Re: Access-Accept if user exists in database

2012-01-30 Thread Alexandre Chapellon
-exists-in-database-tp5441329p5441329.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me

Re: freeradius+openvpn disconnect user from radius

2012-01-05 Thread Alexandre Chapellon
try it now. On 1/4/2012 5:49 PM, Alexandre Chapellon a wrote: pptp does it very well (at least poptop does). Never tried with L2TP itself but I know ppp sessions inside L2TP tunnels works as expected... but that inly pppd works ok with session-timeout. Regards. Le 04/01/2012 12:19, Azfar Hashmi

Re: freeradius+openvpn disconnect user from radius

2012-01-05 Thread Alexandre Chapellon
attributes trick? On 1/5/2012 6:30 PM, Alexandre Chapellon wrote: From the ./UserAuth.cpp file in the radiusplugin code: /**The method send an authentication packet to the radius server and * calls the method parseResponsePacket(). The following attributes are in the packet: * - User_Name

Re: freeradius+openvpn disconnect user from radius

2012-01-04 Thread Alexandre Chapellon
://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius+openvpn disconnect user from radius

2012-01-04 Thread Alexandre Chapellon
this with pptp and lt2p also, do they support it? On 1/4/2012 4:14 PM, Azfar Hashmi wrote: Hi Alexandre, Thanks for sharing your experience. On 1/4/2012 4:02 PM, Alexandre Chapellon wrote: I tried to setup exactly the same things a while ago using the radiusplugin for openvpn. It just don't work

Re: Radius Client vs. Radius Client-NG

2011-12-08 Thread Alexandre Chapellon
recommended or have benefits over the other? Thanks in Advance, Nicholas. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com

Re: annoying stop retransmissions.

2011-12-01 Thread Alexandre Chapellon
of overhead. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http

Re: annoying stop retransmissions.

2011-11-29 Thread Alexandre Chapellon
Le 29/11/2011 10:20, Fajar A. Nugraha a écrit : On Tue, Nov 29, 2011 at 3:57 PM, Alan DeKokal...@deployingradius.com wrote: Alexandre Chapellon wrote: I don't understand what you mean by writing a detailed state machine... state machine? Write down what the server receives, and what you

annoying stop retransmissions.

2011-11-28 Thread Alexandre Chapellon
find out how to do that... Thanks for reading that long post (I hope it's understandable enough). -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http

Re: annoying stop retransmissions.

2011-11-28 Thread Alexandre Chapellon
Le 28/11/2011 13:53, Alan DeKok a écrit : Alexandre Chapellon wrote: This work as epected for most of my NASes. Unfortunately, i have some NASes that are behind a satelite link, which is a very unreliable link with regular packets loss. UDP retramission of packet make the systems work even

Re: Freeradius process crash receiving answers from Microsoft NPS Server

2011-11-14 Thread Alexandre Chapellon
://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe

Re: Freeradius process crash receiving answers from Microsoft NPS Server

2011-11-13 Thread Alexandre Chapellon
Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius Losing packets in Multi-Threads mode

2011-10-26 Thread Alexandre Chapellon
Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

wiki

2011-10-20 Thread Alexandre Chapellon
it to the wiki. Unfortunately I messed up things and now this page is not readable anymore. I haven't found a way to solve this or to get back to previous version Thank you for your help. -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me

Re: wiki

2011-10-20 Thread Alexandre Chapellon
changes. Interesting result :) Thanks for fixing it up. -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

radius/diameter

2011-10-13 Thread Alexandre Chapellon
)? And at least is it possible to build some kind of gateway between radius and diameter? Bests regards. -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe

Re: about Simultaneous-Use and Multiple NAS

2011-10-10 Thread Alexandre Chapellon
NAS1 and second simultaneous login must be from NAS2. Thanks, - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com

Re: AW: Dynamic Attributes Based on NAS Type !

