On 29 Oct 2012, at 17:14, Edinilson - ATINET wrote:
> Hi,
>
> After upgrade perl to version 5.16 checkrad was returning the following error:
>
> Can't modify constant item in scalar assignment at
> /usr/local/sbin/checkrad line 477, near ");"
> Execution
Hi,
After upgrade perl to version 5.16 checkrad was returning the following
error:
Can't modify constant item in scalar assignment at
/usr/local/sbin/checkrad line 477, near ");"
Execution of /usr/local/sbin/checkrad aborted due to compilation errors.
I don´t know exactly ho
HI,
I have set the Interm-Update interval to 5min so accounting packet is
received every 5 min.
The basic purpose I want to run checkrad script is the check
"Simultaneous-Use" in multiple server environment.
I will paste the Accounting Packet output here as soon as I get home.
--
Ki
Mudasir Mirza wrote:
> Hi,
> Thanks for your reply. Can you tell me what information from my side
> will help in finding the root cause.
>
> I have also read the doc for "Simultaneous-Use" and as far as I can see
> I have done all the necessary things.
Well, you didn't show the output when the
I,
>
> I have just configured FreeRadius for my Test lab, and I am unable to get
> the checkrad script to work.
> I have written a custom checkrad script to work for the server that I am
> using.
>
> Attached is the file of output "radiusd -X"
>
> I have also set
Mudasir Mirza wrote:
> I have just configured FreeRadius for my Test lab, and I am unable to
> get the checkrad script to work.
> I have written a custom checkrad script to work for the server that I am
> using.
>
> Attached is the file of output "radiusd -X"
Which
HI,
I have just configured FreeRadius for my Test lab, and I am unable to get
the checkrad script to work.
I have written a custom checkrad script to work for the server that I am
using.
Attached is the file of output "radiusd -X"
I have also set "Simultaneous-Use := 1" in
s-use := 1 ).
So far so good, but if i choose nastype=cisco, the user can log in as
often as wanted. Checkrad gets executed and logs the following:
/var/log/radius/checkrad.log
--snip---
Fri Jun 1 15:18:27 2012 checkrad cisco 141.72.65.21 1
cat /usr/share/freeradius/dictionary.juniper
Best regards,
Fred MAISON
2011/7/15, Igor Smitran :
> It is my first time to setup Juniper ERX-1440 with freeradius. All my
> other NAS's are cisco.
> I was trying to setup checkrad to check for simultaneous connections and
> realize
It is my first time to setup Juniper ERX-1440 with freeradius. All my
other NAS's are cisco.
I was trying to setup checkrad to check for simultaneous connections and
realized that juniper is not listed in nas type list.
Can someone help me with getting chekrad to work with Juniper ERX?
Hi
I know its not the best way to do it but I would really like to use
simultaneous-use attribute without using the checkrad script.
meaning the radius server does the check in radacct table and if the check
is true, deny authentication. is this possible?
I am using sql and in the radgroupcheck
George,
Thanks for the reply. I will doublecheck my configuration. The one
thing I noticed, even though checkrad is working, I can't find any clue
in any log or debug output. I set it to log to checkrad.log, but that
only works when I manually run /usr/sbin/checkrad. Is there an
On 06/04/2011 06:28 AM, Dan Brisson wrote:
Just finished setting up the latest Freeradius - 2.1.10. Checkrad is
working. I've replicated the settings from 2.1.7 so I have to think
something has changed from 2.1.7 to 2.1.10.
hm.. I would compare both setups to eliminate any typos in
Just finished setting up the latest Freeradius - 2.1.10. Checkrad is
working. I've replicated the settings from 2.1.7 so I have to think
something has changed from 2.1.7 to 2.1.10.
I'm running on CentOS with 2.1.7 installed from Yum. My 2.1.10 was
built from source on RHEL5.
