%RADIUS-4-RADIUS_ALIVE %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
I'm getting the following messges/alarms from freereadius server version 1.1.6. and when i oberserved the radiusd process it's stopped. Why this happens? Apr 26 00:18:44.498: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.199.32.34:0,1813 is being marked alive. Apr 26 00:18:50.777:

%RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
I'm seeing the following weirdness from my freeradiusserver and when i see the radiusd process its stopped status. why this happens. any valid reasons for this? Apr 26 00:18:44.498: %RADIUS-4-RADIUS_ALIVE: RADIUS server X.X.X.X:0,1813 is being marked alive. Apr 26 00:18:50.777:

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread Nicolas Goutte
Am 27.04.2009 um 09:08 schrieb ramesh p: I'm seeing the following weirdness from my freeradiusserver and when i see the radiusd process its stopped status. why this happens. any valid reasons for this? Apr 26 00:18:44.498: %RADIUS-4-RADIUS_ALIVE: RADIUS server X.X.X.X:0,1813 is being

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread Borislav Dimitrov
Hi there, I may be mistaken but... these are log message on the NAS aren't they? If this is the case, I've experienced similar behavior with Cisco VoIP routers (RADIUS Server DEAD and then... ALIVE). This happens if you haven't properly enabled concurrency in FreeRADIUS - the CPU usage

RE: Adding vendor specefic attributes

2009-04-27 Thread anoop c
Hi Is it possible to configure vendor specific attributes in Free RADIUS. Please guide where can I edit the configuration. I am using MAC authentication by editing the user file shown below. '020a6-5a7fd9 Auth-Type:=Local,User-Password==secret MAC authentication is working and I would

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
Thanks. How to configure it? On Mon, Apr 27, 2009 at 1:29 PM, Borislav Dimitrov b.dimit...@ngsystems.net wrote: Hi there, I may be mistaken but... these are log message on the NAS aren't they? If this is the case, I've experienced similar behavior with Cisco VoIP routers (RADIUS Server DEAD

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
And why the process is stopped automaticaly? any reasons. On Mon, Apr 27, 2009 at 2:05 PM, ramesh p rock786...@gmail.com wrote: Thanks. How to configure it? On Mon, Apr 27, 2009 at 1:29 PM, Borislav Dimitrov b.dimit...@ngsystems.net wrote: Hi there, I may be mistaken but... these are

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread Borislav Dimitrov
Why do you think that the process is stopped? It's probably sleeping which is its normal state if you're looking at the `ps`s output. About the thread pool, check the documentation. Anyways, here's what it looks like: # THREAD POOL CONFIGURATION thread pool { start_servers = 1

Re: Adding vendor specefic attributes

2009-04-27 Thread Borislav Dimitrov
FIrst of all, have you enabled VSA on the NAS? A lot of VSAs for different vendors are already supported. Check the dictionary files. It's them that you should edit, if you need to at all. First check the dictionary file in etc/raddb - it only includes various dictionary files from (say

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread Ivan Kalik
Well, has it? Servers don't just go dead and back alive just like that. It's much more likely that server was never dead at all. Stop looking at NAS messages and examine why radius server didn't respond: - did it get the request at all? Maybe your network is loosing packets. - did something else

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
Thanks alot for providing very good suggestions. On Mon, Apr 27, 2009 at 4:12 PM, Ivan Kalik t...@kalik.net wrote: Well, has it? Servers don't just go dead and back alive just like that. It's much more likely that server was never dead at all. Stop looking at NAS messages and examine why

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
Accounting server was alive and receving packets till yesterday. And suddenly got receiving dead alive messages. So restarted radiusd process then it got resolved. However it repeating frequently once a week Unable to findout the exact reason for this. On Mon, Apr 27, 2009 at 4:38 PM,

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, are you sure that the accounting server was ever alive and handling accounting packets? Those logs look exactly like they would if , for example, you were sending auth+acct to an IAS RADIUS server not configured for accounting. the RADIUS server attempts to send an accounting packet to

Re: [Wimax TTLS with Alcatel - Lucent ASN GW]

