Re: Removing tunnel attributes only for specific NAS

2009-05-19 Thread liran tal
gt; > > > So the Nomadix is configured as RADIUS client, connected to the FreeRADIUS > server. I have tested the connection with test users stored in freeRADIUS´ > “users” file, and everything worked fine. The problem starts with the > Access-Accept RADIUS message. This message inclu

Re: Tunnel attributes

2009-01-20 Thread tnt
>By the way, what about cisco-vsa-hack? > >Quoting SQL HOWTO >"If you have a Cisco nas, set the cisco-vsa-hack" > >How and where is this set? > Uh, I haven't seen that for a while. It used to be in preprocess in radiusd.conf in old version with all the other hacks. But that's not going to help. It

Re: Tunnel attributes

2009-01-20 Thread Luciano Afranllie
On Tue, Jan 20, 2009 at 8:31 AM, wrote: >>At present we are not recommended for upgrading. > > I would really like to know who recommends that *new* installations > should use outdated, insecure and buggy versions? > >>So is there any way to >>parse Cisco-AVpair attributes in sql.conf file itself

Re: Tunnel attributes

2009-01-20 Thread tnt
>At present we are not recommended for upgrading. I would really like to know who recommends that *new* installations should use outdated, insecure and buggy versions? >So is there any way to >parse Cisco-AVpair attributes in sql.conf file itself? > No. But you can copy the perl module from free

Re: Tunnel attributes

2009-01-19 Thread ramesh p
At present we are not recommended for upgrading. So is there any way to parse Cisco-AVpair attributes in sql.conf file itself? Regards, Ramesh. 2009/1/19 > Upgrade to the latest version. > > Ivan Kalik > Kalik Informatika ISP > > > Dana 19/1/2009, "ramesh p" piše: > > >Does freeradius.1.1.6 su

Re: Tunnel attributes

2009-01-19 Thread tnt
Upgrade to the latest version. Ivan Kalik Kalik Informatika ISP Dana 19/1/2009, "ramesh p" piše: >Does freeradius.1.1.6 supoorts? which version of freeradius supports?? > >2009/1/19 > >> Upgrade. perl is experimental there. >> >> Ivan Kalik >> Kalik Informatika iSP >> >> Dana 19/1/2009, "rame

Re: Tunnel attributes

2009-01-19 Thread ramesh p
Does freeradius.1.1.6 supoorts? which version of freeradius supports?? 2009/1/19 > Upgrade. perl is experimental there. > > Ivan Kalik > Kalik Informatika iSP > > Dana 19/1/2009, "ramesh p" piše: > > >am using freeradius-1.1.6 > > > >2009/1/19 ramesh p > > > >> One more question how to include

Re: Tunnel attributes

2009-01-19 Thread tnt
Upgrade. perl is experimental there. Ivan Kalik Kalik Informatika iSP Dana 19/1/2009, "ramesh p" piše: >am using freeradius-1.1.6 > >2009/1/19 ramesh p > >> One more question how to include the perl script for parsing. I haven't >> done this before. Please kindly give suggestions. >> >> Thanks

Re: Tunnel attributes

2009-01-19 Thread tnt
Configure perl module to use your script (raddb/modules/perl). Script should use sub acconting. List perl in accounting. Ivan Kalik Kalik Informatika ISP Dana 19/1/2009, "ramesh p" piše: >One more question how to include the perl script for parsing. I haven't done >this before. Please kindly g

Re: Tunnel attributes

2009-01-19 Thread ramesh p
am using freeradius-1.1.6 2009/1/19 ramesh p > One more question how to include the perl script for parsing. I haven't > done this before. Please kindly give suggestions. > > Thanks in advance! > Ramesh. > > 2009/1/19 > > Yes. That's the general idea - create custom attributes; fill them with >

Re: Tunnel attributes

2009-01-19 Thread ramesh p
One more question how to include the perl script for parsing. I haven't done this before. Please kindly give suggestions. Thanks in advance! Ramesh. 2009/1/19 > Yes. That's the general idea - create custom attributes; fill them with > vaues from avpairs; alter radacct and queries to store new a

Re: Tunnel attributes

2009-01-19 Thread tnt
Yes. That's the general idea - create custom attributes; fill them with vaues from avpairs; alter radacct and queries to store new attributes. Ivan Kalik Kalik Informatika ISP Dana 19/1/2009, "ramesh p" piše: >Thanks. Is this digest helps for making changes? >http://osdir.com/ml/gnu.radius.gen

