok. - List

RE: wireshart shows wrong information

2013-04-25 Thread Juan Pablo L.
thank you very much for your reply, please find attached the pcap file. the access-accept are my packages .. those are the ones with the problem. thanks! From: jpablolorenze...@hotmail.com To: freeradius-users@lists.freeradius.org Subject: RE: wireshart shows wrong information Date: Thu, 25 Apr

Re: Is there a way to renew pptp user information of a user connected mikrotik?

2012-12-24 Thread Stephan Kirsten
. The user wants to use it for another months and he already has paid And because the user paid for another month, he absolutely doesn't want to be disconnected at 00:00. Then, I added him for another month in dialup_admin. I'd like to renew the user's information by transfering radcheck table

Is there a way to renew pptp user information of a user connected mikrotik?

2012-12-23 Thread 조명산
I am using freeradius 2.1.7 + mysql + mikrotik. The user recharged while he was connected on the day of expiration and he didn't want to be disconnected at 00:00. Is there a solution for that? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Is there a way to renew pptp user information of a user connected mikrotik?

2012-12-23 Thread Jed Gainer
I do not understand your question. On Sun, Dec 23, 2012 at 9:35 PM, 조명산 k2...@nate.com wrote: mikrotik - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re:Re: Is there a way to renew pptp user information of a user connected mikrotik?

2012-12-23 Thread 조명산
months and he already has paid And because the user paid for another month, he absolutely doesn't want to be disconnected at 00:00. Then, I added him for another month in dialup_admin. I'd like to renew the user's information by transfering radcheck table information to mikrotik nas

Re: share information between authorize and authenticate sections (rlm_perl rlm_python)

2012-12-13 Thread Alan Buxey
Hi, in perl, i could write some new attributes in RAD_CHECK ??, then authenticate() will access them. in python, attributes are read only, so i cannot use them to pass information to authenticate(). A simple database, like redis, could be a solution by adding info with the id

Re: share information between authorize and authenticate sections (rlm_perl rlm_python)

2012-12-13 Thread Phil Mayers
On 12/12/12 22:04, laurent.fe...@free.fr wrote: Hello, If someone can advise me... How to share information between the authorize() function and the authenticate() function within a perl or python script ? Just set an attribute: authorize { update request { Tmp-String-0

Re: share information between authorize and authenticate sections (rlm_perl rlm_python)

2012-12-13 Thread laurent . feron
Yes, just found this attribute. Thanks. Works well with Perl :), but not with Python :( - Mail original - De: Phil Mayers p.may...@imperial.ac.uk À: freeradius-users@lists.freeradius.org Envoyé: Jeudi 13 Décembre 2012 13:05:23 Objet: Re: share information between authorize

share information between authorize and authenticate sections (rlm_perl rlm_python)

2012-12-12 Thread laurent . feron
Hello, If someone can advise me... How to share information between the authorize() function and the authenticate() function within a perl or python script ? For example, i get some information from a database in authorize() that will reuse it in authenticate()? I could resubmit the sql request

Re: radwho: No configuration information in radutmp section of radiusd.conf

2012-11-19 Thread Fajar A. Nugraha
On Mon, Nov 19, 2012 at 2:28 PM, Angel L. Mateo ama...@um.es wrote: accounting { detail unix #radutmp Well, that won't help. You're trying to use radwho, but aren't logging accounting information. That means radwho will NEVER show you anything. I'm

Re: radwho: No configuration information in radutmp section of radiusd.conf

2012-11-19 Thread Angel L. Mateo
El 19/11/12 09:15, Fajar A. Nugraha escribió: On Mon, Nov 19, 2012 at 2:28 PM, Angel L. Mateo ama...@um.es wrote: accounting { detail unix #radutmp Well, that won't help. You're trying to use radwho, but aren't logging accounting information. That means radwho

Re: radwho: No configuration information in radutmp section of radiusd.conf

2012-11-19 Thread Fajar A. Nugraha
the regresession, or (even better) provide a patch to fix this :) If this was the only problem, it wouldn't be any problem, but I'm having the same problem with radzap: /usr/bin/radzap -P 131833856 -u user -N ip localhost secret radwho: No configuration information in radutmp section

