Hi,
I'm running a newly configured freeradius-0.4 here. The only client
is a cisco 4000 with IOS 12.1. On every PPP logout I get this message
Error: Accounting: logout: login entry for NAS CVK_NAS port 20003 not found
but before that there is also the corresponding login entry
Login OK: [bar] (from nas CVK_FW port 20003 cli 5219719188)

Both requests are going through a firewall application proxy. So the IP
Source
Address of the request packets is modified to the FW internal interface
address.
The FW Proxy is no application specific radius proxy.

As for now, I suspect that the following happens:
The client address for the login request is taken from the request packet
itself.
Obviously this is the original Router IP Address. 
The client address for the accounting request is the IP source address. This
is
the FW interface address.
I've got Evidence for this behaviour from removing either IP Address from
the
naslist and clients.conf files. Therefore one or the other request was
denied.

My guess is, that the problem lies here. Is there a possibility to tell the
radius
server that one client can have more than one IP-Address? May be that's the
solution.

Can anyone help?

Best regards,
--
Thomas Bartschies 

Cornelsen Verlagskontor GmbH & Co. KG
Kammerratsheide 66
33609 Bielefeld

Telefon:        0521 9719310
Telefax:                0521 971993310
E-Mail:         mailto:[EMAIL PROTECTED]
Internet:       http://www.cvk.de



- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to