Re: freeradius upgrade help

2009-04-29 Thread A . L . M . Buxey
Hi, I'm currently using freeradius version 1.1.6, planning to upgrdate to a stable version. Please suggest a version which is stable. My radius box running linux. compared to 1.1.6 any of the 2.1.x are more stable ;-) alan - List info/subscribe/unsubscribe? See

Re: rlm_sql_mysql encoding issue

2009-04-29 Thread Ivan Kalik
This is my radcheck table: mysql select * from radcheck; ++--+++-+ | id | username | attribute | op | value | ++--+++-+ | 1 | MACH01\testuser | Cleartext-Password | := | mysecret |

Re: Vendor Specified Attribute

2009-04-29 Thread Alan DeKok
Tseveendorj wrote: Hello, Can I put one attribute in database like following 256Kbps Cisco-AVPair := ip:sub-policy-Out=256Kbps 256Kbps Cisco-AVPair := ip:sub-policy-In=256Kbps Yes. Just insert them the same as any reply attributes. But you will need to use

Re: Looking for client configurations for dynamic client

2009-04-29 Thread Ivan Kalik
Hi guys I'm running Debian lenny... in production server I have installed freeradius 1.x and in client.conf i have seted client 0.0.0.0/0 { secret = mySecret shortname = everyone } In Debian lenny is available freeradius 2.0.4 in this version that setting for client is not

Re: Looking for client configurations for dynamic client

2009-04-29 Thread Alan DeKok
Fabián Omar Franzotti wrote: In Debian lenny is available freeradius 2.0.4 in this version that setting for client is not available. Some time ago Alan told me that use 2.0.5 version to this settings, I did try to build a .pkg to install in my server but never can done it, because i did

Re: Vendor Specified Attribute

2009-04-29 Thread Tseveendorj
Thank you very much. I'm understanding my question was very fool when I got answer from someone. I think that's comes from my knowledge of RADIUS and AAA. Sincerely, Tseveen. Alan DeKok wrote: Tseveendorj wrote: Hello, Can I put one attribute in database like following 256Kbps

checking authorization in the duration of connection

2009-04-29 Thread Eric
Hi, My radius server use ldap server for authorize and authentication.I set an attribute in ldap server that is the check-name in sqlcounter to limit users Input traffic. I want when user traffic reaches to this amount the user become stop but radius checks ldap attributes only at the first of

User login Portal

2009-04-29 Thread tudorg
I am trying to create a user login area where they can view their usage. my php is very basic My radius will authenticate user by mac address which i have working so the user login for will take them to a home page in that page will be a link to view usage i would like a small pop up window (in

Re: checking authorization in the duration of connection

2009-04-29 Thread Alan DeKok
Eric wrote: Hi, My radius server use ldap server for authorize and authentication.I set an attribute in ldap server that is the check-name in sqlcounter to limit users Input traffic. I want when user traffic reaches to this amount the user become stop but radius checks ldap attributes only at

Re: radiusd only sending a NAK after a retransmission

2009-04-29 Thread Jeremy M. Guthrie
Sorry for the resend but I didn't get anything back. Does anyone have any ideas? On Tuesday 21 April 2009, Jeremy M. Guthrie wrote: We are having an issue with failed logins with FreeRADIUS. The problem is that FreeRADIUS doesn't appear to actually send a RADIUS Reject until the second

Re: rlm_sql_mysql encoding issue

2009-04-29 Thread Alan DeKok
Eric Hoeve wrote: Is there a way to change the way rlm_sql_mysql does its encoding? So I can leave it as 'MACH01\testuser'. Yes. Read raddb/sql/mysql/dialup.conf, and look for 'safe_characters'. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radiusd only sending a NAK after a retransmission

2009-04-29 Thread Alan DeKok
Jeremy M. Guthrie wrote: Sorry for the resend but I didn't get anything back. Does anyone have any ideas? I responded on 4/21. Check your spam filters, or the web archive of the mailing list. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

want to change one module in freeradius

2009-04-29 Thread new conf
Dear all; If I have to change the module in FreeRadius that uses EAP-TLS to communicate with clients(to use it with other way then openSSL (ssl will generate keys and certficate seperately in another form) ).. the function I have to delete or change is-it *rlm_eap.c* ? thank you for help :) -

