Re: Dynamic VLAN assignment depending on LDAP user group and MAC address

2013-10-14 Thread Matthew Newton
On Mon, Oct 14, 2013 at 10:40:19AM +0100, Matthew Newton wrote: > On Fri, Oct 11, 2013 at 05:41:07PM +0100, Fabrizio Vecchi wrote: > > As you can see, the device wasn't listed in the file, the authentication > > went fine, saying that the tunnel that I should get has ID 40, but that > > wasn't over

Re: Dynamic VLAN assignment depending on LDAP user group and MAC address

2013-10-14 Thread Matthew Newton
On Fri, Oct 11, 2013 at 05:41:07PM +0100, Fabrizio Vecchi wrote: > As you can see, the device wasn't listed in the file, the authentication > went fine, saying that the tunnel that I should get has ID 40, but that > wasn't overwritten by the authorized_macs check... Add DEFAULT Auth-Type := Rejec

Re: Dynamic VLAN assignment depending on LDAP user group and MAC address

2013-10-12 Thread Alan DeKok
Fabrizio Vecchi wrote: > I guess at the end of the day my question boils down to the following: > where should I put the MAC check, so that the user gets assigned to the > right VLAN? In post-auth. > If I put it in the authorize part of sites-enabled/default, the VLAN > update request will get

Re: Dynamic VLAN assignment depending on LDAP user group and MAC address

2013-10-12 Thread Fabrizio Vecchi
Hi Alan and thanks for the reply. On 12 October 2013 13:42, Alan DeKok wrote: > > So far, I managed to do the dynamic VLAN assignment, but cannot seem to > > get it to work together with the MAC checking. > Get them working independently. Then, put the pieces together. I managed to get the

Re: Dynamic VLAN assignment depending on LDAP user group and MAC address

2013-10-12 Thread Alan DeKok
Fabrizio Vecchi wrote: > First of all, sorry if my email is very long, I am just trying not to > leave any important details out. :) That's good. > So far, I managed to do the dynamic VLAN assignment, but cannot seem to > get it to work together with the MAC checking. They key thing to remem

Re: Dynamic vlan assignment

2013-07-20 Thread Martin Kraus
On Fri, Jul 19, 2013 at 06:03:31PM +0200, Dario Palmisano wrote: > •RADIUS-assigned VLANs are not supported when you enable multiple BSSIDs." > > So it seems not to be related to the IOS version, is it? > > Is there any way to overcome this somehow, if not... Do you actually need multiple bssids

Re: Dynamic vlan assignment

2013-07-19 Thread Alan Buxey
I'm sure there was some late in the day ios updates for 1130 series AP this stuff works with capwap/lwapp 1131 anyway, if MBSSID is not supported with dynamic vlan assignment so don't use mbssid, use guest mode instead. alan - List info/subscribe/unsubscribe? See http://www.freeradiu

Re: Dynamic vlan assignment

2013-07-19 Thread Dario Palmisano
At the end, thanks to the list suggestions I found in the cisco docs the sentence: "Keep these guidelines in mind when configuring multiple BSSIDs: •RADIUS-assigned VLANs are not supported when you enable multiple BSSIDs." So it seems not to be related to the IOS version, is it? Is there any w

Re: Dynamic vlan assignment

2013-07-19 Thread Martin Kraus
On Fri, Jul 19, 2013 at 04:20:51PM +0200, Dario Palmisano wrote: > > is this a 'fat/autonomous' AP? if so, then only latest firmware can handle > > multiple VLANS per 802.1X SSID with multiple BSSIDs present. > > This could be the problem, I found something in the Cisco documentation but > was u

Re: Dynamic vlan assignment

2013-07-19 Thread Dario Palmisano
On Friday 19 July 2013 16:54:13 a.l.m.bu...@lboro.ac.uk wrote: > Hi, > > > The specific configuration works fine I remove the following line from > > users file: > > Tunnel-Type := VLAN, Tunnel-Medium-Type := IEEE-802, Tunnel-Private- > > Group-ID := 218 > > Tunnel-Type = VLAN, >

Re: Dynamic vlan assignment

2013-07-19 Thread Dario Palmisano
On Friday 19 July 2013 16:29:57 Arran Cudbard-Bell wrote: > On 19 Jul 2013, at 15:10, Dario Palmisano wrote: > > On Friday 19 July 2013 15:49:55 Arran Cudbard-Bell wrote: > >> On 19 Jul 2013, at 14:37, Dario Palmisano wrote: > >>> Hello Everybody, > >>> > >>> I am configuring my freeradius to be

Re: Dynamic vlan assignment

2013-07-19 Thread A . L . M . Buxey
Hi, > Here you can download the (almost complete) debug log. Near the end I added a > text to make evident when I disconnected. > > http://webshare.icgeb.org//data/public/ce2e2ee9fbd84c362fd49b10805b36c8.php?lang=en please dont ask me to visit random web sites that require to to click on things