I
On 6/3/2011 9:21 AM, George Chelidze wrote:
On 06/03/2011 02:35 PM, Dan Brisson wrote:
It really seems like this line in the radutmp "modules" file is not
being executed:
check_with_nas = yes
But from radiusd -X, it does seem to be:
It's a configuration option not a command to be executed
On 06/03/2011 02:35 PM, Dan Brisson wrote:
It really seems like this line in the radutmp "modules" file is not
being executed:
check_with_nas = yes
But from radiusd -X, it does seem to be:
It's a configuration option not a command to be executed
check_with_nas = yes
So, it's there
Can y
AM, Dan Brisson wrote:
George,
Sorry, I had commented out the simul_verify_query as a troubleshooting
step but actually do have it uncommented at this point, but it still
won't work.
I checked radiusd.conf and found this:
# The program to execute to do concurrency checks.
checkrad =
George,
Sorry, I had commented out the simul_verify_query as a troubleshooting
step but actually do have it uncommented at this point, but it still
won't work.
I checked radiusd.conf and found this:
# The program to execute to do concurrency checks.
checkrad = ${sbindir}/checkra
dule can handle this.
# The rlm_sql module is *much* faster
session {
radutmp
#
# See "Simultaneous Use Checking Queries" in sql.conf
sql
}
Do you really need both?
modules/perl:
func_checksimul = checksimul
I would enable checkrad statement in radiusd.conf as it seems to be used
# See "Simultaneous Use Checking Queries" in sql.conf
sql
}
modules/perl:
func_checksimul = checksimul
And in my MySQL radcheck table I have:
testuser Simultaneous-Use := 1
Thanks in advance for any insight,
-dan
On 6/2/11 5:54 AM, Alan DeKok wrote:
Dan Brisson wrote:
Dan Brisson wrote:
> I was wondering if someone could help me determine why checkrad isn't
> being called. I've followed the directions in the doc/Simultaneous-Use
> but still cannot get checkrad to fire off when I login. It will check
> radutmp, but never reaches out to my
I was wondering if someone could help me determine why checkrad isn't
being called. I've followed the directions in the doc/Simultaneous-Use
but still cannot get checkrad to fire off when I login. It will check
radutmp, but never reaches out to my NAS with checkrad, as evidenced
Galatóczki István wrote:
> I use Freeradius 2.0.4(deb pack) with Mysql 5.0.51.
You should really upgrade to 2.1.8.
> The online users check not work in the NAS with checkrad script my network.
>
> I read the list and forums but not founded solution.
> I have read and follo
Hi All!
I use Freeradius 2.0.4(deb pack) with Mysql 5.0.51.
The online users check not work in the NAS with checkrad script my network.
I read the list and forums but not founded solution.
I have read and followed the step of below comment:
http://www.mail-archive.com/freeradius-users
Hi All!
I use Freeradius 2.0.4(deb pack) with Mysql 5.0.51.
The online users check not work in the NAS with checkrad script my network.
I read the list and forums but not founded solution.
Question: working the checkrad script without radutmp?
my config:
radcheck- Simultaneous-Use: =1
> In order to implement simultaneous use checking in my environment I
> added a subroutine to checkrad that handles snmp checks to the Cisco
> 3000 series VPN concentrators. I am happy to share my work/experience
> with anyone that may have a similar environment.
While we are on th
Greetings,
In order to implement simultaneous use checking in my environment I
added a subroutine to checkrad that handles snmp checks to the Cisco
3000 series VPN concentrators. I am happy to share my work/experience
with anyone that may have a similar environment.
Sincerely,
Bill McCormick
> From: "Alan DeKok"
>>"If you want to check the stripped user name... then use it."
>
> How can I control this? I am assuming you are referring to proxy.con
> realm
> configuration?
>
> "Why you ask?"
>
> The 'powers that be' have declared that the same userid may log in via
> multiple realms (a
..)
