Re: problem with test aaa-server in ciscoasa

2012-11-24 Thread Alan Buxey
As previously mentioned, only add that user/pass to the users file... nothing else. Don't add all that stuff that you did alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: problem with test aaa-server in ciscoasa

2012-11-24 Thread Alan Buxey
...oh, and make sure you are editing the CORRECT users file ;) alan -- This smartphone uses free WiFi around the world with eduroam, now that's what I call smart. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Duplicate NAS name

2012-11-24 Thread Lorenzo Milesi
Hi. I'm performing some test upgrades from 1.1.x and ran into the nas table problem: in FR1 I had a list of NASes with duplicate names, maybe because we had several hotspots with different shortnames NAT'ed on the same ip. I see now FR complains at startup for duplicate name. How can I deal with

Re: Duplicate NAS name

2012-11-24 Thread Alan DeKok
Lorenzo Milesi wrote: Hi. I'm performing some test upgrades from 1.1.x and ran into the nas table problem: in FR1 I had a list of NASes with duplicate names, maybe because we had several hotspots with different shortnames NAT'ed on the same ip. I see now FR complains at startup for

Re: Duplicate NAS name

2012-11-24 Thread Lorenzo Milesi
Change the NAS name. RADIUS is not compatible with NAT. But FR1 was... So the only solution is VPN? This is not always easy with embedded devices like ddwrt or coovaap. thanks! -- Lorenzo Milesi - lorenzo.mil...@yetopen.it GPG/PGP Key-Id: 0xE704E230 - http://keyserver.linux.it - List

Re: Newbie question about rlm_exec usage

2012-11-24 Thread Hoggins!
I don't know if I understand the process correctly : as far as I understand, an authentication request is handled successively by the listed modules in the authorize {} section, right ? So, now that I figured that I have to use PAP as phase2, I can have the cleartext password. But I don't know

Re: Newbie question about rlm_exec usage

2012-11-24 Thread Phil Mayers
On 11/24/2012 08:40 PM, Hoggins! wrote: I don't know if I understand the process correctly : as far as I understand, an authentication request is handled successively by the listed modules in the authorize {} section, right ? So, now that I figured that I have to use PAP as phase2, I can have