Re: Freeradius privilege separation

2010-05-14 Thread Alan DeKok
Michał Dopierała wrote: It is possible in freeradius to have one user who has full privilege level to one equipment (one cisco router privilege lvl15), and limited privilege level to other equipment (other router with smaller privilege e.g. lvl10 which will be configured on router)? Yes.

Re: Pending release of 2.1.9

2010-05-14 Thread Johan Meiring
On 2010/05/14 07:46 AM, Alan DeKok wrote: Johan Meiring wrote: There is a log of warnings though. Small subset says this. - dpkg-shlibdeps: warning: symbol radlog used by debian/freeradius/usr/lib/freeradius/rlm_checkval-2.1.9.so found in

Re: Pending release of 2.1.9

2010-05-14 Thread Alan DeKok
Johan Meiring wrote: I compiled the server and can confirm it runs ok on my develepment machine. OK. On another note, every time a new release comes out, I manually add rlm_raw and recompile. I updated rlm_raw to work with FR2 a while ago and have been running it successfully in

Re: Pending release of 2.1.9

2010-05-14 Thread Johan Meiring
On 2010/05/14 10:35 AM, Alan DeKok wrote: Johan Meiring wrote: The dynamic clients' code runs modules before the packet is decoded... but that's only because it doesn't *receive* the packet. So any raw access to the packet will return nothing. What are you doing with the module? I

Diameter roaming

2010-05-14 Thread VU VAN HUNG
Hi all, Do anyones know why Diameter support faster roaming than RADIUS ? I've read some references but I dont understand. Hung, - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Diameter roaming

2010-05-14 Thread Alan DeKok
VU VAN HUNG wrote: Do anyones know why Diameter support faster roaming than RADIUS ? It doesn't. I've read some references but I dont understand. Diameter is useful if you have an ISP / phone company with 10 million users, and $5-10 million to spend on a Diameter infrastructure. And even

Re: Diameter roaming

2010-05-14 Thread VU VAN HUNG
Alan DeKok wrote: VU VAN HUNG wrote: Do anyones know why Diameter support faster roaming than RADIUS ? It doesn't. I means roaming between 2 client with 1 AAA Server in network (ex: wireless mesh network). Is roaming with Diameter faster than with Radius? I've read some

Re: Diameter roaming

2010-05-14 Thread Bjørn Mork
VU VAN HUNG vanhung2...@gmail.com writes: Do anyones know why Diameter support faster roaming than RADIUS ? Higher marketing budgets I've read some references but I dont understand. In my experience, that often means that the claim just is not true. Anyway, I believe you'd better ask

Re: Diameter roaming

2010-05-14 Thread Alan DeKok
VU VAN HUNG wrote: I means roaming between 2 client with 1 AAA Server in network (ex: wireless mesh network). Is roaming with Diameter faster than with Radius? What did I say? I'm sure that Diameter do authentication and accounting. Check it out,

Re: Pending release of 2.1.9

2010-05-14 Thread Johan Meiring
On 2010/05/14 11:08 AM, Johan Meiring wrote: Its dynamic clients. Alan, I just saw you were cc-ed on the mail sent to this list. Not intentional. I know you hate it. I always use reply-to-all as a habit. It then replied to you as well. Apologies -- Johan Meiring Cape PC Services

Re: configuration freeradius with mysql

2010-05-14 Thread David Seira
Have you decommented the $INCLUDE sql.conf line in radiusd.conf? I had the same problem when I compiled freeradius-2.1.8. If I compiled freeradius without libmysqlclient15-dev package the problem appeared. Try it. 2010/5/14 dorra aa dj_dido2...@hotmail.com hi i installed mysql. and i

Re: Pending release of 2.1.9

2010-05-14 Thread Alan DeKok
Johan Meiring wrote: You made a modification to dynamic clients a while ago where you could get hold of the whole packet inside dynamic clients. Ah... yes. The rlm_raw won't go into 2.1.x. It's a new feature, and doesn't belong there. I'm not sure it will go into 2.2.x, either. It's

A question about disconnections

2010-05-14 Thread Nick Warr
We're a WISP using freeradius to do our AAA, and are in the process of updating our backend to the latest version of freeradius (probably 2.1.8), and we've been able to resolve a lot of issues with our current setup, except for a few (possibly vital) problems. The one we haven't been able to

Re: Freeradius privilege separation

2010-05-14 Thread Michał Dopierała
Thanks for response! So, users file can look like this: users= mdopierala Packet-Src-IP-Address == 192.168.1.1, Crypt-Password = some_hash Service-Type = Administrative-User,

Re: Freeradius privilege separation

2010-05-14 Thread Alan DeKok
Michał Dopierała wrote: Thanks for response! So, users file can look like this: Yes. users= mdopierala Packet-Src-IP-Address == 192.168.1.1, Crypt-Password = some_hash It's NOT a hash. It's a password. This way

Re: Configuration trouble (2.1.8 for use with WiMAX)

2010-05-14 Thread Sumedh Sathaye
Hi Alan, Thanks for pointing out what I am doing wrong. Being a newbie to the whole field of AAA, can you give me a few pointers where/what I can read up to configure EAP for the TLS method (rather than MD5)? I appreciate your help. Best Regards, Sumedh Sathaye | | From: |

Re: autthentication error

2010-05-14 Thread shirkavand
Hi there, Thanks for the fast reply. I did not build myself freeradius, i have installed Freeradius on ubuntu 9.10 using sudo apt-get install freeradius* But maybe this does not installed openSSL support so I am going to check if i have dev packages and ssl support properly installed, and come

Re: Configuration trouble (2.1.8 for use with WiMAX)

2010-05-14 Thread Alan DeKok
Sumedh Sathaye wrote: Thanks for pointing out what I am doing wrong. Being a newbie to the whole field of AAA, can you give me a few pointers where/what I can read up to configure EAP for the TLS method (rather than MD5)? I appreciate your help. See the Wiki my web page:

Re: A question about disconnections

2010-05-14 Thread Alan DeKok
Nick Warr wrote: We have a central radius server, and a few point to point connections where we have our point to multipoint connections (base stations) each base stations is a NAS, which for the most part works just fine. Our problem happens if something interrupts the point to point

EAP-TLS and MAC Authentication

2010-05-14 Thread John McDonnell
First a little information on our setup. When I first started working here, the wireless network had been in place for a year already and was rather small, only 3 access points and ~90 laptops. My boss set it up as static WEP (I don't know why WEP instead of WPA) and used the AP's (Cisco 1121

Authentication with existing MySQL database

2010-05-14 Thread Quentin Smith
Hello all, I've set up and configured freeradius to properly authenticate users using the MySQL database schema specified on the freeradius.org website. However, since we already have a different database set up with users' passwords that is updated by scripts when users change their passwords or

Re: autthentication error

2010-05-14 Thread shirkavand
HI there, Ok i have tryed to add ssl support to freeradius in my ubuntu 9.10. As i mentioned before i have installed freeradius using apt-get. The thing is that every tutorial i followed did not woked, and after hours of trying...i read that freeradius over ubuntu does not have ssl support for

Re: autthentication error

2010-05-14 Thread shirkavand
hi, i have followed this tutorial(because this is what i need exacty to do) but it does not worked either. http://www.wains.be/index.php/2009/09/13/wpa2-freeradius-eap-tls/ Cheers - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html