Thanks,
-craig
- Original Message -
From: "Alan DeKok"
To: "FreeRadius users mailing list"
Sent: Thursday, September 10, 2009 4:16 AM
Subject: Re: Checkrad / Simultaneous-Use clarification please
Craig Campbell wrote:
We currently have users that log in
Craig Campbell wrote:
> We currently have users that log in both with and without realms.
Well... then you have to manage that.
> In radutmp we log the stripped username (i.e. no realm component).
Why?
> Since the radutmp data has no realm part for the username, how do I get
> the Simultan
I am investigaitng using the Simultaneous-Use feature with freeradius 2.1.6.
We currently have users that log in both with and without realms.
In radutmp we log the stripped username (i.e. no realm component).
Since the radutmp data has no realm part for the username, how do I get the
Simulta
Thanks for excellent help.
On Fri, Apr 24, 2009 at 5:47 PM, wrote:
> > Do I understand right or not about checkrad? Please drive me right
> > direction.
> >
> > radius# checkrad
> > Usage: checkrad nas_type nas_ip nas_port login session_id
> >
>
> Chec
> Do I understand right or not about checkrad? Please drive me right
> direction.
>
> radius# checkrad
> Usage: checkrad nas_type nas_ip nas_port login session_id
>
Checkrad checks if the accounting session open in the database is still
open on the NAS as well. You can fin
Tseveendorj wrote:
> What is nas_port ? is it mean 1645, 1646 ?
No. It's not a UDP port. It means "port on the NAS". See
http://freeradius.org/rfc/attributes.html. Click on "NAS-Port"
Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Hello,
Do I understand right or not about checkrad? Please drive me right
direction.
radius# checkrad
Usage: checkrad nas_type nas_ip nas_port login session_id
What is nas_port ? is it mean 1645, 1646 ?
I found the session_id from cisco router with following command
hostname#sh pppoe
On Wed, 02 Jul 2008 18:02:18 +0200
Alan DeKok <[EMAIL PROTECTED]> wrote:
> i.e. "when the server starts properly", checkrad works. When the
> server doesn't start properly, it doesn't.
>
> > So it is not a severe bug of checkrad in 2.0.5, it just
Ok... so that client definition was wrong. Version 2.0.5 *should*
fail to start at that point.
Hmm... I've tracked down the issue and committed a fix to CVS.
> Version 2.0.5 then rejects all users from *all the other* clients, when
> checkrad is invoked and when radiusd wasn't abl
Alan DeKok wrote:
oz wrote:
M. S. wrote:
Can I put this in bugzilla? Seems like simultaneous use is completely
broken in 2.x which is a fairly significant feature.
I would agree. I'm not sure why it's broken...
To me checkrad seems to be broken too. I'm using 2.0.5
oz wrote:
> M. S. wrote:
>> Can I put this in bugzilla? Seems like simultaneous use is completely
> broken in 2.x which is a fairly significant feature.
I would agree. I'm not sure why it's broken...
> To me checkrad seems to be broken too. I'm using 2
P.S. Sorry, I posted to the developers-list, but I meant the users-list, so
here it should be discussed:
M. S. wrote:
> Can I put this in bugzilla? Seems like simultaneous use is completely
broken in 2.x which is a fairly significant feature.
To me checkrad seems to be broken too. I'
.
You need additional perl module HTTP::Lite(downloadable from CPAN). I've
tested and it's working well.
In order to deploy checkrad you need to set your nas type to "nocat" and
enable simultaneous-use checking for your user(Simultaneous-Use:=1 in users
file|radcheck|radgroupcheck)
Hello,
I need help!
I have a freeradius server 1.1.3 with mysql 4.1.11 backend
and we manage ip address pools with the NAS (Redback SMS), it works fine.
Now we need to have subscribers groups with particular ip address
pools for
each group.
I don't how to configure it with the NAS so i want
ibers.
>> The aaa is a freeradius 1.1.3 server
>> and the NAS is a REDBACK SMS.
>>
>> The Simultaneous-Use don't work!