Re: checking authorization in the duration of connection

2009-04-29 Thread Ivan Kalik
My radius server use ldap server for authorize and authentication.I set an attribute in ldap server that is the check-name in sqlcounter to limit users Input traffic. I want when user traffic reaches to this amount the user become stop but radius checks ldap attributes only at the first of

radius process dying help

2009-04-29 Thread ramesh p
I'm using freeradius version 1.1.6. My radius process 'radiusd' is dying frequently due to mysterious reasons. So is it safe to use 'radwatch' script to monitor? Thanks. Rams. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: User login Portal

2009-04-29 Thread Arran Cudbard-Bell
On 29/4/09 13:12, tudorg wrote: I am trying to create a user login area where they can view their usage. my php is very basic My radius will authenticate user by mac address which i have working so the user login for will take them to a home page in that page will be a link to view usage i would

Re: User login Portal

2009-04-29 Thread Ivan Kalik
I am trying to create a user login area where they can view their usage. my php is very basic So are your requirements. My radius will authenticate user by mac address which i have working so the user login for will take them to a home page in that page will be a link to view usage i

Re: radius process dying help

2009-04-29 Thread Ivan Kalik
I'm using freeradius version 1.1.6. My radius process 'radiusd' is dying frequently due to mysterious reasons. So is it safe to use 'radwatch' script to monitor? doc/supervise-radiusd.txt Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

Re: checking authorization in the duration of connection

2009-04-29 Thread John Dennis
Eric wrote: Hi, My radius server use ldap server for authorize and authentication.I set an attribute in ldap server that is the check-name in sqlcounter to limit users Input traffic. I want when user traffic reaches to this amount the user become stop but radius checks ldap attributes only at

Re: User login Portal

2009-04-29 Thread Tudor
like i say my php is basic this is answer is helpful thanks i have changed it a bit as the user will not be logging in with their real username in the radius server as it is a mac adress so i changed the line FROM radacct WHERE UserName = '00-00-00-00-00-13' the idea is that the users home

Re: rlm_sql_mysql encoding issue

2009-04-29 Thread Eric Hoeve
Alan DeKok said the following, On 4/29/2009 7:27 AM: Eric Hoeve wrote: Is there a way to change the way rlm_sql_mysql does its encoding? So I can leave it as 'MACH01\testuser'. Yes. Read raddb/sql/mysql/dialup.conf, and look for 'safe_characters'. Alan DeKok. - List

Re: User login Portal

2009-04-29 Thread Arran Cudbard-Bell
On 29/4/09 15:09, Tudor wrote: like i say my php is basic this is answer is helpful thanks i have changed it a bit as the user will not be logging in with their real username in the radius server as it is a mac adress so i changed the line FROM radacct WHERE UserName = '00-00-00-00-00-13' the

Re: User login Portal

2009-04-29 Thread Tudor
still blank heres what i have done so far still need big help much appreciated ?php error_reporting(E_ALL); $unitsBytesBin = array('B','KiB','MiB','GiB','TiB','PiB','EiB','ZiB','YiB'); function bcHighPow($val, $precision = 2, $expLimit = 10, $base = 1024){ $i = 0; $pDiv = 1; $val = (string)

Re: User login Portal

2009-04-29 Thread Tudor
ok now getting the number 0 appearing top left of page getting closer - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Mac-Based auth and HP chap

2009-04-29 Thread jehan procaccia
{...} ++[preprocess] returns ok [auth_log] expand: /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d - /var/log/radius/radacct/157.159.17.138/auth-detail-20090429 [auth_log] /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands to /var/log/radius/radacct/157.159.17.138

Re: Mac-Based auth and HP chap

2009-04-29 Thread Alan DeKok
jehan procaccia wrote: hello, I use FreeRADIUS Version 2.1.3, and I try a basic configuration from my HP procurve2650 to do Mac-based radius auth. for this I've setup a simple users file 005004B7252EAuth-Type := Local, Cleartext-Password := 005004B7252E Delete the Auth-Type := Local.