2009-04-27 Thread Thomas Fagart
On Sun, 26 Apr 2009 00:18:29 +0100 (BST), Ivan Kalik t...@kalik.net wrote: I am trying to use freeradius as AAA server with ASNGW to authenticate WiMAX device. Would you be kind enough to provide details on how to configure freeradius for this? I saw that you were successful in getting it

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
Same box. On Mon, Apr 27, 2009 at 4:57 PM, a.l.m.bu...@lboro.ac.uk wrote: Hi, Accounting server was alive and receving packets till yesterday. And suddenly got receiving dead alive messages. So restarted radiusd process then it got resolved. are we talking about the same box? I'm not

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, Accounting server was alive and receving packets till yesterday. And suddenly got receiving dead alive messages. So restarted radiusd process then it got resolved. are we talking about the same box? I'm not talking about this FreeRADIUS box you gave logs from, I'm talking about the box

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, Same box. and you do live accounting database insertions? This sounds to me very much like the classic 'tables have now grown just too big' - everything works fine then barfs one day. the request isnt getting serviced in time therefore its marking as dead..check your query times...remove

Re: [Wimax TTLS with Alcatel - Lucent ASN GW]

2009-04-27 Thread Ivan Kalik
Anyway If I may reask a new question about adding multiple attribute to reply on the radius that proxy. The solution you gave me, (eg use users file and match the Realm Attribute, DEFAULT Realm == whatever) is ok for a ISP radius (eg end radius), not for a Wholesale radius (eg radius

RE: Adding vendor specefic attributes

2009-04-27 Thread Ivan Kalik
Is it possible to configure vendor specific attributes in Free RADIUS. Please guide where can I edit the configuration. Nowhere. I am using MAC authentication by editing the user file shown below. '020a6-5a7fd9 Auth-Type:=Local,User-Password==secret There is so much wrong with this

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread Borislav Dimitrov
Hi, As far as I can see, the people on the list have provided you with a lot of very useful suggestions on what could cause the problem. As I said earlier (let me clarify) and to help you narrow things a little bit - it's probably due to the RADIUS response timing out hence the NAS

freeradius with active directory

2009-04-27 Thread David N'DAKPAZE
hello, I am configuring freeradius for authentication with active directory.I've used http://deployingradius.com/documents/configuration/active_directory but freeradius reject all the requests because of no known password.It what i have when i make a request: Ready to process requests. rad_recv:

Re: radpostauth sql logging of bad passwords

2009-04-27 Thread Guy Fraser
I am obviously missing something. I tried commenting out that section and it did not work I then changed it to : post-auth { reply_log sql sql_log exec Post-Auth-Type REJECT { sql_log } } Could someone toss me a bone or tell me

Re: freeradius with active directory

2009-04-27 Thread bastardinho69
David N'DAKPAZE wrote: hello, I am configuring freeradius for authentication with active directory.I've used http://deployingradius.com/documents/configuration/active_directory but freeradius reject all the requests because of no known password.It what i have when i make a request: Ready

Re: radpostauth sql logging of bad passwords

2009-04-27 Thread Alan DeKok
Guy Fraser wrote: I am obviously missing something. I tried commenting out that section and it did not work I then changed it to : So... what happens? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius with active directory

2009-04-27 Thread David N'DAKPAZE
Yes it is ntlm_auth for ms-chap i have confofigured but i still have the same response.Idon't know why. 2009/4/27 bastardinho69 bastardinh...@gmail.com David N'DAKPAZE wrote: hello, I am configuring freeradius for authentication with active directory.I've used

Re: radpostauth sql logging of bad passwords

2009-04-27 Thread Guy Fraser
On 2009-Apr-27, at 11:27, Alan DeKok wrote: Guy Fraser wrote: I am obviously missing something. I tried commenting out that section and it did not work I then changed it to : So... what happens? As far as I could tell nothing changed when I commented out the REJECT section :

Re: freeradius with active directory

2009-04-27 Thread Ivan Kalik
Yes it is ntlm_auth for ms-chap i have confofigured but i still have the same response.Idon't know why. Because - you are *not* following the instructions. 2009/4/27 bastardinho69 bastardinh...@gmail.com David N'DAKPAZE wrote: hello, I am configuring freeradius for authentication with