Re: Dynamic vlan assignment

2013-07-19 Thread A . L . M . Buxey
Hi, > The specific configuration works fine I remove the following line from users > file: > Tunnel-Type := VLAN, Tunnel-Medium-Type := IEEE-802, Tunnel-Private- > Group-ID := 218 Tunnel-Type = VLAN, Tunnel-Medium-Type = IEEE-802, Tunnel-Private-Group-ID =

Re: Dynamic vlan assignment

2013-07-19 Thread Arran Cudbard-Bell
On 19 Jul 2013, at 15:10, Dario Palmisano wrote: > On Friday 19 July 2013 15:49:55 Arran Cudbard-Bell wrote: >> On 19 Jul 2013, at 14:37, Dario Palmisano wrote: >>> Hello Everybody, >>> >>> I am configuring my freeradius to be integrated in the EDUROAM >>> federation. It works when the VLAN (a

Re: Dynamic vlan assignment

2013-07-19 Thread Dario Palmisano
You are right, I know! On Friday 19 July 2013 15:52:43 a.l.m.bu...@lboro.ac.uk wrote: > Hi, > > > I am configuring my freeradius to be integrated in the EDUROAM > > federation. It works when the VLAN (as configured in the accesspoint) is > > statically assigned. > > there are hundreds of sites us

Re: Dynamic vlan assignment

2013-07-19 Thread Dario Palmisano
On Friday 19 July 2013 15:49:55 Arran Cudbard-Bell wrote: > On 19 Jul 2013, at 14:37, Dario Palmisano wrote: > > Hello Everybody, > > > > I am configuring my freeradius to be integrated in the EDUROAM > > federation. It works when the VLAN (as configured in the accesspoint) is > > statically assig

Re: Dynamic vlan assignment

2013-07-19 Thread A . L . M . Buxey
Hi, > I am configuring my freeradius to be integrated in the EDUROAM federation. > It works when the VLAN (as configured in the accesspoint) is statically > assigned. there are hundreds of sites using this sort of configuration for eduroam - so its perfectly possible and fine (and standard!) so

Re: Dynamic vlan assignment

2013-07-19 Thread Arran Cudbard-Bell
On 19 Jul 2013, at 14:37, Dario Palmisano wrote: > Hello Everybody, > > I am configuring my freeradius to be integrated in the EDUROAM federation. > It works when the VLAN (as configured in the accesspoint) is statically > assigned. > > Now I would like to implement a "dynamic vlan assignment

Re: Dynamic vlan assignment with ldap groups

2013-07-16 Thread val john
Hi guys I had to also set the "*use_tunneled_reply=yes*" in the eap.conf to get the Dynamic vlan assignment to work On 12 July 2013 19:42, val john wrote: > Hi guys , > > Small question , do i need to import radius ldap schema ( items like > radiusprofiles > ) to our ldap server to get this

Re: Dynamic vlan assignment with ldap groups

2013-07-12 Thread val john
Hi guys , Small question , do i need to import radius ldap schema ( items like radiusprofiles ) to our ldap server to get this VLAN assignment work Thank You john On 12 July 2013 18:39, Arran Cudbard-Bell wrote: > > On 12 Jul 2013, at 13:57, val john wrote: > > > Hi guys , > > > > i have a

Re: Dynamic vlan assignment with ldap groups

2013-07-12 Thread Arran Cudbard-Bell
On 12 Jul 2013, at 13:57, val john wrote: > Hi guys , > > i have a freeradius setup that works with ldap group authentication ,i also > need to configure the dynamic VLAN assignment , so i configured the "users" > file as fallows , > > DEFAULT Ldap-Group == "cn=staff,ou=groups,dc=ldap,dc=e

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-25 Thread schilling
I believe I resolved this. I used eapol_test to get all wanted result, and will try on real NAS later on. The following is what I did. Basically I followed Alexander's example, Modified peap section in eap.conf to use another virtual server "auth" instead of inner-tunnel virtual server. I almost

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-25 Thread Alexander Clouter
schilling wrote: > > Thanks a lot. > > More questions. > > If you want to lower the load (and authentication latency) on your AD > servers then you might want to look at the following too: > > http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg65781.html > First things first,

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-24 Thread schilling
Thanks a lot. More questions. If you want to lower the load (and authentication latency) on your AD servers then you might want to look at the following too: http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg65781.html I am trying to follow your comment on this. I now realiz

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-24 Thread Alexander Clouter
schilling wrote: > > I am trying to play with your configuration, basically I have a > virtual server call auth as your example, and modified my eap.conf for > peap to use auth. > > what's the config:local.MY.realm? My debug showed > Phil pretty much covered it (and in a neater manner I was not