2011-10-09 Thread Alexandre Chapellon
anything as i have no clue on the same so some highlights on the approach will be a good starting point for me. Cheers Suman - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et

radius dhcp

2011-10-05 Thread Alexandre Chapellon
possible with redback xxxSE BRAS? Regards. -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius for Lan

2011-10-02 Thread Alexandre Chapellon
to setup 802.1X port authentication... if your Wlan AP supports it. Thanks Andreas - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http

Re: Problem expand: %{Acct-Input-Gigawords} - always get nothing!

2011-09-27 Thread Alexandre Chapellon
from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Alexandre Chapellon Ingnierie des systmes open sources et rseaux. Follow me on twitter

Re: Problem expand: %{Acct-Input-Gigawords} - always get nothing!

2011-09-27 Thread Alexandre Chapellon
/users.html -- http://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Limit guest/anonymous users for 15 minutes

2011-09-27 Thread Alexandre Chapellon
://www.horoa.net Alexandre Chapellon Ingénierie des systèmes open sources et réseaux. Follow me on twitter: @alxgomz http://www.twitter.com/alxgomz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Access Accept

2011-09-24 Thread Alexandre Chapellon
://freeradius.1045715.n5.nabble.com/Access-Accept-tp4832711p4834972.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Alexandre Chapellon Ingnierie

Re: Access Accept

2011-09-23 Thread Alexandre Chapellon
/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Alexandre Chapellon Ingnierie des systmes open sources et rseaux. Follow me on twitter: @alxgomz attachment: a_chapellon.vcf- List info/subscribe

Re: Access Accept

2011-09-23 Thread Alexandre Chapellon
at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Alexandre Chapellon Ingnierie des systmes open sources et rseaux. Follow me on twitter: @alxgomz attachment

Re: Access Accept

2011-09-23 Thread Alexandre Chapellon
that I have it dictionary (dictionary.rfc2866). don't you have single quotes somewhere that would prevent variable expansion? BR, Miha On 9/23/2011 3:38 PM, Alexandre Chapellon wrote: Le 23/09/2011 1

Re: Freeradius/Oracle compilation

2010-12-20 Thread Alexandre Chapellon
...@deployingradius.com) Subject: Re: Freeradius/Oracle compilation To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Alexandre Chapellon wrote: Hello I didn't have even a comment about this. Is there something stupid in the proposed patch? I've been busy. Off of the top of my

Re: wifi ip allocation

2010-12-14 Thread Alexandre Chapellon
Le mardi 14 décembre 2010 à 14:25 -0800, pauvre a écrit : Hello all, I'm also trying to assign pools of IPs based on LDAP group membership. Since your conversation is very technical and not easy to put in place by someone who just started with RADIUS, I was looking for a descriptive way to

Re: Freeradius/Oracle compilation

2010-12-14 Thread Alexandre Chapellon
Hello I didn't have even a comment about this. Is there something stupid in the proposed patch? regards. Le samedi 11 décembre 2010 à 18:43 -1000, alexandre.chapel...@mana.pf a écrit : Unless I missunderstood the compil process it seems to me that todays source tree is stuck to Oracle 10g.

Re: wifi ip allocation

2010-12-02 Thread Alexandre Chapellon
Le jeudi 02 décembre 2010 à 07:38 +0100, Alan DeKok a écrit : Alexandre Chapellon wrote: Am not sure to understand... Once the wifi user entered the network (level2: no IP yet), I have an entry for its sessions in my accouting database, with username, sessionID, maybe mac_address and so

Re: wifi ip allocation

2010-12-01 Thread Alexandre Chapellon
Le mardi 30 novembre 2010 à 21:01 +0100, Alan DeKok a écrit : Alexandre Chapellon wrote: Hi every body, While all the documentation on the web seems to answer *NO*, and because I feel like i need to talk to someone today, I was wondering if there is any way to allocate IP address to wifi

wifi ip allocation

2010-11-30 Thread Alexandre Chapellon
Hi every body, While all the documentation on the web seems to answer *NO*, and because I feel like i need to talk to someone today, I was wondering if there is any way to allocate IP address to wifi user using radius Attributes instead of DHCP? Or maybe I should ask... How can i allocate IP