>>
>> We want plan to use checkrad but
>> there is no snmp script for redback!
>> The telnet options is not good i think
#x27;t work!
>
> We want plan to use checkrad but
> there is no snmp script for redback!
> The telnet options is not good i think because we have 18000
> subscribers.
>
> Please help me with a snmp script for redback or with an other
> solution for Simultaneous-Use
Hello,
I'am facing a Simultaneous-Use problem.
We are ISP and we have adsl subscribers.
The aaa is a freeradius 1.1.3 server
and the NAS is a REDBACK SMS.
The Simultaneous-Use don't work!
We want plan to use checkrad but
there is no snmp script for redback!
The telnet options is
Dear guys
I have solve the problem of checkrad for simultenous login i have
face many problem first time but finaly i got solution and i have modifiy my
script for my nas
i have freeradius-1.1.0 with MSSQL2000 with cisco 3700 NAS
i want to share my solution with all freeradius
idle-timeout attributes but it's also not work ??? what is the
problem of users stuck in database thats why i want to change my
simultaneouse-use with checkrad script is it solve by checkrad
script.???
[EMAIL PROTECTED] wrote: radwho lists online users according to radutmp
checkr
ot able to login how can i automaticaly close this
>session is there any attribute which is automaticaly clear idle session one
>more thing i have set idle-timeout attributes but it's also not work ??? what
>is the problem of users stuck in database thats why i want to change m
attributes but it's also not work ??? what is the
problem of users stuck in database thats why i want to change my
simultaneouse-use with checkrad script is it solve by checkrad
script.???
[EMAIL PROTECTED] wrote: radwho lists online users according to radutmp
checkrad doesn&
radwho lists online users according to radutmp
checkrad doesn't use radwho. It "asks" NAS if user so and so is on
port so and so with session ID so and so.
In session you choose if looking for online users will be done in
database or radutmp. checkrad will be called when online user
can i replace checkrad with another script
$ cat ~/satish/url.txt
System administrator ( Data Center )
please visit this site
http://linux.tulipit.com
-
Heres a new way to find what you're looking for - Yahoo! An
Dear alll
I have problem last 2 month nobady give me solution of this error
when i run checkrad manually i got this error
[EMAIL PROTECTED] satishp]# checkrad cisco 192.168.1.1 1034 mlpm542 999
SNMP Error:
Received SNMP response with error code
error status: noSuchName
index 1
anyone help me please
I have many problem for simultaneous login user problem i have freeradius-1.1.0
with MSSQL with cisco VPDN configuration i dont know why simultaneous not
working with checkrad script
can u explain me i have confusen in radwho and checkrad command so checkrad
command
This is how it should work:
setting Simultaneous-Use will produce a check in the database if the user
is online;
if the user is online according to database (end of story if nastype is
set to "other") checkrad is called to see if the NAS agrees
if user is not online according to NAS
Dear sir
i have useing freeradius + cisco vpdn router but i have this
problem when i run checkrad manually
[EMAIL PROTECTED] ~]# checkrad cisco 192.168.1.1 800 mlpm034 C555
SNMP Error:
Received SNMP response with error code
error status: noSuchName
index 1 (OID
Is OID correct? Do snmpwalk for your router and see if that OID (without
766 at the end) is listed.
Ivan Kalik
Kalik Informatika ISP
Dana 11/3/2007, "satish patel" <[EMAIL PROTECTED]> piše:
>I have getting this error when i run manualy checkrad
>
>[EMAIL PROTECT
I have getting this error when i run manualy checkrad
[EMAIL PROTECTED] mibs]# checkrad cisco 192.168.1.1 766 mlpm264 BC3F
SNMP Error:
Received SNMP response with error code
error status: noSuchName
index 1 (OID: 1.3.6.1.4.1.9.2.9.2.1.18.766)
SNMPv1_Session (remote host: "192.16
Dear Sir,
I want to know the setup for the simultaneous
logins and checkrad script with Cisco Router SNMP enabled. The settings
are configured but checkrad is not returning any results from cisco snmp.
