Re: [RADIATOR] eap auth against active directory

2012-10-17 Thread James
Hugh, Looks like my logging configuration may have been incorrect. Let me keep tinkering with it and if I can't figure it out I'll start a new thread. Unfortunately because of the issues that host authentication is causing we've had to move over to an NTLM-based authentication configuration for n

Re: [RADIATOR] eap auth against active directory

2012-10-17 Thread Hugh Irvine
Hello James - As long as the User-Name contains "host/.…." this Handler should be called provided another Handler doesn't catch it. Without seeing the debug and the corresponding configuration file I can't really say much else. If you have "Trace 4" in your configuration file you will see the

Re: [RADIATOR] eap auth against active directory

2012-10-17 Thread James Zee
Hugh, Yes, that is correct. This capture was taken before the change (second link that contains configuration in m previous post). Now I have this handler: Host 10.136.234.80 Secret mysecret AuthPort 1812 AcctPort 1813 The Trace 4 shows that the RADI

Re: [RADIATOR] eap auth against active directory

2012-10-17 Thread Hugh Irvine
Hello James - The problem is here: • Mon Oct 15 01:20:47 2012 564812: DEBUG: Packet dump: • *** Received from 10.136.235.240 port 32768 • Code: Access-Request • Identifier: 47 • Authentic: %wa<14><212>v<209>S<143>a<132>z<21><194>5` • A

Re: [RADIATOR] Change of Authorization

2012-10-17 Thread Hugh Irvine
Hello Rohan - What I described was one typical way it is done automatically, but obviously other methods are possible. regards Hugh On 18 Oct 2012, at 02:49, wrote: > Thanks Hugh. > > > Oh Yes! I recall there was discussion around tracking usage via interim > accounting. But its an exte

Re: [RADIATOR] How to create a log file of user <-> IP association

2012-10-17 Thread Hugh Irvine
Ciao Paolo - As you have seen, the debug log is not what you want. Rather, you should be using the RADIUS accounting requests to write to a file. You can have a separate file for each user by doing something like this: # Realm or Handler AcctLogFileName %L/accounting-for-%n

Re: [RADIATOR] How to create a log file of user <-> IP association

2012-10-17 Thread Heikki Vatiainen
On 10/17/2012 06:02 PM, Paolo Di Francesco wrote: Hello Paolo, > in oder to keep track of the user getting in and getting out of my > network I would like to do the following: let radiator write into a file > (mounted on some linux syslogd) when a user is getting into the network > and when th

Re: [RADIATOR] Change of Authorization

2012-10-17 Thread rohan.henry
Thanks Hugh. Oh Yes! I recall there was discussion around tracking usage via interim accounting. But its an external system (linked to our billing system) that will monitor user sessions for usage thresholds and initiate the COA as well as modify the user profile in LDAP temporarily should a u

[RADIATOR] How to create a log file of user <-> IP association

2012-10-17 Thread Paolo Di Francesco
Dear All in oder to keep track of the user getting in and getting out of my network I would like to do the following: let radiator write into a file (mounted on some linux syslogd) when a user is getting into the network and when the user is leaving. I found the log file command but not sure i