Re: Accounting Log

2010-11-08 Thread Alexandre Chapellon
I have the very same behaviour here on my FR2.1.6 setup with PGSQL accoutning. It produce noisy logs but nothing unacceptable. You can change this by not doing accouting for Stop Accounting packet that show up null session-time: in your acccouting section: if (Acct-Status-Type == Stop

Re: (Fwd) (Fwd) Re: Accounting Log

2010-11-08 Thread Alexandre Chapellon
to: nicolas.bre...@belcenter.biz Date sent: Mon, 08 Nov 2010 23:00:40 +0100 From: Alexandre Chapellon alexandre.chapel...@mana.pf I have the very same behaviour here on my FR2.1.6 setup with PGSQL accoutning. It produce noisy logs but nothing unacceptable. You

Re: Setting Service-Type

2010-10-26 Thread Alexandre Chapellon
A solution would be to use the operator := instead of = in users file with the default entry (should work using unlang too). http://wiki.freeradius.org/Operators Le mardi 26 octobre 2010 à 19:23 +, Rowley, Mathew a écrit : I have a perl module that I want to set the Service-Type

replylog

2010-10-05 Thread Alexandre Chapellon
Hy everybody, I would like to add the username to the replylog when logging access replies. Of course I do not want the attributes to be sent, just to be logged. I have seen the supress stanza in the example detail.log module. Is there any add stanza? regards -- Follow us on: twitter

deleteing attribute

2010-08-30 Thread Alexandre Chapellon
Hello, I want to delete an attribute I send to NASes in Access-reply, regardless of its value. Apparently I cannot use '!*' operator which is only for check items, and '-=' doesn't support wilcards (unless i mistaken) How can I do it? Am using freeradius 2.1.6 on Debian x86_64 P.S: of course I

Re: deleteing attribute

2010-08-30 Thread Alexandre Chapellon
Le mardi 31 août 2010 à 04:31 +0200, Alan DeKok a écrit : Alexandre Chapellon wrote: Hello, I want to delete an attribute I send to NASes in Access-reply, regardless of its value. Apparently I cannot use '!*' operator which is only for check items, and '-=' doesn't support wilcards

RE: How to set properly failover ?

2010-07-23 Thread Alexandre Chapellon
Le vendredi 23 juillet 2010 à 20:09 +0200, Jevos, Peter a écrit : Hi alex, thank you for your mail, helped a lot : ) Now it's working, no idea why and how but working : ) Here is my config: Users: DEFAULT Auth-Type := vpn_auth_name,Huntgroup-Name == vpn

attribute name manipulation

2010-06-11 Thread Alexandre Chapellon
the previous one? Regards. -- Alexandre Chapellon alexandre.chapel...@mana.pf Mana SAS - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

radmin

2010-06-10 Thread Alexandre Chapellon
'NAS-Port = 302458251,Client-IP-Address = 192.168.110.45,NAS-IP-Address = 42.123.21.78,Acct-Session-Id = 0001003F28000B60-4C11A0B6,User-Name = a4nj...@toto' Does anybody uses this feature of radmin successfully? Is it supposed to be stable? Thx -- Alexandre Chapellon alexandre.chapel...@mana.pf

Re : What is the Class attribute for?

2010-05-25 Thread Alexandre Chapellon
Yes, the attribute you need to return Back to your NAS, might be vendor specific (take a look at the dictionnaries). Sending this Attr in Access-Accept, should do the trick but I suggest you still use accounting cause It's always helpfull, and because It's one A in AAA! Sent from my HTC.

Re : What is the Class attribute for?

