Re: FR 2.1.0 (ubuntu) proxying to NPS/IAS.

2009-08-31 Thread Alan DeKok
Ville Leinonen wrote: I try to use FR to forwarding access-request to NPS servers, but some reason FR/NPS gives User password is incorrect message. I have tripple check that password is correct. When i test IAS to NPS proxy it works. I have enable in NPS side MS-CHAP-v2, MS-CHAP, CHAP and

Re: FR 2.1.0 (ubuntu) proxying to NPS/IAS.

2009-08-31 Thread Ville Leinonen
Hi, I have also changed shared secrets and it's not helping. Br, Ville Ville Leinonen wrote: I try to use FR to forwarding access-request to NPS servers, but some reason FR/NPS gives User password is incorrect message. I have tripple check that password is correct. When i test IAS to NPS

Re: FR 2.1.0 (ubuntu) proxying to NPS/IAS.

2009-08-31 Thread Ville Leinonen
Hi, I have also changed shared secrets and it's not helping. Br, Ville Ville Leinonen wrote: I try to use FR to forwarding access-request to NPS servers, but some reason FR/NPS gives User password is incorrect message. I have tripple check that password is correct. When i test IAS to NPS

How to desactivate freeradius to open the network ?

2009-08-31 Thread via . lej
Hello, I use Freeradius on Debian with mac-based authentification along with a MySQL database containing the mac addresses (as Login Password). I would like to open the network to everyone, so I wonder how to make freeradius to authorize any mac address to open the network ? Regards,

Re: monitoring buffered-sql

2009-08-31 Thread ramesh p
Thanks Ivan. How do i examine the packet that caused freeze? Using detail.work file? please suggest. Thanks, Rams. I installed freeradius with detail, buffered-sql active. How to monitor the buffered-sql module. If it stops or sleeps for very long time responding to mysql db.? I saw all

Re: How to desactivate freeradius to open the network ?

2009-08-31 Thread Gary Gatten
Check out the users file and the DEFAULT directive. - Original Message - From: freeradius-users-bounces+ggatten=waddell@lists.freeradius.org freeradius-users-bounces+ggatten=waddell@lists.freeradius.org To: freeradius-users@lists.freeradius.org

Radius Logs in database (It was Re: rlm_ldap logs)

2009-08-31 Thread Sergio Belkin
2009/8/28 Sergio Belkin seb...@gmail.com: Hi I am using Version 2.1.1 with openldap on Centos 5 I wonder if is feasible dumping to logs when user gets login incorrect if due to non-existance of that uid on Ldap. Thanks in advance! -- -- Shame on me! That's is something that already logs

freeradius2.1.6| buffered-sql | acctstoptime problems

2009-08-31 Thread ramesh p
Hi All, I'm using freeradius2.1.6 with buffered-sql , detail files for accounting. In accounting queries i observed acctstoptime = %S. my db some how freezed and radius stopped updating packets from detail.wotk file. When restarted it started updating but updating the packets with new timestamps

Re: How to desactivate freeradius to open the network ?

2009-08-31 Thread Ivan Kalik
I use Freeradius on Debian with mac-based authentification along with a MySQL database containing the mac addresses (as Login Password). I would like to open the network to everyone, so I wonder how to make freeradius to authorize any mac address to open the network ? Why bother

Re: freeradius2.1.6| buffered-sql | acctstoptime problems

2009-08-31 Thread Ivan Kalik
I'm using freeradius2.1.6 with buffered-sql , detail files for accounting. In accounting queries i observed acctstoptime = %S. my db some how freezed and radius stopped updating packets from detail.wotk file. When restarted it started updating but updating the packets with new timestamps

Re: How to desactivate freeradius to open the network ?

2009-08-31 Thread via . lej
I have too much NAS and it's just temporary. Regards, RedVivi - Mail Original - De: Ivan Kalik t...@kalik.net À: FreeRadius users mailing list freeradius-users@lists.freeradius.org Envoyé: Lundi 31 Août 2009 16h15:33 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockholm / Vienne

Re: monitoring buffered-sql

2009-08-31 Thread Ivan Kalik
Thanks Ivan. How do i examine the packet that caused freeze? Using detail.work file? please suggest. Yes, that will be the packet(s) in detail.work file. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Out and into tunnel log files

2009-08-31 Thread Sergio Belkin
Hi, I have configured three virtual servers: default, inner (uses eap-ttls), inner-peap (uses eap-peap). I guess that out of tunnel attempts go to default server log files. cron performs a daily task that more or less perform something like that: grep OK /var/log/radius/radiusd-*-$date.log |

Username from LDAP in proxy request

2009-08-31 Thread Winnicki, Brian (GE, Corporate)
Hi, I'm looking for some help with proxying requests using free-radius. I have a situation where I need to perform a query to an LDAP that contains both the back-end authentication server as well as username for a user. For example, the User-Name in the originating request may be User1.

