Re: Multiple NAS configuration

2011-09-21 Thread Alan Buxey
That error message has nothing to do with the NAS-IP-Address config (clients.conf looks fine) , ensure that the test you send uses a method that your RADIUS server can deal with. What/how are you doing the testing and you'd help enormously by providing 'radius -X' output. This sort of thing

SQL Insert Problem for attribute values including #

2011-09-21 Thread denizaydin
Hi, I have called-station-id attribute in accounting requests like ; Calling-Station-Id = #AXDI_06ULUS_15 atm 1/1/06/01:8.35 While inserting to database freeradius inserts it like =23AXDI_06ULUS_15 atm 1/1/06/01:8.35. It replaces # with = . I have tried with other attributes like Connect-Info

RE: User + X Authentication

2011-09-21 Thread Raz Muhammad
Thanks Chris. This what I would have gone for, but a quick google search for EAP/TLS capable DSL router, does not really return any feasible router. This is mostly used/deployed on WiFi networks, using APs, or WiFi clients. Are you aware of any DSL router which can use EAP/TLS with PPP? I know

Re: SQL Insert Problem for attribute values including #

2011-09-21 Thread Alan DeKok
denizaydin wrote: I have called-station-id attribute in accounting requests like ; Calling-Station-Id = #AXDI_06ULUS_15 atm 1/1/06/01:8.35 While inserting to database freeradius inserts it like =23AXDI_06ULUS_15 atm 1/1/06/01:8.35. It replaces # with = . read dialip.conf. Look for

Re: Freeradius + Fedora-DS + EAP-MSCHAPv2 for WIFI/AP authentication

2011-09-21 Thread Phil Mayers
On 21/09/11 03:11, Christ Schlacta wrote: Very true, thank you for pointing that out as well. Note to anyone following: If you use a certificate signed by a general authority (verisign for example) then anyone with a verisign cert will be trusted in your place, and able to authenticate your

Re: Radius client redundance

2011-09-21 Thread Alan DeKok
oleaweel wrote: Just for information, I have not been working to much with FreeRadius:). I have read the proxy.conf file but im having problems understanding the configuration. When it say home_server is this a general name ? I don't know what you mean by that. If I understand correct i

NAS/IP added to different virtuell servers

2011-09-21 Thread Christopher Petermann
Hello I want to implement 2 virtuell Radius Server to provide service for wireless auth (server 1) hotspot auth (server 2) In my test enviroment I have one NAS which has an wireless interface and a hotspot function on it. So I config the NAS that I should use virtuell Radius Server 1 for

Re: NAS/IP added to different virtuell servers

2011-09-21 Thread Fajar A. Nugraha
On Wed, Sep 21, 2011 at 10:14 PM, Christopher Petermann c.peterm...@funknetz.at wrote: Hello I want to implement 2 virtuell Radius Server to provide service for wireless auth (server 1) hotspot auth  (server 2) In my test enviroment I have one NAS which has an wireless interface and a

WARNING about auth-type = Local

2011-09-21 Thread Johan Meiring
Hi, I use a completely custom setup. Not using the default server at all. All is working fine, except for a warning. In the authorise section, I have rlm_sql that selects the cleartext password from a database. The query looks like this. authorize_check_query = SELECT AccountID, Login,

Re: WARNING about auth-type = Local

2011-09-21 Thread Phil Mayers
On 21/09/11 17:11, Johan Meiring wrote: - [sql] expand: SELECT AccountID, Login, 'Cleartext-Password', Password, ':=' [sql] User found in radcheck table rlm_sql (sql): Released sql socket id: 1 +++[sql] returns ok ++- else else returns ok WARNING:

Re: WARNING about auth-type = Local

2011-09-21 Thread Alan DeKok
Johan Meiring wrote: My authorise and authenticate section looks like this. authorize { authorisation_log chap mschap sql pap } You need the pap module last in the authorize section. It will set Auth-Type for you. In 3.0, the Auth-Type = Local warnings

Re: WARNING about auth-type = Local

2011-09-21 Thread Johan Meiring
On 2011/09/21 06:19 PM, Alan DeKok wrote: Johan Meiring wrote: My authorise and authenticate section looks like this. authorize { authorisation_log chap mschap sql pap } You need the pap module last in the authorize section. It will set

Re: WARNING about auth-type = Local

2011-09-21 Thread Alan DeKok
Johan Meiring wrote: Thanks, makes perfect sense. Good... What now interests me, is how authentication worked at all previously? Magic. :( The server core had hacks to work around legacy configurations from version 0.x. That's bad, and should be removed from the server. Is that the

Confusion between Freeradius + MSCHAPv2 + Samba

2011-09-21 Thread Andreas Rudat
Hello, I have two machines. Freeradius + Samba as PDC. I auth. wlan clients against Radius and I want to store any user data on my Samba. The client auth, will be realized with PEAP+MSCHAPv2. So the problem is the bad thing with MSCHAPv2 and NTLMv1. So an other way could be kerberos and I

Re: Confusion between Freeradius + MSCHAPv2 + Samba

2011-09-21 Thread Alan DeKok
Andreas Rudat wrote: but is it usefull to use kerberos with two machines? Most of the time: no. I think it would be a contradiction of kerberos and would it work without AD/ldap? I have no idea what that means. And could I use a sql database to save the encrypted passwords by using

Re: Confusion between Freeradius + MSCHAPv2 + Samba

2011-09-21 Thread Andreas Rudat
Am 21.09.2011 22:09, schrieb Alan DeKok: Andreas Rudat wrote: but is it usefull to use kerberos with two machines? Most of the time: no. I think it would be a contradiction of kerberos and would it work without AD/ldap? I have no idea what that means. And could I use a sql database

CHAP WITH MD5 SQL PASSWORD

2011-09-21 Thread Ivaylo Petkov
Hi There, I have a FREE RADIUS Ubuntu installation and i am trying to get a CHAP authentication working with password that is stored in MD5 hash format in MySQL database. If i put a cleat text password the authentication works perfect with CHAP and PAP but the moment i use a md5 hashed

Re: CHAP WITH MD5 SQL PASSWORD

2011-09-21 Thread Arran Cudbard-Bell
On 22 Sep 2011, at 08:08, Ivaylo Petkov wrote: Hi There, I have a FREE RADIUS Ubuntu installation and i am trying to get a CHAP authentication working with password that is stored in MD5 hash format in MySQL database. If i put a cleat text password the authentication works perfect with

Authention Failure when putting NAS in private network.

2011-09-21 Thread 2394263740
Hello, Here is my freeradius enviroment. The freeradius is used for WIFI users access authentication. OS: Linux Enterprise Server 6.1 Radius: free radius server 2.1.11 Database: Mysql The freeradius server was put on internet. Sometime, the WIFI router need be put on the private