2010-05-24 Thread Alexandre Chapellon
I personnally use it for QoS definition. It works as expected but i can't garantee this is the regular use for this attribute. What's special with the class attribute is that if you send It in Access-Accept, It should be added in later accounting packets. This can be very usefull and if you

Re: openssl

2010-05-04 Thread Alexandre Chapellon
to enable eap module. sudo apt-get install libssl-dev and then recompile with --with-rlm-eap This is just a guess. Kornel - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Alexandre Chapellon alexandre.chapel...@mana.pf Mana SAS - List info

Re: Limit Bandwith

2010-03-18 Thread Alexandre Chapellon
Le jeudi 18 mars 2010 à 17:27 +0800, sugiarto tjahyono a écrit : Sorry if this topic already posted or on wrong forum How can we set speed if the user already over quota ie first day of month they get 1Mbps bandwith after spent 1Gig the speed will decrease to 512Kbps until end of month

Re: Determine number of client requests sent to the free radius server

2010-03-10 Thread Alexandre Chapellon
You can graph this using cacti: http://forums.cacti.net/viewtopic.php?t=29880 Or just query your freeradius server using radclient if status server is enabled, or use radmin (which is not always very stable, i would not recommend using it... at least with version 2.1.6) Le mercredi 10 mars 2010

Re: monitoring freeradius

2010-02-23 Thread Alexandre Chapellon
Le mardi 23 février 2010 à 13:39 -0500, Mark Jones a écrit : How does one go about monitoring freeradius in that to see if it is reaching process limits or max clients etc.. I have made a cacti template, it won't do any sentry upon max-client or process-limit as you asked for. But it may

Re: correctly set num_sql_sock in sql accoutnig

2009-09-14 Thread Alexandre Chapellon
Le lundi 14 septembre 2009 à 22:32 +0200, Alan DeKok a écrit : Alexandre Chapellon wrote: Is there a way to know how many sql sockets needs to be open at startup for a particular accounting db? How long do database writes take? How many writes can you do simultaneously

Re: Copy of accounting packets

2009-08-27 Thread Alexandre Chapellon
You have defined your 2 home server in a single pool Unfortunately, home_server_pool are only of type fail-over (packet sent to the second server *ONLY* if first fails) or load-balance (differents flavours) but not type allow for acct packet to be sent to both server. You must use detail-file and

Re: freeradius with oracle

2009-08-20 Thread Alexandre Chapellon
Of course it implies you have installed the oracle instantclient provided by oracle in /opt/oracle... If not point to where the oracle libs are depending on your unix flavour. As far as i remember the post you quoted in your mail was about ubuntu Linux radius server with no oracle instance

Re: MAX-Monthly-Traffic V2 Post

2009-08-20 Thread Alexandre Chapellon
Le jeudi 20 août 2009 à 01:07 +0100, Neville a écrit : Hi Alex, You are expecting an interim update to send session-timeout to your nas so it disconnect your user? If so, two things seems incorrect to me. 1- You're measuring traffic volume and want disconnection to set based on

Re: MAX-Monthly-Traffic V2 Post.

2009-08-19 Thread Alexandre Chapellon
You are expecting an interim update to send session-timeout to your nas so it disconnect your user? If so, two things seems incorrect to me. 1- You're measuring traffic volume and want disconnection to set based on time (session-timout)... a bit tricky isn't it? 2- I think the attribute

Re: MAX-Monthly-Traffic V2 Post

2009-08-19 Thread Alexandre Chapellon
Le jeudi 20 août 2009 à 01:07 +0100, Neville a écrit : Hi Alex, You are expecting an interim update to send session-timeout to your nas so it disconnect your user? If so, two things seems incorrect to me. 1- You're measuring traffic volume and want disconnection to set based on

redback nas

2009-08-19 Thread Alexandre Chapellon
Hello, This is not really an freeradius related question... sorry about that. Does anyone know about attributes supported by redback devices that would allow disconnection of sessions based on the amount of traffic transfered during the session and which could be set to higher than 4Gb? thanks

