Re: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread alan buxey
Hi, I know this subject have been brought up but I'm kind of stuck and I hope I can get a little help. I am trying to assign vlans from freeradius to a cisco 3550 switch but its not working. I keep getting the following in the debug in the switch: 3w6d: RADIUS: 

Re: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread Wassim Zaarour
Hi Alan and thanks for your reply, I changed it as you suggested and I still got the same behavior: Users wassim Cleartext-Password := wassim Tunnel-Medium-Type = IEEE-802, Tunnel-Type = VLAN, Tunnel-Private-Group-Id = 100 Radiusd -X: # Executing section post-auth from

Re: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread Phil Mayers
On 04/25/2012 08:52 AM, Wassim Zaarour wrote: Hi Alan and thanks for your reply, I changed it as you suggested and I still got the same behavior: You're sending the right replies; the problem is with the NAS. Suggest you consult the Cisco docs. The 3550 is an older switch; are you sure it

Re: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread Wassim Zaarour
Hi Phil, Look at this http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg40162. html The user says that it worked, I tried the attributes he used and still got the same error. On 4/25/12 11:10 AM, Phil Mayers p.may...@imperial.ac.uk wrote: On 04/25/2012 08:52 AM,

RE: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread David Peterson
@lists.freeradius.org [mailto:freeradius-users-bounces+davidp=wirelessconnections.net@lists.freera dius.org] On Behalf Of Wassim Zaarour Sent: Wednesday, April 25, 2012 1:56 AM To: FreeRadius users mailing list Subject: Assign VLAN from freeradius to Cisco 3550 switch. Hi all, I know this subject have been

Re: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread Phil Mayers
On 25/04/12 09:28, Wassim Zaarour wrote: Hi Phil, Look at this http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg40162. html The user says that it worked, I tried the attributes he used and still got the same error. Then logically, the problem is at your end. Check the

Re: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread Wassim Zaarour
: Wednesday, April 25, 2012 1:50 PM To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Subject: RE: Assign VLAN from freeradius to Cisco 3550 switch. I am seeing EAP in the messages. Have you enabled EAP in your inner-tunnel or at all in your config? Either way this seems pretty

RE: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread Brian Julin
Wassim Zaarour wrote: Look at this http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg40162.html The user says that it worked, I tried the attributes he used and still got the same error. I don't even know how this was ever working for that user. On my wired switch

Re: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread Wassim Zaarour
Hi Brian, Thanks for your reply, where do I exactly need to put this configuration? In the users file? Do you have any experience with the 2960 switches? Wassim On 4/25/12 4:07 PM, Brian Julin bju...@clarku.edu wrote: Wassim Zaarour wrote: Look at this

Re: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread alan buxey
Hi, Thanks for your reply, where do I exactly need to put this configuration? In the users file? I can tell you right now that you dont need that hack to assign VLANs on cisco switches (well, not if you are running reasonably up to date firmware on the cisco devices anyway - ie something less

RE: Assign VLAN from freeradius to Cisco 3550 switch.

2012-04-25 Thread Brian Julin
Alan Buxley wrote I can tell you right now that you dont need that hack to assign VLANs on cisco switches (well, not if you are running reasonably up to date firmware on the cisco devices anyway - ie something less than 2 years old) The latest public firmware for the 3550 is 3+ years old,

Re: vlan and freeradius

2010-03-04 Thread omega bk
hello, still with the same issue about vlan assignment. so to sum up In my users file: doctorCleartext-Password := mypass cisco-avpair= tunnel-type(#64)=VLAN(13), cisco-avpair= tunnel-medium-type(#65) = 802 media(6),

Re: vlan and freeradius

2010-03-04 Thread omega bk
means vlan is not communicated between the freeradius and switch, but we don't know why 2010/3/4 omega bk omeg...@gmail.com hello, still with the same issue about vlan assignment. so to sum up In my users file: doctorCleartext-Password := mypass

Re: vlan and freeradius

2010-03-04 Thread omega bk
authentication was successful. [peap] SUCCESS [peap] Saving tunneled attributes for later means freeradius sent correctly VLAN attributes, but switch doesn't received them. Any one can help me? 2010/3/4 omega bk omeg...@gmail.com means vlan is not communicated between the freeradius and switch