Re: Username from LDAP in proxy request

2009-08-31 Thread Ivan Kalik
I'm looking for some help with proxying requests using free-radius. I have a situation where I need to perform a query to an LDAP that contains both the back-end authentication server as well as username for a user. For example, the User-Name in the originating request may be User1.

Simple Accounting 'radrelay' functionality - Version 2.1.6

2009-08-31 Thread Craig Campbell
+- entering group accounting {...} [detail]expand: /var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d - /var/log/radius/radacct/192.168.1.101/detail-20090831 [detail] /var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands to /var/log/radius/radacct/192.168.1.101/detail

Re: Simple Accounting 'radrelay' functionality - Version 2.1.6

2009-08-31 Thread Ivan Kalik
Sending Accounting-Response of id 70 to 192.168.1.101 port 50125 Finished request 0. Cleaning up request 0 ID 70 with timestamp +1 Going to the next request Waking up in 0.3 seconds. You have cut off the debug at the interesting point. Does it poll the detail file after these 0.3 seconds. It

Re: Simple Accounting 'radrelay' functionality - Version 2.1.6

2009-08-31 Thread Craig Campbell
/radacct/192.168.1.101/detail-20090831 [detail] /var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands to /var/log/radius/radacct/192.168.1.101/detail-20090831 [detail]expand: %t - Mon Aug 31 15:32:59 2009 ++[detail] returns ok ++[unix] returns ok [nameonly] expand

Re: Setting FreeRadius + WPA - Enterprises (PEAP) CA Cert?

2009-08-31 Thread Steven Sprague
Hello Experts, Now that I have my 1st. test user working with clear text passwords I am ready to setup WPA - Enterprise (PEAP). I noticed in my client (RedHat RHEL Workstation) will need a CA.Cert in the connection settings. Can I simply copy the FR ca.pem file to my client for this or not?

Re: FR 2.1.0 (ubuntu) proxying to NPS/IAS.

2009-08-31 Thread Alan Buxey
Hi, Hi, I try to use FR to forwarding access-request to NPS servers, but some reason FR/NPS gives User password is incorrect message. I have tripple check that password is correct. When i test IAS to NPS proxy it works. I have enable in NPS side MS-CHAP-v2, MS-CHAP, CHAP and PAP/SPAP

Re: Setting FreeRadius + WPA - Enterprises (PEAP) CA Cert?

2009-08-31 Thread Ivan Kalik
Now that I have my 1st. test user working with clear text passwords I am ready to setup WPA - Enterprise (PEAP). I noticed in my client (RedHat RHEL Workstation) will need a CA.Cert in the connection settings. Can I simply copy the FR ca.pem file to my client for this or not? Yes. If I

process auth request from any AP

2009-08-31 Thread William Rettig
Is there a way to configure FreeRADIUS to accept authentication requests from any AP. In other words, I don't want to have to pre-configure access points in the client.conf. Thank you, Bill - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: process auth request from any AP

2009-08-31 Thread Ivan Kalik
Is there a way to configure FreeRADIUS to accept authentication requests from any AP. In other words, I don't want to have to pre-configure access points in the client.conf. No. You have to configure shared secret for radius to work. ipaddr accepts subnets as well. Ivan Kalik Kalik

RE: process auth request from any AP

2009-08-31 Thread Gary Gatten
Yep - I think you'd need at least a couple lines in Clients.conf, but you don't have to configure a separate block for EVERY AP. -Original Message- From: freeradius-users-bounces+ggatten=waddell@lists.freeradius.org

sqlippool - Duplicate IP

2009-08-31 Thread Neville
NAS-Port = 0 +- entering group authorize {...} ++[preprocess] returns ok [auth_log] expand: /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d - /var/log/radius/radacct/NASIPHERE/auth-detail-20090831 [auth_log] /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d

Re: Setting FreeRadius + WPA - Enterprises (PEAP) Test Results

2009-08-31 Thread Steven Sprague
Ivan, I copied over the servers ca.pem to my workstation for use in this test. My first try gave me client errors so I fixed those by creating a network -copied this from the example. client 192.168.0.0/24 { require_message_authenticator = no secret = testing123

Re: FR 2.1.0 (ubuntu) proxying to NPS/IAS.

2009-08-31 Thread Ville Leinonen
Hi, I just compile 2.1.6 from src and it's start to works. Thanks for everyone that tryed to help me. Br, Ville Hi, Hi, I try to use FR to forwarding access-request to NPS servers, but some reason FR/NPS gives User password is incorrect message. I have tripple check that password is

NAS with freeradius and telephone number

2009-08-31 Thread Magui
excuse me, somebody know if freeradius can see of some way the telephone number that one remote user is wearing in order to call me with his modem.My line(pair of copper) give me this information trhough a single telephone ,then can a NAS with freeradius give me the same information. if the

Radius Server Authenticate the user but Windows XP generate a error 691

2009-08-31 Thread amritap sinha
Dear freeradius-users, I have implemented Free Radius Server SUSE 9.3 Prof and using mysql database with Perle JETSTREAM 4000 RAS device. My problem is that when I try to connect a user through modem in windows XP client machine its occure a error 691 but radius