Re: Re: Restart radiusd after new user added

2009-08-03 Thread Alexandre Chapellon
/freeradius/sites-enabled/ is a short-cut to /etc/freeradius/sites-available/, and the file already has uid/gid and mode =rw, but they are all commented out. Should I un-comment them and then try it again? On Jul 31, 2009 5:37pm, Alexandre Chapellon alexandre.chapel...@mana.pf wrote: Le

freeradius upgrade

2009-08-03 Thread Alexandre Chapellon
Hello, I have to plan an upgrade of my freeradius setup. I am wondering if I shall upgrade now to 2.1.6 or wait until the next comming 2.1.7 release. What are the new features, improvements, or bug fixes that should come with 2.1.7? Is there Major leacks in 2.1.6? thanks - List

load-balance behavior

2009-07-31 Thread Alexandre Chapellon
Hello the list, Does the load-balance type in home_server_pool can handle when one the home_server of the pool is down? Does it loose tickets in such a situation or can i consider it as a fail-over pool too? thx - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Restart radiusd after new user added

2009-07-31 Thread Alexandre Chapellon
Le vendredi 31 juillet 2009 à 14:45 -0500, Blalock, Paul (NCC) a écrit : I am setting up freeradius, and am having issues with adding users and having to restart radiusd to pick up the new users. Is sql the only other way to go, or is there a way to point the users file to another directory?

Re: Restart radiusd after new user added

2009-07-31 Thread Alexandre Chapellon
Please reply to the list. Le vendredi 31 juillet 2009 à 16:17 -0500, Paul Blalock a écrit : I tried the radmin hup files, command, with no luck. The command was accepted, but it did nothing. What version of freeradius are you runing? If you have 2.1.1 or greater, just activate the

Re: DB Handles Rejects

2009-07-30 Thread Alexandre Chapellon
Le jeudi 30 juillet 2009 à 22:53 +0100, Dean Smith a écrit : During a recent network incident we had some very high churn in PPP clients. Our NASes (Multiple Cisco 7200 as VPDN LNS) didn’t appear to be able to authenticate as quickly as they needed to. In the Radius packet logs we see quite a

accounting manipulation

2009-03-11 Thread Alexandre Chapellon
I have a working freeradius2 setup, in which I proxy accounting tickets to many home_servers using details file writing and detail listeners. For one of this home_server (let's call it HS1) I want to rewrite the Acct-(In|Out)put-Octets and Acct-(|n|Out)put-Gigawords with a value* taken from

Re: Freeradius with Oracle

2009-02-20 Thread Alexandre Chapellon
What is AuthBlock? An PL/SQL function? A stored procedure? Whatever it is, it MUST return data presented as freeradius expect it (an array that mirror the users file syntax) Personally, I use a PL/SQL function. Called like this: authorize_check_query = SELECT * FROM tables (my_sql_func('param1,

Re: Simultaneous-Use for roaming wireless user

2009-02-13 Thread Alexandre Chapellon
Well if you know a way to check if the session is really up or no on your NAS i might not be hard to write a checkrad script to enable stale session deletion. Le 12.02.2009 18:33, ST Wong (ITSC) a écrit : Hi all, We enabled Simultaneous-Use checking with checking against accouting data

attribute filter prior to prxy

2009-01-29 Thread Alexandre Chapellon
Hello, I want to remove all attributes from packets to proxy except some of them i do say are allowed... I thought the following would do the job in the pre-proxy section, but when i check what the freeradius proxies (using tcpdump) i see the filter just filters nothing DEFAULT

Re: attribute filter prior to prxy

2009-01-29 Thread Alexandre Chapellon
Ugh! My fault i placed it in pre-acct instead of pre-proxy :p Le 29.01.2009 10:01, Alexandre Chapellon a écrit : Hello, I want to remove all attributes from packets to proxy except some of them i do say are allowed... I thought the following would do the job in the pre-proxy section