Re: Tunnel attributes

2009-01-19 Thread ramesh p
Thanks. Is this digest helps for making changes? http://osdir.com/ml/gnu.radius.general/2003-04/msg00086.html Regards, Ramesh. On Mon, Jan 19, 2009 at 6:15 PM, wrote: > >I need to have both Disc-Cause-Ext, PPP-Disconnect-Cause as columns in > >radacct table. For that do i need to do parsing? How

Re: Tunnel attributes

2009-01-19 Thread tnt
>I need to have both Disc-Cause-Ext, PPP-Disconnect-Cause as columns in >radacct table. For that do i need to do parsing? How to proceed. For parsing best use perl. You might want to add some attributes to raddb/dictionary and store parsed values there. And you will need to alter radacct table sch

Re: Tunnel attributes

2009-01-19 Thread ramesh p
Thanks alot Ivan Kalik. I need to have both Disc-Cause-Ext, PPP-Disconnect-Cause as columns in radacct table. For that do i need to do parsing? How to proceed. ANy references? Thanks, Ramesh. On Mon, Jan 19, 2009 at 5:23 PM, wrote: > >I understand this will be received like > >cisco-avpair=Disc

Re: Tunnel attributes

2009-01-19 Thread tnt
>I understand this will be received like >cisco-avpair=Disc-Cause-Ext=No Reason >cisco-avpair=PPP-Disconnect-Cause=some cause. >How to store in radacct table both Disc-Cause-Ext, PPP-Disconnect-Cause >attributes individually? > Attribute => Cisco-AVPair Value => Disc-Cause-Ext = whatever Ivan Kal

Re: Tunnel attributes

2009-01-18 Thread ramesh p
I understand this will be received like cisco-avpair=Disc-Cause-Ext=No Reason cisco-avpair=PPP-Disconnect-Cause=some cause. How to store in radacct table both Disc-Cause-Ext, PPP-Disconnect-Cause attributes individually? Thanks, Ramesh. On Mon, Jan 19, 2009 at 12:39 PM, ramesh p wrote: > These

Re: Tunnel attributes

2009-01-18 Thread ramesh p
These are *Cisco*- *AVpair's. *Any suggestion how to add them to sql.conf and sql database. Any syntax references?? Thanks in Advance! Ramesh. On Fri, Jan 9, 2009 at 4:30 PM, wrote: > >How to support these attributes ...Disc-Cause-Ext, PPP-Disconnect-Cause. > Are > >they supported in freeradius

Re: Tunnel attributes

2009-01-09 Thread tnt
>How to support these attributes ...Disc-Cause-Ext, PPP-Disconnect-Cause. Are >they supported in freeradius version 1.1.6? > >Do i need to import any dictionary files if this version doesn't supports? > They look like vendor specific. Look in the vendor dictionary. Are those Cisco avpairs? Ivan K

Re: Tunnel attributes

2009-01-08 Thread ramesh p
at 7:36 PM, ramesh p wrote: > Thank you. > > > On Thu, Jan 8, 2009 at 7:23 PM, wrote: > >> >How to start supporting Tunnel attributes for freeradius vers 1.1.6. Any >> >document references?? >> >> No documentation. They are supported just like any

Re: Tunnel attributes

2009-01-08 Thread ramesh p
Thank you. On Thu, Jan 8, 2009 at 7:23 PM, wrote: > >How to start supporting Tunnel attributes for freeradius vers 1.1.6. Any > >document references?? > > No documentation. They are supported just like any other attribute. > > >Which will be the starting point fo

Re: Tunnel attributes

2009-01-08 Thread Alan DeKok
ramesh p wrote: > How to start supporting Tunnel attributes for freeradius vers 1.1.6. Any > document references?? They are just normal attributes like any other. > Which will be the starting point for this. Do i need to change > configuration of mysql.conf file? Or directly creat

Re: Tunnel attributes

2009-01-08 Thread tnt
>How to start supporting Tunnel attributes for freeradius vers 1.1.6. Any >document references?? No documentation. They are supported just like any other attribute. >Which will be the starting point for this. Do i need to change configuration >of mysql.conf file? Or directly creat

Tunnel attributes

2009-01-08 Thread ramesh p
How to start supporting Tunnel attributes for freeradius vers 1.1.6. Any document references?? Which will be the starting point for this. Do i need to change configuration of mysql.conf file? Or directly creating database helps? some of the attributes to be highlighted.. Tunnel Type, Tunnel-Server

Re: inner/outer Tunnel attributes of TTLS/MS-CHAPv2

2008-02-04 Thread Arran Cudbard-Bell
Vincent Magnin wrote: Hello Alan, You have right, this version is too old and do not support this feature (I've checked src/modules/rlm_eap/types/rlm_eap_ttls/ttls.c). This version is the one supplied with Redhat Enterprise 4. I'll compile 1.1.7 from source. Really I would go with 2.01, it's t