Re: Mac-Based auth and HP chap

2009-04-29 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The example in the wiki was written *for* HP Mac-Auth http://wiki.freeradius.org/Mac-Auth You may need to change the Service-Type check to Framed-User for older firmware revisions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.9 (Darwin)

Re: Mac-Based auth and HP chap

2009-04-29 Thread Guy Fraser
= 0x4f687fe44ece7630d3470b37598b43b8 +- entering group authorize {...} ++[preprocess] returns ok [auth_log] expand: /var/log/radius/radacct/%{Client-IP-Address}/ auth-detail-%Y%m%d - /var/log/radius/radacct/157.159.17.138/auth- detail-20090429 [auth_log] /var/log/radius/radacct/%{Client-IP-Address}/auth-detail- %Y%m%d

Re: radius process dying help

2009-04-29 Thread ramesh p
Thanks Ivan. So am stopped the server using following command: /usr/local/etc/init.d/radiusd stop Then added the supervision using inittab file. This started process as *radiusd -f -s * automatically and radiusd.pid will not updated. Any issues with this? Thanks, Ramesh. On Wed, Apr 29, 2009

Re: radius process dying help

2009-04-29 Thread ramesh p
One more question: how much traffic can efford freeradius version? if there are calls morethan 1 lakh in number per day will it afford? My radius server process 'radiusd' is dying due to more traffic these days. That's why i want to know. Thank you. Rams. On Wed, Apr 29, 2009 at 10:20 PM, ramesh

Re: radius process dying help

2009-04-29 Thread ramesh p
Sorry for typos. One more question: how much traffic can freeradius server can manage/afford? if there are calls more than 1 lakh in number per day, will it afford? My radius server process 'radiusd' is dying due to more traffic these days frequently . That's why i want to know. On Wed, Apr 29,

Re: Mac-Based auth and HP chap

2009-04-29 Thread jehan procaccia
= 0x3eae4885821478bc7bbcf7e45618c453 +- entering group authorize {...} ++[preprocess] returns ok [auth_log] expand: /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d - /var/log/radius/radacct/157.159.7.138/auth-detail-20090429 [auth_log] /var/log/radius/radacct/%{Client-IP

rlm_perl authorization/authentication and %RAD_CONFIG questions

2009-04-29 Thread dorkusmonkey
I am running FreeRADIUS Version 2.1.5, for host i686-pc-linux-gnu, have successfully configured rlm_perl and have it working with a modified example.pl file. I have noticed that the authorize callback in example.pl gets called before the authentication callback. From

Re: rlm_perl authorization/authentication and %RAD_CONFIG questions

2009-04-29 Thread Alan DeKok
dorkusmonkey wrote: I am running FreeRADIUS Version 2.1.5, for host i686-pc-linux-gnu, have successfully configured rlm_perl and have it working with a modified example.pl file. I have noticed that the authorize callback in example.pl gets called before the authentication callback. From

Re: [Wimax TTLS with Alcatel - Lucent ASN GW]

2009-04-29 Thread Thomas Fagart
Files module supports use of files in post-auth and post-proxy. Add this to raddb/modules/files: postproxy_usersfile = ${confdir}/postproxy_users Then create postproxy_users in raddb directory (where other users files are) and list that DEAFAULT entry there. Ivan Kalik Kalik Informatika ISP

Re: Help with Freeradius + OpenLDAP/Samba + 802.1x WLan auth for Windows

2009-04-29 Thread Albrecht Dreß
Am 24.04.09 23:23 schrieb(en) Ivan Kalik: rlm_eap: Identity does not match User-Name, setting from EAP Identity. Username was altered. Got it - Win sends the domain in uppercase, and I had conversion to lowercase enabled. Works fine now. Thanks, Albrecht. pgp85LHExAchz.pgp

How to Run PPPoE-SERVER RP-PPPoE in Kernel Mode, Calling-Station-ID

2009-04-29 Thread EasyHorpak.com
As I try to find out the method now i can resolve it. and i need to share this to whom want it. Cheer!! How to Run PPPoE-SERVER RP-PPPoE in Kernel Mode, Calling-Station-ID This method setup on Ubunutu 8.10 server ppp-2.4.4 rp-pppoe-3.10 1. Remove ppp-2.4.4 which install by ubuntu