Re: How to load the freeswitch dictionary

2009-01-26 Thread Alexandre Chapellon
there is not two different dictionanries, the support juste told you that the dictionnary they gave is meant to be used with radclient standalone installations. If you have a whole freeradius server installled, most of the attributes contained in this file are already definec elsewhere. Just

deletestalesessions

2009-01-23 Thread Alexandre Chapellon
Hello I would like to have more informations about the deletestalesessions option of rlm_sql. - What does it do? - What's its behaviour? - How does it achieve what it does? regards - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: regular expression problem on 2.1.3

2009-01-23 Thread Alexandre Chapellon
when i use regex, i use it with unlang so it might differ from a users file but here is how i would write it for unlang: DEFAULT NAS-IP-Address =~ /192.168.1.1|10.0.1.1/ Le 23.01.2009 14:18, Tim Lightfoot a écrit : Thanks for the suggestion - this also gives the same result: [files]

Re: regular expression problem on 2.1.3

2009-01-23 Thread Alexandre Chapellon
processing the expressions here. From: freeradius-users-bounces+tim.lightfoot=sota.co...@lists.freeradius.org [mailto:freeradius-users-bounces+tim.lightfoot=sota.co...@lists.freeradius.org] On Behalf Of Alexandre Chapellon Sent: 24 January 2009 00:30

Re: Best Config

2009-01-23 Thread Alexandre Chapellon
I am at the moment experiencing problem of load with mysql as acct DB (query failure during database backup of massive radius ticket injection) for a setup of 15000 concurrent users so I would recommend its use! Le 23.01.2009 17:54, tech.subscripti...@shepherdhill.biz a écrit : Hi, From

case sensitivity

2009-01-21 Thread Alexandre Chapellon
HEllo, Is there a way to make usernames stored n users file be case non-sensitive? regards. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Bandwidth limit

2009-01-14 Thread Alexandre Chapellon
Do you mean you when to apply QoS on the sessions or do you mean you want to limit the amount of data a user can xfer during a specified time? Le 13.01.2009 17:48, Gunza a écrit : Dear All, I have installed Mikrotik Router OS server for PPPoE and I have installed Ubuntu Server 8.10 with

Re: Is FreeRADIUS 2.1.1 capable of handling NAI decorations

2008-12-08 Thread Alexandre Chapellon
Change sql_user_name = %{User-Name} to sql_user_name = %{Stripped-User-Name} in dialup.conf Le 02.12.2008 06:37, Luca Adamo a écrit : Thank you for the quick reply. I've tried this solution but the results are not what I expected. In fact i defined the following /realm /module: realm

Re: Programatically provision users to server.

2008-12-04 Thread Alexandre Chapellon
http://wiki.freeradius.org/SQL_HOWTO http://wiki.freeradius.org/Rlm_sql_mysql Le 04.12.2008 09:03, Matthew Carriere a écrit : This is great thank you. I was trying to find something in the documentation about doing this. Could anyone point me in the direction of documentation that outlines

Re: Check on bytes used

2008-12-02 Thread Alexandre Chapellon
Le 02.12.2008 10:25, Marcel Grandemange a écrit : Its for Time. I want count on bytes used. and one other problem, its return value is Session-Timeout. It represents remaining time not remaining bytes. any clue which attribute will tell remaining bytes??? This attribute is NAS

Re: Class attribute

2008-11-28 Thread Alexandre Chapellon
Le 27.11.2008 21:41, Alan DeKok a écrit : Alexandre Chapellon wrote: I have noticed that the Class attribute as defined in rfc2865 is a string value, but looking at dictionary that comes with freeradius i saw that it's an octet value. FreeRADIUS was the first to mark some

math operation

2008-11-28 Thread Alexandre Chapellon
Is it possible to do math operation upon attribute value and have a result that is greater than a 32bit number? (I would like to send this result in an ttribute, to proxy it to a home server) - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

broken home server communication

2008-11-28 Thread Alexandre Chapellon
Hy, I have a weird problem I am proxying accounting to a home server which is an AIX with kind a fault tolerant setup (HACMP). In some situations (HACMP in degraded mode) , this home server responds to my proxied queries with random source IP address. So freeradius doesn't realise the quey has