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-24 Thread Phil Mayers
On 01/24/2011 08:35 PM, schilling wrote: Hi Alexander, I am trying to play with your configuration, basically I have a virtual server call auth as your example, and modified my eap.conf for peap to use auth. what's the config:local.MY.realm? My debug showed FreeRadius lets you write *any* con

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-24 Thread schilling
Hi Alexander, I am trying to play with your configuration, basically I have a virtual server call auth as your example, and modified my eap.conf for peap to use auth. what's the config:local.MY.realm? My debug showed [suffix] Looking up realm "foo.edu" for User-Name = "sd...@foo.edu"^M [suffix]

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-22 Thread schilling
I have the following questions for using perl though. Since I already use LDAP or ntlm_auth for inner-tunnel mschapv0 authentication. Will there any flag set so I can know whether LDAP or ntlm_auth is using for mschapv0 authentication in perl script? Also if if I need to check ldap/AD for certain a

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-21 Thread Alexander Clouter
schilling wrote: > > Where should I put the perl script? I already have a perl module for > another virtual server to use radscript. > > I also tried unlang in post-auth, like > if ( %{User-Name} =~ /\@/ && fooEmployeeStatus =~ /active/i ) { >update outer.reply { >

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-20 Thread Alan Buxey
Hi, > Where should I put the perl script? I already have a perl module for > another virtual server to use radscript. > > I also tried unlang in post-auth, like > if ( %{User-Name} =~ /\@/ && fooEmployeeStatus =~ /active/i ) { > update outer.reply { >

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-20 Thread schilling
Where should I put the perl script? I already have a perl module for another virtual server to use radscript. I also tried unlang in post-auth, like if ( %{User-Name} =~ /\@/ && fooEmployeeStatus =~ /active/i ) { update outer.reply { Service-Type = "

Re: dynamic VLAN assignment w/ mschapv2 against AD and LDAP

2011-01-20 Thread Alan DeKok
schilling wrote: >Basically, I want to achieve > If (ldap authorization) { > if (ldap.employeeStatus = facstaff) { > REPLY{'Service-Type'}= "Framed-User"; > REPLY{'Tunnel-Type'} = "VLAN"; > REPLY{'Tunnel-Medium-Type'} = "IEEE-802"; >

Re: Dynamic VLAN assignment on NAS

2010-11-18 Thread Alan DeKok
Attou eric wrote: >The access point just put user1 on VLAN 30. My NAS ignore the VLAN ID > 60 (Tunnel-Private-Group-Id:0 = "60") Then the NAS is broken. > contained in the Access-Accept. I try with two different models of > Access point (zcomax and cisco) > >My question: Is there a par

Re: Dynamic VLAN Assignment based on a certificate, not a user.

2010-11-01 Thread Alan DeKok
Бисер Миланов wrote: > Hello! > Some time ago Alan mentioned that the new 2.1.10 version will support such a > thing. However, I can't seem to find it in the docs. Can anyone shed some > light on how that can be done with the new functionality? Read the "ChangeLog". There are new attributes

Re: Dynamic VLAN with AD/LDAP - Best Practice / preferred option?

2010-04-26 Thread Peter Lambrechtsen
This may help you. http://lists.freeradius.org/mailman/htdig/freeradius-users/2009-November/msg1.html Using the Postauth_users restricting it via a ldap group should work. On Tue, Apr 27, 2010 at 11:50 AM, Gary Gatten wrote: > Hello all, > > > > I currently have FR v2.1.6 (Yes, I’ll upgra

Re: Dynamic Vlan assigment 802.1x with cisco

2010-04-22 Thread Alexander Clouter
Alan Buxey wrote: > >> > steve Cleartext-Password := "testing" Service-Type = Framed-User, >> > Tunnel-Type = VLAN, Tunnel-Medium-Type = IEEE-802, >> > Tunnel-Private-Group-ID = 2 >> > >> I have no idea why people keep insisting on doing this, but make >> 'Tunnel-Private-Group-ID' the VLAN *na

Re: Dynamic Vlan assigment 802.1x with cisco

2010-04-22 Thread Alexander Clouter
Alan Buxey wrote: > >> > steve Cleartext-Password := "testing" Service-Type = Framed-User, >> > Tunnel-Type = VLAN, Tunnel-Medium-Type = IEEE-802, >> > Tunnel-Private-Group-ID = 2 >> > >> I have no idea why people keep insisting on doing this, but make >> 'Tunnel-Private-Group-ID' the VLAN *na

Re: Dynamic Vlan assigment 802.1x with cisco

2010-04-22 Thread Alan Buxey
Hi, > > steve Cleartext-Password := "testing" Service-Type = Framed-User, > > Tunnel-Type = VLAN, Tunnel-Medium-Type = IEEE-802, > > Tunnel-Private-Group-ID = 2 > > > I have no idea why people keep insisting on doing this, but make > 'Tunnel-Private-Group-ID' the VLAN *name*. You are only goi

Re: Dynamic Vlan assigment 802.1x with cisco

2010-04-22 Thread Alexander Clouter
Guillermo Borrallo wrote: > > I have a problem to change vlan on a Catalyst 2950 switch using the > 802.1x protocol. The problem is that no changes to the vlan you > specified. The authentication and validation of the user is correct, > but does not change vlan. > You might want to consider re

RE: Dynamic VLAN assignment works on EAP-MD5, but not EAP-PEAP!!!

