Re: Trying other authentication methods when the first is invalid

2013-01-11 Thread Alan DeKok
Meyers, Dan wrote: > Anyway, we have got some Juniper EX2200 switches. The problem with these is > that they do mac-auth as a 'fake' 802.1x auth. The request has the User-Name > attribute set to the MAC address correctly, but also has an EAP-Message > present, it just doesn't contain anything we

Re: Trying other authentication methods when the first is invalid

2013-01-11 Thread Phil Mayers
On 11/01/13 13:23, Meyers, Dan wrote: Anyway, we have got some Juniper EX2200 switches. The problem with these is that they do mac-auth as a 'fake' 802.1x auth. The request has the User-Name attribute set to the MAC address correctly, but also has an EAP-Message present, it just doesn't contain

Trying other authentication methods when the first is invalid

2013-01-11 Thread Meyers, Dan
Sorry for the wall of tet, I'd rather give too much info than not enough. Our FreeRADIUS server (version 2.1.8 running on Ubuntu 10.04 LTS x64, installed from packages) currently does mac-based authentication of hosts onto edge switches using perl scripts (rlm_perl) talking to the API for our ne