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread Alexandre Chapellon
Le 27.11.2008 07:17, Douglas Macedo a écrit : Hey TNT, On Thu, Nov 27, 2008 at 2:54 PM, [EMAIL PROTECTED] mailto:[EMAIL PROTECTED] wrote: i force in WIndows Client to use only mschap2, but the problem continue: - Module: Instantiated radutmp (radutmp)

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread Alexandre Chapellon
-Type EAP 5 # MS-Acct-EAP-Type Values VALUE MS-Acct-EAP-Type MD5 4 VALUE MS-Acct-EAP-Type OTP 5 VALUE MS-Acct-EAP-Type Generic-Token-Card 6 VALUE MS-Acct-EAP-Type TLS 13 Thanks in advanced! Douglas On Thu, Nov 27, 2008 at 4:06 PM, Alexandre Chapellon [EMAIL PROTECTED] mailto:[EMAIL

Class attribute

2008-11-27 Thread Alexandre Chapellon
Hello, This message is more precisely direted to Alan. I have noticed that the Class attribute as defined in rfc2865 is a string value, but looking at dictionary that comes with freeradius i saw that it's an octet value. As far as I know none of the rfc updating 2865 redefine the class attribute.

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Alexandre Chapellon
trying forcing windows pptp client to use mschapv2 Le 26.11.2008 09:15, Douglas Macedo a écrit : Sorry Alan, but the webpage tells that its don't work. Its impossible? Correct? So, how I can fix that the other way? My pptp-options: == epiderme:/etc/ppp# cat pptpd-options name pptpd

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Alexandre Chapellon
the user auth: Failed to validate the user. Login incorrect: [nobody] (from client access-vpn port 0) Delaying request 1 for 1 seconds Finished request 1 Going to the next request -- Any idea? Thanks in advanced, Douglas On Wed, Nov 26, 2008 at 5:27 PM, Alexandre Chapellon [EMAIL PROTECTED

Re: Could not link driver rlm_sql_oracle: libclntsh.so.10.1

2008-11-24 Thread Alexandre Chapellon
Le 23.11.2008 17:39, Ilya a écrit : hello, i've got Linux 2.6.9-22 and freeRADIUS server v.2.1.1. after installing and configured FreeRADIUS i try to to start the daemon with -X parametr and get the error: Could not link driver rlm_sql_oracle: libclntsh.so.10.1: cannot open shared

Re: Fail to disable the Simultanous-use, somebody help me.

2008-11-20 Thread Alexandre Chapellon
I don't your problem have anything to deal with simultaneous-use checking... Indeed, when enabled Sim-Use would REJECT NEW users trying to connect to if the login used has reached the limit What you say is that new user (same login) disconnect existing session... This sounds more like

Re: Problem in setting up radius database in sql

2008-11-20 Thread Alexandre Chapellon
your freeradius seems to be compiled/installed without the mysql extensions rlm_sql_mysql - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Fwd: Re:Re: Fail to disable the Simultanous-use, somebody help me.