2009-12-19 Thread tnt
> Thank you very much for your help! Now it works beautifully! > > My next step is to integrate FreeRadius with my Windows domain to use > Windows AD for authentication. I am sure I will more questions for you > guys! http://deployingradius.com/documents/configuration/active_directory.html Ivan K

RE: Dynamic VLAN assignment works on EAP-MD5, but not EAP-PEAP!!!

2009-12-18 Thread Difan Zhao
:53 PM To: FreeRadius users mailing list Subject: Re: Dynamic VLAN assignment works on EAP-MD5, but not EAP-PEAP!!! > I have figured out how to configure attributes. Here is my "user" file: > > > > test Cleartext-Password := "test" > > Tunnel-Type =

Re: Dynamic VLAN assignment works on EAP-MD5, but not EAP-PEAP!!!

2009-12-17 Thread tnt
> I have figured out how to configure attributes. Here is my "user" file: > > > > test Cleartext-Password := "test" > > Tunnel-Type = 16777229, > > Tunnel-Medium-Type = 16777222, > > Tunnel-Private-Group-ID = 3 > > > > When I use MD5-Challenge, I got put in the right vlan

Re: Dynamic VLAN attribute in LDAP or AD?

2009-08-25 Thread Alan DeKok
Gary Gatten wrote: > I'm assuming I can do roughly the same thing with NTLM_AUTH? I "have" > to use NTLM_Auth for 8021x (right? - at least all docs say this), No, they don't. They say that you need to use ntlm_auth for authentication in *certain* cases, when the user database is Active Direc

Re: Dynamic VLAN attribute in LDAP or AD?

2009-08-24 Thread Ivan Kalik
> Agreed. I didn't know if I could do some group checking with ntlm_auth, > more accurately get a list of groups a user belongs to? If I used FQDN I > could prolly parse out the info I need from the user name as well: > gary.neteng.waddell Ill try LDAP - good learning experience! > No need. AD

RE: Dynamic VLAN attribute in LDAP or AD?

2009-08-24 Thread Ivan Kalik
> So, by looking at this more carefully I'll have to do a bunch of > if/else's or cases? What if for instance I have 500 departments/groups > - 500 different vlans? I'll have to test each one? > > I guess what I was hoping to do was something like: > > Get attribute "n" for user y (where n = a va

Re: Dynamic VLAN attribute in LDAP or AD?

2009-08-24 Thread Gary Gatten
ginal Message - From: freeradius-users-bounces+ggatten=waddell@lists.freeradius.org To: freeradius-users@lists.freeradius.org Sent: Mon Aug 24 15:48:40 2009 Subject: RE: Dynamic VLAN attribute in LDAP or AD? > Interesting... I'm assuming I could use existing LDAP attribs and re

RE: Dynamic VLAN attribute in LDAP or AD?

2009-08-24 Thread Jason Alderfer
ntication tool that returns 0 or 1 depending on the correctness of a password. This is an authorization question - what kind of access will the authenticated user be given? > -Original Message- > From: Jason Alderfer [mailto:j...@emu.edu] > Sent: Monday, August 24, 2009 2:10 PM

RE: Dynamic VLAN attribute in LDAP or AD?

2009-08-24 Thread Gary Gatten
riginal Message- From: Gary Gatten Sent: Monday, August 24, 2009 10:34 AM To: 'FreeRadius users mailing list' Cc: 'Jason Alderfer' Subject: RE: Dynamic VLAN attribute in LDAP or AD? I'm assuming I can do roughly the same thing with NTLM_AUTH? I "have" to us

RE: Dynamic VLAN attribute in LDAP or AD?

2009-08-24 Thread Gary Gatten
lists.freeradius.org [mailto:freeradius-users-bounces+ggatten=waddell@lists.freeradius.or g] On Behalf Of Jason Alderfer Sent: Tuesday, August 18, 2009 2:18 PM To: FreeRadius users mailing list Subject: Re: Dynamic VLAN attribute in LDAP or AD? > So, I'm trying to use 802.1x dynamic V

Re: Dynamic VLAN attribute in LDAP or AD?