Also, how can I know whether radius
will block MPP attempts? I am looking for configuration
Hi,
I am facing problem with checkrad in icradius. I am
sorry for mailing this question on this mailing list because i could not find
solution any where.We have recently added ascend MAX TNT in list of NAS, before
that simultenous use was working fine, now with Max simultenous use is not
On Wednesday 09 November 2005 00:35, Christopher Carver wrote:
> The proxy'ing radius servers and NAS's of the other company from whom we
> lease equipment are unavailable to checkrad. By default shouldn't it be
> allowing these people on? I looked at the code and it seem
Christopher Carver <[EMAIL PROTECTED]> wrote:
> The proxy'ing radius servers and NAS's of the other company from whom we
> lease equipment are unavailable to checkrad. By default shouldn't it be
> allowing these people on?
It depends what you want. The current
Nov 8 23:32:38 2005 : Auth: Multiple logins (max 1) [MPP attempt]:
[user3] (from client pa-230-radius0 port 3699 cli async)
The proxy'ing radius servers and NAS's of the other company from whom we
lease equipment are unavailable to checkrad. By default shouldn't it be
allowin
Dusty Doris wrote:
radius-server attribute nas-port format X
with X being dependant on the type of connections
I don't know if this will force it, but perhaps the default type is
something that doesn't apply to your type of connection. For PPPoA we
use format d, which gives you the slot/mod
On Tue, 25 Oct 2005, Miguel wrote:
Hi, im having problems implementing simultaneous-use on a cisco AS5400, is
the same problem addresses in this thread
http://lists.cistron.nl/pipermail/freeradius-users/2005-March/041894.html
Ok, i know what the problem is, but how can i instruct the cisco th
Jonathan De Graeve wrote:
Depends on the nas.
Which nas?
Cisco AS5400
---
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
>Ok, i know what the problem is, but how can i instruct the cisco that
it
>must send the NAS-Port attribute?, is this even posible?
Depends on the nas.
Which nas?
J.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Miguel <[EMAIL PROTECTED]> wrote:
> Ok, i know what the problem is, but how can i instruct the cisco that it
> must send the NAS-Port attribute?, is this even posible?
No.
Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Hi, im having problems implementing simultaneous-use on a cisco AS5400,
is the same problem addresses in this thread
http://lists.cistron.nl/pipermail/freeradius-users/2005-March/041894.html
Ok, i know what the problem is, but how can i instruct the cisco that it
must send the NAS-Port attribu
Felix Chang <[EMAIL PROTECTED]> wrote:
> Sorry.. just something very confuse. I am using a
> FreeBsd computer as my NAS, may I know what is the
> nastype for this NAS? Is it "other"?
Yes.
> I know when the nastype is "other", the radius server won'
Sorry.. just something very confuse. I am using a
FreeBsd computer as my NAS, may I know what is the
nastype for this NAS? Is it "other"? I know when the
nastype is "other", the radius server won't call for
the checkrad. Therefore, if I want to use the checkrad
to check
"Nurul Faizal M.Shukeri" <[EMAIL PROTECTED]> wrote:
> mmm.. can I just check double login, perhaps by query database only without
> snmpwalk to ap.
If you don't run checkrad, the server assumes that it's database is
correct.
Set the nas type to "other&qu
EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Alan
DeKok
Sent: Thursday, August 04, 2005 11:00 AM
To: FreeRadius users mailing list
Subject: Re: Regarding checkrad
"Nurul Faizal M.Shukeri" <[EMAIL PROTECTED]> wrote:
> Any suggestion for solution, perhaps my server conf
"Nurul Faizal M.Shukeri" <[EMAIL PROTECTED]> wrote:
> Any suggestion for solution, perhaps my server configuration. I'm stupid
> about snmp.
It's not the server. It's the NAS.
Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
iling list'
Subject: RE: Regarding checkrad
Thank Alan, perhaps my AP problem, coz I already enable the feature.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Alan
DeKok
Sent: Thursday, August 04, 2005 12:28 AM
To: FreeRadius users mailing list
Subject
Thank Alan, perhaps my AP problem, coz I already enable the feature.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Alan
DeKok
Sent: Thursday, August 04, 2005 12:28 AM
To: FreeRadius users mailing list
Subject: Re: Regarding checkrad
"Nurul F
"Nurul Faizal M.Shukeri" <[EMAIL PROTECTED]> wrote:
> My ap is cisco 340 and I already enable snmp feature. I don't know what the
> problem is. Plz help me.
Checkrad isn't able to talk to the AP. The AP isn't listening on SNMP.
Alan DeKok.
-
List
Hi all...
I'm trying to use checkrad to check for double login. I have read
doc/Simultaneous-Use. The problem is when I'm trying to use checkrad, this
is the output :-
sony# checkrad cisco 10.201.1.3 37 ultrabalad 3706
Timeout: No Response from 10.201.1.3.
Timeout: No Response from
---22*[mysqld]
|-radiusd---radiusd-+-2*[radiusd---6*[checkrad]]
| |-radiusd---5*[checkrad]
| |-radiusd---10*[checkrad]
| `-radiusd---9*[checkrad]
radius01:/usr/local/dialup_admin/bin# ps ax
[...]
21874 ?Z 0:00 [checkrad ]
diusd---6*[checkrad]]
| |-radiusd---5*[checkrad]
| |-radiusd---10*[checkrad]
| `-radiusd---9*[checkrad]
radius01:/usr/local/dialup_admin/bin# ps ax
[...]
21874 ?Z 0:00 [checkrad ]
22080 ?Z 0:00 [checkrad ]
ling list
Subject: Re: Problem checkrad cisco ap1200 Date: Thu, 16 Jun 2005 13:20:32
-0400
"ph b." <[EMAIL PROTECTED]> wrote:
> Furthermore, when i use the tool snmpge for the oid
> 1.3.6.1.4.1.9.2.9.2.1.18.XXX, it return me the same result : noSuchName.
The MIBs used by t
"ph b." <[EMAIL PROTECTED]> wrote:
> Furthermore, when i use the tool snmpge for the oid
> 1.3.6.1.4.1.9.2.9.2.1.18.XXX, it return me the same result : noSuchName.
The MIBs used by that AP are unknown to checkrad.
You were told this yesterday on the cistron list. Di
Hello,
The script "checkrad" not run with my ap1200, when i test it i have :
SNMP Error:
Received SNMP response with error code
error status: noSuchName
index 1 (OID: 1.3.6.1.4.1.9.2.9.2.1.18.XXX)
SNMPv1_Session (remote host: "192.XXX.XXX.XXX" [
Stephan Jaeger <[EMAIL PROTECTED]> wrote:
> I just compiled HEAD but somehow the proxy radius server does not
> recognize the replies from the home radius server:
Fixed.
Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Am Mittwoch, den 27.04.2005, 05:39 -0400 schrieb Alan DeKok:
> > Ignoring request from unknown home server 127.0.0.1 port 1815
>
> Is that the correct IP?
Yes, thats the right one.
> Oh well, at least this narrows the scope where the bug can be.
That sounds good ;)
Regards
Stephan Jaeger
Stephan Jaeger <[EMAIL PROTECTED]> wrote:
> I just compiled HEAD but somehow the proxy radius server does not
> recognize the replies from the home radius server:
I'm not *too* surprised. I've been working on IPv6 support, which
means lots of little changes throughout the server core. If proxy
Am Dienstag, den 26.04.2005, 09:51 -0400 schrieb Alan DeKok:
> Stephan Jaeger <[EMAIL PROTECTED]> wrote:
> > For testing purposes i replaced the call to rad_waitpid with waitpid.