Re: radwho: No configuration information in radutmp section of radiusd.conf

2012-11-18 Thread Angel L. Mateo
I get is; radwho: No configuration information in radutmp section of radiusd.conf You need to have a modules section, with radutmp listed in it. In my modules section I have modules { ... $INCLUDE ${confdir}/modules/ .. } and I have a file ${confdir}/modules/radutmp

radwho: No configuration information in radutmp section of radiusd.conf

2012-11-16 Thread Angel L. Mateo
Hello, I have a problem with radwho since I upgraded from 2.1.10 to 2.2.0. The same configuration (I'm trying now the default configuration installed from ubuntu packages) works with version 2.1.10 and not with 2.2.0. The error I get is; radwho: No configuration information in radutmp

Re: radwho: No configuration information in radutmp section of radiusd.conf

2012-11-16 Thread Alan DeKok
information in radutmp section of radiusd.conf You need to have a modules section, with radutmp listed in it. My config (for default virtual server) is: Which doesn't really help. What's in the modules directory? accounting { detail unix #radutmp Well, that won't

Re: FreeRADIUS performance information (tuning, benchmark)

2012-07-24 Thread Phil Mayers
On 24/07/12 13:26, Andrei Petru Mura wrote: I'm running FreeRADIUS on a PC with a dual CPU of 2 GHz and 2 GB of RAM. It is working with PostgreSQL database. When I perform tests with radperf, running : radperf -s -f ../users.csv -p 800 -a pap 10.3.1.1 auth radiussomething where users.csv file

Re: FreeRADIUS performance information (tuning, benchmark)

2012-07-24 Thread Arran Cudbard-Bell
On 24 Jul 2012, at 13:49, Phil Mayers wrote: On 24/07/12 13:26, Andrei Petru Mura wrote: I'm running FreeRADIUS on a PC with a dual CPU of 2 GHz and 2 GB of RAM. It is working with PostgreSQL database. When I perform tests with radperf, running : radperf -s -f ../users.csv -p 800 -a pap

Re: FreeRADIUS performance information (tuning, benchmark)

2012-07-24 Thread Alexander Gattin
On Tue, Jul 24, 2012 at 01:49:27PM +0100, Phil Mayers wrote: On 24/07/12 13:26, Andrei Petru Mura wrote: radperf -s -f ../users.csv -p 800 -a pap 10.3.1.1 auth radiussomething ... 0.1s : 3758 s: 5897 10s : 344 ... I would need a sever able to manage a much greater amount

Re: FreeRADIUS performance information (tuning, benchmark)

2012-07-24 Thread alan buxey
Hi, you could look at PGSQL optimization - ensure that the table has the right indexes and the table is in cache etc. Try this: convert your SQL users into a users text file, like so: username Cleartext-Password := password ...and disable SQL, then re-run the test. I think it will

Re: FreeRADIUS performance information (tuning, benchmark)

2012-07-24 Thread alan buxey
Hi, I would need a sever able to manage a much greater amount of users ( 5, up to 100). But for now I'm interested how to get the server working well with ~(5-10) users. for what its worth, we deal with around 8000 users concurrently on an 802.1X connection (so all

Re: FreeRADIUS performance information (tuning, benchmark)

2012-07-24 Thread Phil Mayers
On 24/07/12 13:57, Arran Cudbard-Bell wrote: 1000 auths/sec is quite a lot. It implies you need to perform 1000 SQL queries/sec (at LEAST). I'm not sure this is accurate given the number of failed requests, i'd investigate that then re-run the tests. Ah, I didn't spot the failed count. -

Re: FreeRADIUS performance information (tuning, benchmark)

2012-07-24 Thread Phil Mayers
On 24/07/12 14:10, alan buxey wrote: Hi, you could look at PGSQL optimization - ensure that the table has the right indexes and the table is in cache etc. Try this: convert your SQL users into a users text file, like so: usernameCleartext-Password := password ...and disable SQL,

Some information about clients.conf

2012-06-10 Thread Awais
in client 192.168.0.0/*24* cient 192.168.0.0/*16* -- View this message in context: http://freeradius.1045715.n5.nabble.com/Some-information-about-clients-conf-tp5713634.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http