2009-08-18 Thread Alan Buxey
Hi, > > > Where coudl I put this code Authorize, autenticate, postatuh, ldap module? > > Authorize postauth ? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Dynamic VLAN attribute in LDAP or AD?

2009-08-18 Thread Alan DeKok
Gary Gatten wrote: > Dude, if it's this easy that would be SWEET! The How To's for TLS/PEAP > are a little outdated so I'm working on getting the CA working now > (CA.all doesn't exist anymore.) See my message to the list of an hour or two ago. In v2, you have to do almost *nothing* to get PEA

Re: Dynamic VLAN attribute in LDAP or AD?

2009-08-18 Thread Jason Alderfer
> Where coudl I put this code Authorize, autenticate, postatuh, ldap module? Authorize >>> So, I'm trying to use 802.1x dynamic VLAN assignment.  I have this >>> working when I conf the "users" file.  However, I don't want to >>> create/maintain the users file for 2,000 users! >>> >>> Is there

Re: Dynamic VLAN attribute in LDAP or AD?

2009-08-18 Thread Rokkhan
Where coudl I put this code Authorize, autenticate, postatuh, ldap module? 2009/8/18 Jason Alderfer : > >> So, I'm trying to use 802.1x dynamic VLAN assignment.  I have this >> working when I conf the "users" file.  However, I don't want to >> create/maintain the users file for 2,000 users! >> >>

RE: Dynamic VLAN attribute in LDAP or AD?

2009-08-18 Thread Gary Gatten
s-bounces+ggatten=waddell@lists.freeradius.org [mailto:freeradius-users-bounces+ggatten=waddell@lists.freeradius.or g] On Behalf Of Jason Alderfer Sent: Tuesday, August 18, 2009 2:18 PM To: FreeRadius users mailing list Subject: Re: Dynamic VLAN attribute in LDAP or AD? > So, I'm trying to u

Re: Dynamic VLAN attribute in LDAP or AD?

2009-08-18 Thread Jason Alderfer
> So, I'm trying to use 802.1x dynamic VLAN assignment. I have this > working when I conf the "users" file. However, I don't want to > create/maintain the users file for 2,000 users! > > Is there an attribute in AD / LDAP I can use for the dynamic VLAN? > Ideally I could do this at the "Group" l

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread tnt
>>>I'm using version 1.1.3 so, I moved the "files" entry below the ldap >>>entry but my DEFAULT entry in the file: users does not match or return >>>any value. >>> >> >> You should upgrade. Did something else match in files? Post the debug. > >Stuck with this version for now. > >I have a "catchall"

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread Paul Dealy
On Tue, Feb 17, 2009 at 11:44 AM, wrote: >>I'm using version 1.1.3 so, I moved the "files" entry below the ldap >>entry but my DEFAULT entry in the file: users does not match or return >>any value. >> > > You should upgrade. Did something else match in files? Post the debug. Stuck with this vers

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread tnt
>I'm using version 1.1.3 so, I moved the "files" entry below the ldap >entry but my DEFAULT entry in the file: users does not match or return >any value. > You should upgrade. Did something else match in files? Post the debug. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? S

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread Paul Dealy
On Tue, Feb 17, 2009 at 11:04 AM, wrote: Am I correct in saying that the LDAP-attribute that is mapped to Tunnel-Private-Group-ID would need to be set to the value of the the VLAN I require? The LDAP-attribute that I wish to use curently contains values like "ITISCP" and "ENISCP

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread tnt
>>>Am I correct in saying that the LDAP-attribute that is mapped to >>>Tunnel-Private-Group-ID would need to be set to the value of the the >>>VLAN I require? The LDAP-attribute that I wish to use curently >>>contains values like "ITISCP" and "ENISCP". I want to say if >>>attribute value == ITI

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread Paul Dealy
On Tue, Feb 17, 2009 at 9:50 AM, wrote: >>Am I correct in saying that the LDAP-attribute that is mapped to >>Tunnel-Private-Group-ID would need to be set to the value of the the >>VLAN I require? The LDAP-attribute that I wish to use curently >>contains values like "ITISCP" and "ENISCP". I wan

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread tnt
>Am I correct in saying that the LDAP-attribute that is mapped to >Tunnel-Private-Group-ID would need to be set to the value of the the >VLAN I require? The LDAP-attribute that I wish to use curently >contains values like "ITISCP" and "ENISCP". I want to say if >attribute value == ITISCP set vl

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-16 Thread tnt
> >I have a value set for an attribute in LDAP, how do I "extract" the >value from the attribute and do a comparison on it in the users file >so I can set the VLAN? > ldap.attrmap file in raddb directory. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freerad

