Re: Automatically proxy?

2003-12-06 Thread Alan DeKok
Gary Algier [EMAIL PROTECTED] wrote:
 I am trying to figure out how to automatically proxy based upon criteri
 in the users file.

  Use the Proxy-To-Realm attribute:

bob   Proxy-To-Realm := realm


 I can see how I can check the NAS-IP-Address, but then
 I don't know how to control where the actual auth gets
 done.

  Don't use NAS-IP-Address.  It can lie.  Use Client-IP-Address.

 In case you are wondering, the other radius server is a
 SecureID ACE server.  I want to use a FreeRadius server as
 a frontend for better control and accounting.

  g  Of course.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Automatically proxy?

2003-12-05 Thread Gary Algier
Hi:

I am trying to figure out how to automatically proxy based upon criteri
in the users file.
For example:

I have a user gary who logs in on a particular NAS (let us say
on IP 192.168.1.1).  When he does so, his authentication should
be passed off to the radius server at 192.168.2.1.
If the same user tries to use the NAS at 192.168.1.2, he should
be rejected by this radius server.
If nancy uses either NAS, it should be handled locally.

All other users should be rejected on NAS 192.168.1.1.,
while all requests for the rest of these users from
the NAS at 192.168.1.2 should be passed off to the radius
server at 192.168.2.1.
How can I do this?

I can see how I can check the NAS-IP-Address, but then
I don't know how to control where the actual auth gets
done.
In case you are wondering, the other radius server is a
SecureID ACE server.  I want to use a FreeRadius server as
a frontend for better control and accounting.
--
Gary Algier, WB2FWZ  gaa at ulticom.com +1 856 787 2758
Ulticom Inc., 1020 Briggs Rd, Mt. Laurel, NJ 08054  Fax:+1 856 866 2033
Nielsen's First Law of Computer Manuals:
People don't read documentation voluntarily.
- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html