Re: Some information about clients.conf

2012-06-10 Thread Fajar A. Nugraha
On Mon, Jun 11, 2012 at 11:55 AM, Awais awai...@hotmail.com wrote: #client 192.168.0.0/24 { #       secret          = testing123-1 #       shortname       = private-network-1 #} # l#cient 192.168.0.0/16 { #       secret          = testing123-2 #       shortname       = private-network-2

Re: Some information about clients.conf

2012-06-10 Thread Awais
Thank you so much fajar :) The link is very useful :) -- View this message in context: http://freeradius.1045715.n5.nabble.com/Some-information-about-clients-conf-tp5713634p5713636.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See

Re: Accessing radwho information or accounting request from rlm_perl

2012-05-09 Thread Alan DeKok
eluna wrote: As you can see the NAS-IP-Address attributes are different, and I need a method to get the value of the accounting request because when I need to for example deauthenticate a user, i need to know what access point is is actually associated to. Any solutions or hints are very much

Accessing radwho information or accounting request from rlm_perl

2012-05-08 Thread eluna
in context: http://freeradius.1045715.n5.nabble.com/Accessing-radwho-information-or-accounting-request-from-rlm-perl-tp5695393.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread yagizozen
of packets arriving to the radius from NAS. I only have 1 client and the radiusd.conf is set to default values. What is the solution Guys? Thank you in advance. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Incoming-Packet-information-do-not-modify-the-Accounting-Table

Re: Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread Alan DeKok
yagizozen wrote: What can be the reason of this situation? Read the debug output to see what the server is doing. Set up a test server. Re-play the packets. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread yagizozen
How can I read the debug output? Server is not running with -X parameter. How can I re-play the packets? -- View this message in context: http://freeradius.1045715.n5.nabble.com/Incoming-Packet-information-do-not-modify-the-Accounting-Table-tp5667090p5667223.html Sent from the FreeRadius - User

Re: Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread Alan DeKok
yagizozen wrote: How can I read the debug output? Server is not running with -X parameter. Read what I wrote: Set up a test server. How can I re-play the packets? $ man radclient It's only hard if you REFUSE to read the answers on this list, and if you REFUSE to read the existing

Re: Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread yagizozen
/Incoming-Packet-information-do-not-modify-the-Accounting-Table-tp5667090p5667272.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread Fajar A. Nugraha
On Thu, Apr 26, 2012 at 5:54 PM, yagizozen yagizo...@yahoo.com wrote: Thank you for your answer Alan. I understand how to re-play the packets using radclient but I wonder if it is possible to see the debug output of an existing running radius server with radiusd command without stopping it.

Re: Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread Alan DeKok
yagizozen wrote: Thank you for your answer Alan. I understand how to re-play the packets using radclient but I wonder if it is possible to see the debug output of an existing running radius server with radiusd command without stopping it. $ man raddebug This is documented. Alan DeKok. -

Re: Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread yagizozen
. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Incoming-Packet-information-do-not-modify-the-Accounting-Table-tp5667090p5667327.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Incoming Packet information do not modify the Accounting Table

2012-04-26 Thread Alan DeKok
yagizozen wrote: So this means that the best way to keep detailed debug log, I need to stop the server and start it in debug mode I guess. That's wrong. You were told it's wrong. You were told what to do. If you're not going to read the answers on this list, then don't ask questions

Private namespace for dictionary attributes (was: Passing information from authenticate to post-auth)

2011-11-27 Thread Edgar Fuß
Define your own [attributes]. That's why the dictionary files are editable. Is there a private name space for that (i.e., X-*) that is guaranteed not to conflict with future official attribute names? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Private namespace for dictionary attributes (was: Passing information from authenticate to post-auth)

2011-11-27 Thread Fajar A. Nugraha
On Sun, Nov 27, 2011 at 7:47 PM, Edgar Fuß e...@math.uni-bonn.de wrote: Define your own [attributes].  That's why the dictionary files are editable. Is there a private name space for that (i.e., X-*) that is guaranteed not to conflict with future official attribute names? You should be able