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Michael Schwartzkopff
Am Freitag, 13. Februar 2009 12:36:09 schrieb Paul Dealy: > On Fri, Feb 13, 2009 at 10:16 PM, Michael Schwartzkopff > > wrote: > > Am Freitag, 13. Februar 2009 11:54:29 schrieb Paul Dealy: > >> On Fri, Feb 13, 2009 at 9:12 PM, Michael Schwartzkopff > >> > >> wrote: > >> > Am Freitag, 13. Februar

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Michael Schwartzkopff
Am Freitag, 13. Februar 2009 13:39:49 schrieb Paul Dealy: > On Fri, Feb 13, 2009 at 11:22 PM, Michael Schwartzkopff > > wrote: > > Am Freitag, 13. Februar 2009 12:36:09 schrieb Paul Dealy: > >> On Fri, Feb 13, 2009 at 10:16 PM, Michael Schwartzkopff > >> > >> wrote: > >> > Am Freitag, 13. Februar

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Paul Dealy
On Fri, Feb 13, 2009 at 11:22 PM, Michael Schwartzkopff wrote: > Am Freitag, 13. Februar 2009 12:36:09 schrieb Paul Dealy: >> On Fri, Feb 13, 2009 at 10:16 PM, Michael Schwartzkopff >> >> wrote: >> > Am Freitag, 13. Februar 2009 11:54:29 schrieb Paul Dealy: >> >> On Fri, Feb 13, 2009 at 9:12 PM,

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Michael Schwartzkopff
Am Freitag, 13. Februar 2009 12:36:09 schrieb Paul Dealy: > On Fri, Feb 13, 2009 at 10:16 PM, Michael Schwartzkopff > > wrote: > > Am Freitag, 13. Februar 2009 11:54:29 schrieb Paul Dealy: > >> On Fri, Feb 13, 2009 at 9:12 PM, Michael Schwartzkopff > >> > >> wrote: > >> > Am Freitag, 13. Februar

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Michael Schwartzkopff
Am Freitag, 13. Februar 2009 12:36:09 schrieb Paul Dealy: > On Fri, Feb 13, 2009 at 10:16 PM, Michael Schwartzkopff > > wrote: > > Am Freitag, 13. Februar 2009 11:54:29 schrieb Paul Dealy: > >> On Fri, Feb 13, 2009 at 9:12 PM, Michael Schwartzkopff > >> > >> wrote: > >> > Am Freitag, 13. Februar

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Paul Dealy
On Fri, Feb 13, 2009 at 10:16 PM, Michael Schwartzkopff wrote: > Am Freitag, 13. Februar 2009 11:54:29 schrieb Paul Dealy: >> On Fri, Feb 13, 2009 at 9:12 PM, Michael Schwartzkopff >> >> wrote: >> > Am Freitag, 13. Februar 2009 11:00:10 schrieb Paul Dealy: >> >> On Fri, Feb 13, 2009 at 6:37 PM, M

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Michael Schwartzkopff
Am Freitag, 13. Februar 2009 11:54:29 schrieb Paul Dealy: > On Fri, Feb 13, 2009 at 9:12 PM, Michael Schwartzkopff > > wrote: > > Am Freitag, 13. Februar 2009 11:00:10 schrieb Paul Dealy: > >> On Fri, Feb 13, 2009 at 6:37 PM, Michael Schwartzkopff > >> > >> wrote: > >> > Am Freitag, 13. Februar 2

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Paul Dealy
On Fri, Feb 13, 2009 at 9:12 PM, Michael Schwartzkopff wrote: > Am Freitag, 13. Februar 2009 11:00:10 schrieb Paul Dealy: >> On Fri, Feb 13, 2009 at 6:37 PM, Michael Schwartzkopff >> >> wrote: >> > Am Freitag, 13. Februar 2009 07:17:17 schrieb Paul Dealy: >> >> I have a working radius server (ver

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Michael Schwartzkopff
Am Freitag, 13. Februar 2009 11:00:10 schrieb Paul Dealy: > On Fri, Feb 13, 2009 at 6:37 PM, Michael Schwartzkopff > > wrote: > > Am Freitag, 13. Februar 2009 07:17:17 schrieb Paul Dealy: > >> I have a working radius server (ver 1.1.3). which I am using for > >> 802.1x authentication of wired swit

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-13 Thread Paul Dealy
On Fri, Feb 13, 2009 at 6:37 PM, Michael Schwartzkopff wrote: > Am Freitag, 13. Februar 2009 07:17:17 schrieb Paul Dealy: >> I have a working radius server (ver 1.1.3). which I am using for >> 802.1x authentication of wired switch ports. I would like to >> dynamically assign users vlans. I have