Re: Re: inner/outer Tunnel attributes of TTLS/MS-CHAPv2

2008-02-04 Thread Vincent Magnin
Hello Alan, You have right, this version is too old and do not support this feature (I've checked src/modules/rlm_eap/types/rlm_eap_ttls/ttls.c). This version is the one supplied with Redhat Enterprise 4. I'll compile 1.1.7 from source. Regards, Vincent Magnin Alan DeKok <[EMAIL PROTECTED

Re: inner/outer Tunnel attributes of TTLS/MS-CHAPv2

2008-02-04 Thread Alan DeKok
Vincent Magnin wrote: > Running version: freeradius-1.0.1-3.RHEL4.5 Why? I'm not sure if the functionality you need is even in 1.0.1. Why not try 2.0.1, or maybe 1.1.7? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

inner/outer Tunnel attributes of TTLS/MS-CHAPv2

2008-02-04 Thread Vincent Magnin
Hello All, I've an issue with passing attributes from EAP TTLS MS-CHAPv2 to outer: My /etc/raddb/users contains: DEFAULT FreeRADIUS-Proxied-To == 127.0.0.1 User-Name := `%{User-Name}`, Fall-Through = yes And my eap ttls module contains: copy_request_to_tunnel = yes use_tunneled

Removing tunnel attributes only for specific NAS

2006-07-24 Thread Ignacio Siles
configured as RADIUS client, connected to the FreeRADIUS server. I have tested the connection with test users stored in freeRADIUS´ “users” file, and everything worked fine. The problem starts with the Access-Accept RADIUS message. This message includes some tunnel attributes stored in the LDAP, which are

Re: PEAP MS_CHAP V2: problem with tunnel attributes on enterasys V2 switch

2005-11-10 Thread slapeyre
debug mode and with the sniffer,i see the filter_id attributs but not the tunnel attributs. Authentication with filter_id attributes work but not with the tunnel attributes. Is it necessary to active or configure something on FreeRADIUS to use "tunnel" parameters ??? Best regards Stephane

Re: PEAP MS_CHAP V2: problem with tunnel attributes on enterasys V2 switch

2005-11-02 Thread slapeyre
Yes ,i know that The V2 switches (and all Enterasys switches) support EAP-MD5 but i want to implement EAP-PEAP with ms-chapv2 and VLAN assignment It wasn´t a problem to configure EAP-PEAP with freeradius server (running on suse) and Enterasys switches. I want to implement VLAN assignment at a ente

Re: PEAP MS_CHAP V2: problem with tunnel attributes on enterasys V2 switch

2005-10-28 Thread Zoltan Ori
On Friday 28 October 2005 10:40, [EMAIL PROTECTED] wrote: > I am new to this list and would like to know if someone out there > has been successfull in implementing eap-PEAP user authentication > and VLAN assignment with freeradius and Enterasys V2 switches ? > The V2 switches (and all Enterasys

PEAP MS_CHAP V2: problem with tunnel attributes on enterasys V2 switch

2005-10-28 Thread slapeyre
Hello, I am new to this list and would like to know if someone out there has been successfull in implementing eap-PEAP user authentication and VLAN assignment with freeradius and Enterasys V2 switches ? It wasn´t a problem to configure EAP-PEAP with freeradius server (running on suze) and Enter

using tags for tunnel attributes

2004-10-26 Thread marc . van_de_voorde
Can somebody tell me how I should configure the users file to be able to send a tag with the tunnel attributes ? I checked the dictionary and the attributes (like Tunnel-Type) have an extra option "has_tag", but I could not get the radiusserver to recognize it and sent it back to th

Using Tunnel Attributes

2004-07-01 Thread Maqbool Hashim
Hi, I've been looking at the radius attributes page and I think the tunnel attributes may be useful for something I'm trying to achieve with radius. I'll describe an example scenario below. I have a firewall which is connected to an internal network and the Internet. A freerad

Re: TTLS tunnel attributes

2004-06-18 Thread Rok Papez
Hello Htin. Htin Hlaing pravi: Based on the description of use_tunneled_reply = yes in ttls section of eap.conf, I understood it as the reply to the NAS will use the attributes from the inside tunnel. But, with this value set to yes, I still see Access-Accept reply to the NAS still has the user-na

TTLS tunnel attributes

2004-06-17 Thread Htin Hlaing
Hi, Based on the description of use_tunneled_reply = yes in ttls section of eap.conf, I understood it as the reply to the NAS will use the attributes from the inside tunnel. But, with this value set to yes, I still see Access-Accept reply to the NAS still has the user-name from outside, not from