Passing information from authenticate to post-auth (was: Why Authorization before Authentication)

2011-11-25 Thread Edgar Fuß
I was probably too fuzzy about what I actually mean, sorry. Suppose I'm writing my own module or I'm using rlm_perl. Then, in authenticate, I gather some information. Later, in post-auth, I need this information for my authorization policy. So, as far as I can see, I'll have to put

Re: Passing information from authenticate to post-auth

2011-11-25 Thread Alan DeKok
Edgar Fuß wrote: Suppose I'm writing my own module or I'm using rlm_perl. Then, in authenticate, I gather some information. Later, in post-auth, I need this information for my authorization policy. So, as far as I can see, I'll have to put this Information into an attribute. Yes. Am I

Adding dictionary entries (was: Passing information from authenticate to post-auth)

2011-11-25 Thread Edgar Fuß
EF Am I supposed to use the Tmp-Xxx-N attributes for that? ADK Define your own. That's why the dictionary files are editable. Ah, you mean raddb/dictionary, I suppose. Thanks, I over-looked that. Just out of curiosity: What are the pre-defined Tmp-Xxx-N attributes for, then? - List

New VM daloradius for freeradius2 is out - just for your information.

2011-08-12 Thread aceror
Hi all! just post from Liran Tal (Daloradius) Hey everyone, The daloRADIUS Virtual Machine and User Guide which I have been working on for so long are finally available on the daloradius.com blog. I just try it. Working for now!! Lets see tomorrow. I still missing paypal, or visa module But

Add more information to Logfile?

2011-05-30 Thread thomas.dohl
Hello Everyone, in my client config I use netmaskranges. f.e: ... ipaddr = 172.16.0.0 netmask = 12 shortname = swr01 ... Now I only see the following information: Sun May 29 01:52:44 2011 : Auth: Invalid user: [...] (from client swr01 port 417

Re: Add more information to Logfile?

2011-05-30 Thread Alan DeKok
thomas.d...@24-7-it-services.de wrote: It is possible to see the real client IP and the user IP in the log? Read radiusd.conf, and look for the log section. The messages can be customized. This is documented. Alan DeKok. - List info/subscribe/unsubscribe? See

AW: Add more information to Logfile?

2011-05-30 Thread thomas.dohl
...@lists.freeradius.org [mailto:freeradius-users- bounces+thomas.dohl=24-7-it-services...@lists.freeradius.org] Im Auftrag von Alan DeKok Gesendet: Montag, 30. Mai 2011 10:35 An: FreeRadius users mailing list Betreff: Re: Add more information to Logfile? thomas.d...@24-7-it-services.de wrote

Re: Add more information to Logfile?

2011-05-30 Thread Fajar A. Nugraha
On Mon, May 30, 2011 at 8:30 PM, thomas.d...@24-7-it-services.de wrote: Hi, I'm sorry, but I can't find any usefull informations in (http://wiki.freeradius.org/Radiusd.conf). Please, can you give me a little bit more informations? It should be possible to disable auth logging (auth=no) on

Re: AW: Add more information to Logfile?

2011-05-30 Thread Alan DeKok
thomas.d...@24-7-it-services.de wrote: Hi, I'm sorry, but I can't find any usefull informations in (http://wiki.freeradius.org/Radiusd.conf). Please, can you give me a little bit more informations? Look for msg_ Alan DeKok. - List info/subscribe/unsubscribe? See

Who processes VLAN information?

2011-05-25 Thread Alexandros Gougousoudis
Hi, if I'am transmitting VLAN Information back to the supplicant, after an Acces-Accept (see below), who does this information use? Is it an information for the Switch, working an an Authenticator, to put the switchport into VLAN 22 or is it for the Supplicant/Client to enable VLAN tagging

Re: Who processes VLAN information?

2011-05-25 Thread Alan DeKok
Alexandros Gougousoudis wrote: if I'am transmitting VLAN Information back to the supplicant, No, you're not. RADIUS conversations are between a RADIUS client and server. The VLAN information is going to the client, i.e. switch. after an Acces-Accept (see below), who does this information

Re: Who processes VLAN information?

