Re: How to change request attribute based on NAS IP address

2013-04-24 Thread Giuseppe Marocchio
Hello, is simple stupid. if (Cisco-AVpair =~ /^client-mac-address=([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9])$/) { if (!Calling-Station-Id) { update request {

Re: RADIUS server is dumping core

2013-04-24 Thread ramakrishna
Hi Alan, I am using FreeRADIUS in solaris sever in which valgrind is not supported. Do you suspect access errors in RADIUS server for the dump based on the gdb log? In Solaris, we use dbx or bcheck to find access errors or memory leaks. Is it ok if i produce logs of those tools? Thanks, On

How to fix the proxy source port

2013-04-24 Thread Okis Chuang
Hi all, Can I FIX the source port rather than random src port when proxy request to other RADIUS server? I know it is able to fix src IP address in proxy.conf, but seems no config about fixed src port. What if I set src_ipaddr = 127.0.0.1:3100 in proxy.conf, could this work? Thanks in

authentification ldap subgroup

2013-04-24 Thread REYNALD chekhina
Hello all ! I have configured freeradius 2.1.12-4 with ldap group authorization. My problem is it's doesn't work with subgroup. I have a group with subgroup and when ldap verify group of user it doesn't see subgroup of user. my ldap configuration modules : ldap {#Note that this needs to match

Re: SQL and Huntgroups

2013-04-24 Thread gregoire . leroy
Hello, So... what do you want to do? You've been very clear that you want help with a particular *solution*. Because your assumptions are wrong, your solution is wrong. So I can't really help you with that. What do you have, and hat do you want? - you want the user to be

Re: How to change request attribute based on NAS IP address

2013-04-24 Thread Mehdi Ravanbakhsh
Dear Giuseppe Marocchio it works :) thanks. On Wed, Apr 24, 2013 at 11:15 AM, Giuseppe Marocchio giuse...@marocchio.com wrote: Hello, is simple stupid. if (Cisco-AVpair =~ /^client-mac-address=([a-f0-9]** [a-f0-9])([a-f0-9][a-f0-9]).([**a-f0-9][a-f0-9])([a-f0-9][a-**

Re: How to fix the proxy source port

2013-04-24 Thread Alan DeKok
Okis Chuang wrote: Can I FIX the source port rather than random src port when proxy request to other RADIUS server? I know it is able to fix src IP address in proxy.conf, but seems no config about fixed src port. What if I set “ src_ipaddr = 127.0.0.1:3100 “ in proxy.conf, could this

Re: Have anyone test the performance about FreeRADIUS+jRadius on authentication?

2013-04-24 Thread Alan DeKok
Okis Chuang wrote: Yes, I'm under this slow performance trouble now Actually I tried let it not going into jradius and completing my easy job only in FreeRADIUS yesterday. And it did it well. It can finish 1 auth request in 13 sec. Exactly. However, our goal is more than that ...

Re: SQL and Huntgroups

2013-04-24 Thread Alan DeKok
gregoire.le...@retenodus.net wrote: I want the following behaviour : 1) Set the password for the user 2) Authentication of the user 3) X is always added to the reply if the user is authenticated 4) Moreover, Y is added to the reply for NAS, still if the user is authenticated. That's

case insensitive password

2013-04-24 Thread Mehdi Ravanbakhsh
how i could check case insensitive password for user.. many of users use wring password based on Caps Lock , so i need to check password insensitive and it is better if i could limit this kind of password check for some nas-ip-adress. which part of config file should be modified for this

Re: case insensitive password

2013-04-24 Thread Alan DeKok
Mehdi Ravanbakhsh wrote: how i could check case insensitive password for user.. You don't. and it is better if i could limit this kind of password check for some nas-ip-adress. Write unlang rules to do that. which part of config file should be modified for this problem? Write a

EAP-AKA testing without HLR/HSS

2013-04-24 Thread antoni milton
Hi,       Please let me know , if its possible to test EAP-AKA authentication without HLR/HSS using freeradius. i.e can freeradius gernarte the quients from given RAND, Key value ?. if yes means , where can get the code for this algorithm? Thanks Antoni Milton.- List

Re: case insensitive password

2013-04-24 Thread Mehdi Ravanbakhsh
Dear Alan DeKok thanks for your help i use it to get some to=ime to transfer all user information from other AAA server. i try to change Cleartext-Password to lower case by this code in authorize section But if password saved in database in upercase it can not be match to client lowercase

Problem with Discarding packets. It is the Radius, MySQL or PostgreSQL?

2013-04-24 Thread Michell
Hello guys, I would like an opinion concerning a situation that is happening with us. I'm sure you have faced a similar situation. Currently I have about 3000 clients connected simultaneously in 8 concentrators Mikrotik. These concentrators authenticate to 3 servers freeradius doing consulting

FreeRadius connection pooling

2013-04-24 Thread Bruce Bauman
I'm updating an environment from freeradius 2.1.x to freeradius 2.2.x, and I'm trying to figure out connection pooling. Our current configuration has 5 sql {} stanzas in the sql.conf file, each specifying num_sql_socks and several other SQL related variables. WIth connection pooling, can I

Re: Problem with Discarding packets. It is the Radius, MySQL or PostgreSQL?

2013-04-24 Thread A . L . M . Buxey
Hi, I would like an opinion concerning a situation that is happening with us. I'm sure you have faced a similar situation. yes. live accounting to DB requires REALLY optimised DB. you've made the move to postgres, which will help...and you can spend some time adjusting the buffers,

implementing 3gpp2 attributes

2013-04-24 Thread Juan Pablo L.
Hi, i m in the early stages of implementing a prepaid service for a CDMA network, i have to exchange radius package using the 3gpp2 standard which is an extension to the basic radius protocol. i m facing an issue and that is that the attributes in the 3gpp2 standard included attributes that

Re: Problem with Discarding packets. It is the Radius, MySQL or PostgreSQL?

2013-04-24 Thread Fajar A. Nugraha
On Thu, Apr 25, 2013 at 3:20 AM, Michell bill.c...@gmail.com wrote: So we did the installation of new server Mysql and changed the parameters possible and even indicated by mysqltunner and mysqlprimer, but the message continued Discarding occurs. ( sigh ) no program can replace a qualified