Re: Dynamic Vlan Allocation based on LDAP Attribute Value

2009-02-12 Thread Michael Schwartzkopff
Am Freitag, 13. Februar 2009 07:17:17 schrieb Paul Dealy: > I have a working radius server (ver 1.1.3). which I am using for > 802.1x authentication of wired switch ports. I would like to > dynamically assign users vlans. I have cisco gear and have achieved > basic vlan allocation by configuring

Re : Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Um... i think i just sent an empty response, sorry about that and thank you for this clear explanation. i just will change my NAS! (but i will call d-link before ). see ya! Joel MBA OYONE wrote: > We all agree that assocation is made before authentication process, in > order to RADIUS to be ab

Re : Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Re: Re : Re : Dynamic VLAN and FreeRadius Joel MBA OYONE wrote: > We all agree that assocation is made before authentication process, in > order to RADIUS to be able to do its stuffs. but the fact is that it > doesn't work, Then your NAS is broken. Buy a real NAS that supports VLAN

Re: Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Alan DeKok
Joel MBA OYONE wrote: > We all agree that assocation is made before authentication process, in > order to RADIUS to be able to do its stuffs. but the fact is that it > doesn't work, Then your NAS is broken. Buy a real NAS that supports VLAN assignment. > and i was wondering what would be the

Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Thank you Joe for your answer! We all agree that assocation is made before authentication process, in order to RADIUS to be able to do its stuffs. but the fact is that it doesn't work, and i was wondering what would be the result if i set: "Tunnel-Private-Group-ID = 100" (when the SSID were i am

Re: Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joe Vieira
HI Joel, I think the issue here is that the D-Link AP's you have are rather limited. Radius can not ever assign an SSID because that step occurs before the user authenticated. Wireless starts with an association from the user to the AP's SSID from there the AP decides what needs to happe

Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Alan, I possess a device from D-Link (DWS-3024). it is a wireless switch controler, and the documentation says that: - One SSID has to be affect to one VLAN on the profile. - An Access point could be configured with up to 8 ifferent SSIDs and it is possible to affect each SSID on its own netw

Re: Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Alan DeKok
Joel MBA OYONE wrote: >> No. VLAN assignment is after SSID association, and after 802.1x >> authentication. > > OK, is it possible to associate in SSID_1 and be assigned to a different > VLAN than the we are associated in ? That doesn't make sense. SSID's aren't tied to VLANs, unless you con

Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Alan DeKok. wrote: > No. VLAN assignment is after SSID association, and after 802.1x > authentication. OK, is it possible to associate in SSID_1 and be assigned to a different VLAN than the we are associated in ? (exemple, when i am associated to SSID_1, which belongs to VLAN100, RADIUS s

Re: Re : Dynamic VLAN and FreeRadius

2008-05-21 Thread Alan DeKok
Joel MBA OYONE wrote: > So if SSID "friend" is assigned to VLAN 100, the end-user will associate > with that SSID, right?? No. VLAN assignment is after SSID association, and after 802.1x authentication. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.h

Re : Dynamic VLAN and FreeRadius

2008-05-21 Thread Joel MBA OYONE
> for example, a Cisco device would want the tunnel medium type, type and > private group id Tunnel-Medium-Type = "IEEE-802" Tunnel-Type = "VLAN" Tunnel-Private-Group-Id = "100" > this would tell the NAS to put the user onto VLAN 100 So if SSID "friend" is assigned to VLAN 100, the end

Re: Dynamic VLAN and FreeRadius

2008-05-21 Thread A . L . M . Buxey
Hi, > I am trying to get the RADIUS server to not only authenticating the > supplicant, but providing the NAS with a VLAN ID. I have tried certain > resources and haven't been able to receive the VLAN ID. Can any provide any > help in this area? depends on your NAR - you need to send back the cor

Re: Dynamic VLAN and FreeRadius

2008-05-20 Thread Michael Schwartzkopff
William E. Russell schrieb: > All, > > I am trying to get the RADIUS server to not only authenticating the > supplicant, but providing the NAS with a VLAN ID. I have tried certain > resources and haven't been able to receive the VLAN ID. Can any provide any > help in this area? > > Thanks > > >

Re: Dynamic VLAN-Assigning with Dell PowerConnect 3448

2007-06-06 Thread André Graf
Hi That could be the solution for my problem, because I didn't find one installed on the system. But where can I download this dictionary? :S Am 06.06.2007 um 08:28 schrieb Jan Schermer / ET NETERA: > Hi, > I was just trying to do the same thing - the device has to support > the VLAN settings

Re: Dynamic VLAN-Assigning with Dell PowerConnect 3448

2007-06-05 Thread Jan Schermer / ET NETERA
Hi, I was just trying to do the same thing - the device has to support the VLAN settings from Radius, otherwise you are screwed :-( download the radius dictionary for powerconnect 3448 and look if the parameters are in here - in my case they were not and got ignored as well... Jan Schermer Li