2011-05-25 Thread Alexandros Gougousoudis
the VLAN information. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Is it possible to write client information into database other than clients.conf in default virtual server?

2011-04-06 Thread 魏景鹏
Dear All, I know a little about dynamic client, it may be used in virtual server; But just as the mentioned subject, is it possible to write client information into database other than clients.conf in default virtual server? thx all WeiJingPeng - List info/subscribe/unsubscribe? See http

Is it possible to write proxy information into database other than proxy.conf?

2011-04-06 Thread 魏景鹏
many thx WeiJingPeng - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Is it possible to write client information into database other than clients.conf in default virtual server?

2011-04-06 Thread Alan DeKok
魏景鹏 wrote: is it possible to write client information into database other than clients.conf in default virtual server? Yes. Read raddb/sql.conf. Look for client. And see the NAS schema shipped with the server. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org

Re: Is it possible to write proxy information into database other than proxy.conf?

2011-04-06 Thread Alan DeKok
魏景鹏 wrote: many thx It's not possible. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Request information for EAP TTLS

2011-01-19 Thread Aman Arneja
Hi I am new to Free Radius and was just wondering if some1 can help me out. I am planning to implement an EAP TTLS client and was wondering the following about Free Radius for my testing. 1.) Does Free Radius Implementation of EAP TTLS Support the following a.) Client auth during phase 1

Re: Settign up postauth to record radius-client name and other information

2010-11-17 Thread Alan DeKok
William wrote: What I want to store int he radpostauth table is: ... (I want to add these) Calling_Station, Called_Station, See the debug mode for these attribute names. They're in the packet. Calling-Station-Id and Called-Station-Id. NAS_Short_name from clients.conf That's a

Store Access-Request packet information in database

2010-10-11 Thread c.schwarz
Hi, I would like to achieve some kind of a tracking system for 802.11 wireless clients, therefore every login attempt should be accepted and the necessary information (e.g. nas-ip-address, calling-station-id) should be stored in an extra database table. Example output: rad_recv: Access-Request

Re: Store Access-Request packet information in database

2010-10-11 Thread Phil Mayers
On 11/10/10 11:22, c.schw...@funknetz.at wrote: Hi, I would like to achieve some kind of a tracking system for 802.11 wireless clients, therefore every login attempt should be accepted and the necessary information (e.g. nas-ip-address, calling-station-id) should be stored in an extra database

User Information

2010-08-09 Thread Christian Rahl
I am working on trying to get information from connections such as Mac-Address and last connected IP from the device. Once we get this information I would like to add this to the radius database, either in the radpostauth or radacct. I am completely new to radius so not to sure about if I need

Re: Information not getting into MySQL - UPDATE to radacct

2010-03-19 Thread Alan DeKok
Steve. Parfitt (Siphon) wrote: I can see the accounting requests arrive at free radius and it seems to be writing to the MySQL with an UPDATE method yet I never see any information get into the DB. This is largely a MySQL question. FreeRADIUS is doing an UPDATE. An UPDATE to fields

Re: DHCP-Relay-Agent-Information in reply

2009-11-26 Thread Alexandr Sviridov
Some news, I looked through dhcp.c, and found some, hmmm hacks for PW_DHCP_OPTION_82 in sub fr_dhcp_encode(). After commenting out ifs blocks (DHCP_BASE_ATTR(vp-attribute) == PW_DHCP_OPTION_82) it went ok: DHCP-Offer: Agent-Information Option 82, length 18

Re: DHCP-Relay-Agent-Information in reply

2009-11-26 Thread Alan DeKok
Alexandr Sviridov wrote: Some news, I looked through dhcp.c, and found some, hmmm hacks for PW_DHCP_OPTION_82 in sub fr_dhcp_encode(). After commenting out ifs blocks (DHCP_BASE_ATTR(vp-attribute) == PW_DHCP_OPTION_82) it went ok: Fixed, thanks. Alan DeKok. - List

DHCP-Relay-Agent-Information in reply

2009-11-25 Thread Alexandr Sviridov
Hello I'm playing with freeradius dhcp support, and get the following problem. Freeradius 2.1.7, option 82, for dhcp snooping to work I have not only get DHCP-Relay-Agent-Information (option 82) in request but send it back to dhcp relay. Just test examle (radiusd in debug mode): DHCP