2008-11-20 Thread Alexandre Chapellon
It seems like your NAS sends accounting Stop for the previous session (nas-port is different) after receiving the response of of the accounting Start (for the new session)... this would show your NAS ask the radius to notice a disconnection hit has decided... I don't know how netscreen works,

oracle stored procédure

2008-11-20 Thread Alexandre Chapellon
I'm still trying to setup freeradius authentication with oracle stored procedure. I have a procedure that return data as i expected it to be returned in an sqlplus client: SQL SELECT hss_radcheck_func('[EMAIL PROTECTED]','bas3_SE') FROM DUAL; HSS_RADCHECK_FUNC('K CURSOR

Re: How to filter accountings based on the value of a VSA attribute

2008-11-19 Thread Alexandre Chapellon
Having more details about your conf would help but anyway unlang can do this (man unlang). if (attribute == value) { update control { Proxy-To-Realm := realm } } P.S: this cannot be done in proxy.conf file. Le 19.11.2008 08:55, cris miyata a écrit : Dear FreeRADIUS users, We

stored procedures

2008-11-17 Thread Alexandre Chapellon
Hello, I need to authenticate dial-in users against an sql DB, and to use a stored procedure to do so (there is a lot of condition to treat before returning authentications data).* What is the format the stored procedure can send data to freeradius? Is there any place where it is documented? thx

oracle

2008-11-17 Thread Alexandre Chapellon
Does anyone already used oracle stored proc as auth queries? Is it known to worl or known not to work? regards - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: oracle

2008-11-17 Thread Alexandre Chapellon
] [mailto:[EMAIL PROTECTED] org] On Behalf Of Alexandre Chapellon Sent: Monday, November 17, 2008 7:33 PM To: FreeRadius users mailing list Subject: oracle Does anyone already used oracle stored proc as auth queries? Is it known to worl or known not to work? regards - List info/subscribe

Re: Compiling git-2.1.1 on debian

2008-11-06 Thread Alexandre Chapellon
-to-freeradius.dpatch file, on line 38, the following line: -pidfile = ${run_dir}/radiusd.pid Must be changed to -pidfile = ${run_dir}/${name}.pid Doing that, the standard 2.1.1 package compiles fine. Thank you for your help, Roberto Alexandre Chapellon wrote: try compiling using

Re: sqlippool symbol error

2008-11-05 Thread Alexandre Chapellon
.so found in none of the libraries. Do i have to worry about it, expect unpredistable crashes? Does anyone else have thoose warning? Someone succeded in using sqlippool without rlm_sql link? Le 04.11.2008 11:41, Alexandre Chapellon a écrit : I have compiled and installed FR2.1.1 on ubuntu 8.04

Re: Compiling git-2.1.1 on debian

2008-11-05 Thread Alexandre Chapellon
try compiling using bundled libtools remove --with-system-libtool from debian/rules then relaunch dpkg-builpackages Le 05.11.2008 09:53, rgreiner a écrit : Hi, I'm trying to compile 2.1.1 on debian using the git version (the standard package stops at the beginning due to the problem with the

variable expansion of check item in users file

2008-11-05 Thread Alexandre Chapellon
Hello, I have several accounts stored in users files for which i have set set the Pool-Name controll attribute based on the Huntgoup-Name. So i tried something like this: account1 Cleartext-Password := passwd1, Pool-Name := %{Huntgroup-Name}_suffix Unfortunatly the expansion of the variable

Re: variable expansion of check item in users file

2008-11-05 Thread Alexandre Chapellon
Le 05.11.2008 13:40, [EMAIL PROTECTED] a écrit : I have several accounts stored in users files for which i have set set the Pool-Name controll attribute based on the Huntgoup-Name. So i tried something like this: account1 Cleartext-Password := passwd1, Pool-Name :=

Re: variable expansion of check item in users file

2008-11-05 Thread Alexandre Chapellon
Le 05.11.2008 14:32, [EMAIL PROTECTED] a écrit : Unlang: update control { Pool-Name := whatever } I have to do it only for some of my users... and nothing really differs them from the others... if (User-Name == whatever) { update control { ... Which would

Re: variable expansion of check item in users file

2008-11-05 Thread Alexandre Chapellon
Le 05.11.2008 14:55, [EMAIL PROTECTED] a écrit : Which would make me create more than 100 if (or a case) directives! This would work but *IS* more than painfull, and almost impossible to maintain! More painfull than writing the same thing 100 times in users file??? Why would

  1   2   >