Re: Cisco VPN3000 with freeradius

2003-12-16 Thread Spetzler, Arne \(DZ-SH\)
Alan DeKok [EMAIL PROTECTED] wrote: From: Alan DeKok [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: Cisco VPN3000 with freeradius Date: Mon, 15 Dec 2003 14:39:46 -0500 Reply-To: [EMAIL PROTECTED] Spetzler, Arne (DZ-SH) [EMAIL PROTECTED] wrote: i'am successfully authenticate

Re: Cisco VPN3000 with freeradius

2003-12-16 Thread Oliver Graf
On Tue, Dec 16, 2003 at 05:56:40PM +0100, Spetzler, Arne (DZ-SH) wrote: if the answer from the radius server is _fast_ ( 200ms) _and_ a lot of debugging is enabled - then the vpn3000 may lost the udp packet which contains the answer. The FREERADIUS _is_ fast - in our environement the

Re: Cisco VPN3000 with freeradius

2003-12-16 Thread Alan DeKok
Oliver Graf [EMAIL PROTECTED] wrote: So what about a answer-delay option for sluggy NASes? ;) Yuck. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Cisco VPN3000 with freeradius

2003-12-15 Thread Spetzler, Arne \(DZ-SH\)
Hello there, i'am successfully authenticate Certificate users against freeradius 0.9.0 (from suse 9.0). BUT: only the 'first' time. That means: wait a 'long' time (av. 15 min) authenticate successfull wait a very short time authentication fails wait authentication fails wait 'long' time

Re: Cisco VPN3000 with freeradius

2003-12-15 Thread Alan DeKok
Spetzler, Arne (DZ-SH) [EMAIL PROTECTED] wrote: i'am successfully authenticate Certificate users against freeradius = 0.9.0 (from suse 9.0). BUT: only the 'first' time. That means: wait a 'long' time (av. 15 min) authenticate successfull This has nothing to do with FreeRADIUS. If