Re: vlan and freeradius

2010-03-04 Thread omega bk
this is my show logging on my switch, means that the switch doesn't receive a radius vlan attribute: Log Buffer (4096 bytes): Recv-Key [17] 52 * 02:13:40: RADIUS: Vendor, Microsoft [26] 58 02:13:40: RADIUS: MS-MPPE-Send-Key [16] 52 * 02:13:40: RADIUS: EAP-Message [79] 6

Re: vlan and freeradius

2010-03-04 Thread omega bk
ok, it works now. it was Tunnel-Medium-type = IEEE-802 instead of 802 only. Now i can assign the sucessfull authenticated VLAN. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

vlan and freeradius

2010-03-03 Thread omega bk
Hello, so i would like to redirect my winxp authenticated to VLAN1 and if not authenticated , this client must be in vlan2 i got a switch cisco so how to handla this with freeradius? thank u - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: vlan and freeradius

2010-03-03 Thread Jens Link
omega bk omeg...@gmail.com writes: Hi, so i would like to redirect my winxp authenticated to VLAN1 and if not authenticated , this client must be in vlan2 i got a switch cisco so how to handla this with freeradius? Depends on how you do the authentication: Using certificates (either

Re: vlan and freeradius

2010-03-03 Thread Michael Schwartzkopff
Am Mittwoch, 3. März 2010 15:34:56 schrieb Jens Link: omega bk omeg...@gmail.com writes: Hi, so i would like to redirect my winxp authenticated to VLAN1 and if not authenticated , this client must be in vlan2 i got a switch cisco so how to handla this with freeradius? Depends on

Re: vlan and freeradius

2010-03-03 Thread omega bk
in fact, i got my client wired with winxp and authentication works well in 802.1x this client is connected directly in my switch trough vlan3 i would like dynamically assign a successfull authentication trough vlan2 and faillure authentication to vlan1 autthentication is based in users file

Re: vlan and freeradius

2010-03-03 Thread Alan Buxey
Hi, Hello, so i would like to redirect my winxp authenticated to VLAN1 and if not authenticated , this client must be in vlan2 i got a switch cisco so how to handla this with freeradius? read the cisco docs on dealing with 802.1X. you should never use VLAN1 for users - most would

Re: vlan and freeradius

2010-03-03 Thread Michael Schwartzkopff
Am Mittwoch, 3. März 2010 15:45:56 schrieb omega bk: in fact, i got my client wired with winxp and authentication works well in 802.1x this client is connected directly in my switch trough vlan3 i would like dynamically assign a successfull authentication trough vlan2 and faillure

Re: vlan and freeradius

2010-03-03 Thread omega bk
2) set the switch to use RADIUS return attributes for VLAN (and for session time etc) and set the fail VLAN and guest VLAN to Y = that's really what i want to do so in my users file myuser Cleartext-Password := user Tunnel-type = VLAN,

Re: vlan and freeradius

2010-03-03 Thread Phil Mayers
On 03/03/2010 03:01 PM, omega bk wrote: 2) set the switch to use RADIUS return attributes for VLAN (and for session time etc) and set the fail VLAN and guest VLAN to Y = that's really what i want to do so in my users file myuser Cleartext-Password := user Tunnel-type

Re: vlan and freeradius

2010-03-03 Thread Matt Hite
On Wed, Mar 3, 2010 at 10:44 AM, Phil Mayers p.may...@imperial.ac.uk wrote: but how to set the fail VLAN and guest VLAN to Y ??? Setting the Fail and Guest VLAN by radius doesn't make any sense. The Fail vlan is what to use when the radius server is unavailable. The Guest vlan is what to do

Re: vlan and freeradius

2010-03-03 Thread Alan DeKok
Jens Link wrote: @Alan: I would document VMPS in some more detail in the wiki if my access would be working. ;-) It seems to be fine now. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Alan DeKok
Joel MBA OYONE wrote: So if SSID friend is assigned to VLAN 100, the end-user will associate with that SSID, right?? No. VLAN assignment is after SSID association, and after 802.1x authentication. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Alan DeKok. wrote: No. VLAN assignment is after SSID association, and after 802.1x authentication. OK, is it possible to associate in SSID_1 and be assigned to a different VLAN than the we are associated in ? (exemple, when i am associated to SSID_1, which belongs to VLAN100, RADIUS

Re: Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Alan DeKok
Joel MBA OYONE wrote: No. VLAN assignment is after SSID association, and after 802.1x authentication. OK, is it possible to associate in SSID_1 and be assigned to a different VLAN than the we are associated in ? That doesn't make sense. SSID's aren't tied to VLANs, unless you configure

Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Alan, I possess a device from D-Link (DWS-3024). it is a wireless switch controler, and the documentation says that: - One SSID has to be affect to one VLAN on the profile. - An Access point could be configured with up to 8 ifferent SSIDs and it is possible to affect each SSID on its own

Re: Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joe Vieira
HI Joel, I think the issue here is that the D-Link AP's you have are rather limited. Radius can not ever assign an SSID because that step occurs before the user authenticated. Wireless starts with an association from the user to the AP's SSID from there the AP decides what needs to

Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Thank you Joe for your answer! We all agree that assocation is made before authentication process, in order to RADIUS to be able to do its stuffs. but the fact is that it doesn't work, and i was wondering what would be the result if i set: Tunnel-Private-Group-ID = 100 (when the SSID were i am

Re: Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Alan DeKok
Joel MBA OYONE wrote: We all agree that assocation is made before authentication process, in order to RADIUS to be able to do its stuffs. but the fact is that it doesn't work, Then your NAS is broken. Buy a real NAS that supports VLAN assignment. and i was wondering what would be the

Re : Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
, 17h37mn 46s Objet : Re: Re : Re : Dynamic VLAN and FreeRadius Joel MBA OYONE wrote: We all agree that assocation is made before authentication process, in order to RADIUS to be able to do its stuffs. but the fact is that it doesn't work, Then your NAS is broken. Buy a real NAS that supports VLAN

Re : Re : Re : Dynamic VLAN and FreeRadius

2008-05-22 Thread Joel MBA OYONE
Um... i think i just sent an empty response, sorry about that and thank you for this clear explanation. i just will change my NAS! (but i will call d-link before ). see ya! Joel MBA OYONE wrote: We all agree that assocation is made before authentication process, in order to RADIUS to be

Re: Dynamic VLAN and FreeRadius

2008-05-21 Thread A . L . M . Buxey
Hi, I am trying to get the RADIUS server to not only authenticating the supplicant, but providing the NAS with a VLAN ID. I have tried certain resources and haven't been able to receive the VLAN ID. Can any provide any help in this area? depends on your NAR - you need to send back the

Dynamic VLAN and FreeRadius

2008-05-20 Thread William E. Russell
All, I am trying to get the RADIUS server to not only authenticating the supplicant, but providing the NAS with a VLAN ID. I have tried certain resources and haven't been able to receive the VLAN ID. Can any provide any help in this area? Thanks William E. W. Russell Member of Technical Staff

Re: Dynamic VLAN and FreeRadius

2008-05-20 Thread Michael Schwartzkopff
William E. Russell schrieb: All, I am trying to get the RADIUS server to not only authenticating the supplicant, but providing the NAS with a VLAN ID. I have tried certain resources and haven't been able to receive the VLAN ID. Can any provide any help in this area? Thanks William

Re: Reading VLAN from FreeRadius and sending it to Cisco AP

2005-01-28 Thread Levente Janovszki
On Thu, 27 Jan 2005, Dean Michaels wrote: To support radius assigned vlans, you need to supply the AP with Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID replies. For wireless networks, use these values in the radius profiles. Tunnel-Medium-Type = 802 Tunnel-Type = VLAN

Reading VLAN from FreeRadius and sending it to Cisco AP

2005-01-27 Thread Alejandro Martínez Marcos
Hello, Iam trying to configure My Cisco 1100 AP to use differentSSID's and VLAN's. There is a default SSID and the definite one must be given from freeradius as a result of the authentication process. As authentication is done with LDAP, I have modified ldap.attrmap to read the value,

RE: Reading VLAN from FreeRadius and sending it to Cisco AP

2005-01-27 Thread Alejandro Martínez Marcos
Alejandro -Mensaje original-De: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]En nombre de Alejandro Martínez MarcosEnviado el: jueves, 27 de enero de 2005 12:29Para: Freeradius-UsersAsunto: Reading VLAN from FreeRadius and sending it to Cisco AP Hello, Iam trying to co

Re: Reading VLAN from FreeRadius and sending it to Cisco AP

2005-01-27 Thread Dean Michaels
To support radius assigned vlans, you need to supply the AP with Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID replies. For wireless networks, use these values in the radius profiles. Tunnel-Medium-Type = 802 Tunnel-Type = VLAN Tunnel-Private-Group-ID = vlan-id - List