> > As soon as the checkradius script is exiting the call returns with -1
> > and errno set to "No child processes".
>
Stephan Jaeger <[EMAIL PROTECTED]> wrote:
> For testing purposes i replaced the call to rad_waitpid with waitpid.
> As soon as the checkradius script is exiting the call returns with -1
> and errno set to "No child processes".
It's a bug in 1.0.x. The CVS head has fixes.
Alan DeKok.
-
List
Hi,
i have a problem with freeradius executing the checkrad script.
I get "Check-TS: unknown error in waitpid()"
child_pid = -1;
for (n = 0; n < 10; n++) {
sleep(1);
radlog(L_ERR, "pid: %d", pid);
child_pid = waitpid(pid, &status, WNO
Accounting is working fine, and also I have uncommented that line in
sql.conf to check Simultaneous-Use using sql module.
I see that checkrad is still called after simul_count_query. The
documentation says that checkrad is called once a previuos session is
detected in the database session
Richard Cotrina wrote:
When using Simultaneous-Use, after the session database (either
radutmp or sql) is checked, what is the "session id" value used by
checkrad ? Is it the value from Acct-Session-Id ?
I'm using sql to check Simultaneous-Use, and the radacct table only has
When using Simultaneous-Use, after the session database (either
radutmp or sql) is checked, what is the "session id" value used by
checkrad ? Is it the value from Acct-Session-Id ?
I'm using sql to check Simultaneous-Use, and the radacct table only has a
column called "
Re: Checkrad Mikrotik NAS problem.
I am having the following problem with checkrad and Mikrotik NAS, some users
are able to beat simultaneous-Use:=1 check attribute if they have
auto-redial set to on their PPPoE client, after a few Rejects checkrad gives
in and allows log in (checrad.log
at I'm guessing is going on... We changed IP addresses a
while back. The old IP's no longer exist, but there are apparently a
number of radacct records that were never "stopped" correctly. So
when the checkrad process runs, it sees these old records, can't
identify th
If a utmp is in place, in the above occurance, checkrad would be called
which will verify that the user is NOT logged into the NAS, and thus will
allow the auth. You will however still sit with the stale accounting
records in SQL
No. See src/main/session.c. If the user is no longer logged in
"Chris Knipe" <[EMAIL PROTECTED]> wrote:
> In this situation, the correct approach would be for checkrad to be
> called from FR yes - something, which for some reason it is not
> doing.
It should, but I'm not sure why.
> If a utmp is in place, in the above oc
On Tue, 29 Mar 2005 21:18:06 +0200, Chris Knipe <[EMAIL PROTECTED]> wrote:
> Again, I am guessing this is incomplete code (at this stage).
> you manually reset all the SQL acocunting records)... I hope I'm making
> sense...
Yup.. seems clear anough..
> Again, IMHO ch
It may actually be a good idea to get checkrad to be called if utmp *OR*
SQL
thinks a user is loged in twice But that will require some source
hacking I think.
I guess I don't understand the purpose of the simul checks in the
sql.conf file then.. If utmp is the only thing that check
On Tue, 29 Mar 2005 20:58:45 +0200, Chris Knipe <[EMAIL PROTECTED]> wrote:
> You must run utmp. Even if it is just for simul. use. You can stil have
> all your accounting in SQL instead of detailed files, but utmp must be there
> for checkrad.
Ugh.. So, if my primary radius
I don't have radutmp enabled. I noticed, however, in the radutmp
module definition, the check_with_nas option. It appears that this
causes the checkrad program to be called. If radutmp is not enabled,
checkrad isn't called.. I think.
To my knowledge, checkrad is never called if
d. I noticed, however, in the radutmp
module definition, the check_with_nas option. It appears that this
causes the checkrad program to be called. If radutmp is not enabled,
checkrad isn't called.. I think.
At any rate, I tried enabling simultaneous checking with sql and the
checkrad program
1 - 100 of 126 matches
Mail list logo