Re: problems with some libraires

2009-04-27 Thread Ivan Kalik
First do updatedb. Then see if locate can find this library. If it can, radius will probably run. If it doesn't - well, it's in the FAQ. Ivan Kalik Kalik Informatika ISP OK, i try to find the script where is that part of the libraries but i can't find it..can anyone tell wich is the

Re: radpostauth sql logging of bad passwords

2009-04-27 Thread Guy Fraser
On 2009-Apr-27, at 12:44, Ivan Kalik wrote: On 2009-Apr-27, at 11:27, Alan DeKok wrote: Guy Fraser wrote: I am obviously missing something. Ahem, did you read what sql_log does? Yes it says : modules { ... sql_log { path

looking for a good best practices for campus-wide Freeradius installation

2009-04-27 Thread john
Hi all, I'd would like to install .1x for all wired and wireless users across our campus by next fall. I'm looking for a really good howto/best practices for educational institutions. I hope folks on the list can point me to some good resources as I plan for deployment. Thanks! John - List

RE: looking for a good best practices for campus-wide Freeradius installation

2009-04-27 Thread Danner, Mearl
Best resource for this is EDUCAUSE's Wireless LAN list. Join at: http://listserv.educause.edu/cgi-bin/wa.exe?SUBED1=WIRELESS-LANA=1 Lot's of higher ed guys on the list. Mearl -Original Message- From: freeradius-users- bounces+jmdanner=samford@lists.freeradius.org

Re: looking for a good best practices for campus-wide Freeradius installation

2009-04-27 Thread john
On Mon, Apr 27, 2009 at 1:17 PM, Danner, Mearl jmdan...@samford.edu wrote: Best resource for this is EDUCAUSE's Wireless LAN list. Join at: http://listserv.educause.edu/cgi-bin/wa.exe?SUBED1=WIRELESS-LANA=1 Lot's of higher ed guys on the list. Mearl Thanks Mearl. John - List

error too many open files error reading radiusd.conf

2009-04-27 Thread Angel Rivera
[r...@ws11 ws11]# radiusd -x Starting - reading configuration files ... Errors reading dictionary: dict_init: /usr/share/freeradius/dictionary[55]: Couldn't open dictionary /usr/share/freeradius/dictionary.compat: Too many open files Errors reading radiusd.conf I already adjusted the limit of my

RE: error too many open files error reading radiusd.conf

2009-04-27 Thread Edvin Seferovic
Open files 2048 ?? Man LSOF ?? Regards, E:S From: freeradius-users-bounces+edvin.seferovic=kolp...@lists.freeradius.org [mailto:freeradius-users-bounces+edvin.seferovic=kolp...@lists.freeradius.or g] On Behalf Of Angel Rivera Sent: Dienstag, 28. April 2009 00:51 To:

Re: problems with some libraires

2009-04-27 Thread Ernesto Cadiz
Well I've changed the version problem with the libraries but when i run radius it appear this trouble: tls { rsa_key_exchange = no dh_key_exchange = yes rsa_key_length = 512 dh_key_length = 512 verify_depth = 0 pem_file_type = yes private_key_file =

Re: Freeradius-Users Digest, Vol 48, Issue 116

2009-04-27 Thread Angel Rivera
I also run this line su -c lsof | more and return a long list of files I really need help on this one. Is there anything that should be done to make the radiusd.conf readable Message: 7 Date: Tue, 28 Apr 2009 01:33:18 +0200 From: Edvin Seferovic edvin.sefero...@kolp.at Subject: RE: error

too many open files error reading radiusd.conf (was Re: Freeradius-Users Digest, Vol 48, Issue 116)

2009-04-27 Thread Karl Auer
On Tue, 2009-04-28 at 11:22 +0800, Angel Rivera wrote [r...@ws11 ws11]# radiusd -x Starting - reading configuration files ... Errors reading dictionary: dict_init: /usr/share/freeradius/dictionary[55]: Couldn't open dictionary /usr/share/freeradius/dictionary.compat: Too many open files

RE: Adding vendor specefic attributes

2009-04-27 Thread anoop c
Hi Thanks for the response. I am using free RADIUS version 1.1.7.I just require MAC authentication alone. Is anything wrong in the 'users' file NAS will support the VSA in this case. Vendor has given the following details Network Access Server Vendor- (Code for the specific vendor) Vendor