RE: Combine Proxy Answer with Local Information

2009-11-24 Thread Dan Fisher | Fluidata
Hi, Thanks for the all the pointers, I have got the proxying and post proxy configuration working with your hints. I have one small issue that I need to address. For some of our clients they don't want us to proxy requests before our LAC forwards them. Obviosuly I can configure a default entry

RE: Combine Proxy Answer with Local Information

2009-11-24 Thread tnt
I have one small issue that I need to address. For some of our clients they don't want us to proxy requests before our LAC forwards them. Obviosuly I can configure a default entry in the proxy config so that any domain realm that I havent configured is matched, and specified to be handled

RE: Combine Proxy Answer with Local Information

2009-11-23 Thread Dan Fisher | Fluidata
Hi, My problem is that the response I send to our LAC has to contain extra information depending on the domain. Is it possible to query a local mysql database for this extra information (these are cisco av pairs needed to establish the tunnels between the LAC and LNS) Yes. See man

Re: Combine Proxy Answer with Local Information

2009-11-23 Thread Alan DeKok
Dan Fisher | Fluidata wrote: However I am having real problems getting the mysql part working. I have tried using examples other people are using that work and they either just get treated as a string or the server wont even run in debug mode. If it doesn't run in debugging mode, it prints a

RE: Combine Proxy Answer with Local Information

2009-11-23 Thread tnt
thoughts on this or whether I can obtain the same information another way that would be much appreciated. I will be having potentially hundreds of different relams going through this freeradius instance and I need to add this information for each one Well, you can run sql queries from perl module

Combine Proxy Answer with Local Information

2009-11-18 Thread Dan Fisher | Fluidata
radius servers based on the domain used in the username. I have got all of the proxy'ing working within radius - nice and easy following the wiki and instructions - thanks. My problem is that the response I send to our LAC has to contain extra information depending on the domain. Is it possible

Re: Combine Proxy Answer with Local Information

2009-11-18 Thread tnt
My problem is that the response I send to our LAC has to contain extra information depending on the domain. Is it possible to query a local mysql database for this extra information (these are cisco av pairs needed to establish the tunnels between the LAC and LNS) Yes. See man unlang

Re: over 30 radiusd processes - more information

2009-10-18 Thread Craig Campbell
, but the logic is quite clever, and dissecting it from the middle is quite a challenge. I am hoping that the gdb output might prove helpful to someone already familiar with the logic flow. It seems I can reproduce this issue within 24 hours, so if there is any other information I could gather

Re: over 30 radiusd processes - more information

2009-10-18 Thread Ivan Kalik
, but the logic is quite clever, and dissecting it from the middle is quite a challenge. I am hoping that the gdb output might prove helpful to someone already familiar with the logic flow. It seems I can reproduce this issue within 24 hours, so if there is any other information I could gather

Re: over 30 radiusd processes - more information

2009-10-18 Thread Alan DeKok
Craig Campbell wrote: I have attached the radius.log file below, as well as gdb sessions for the hung processes showing the results of the gd 'bt' and 'list' commands. The log is interesting. Sat Oct 17 02:01:25 2009 : Error: WARNING: Unresponsive child for request 165616, in module sql

Re: over 30 radiusd processes - more information

2009-10-18 Thread Craig Campbell
@lists.freeradius.org Sent: Sunday, October 18, 2009 10:56 AM Subject: Re: over 30 radiusd processes - more information I've continued to try an investigate the root cause of this, and the last run behaved slightly differently - the parent process seems to have terminated, and there are more messages

Re: over 30 radiusd processes - more information

2009-10-18 Thread Ivan Kalik
I think you may be 'jumping the gun' a wee bit. The system currently has over 13,000 active sessions. There were some odd accounting packets, but the vast majority were valid. These could be configuration errors or hack attempts (investigating). Something broke at 2am. Before that you had a

Re: over 30 radiusd processes - more information

2009-10-18 Thread Alan Buxey
Hi, 1) Could bad accounting packets cause the radiusd process to EXIT? 2) Could bad accounting packets result in hung child processes (as seen in the gdb output after the radius log file)? I'd say yes. we ensure that bad packets dont hit our accounting servers eg accounting {

Re: 3GPP string Attributes, containing encapsulated information...