Re: Dynamic VLAN-id setting on wireless AP

2007-05-30 Thread tnt
Restricts as much as the static VLAN can. No, our wireless clients have to use VPN(PPTP) if they want Internet mail etc. Local traffic (game servers etc.) is left wild with only bandwidth restrictions. Ivan Kalik Kalik Informatika ISP Dana 30/5/2007, "Jan Schermer / ET NETERA" <[EMAIL PROTECTED

Re: Dynamic VLAN-id setting on wireless AP

2007-05-30 Thread Jan Schermer / ET NETERA
Do you use this scenario? Does Mikrotik really restrict each user to the given VLAN? Thanks Jan Schermer Linux Administrator ET NETERA | smart e-business solutions [EMAIL PROTECTED] +420 60805 ~ [ www.ahold.cz | www.annonce.cz | www.datart.cz ] [ www.knizniweb.cz | www.siemens.cz |

Re: Dynamic VLAN-id setting on wireless AP

2007-05-30 Thread Arran Cudbard-Bell
Jan Schermer / ET NETERA wrote: > Hi, > I want to tag VLANs on the wireless AP (Mikrotik OS) according to radius > criteria (type of autentization, DN in certificate etc.). Does someone > here have experience with that? > It seems easy enough to do on the freeradius side, but how is this > suppo

Re: Dynamic VLAN-id setting on wireless AP

2007-05-30 Thread tnt
/interface vlan > crete VLAN names, IDs and bind to phisical interface /ip address > assign IP subnets to VLAN interfaces (names) VLANS can only enhance security. Ivan Kalik Kalik Informatika ISP Dana 30/5/2007, "Jan Schermer / ET NETERA" <[EMAIL PROTECTED]> piše: >Hi, >I want to tag VLANs on

Re: Dynamic VLAN - limiting switchs VLANs?

2007-05-25 Thread Alan Dekok
Robert wrote: > I can plug a computer into the switch, have the switch grab the MAC > addy, pass it to FR, hit the DB and return what VLAN that MAC belongs > to, and then have the switch configure to port to the correct VLAN. > > Now the complication that I'm facing is that in our environment, a M

Re: Dynamic VLAN - limiting switchs VLANs?

2007-05-21 Thread Arran Cudbard-Bell
Phil Mayers wrote: > Robert wrote: > >> Hello all, >> >> I currently have FR running and happily doing MAC authentication against >> a MYSQL DB. >> >> I can plug a computer into the switch, have the switch grab the MAC >> addy, pass it to FR, hit the DB and return what VLAN that MAC belongs >>

Re: Dynamic VLAN - limiting switchs VLANs?

2007-05-21 Thread Phil Mayers
Robert wrote: > Hello all, > > I currently have FR running and happily doing MAC authentication against > a MYSQL DB. > > I can plug a computer into the switch, have the switch grab the MAC > addy, pass it to FR, hit the DB and return what VLAN that MAC belongs > to, and then have the switch con

Re: Dynamic VLAN - limiting switchs VLANs?

2007-05-21 Thread A . L . M . Buxey
Hi, > What I need is a way FR can not only match the MAC to a VLAN, but also > to cross reference that result to the VLANs that are available from the > requesting switch. either use larger queries or use an extrenal perl or php script to do the work in your DB you'd need to add a few more colu

Re: Dynamic VLAN assignment

2004-05-25 Thread Bob McCormick
Why not use public secure password forwarding? " Public Secure Packet Forwarding (PSPF) prevents client devices associated to an access point from inadvertently sharing files or communicating with other client devices associated to the access point. It provides Internet access to client devic

RE: Dynamic VLAN assignment

2004-05-25 Thread Hayes, Scott
er [mailto:[EMAIL PROTECTED] Sent: Tuesday, May 25, 2004 10:42 AM To: [EMAIL PROTECTED] Subject: Re: Dynamic VLAN assignment well, i thought Dan was speaking about a new VLAN per user not per AP. this is possible with Cisco APs. as far as i know, 1200 and 1100 can do trunking. ciao artur Wil

Re: Dynamic VLAN assignment

2004-05-25 Thread Artur Hecker
:-) ok, though i don't know what these magic private VLANs would be technically... with VLANs either you mark ports or you mark packets. what can they do in an AP? they can mark the port where it's plugged in as VLANx or they can make the AP send packets marked as appertaining to VLANx... well

Re: Dynamic VLAN assignment

2004-05-25 Thread Artur Hecker
: Artur Hecker [mailto:[EMAIL PROTECTED] Sent: Monday, May 24, 2004 5:40 PM To: [EMAIL PROTECTED] Subject: Re: Dynamic VLAN assignment i don't know, but i would say execute an external program which reads a VLAN list file and attibutes and marks as used the next unused VLAN. but you will end up

  1   2   >