2009-10-17 Thread Alan DeKok
Stefan A. wrote: Is there a way to get Information out of the 3GPP-GPRS-Negotiated-QoS-profile? Perl. The Attribute is defined in the dictionary as: ATTRIBUTE 3GPP-GPRS-Negotiated-QoS-profile5 string The Value of a String might be: 99-0B811F739687877401 To get

3GPP string Attributes, containing encapsulated information...

2009-10-15 Thread Stefan A.
Hi there, Is there a way to get Information out of the 3GPP-GPRS-Negotiated-QoS-profile? The Attribute is defined in the dictionary as: ATTRIBUTE 3GPP-GPRS-Negotiated-QoS-profile5 string The Value of a String might be: 99-0B811F739687877401 To get the encapsulated

Re:freeradius doesn't sent information to mysql

2009-01-11 Thread tnt
I had sent an instance of accounting request from my vpn server to radius server. you send me that I haven't got anything configured in the accounting section. do you mean that vpn server frame is correct but accounting section in radius server doesn't work? It doesn't work on it's own. Entry

Re:freeradius doesn't sent information to mysql

2009-01-10 Thread Eric
I had sent an instance of accounting request from my vpn server to radius server. you send me that I haven't got anything configured in the accounting section. do you mean that vpn server frame is correct but accounting section in radius server doesn't work? rad_recv: Accounting-Request packet

Re:freeradius doesn't sent information to mysql

2009-01-04 Thread Eric
In vpn server or accounting server? To subscribe or unsubscribe via the World Wide Web, visit http://lists.freeradius.org/mailman/listinfo/freeradius-users or, via email, send a message with subject or body 'help' to freeradius-users-requ...@lists.freeradius.org rad_recv:

freeradius doesn't sent information to mysql

2008-12-30 Thread Eric
Hi, My freeradius server was working properly and it's tables in mysql had all the logs and online users. now the informations of users couldn't be intered in tables . what may be the reason? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius doesn't sent information to mysql

2008-12-30 Thread tnt
Are we suposed to use a crystal ball or are you going to post the debug? Ivan Kalik Kalik Informatika ISP Dana 30/12/2008, Eric bbah...@gmail.com piše: Hi, My freeradius server was working properly and it's tables in mysql had all the logs and online users. now the informations of users

802.1x dinamic vlan, using AD information

2008-11-28 Thread Hegedus Gabor
Hi all, I have a question. I use this combination: cisco 2950 sw as NAS freeRadius 2.1.1 as authenticator, Active Directory as the database, and the win xp client. It wokrs fine. I want one more thing, witch is dynamic vlan assignment. How can I implement it? My idea is enlarge the AD schema

Re: 802.1x dinamic vlan, using AD information

2008-11-28 Thread tnt
I use this combination: cisco 2950 sw as NAS freeRadius 2.1.1 as authenticator, Active Directory as the database, and the win xp client. It wokrs fine. I want one more thing, witch is dynamic vlan assignment. How can I implement it? My idea is enlarge the AD schema with vlanids and get it with

Information required regarding the freeradius.

2008-09-02 Thread Praveen Kumar
Hi, I am a newbie for FreeRadius. I need some information on freeradius regarding my requirement for authentication and session control. I want to setup the system like.. 1 One centralized server running on a Linux machine for authentication. 2 Client Linux machine in the network which should

Proxy accounting information in a diffrect table

2007-08-31 Thread justice obrey
How do you configure freeradius to receive accounting information from a proxy radius server ? Is it possible to store this accounting information in a different table in postgresql database? Thanks - Choose the right car based on your needs. Check out

Re: Getting required information from freeradius accounting log

2007-04-06 Thread satish patel
to “extract” the information I want from the /var/log/radius/acct-radius.log? I’d like to be able to obtain a report that would look like this: +-+ | Session Start Date/Time | +-+ | Session

  1   2   >