Simon Allard <[EMAIL PROTECTED]> wrote:
> Are there any plans to have a post authentication module section?

  That would be a good idea.

> What about a post-proxy (Just before you send the radius packet back to
> the NAS)?

  Yes, too.

  Ideally, you could control the flow of packet
authentication/authorization better than you can now, which is just a
simple loop through a list.

> By the looks of the code it would take a bit to implement, but I can see
> alot of potential with it.

  It shouldn't be too hard.

> For example with the ippool stuff. From what I understand a user we get
> assigned an IP before the radius server knows if their password is
> correct. This could be a big whole for IP leaks.

  That's why IP assignments on the server are problematic.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to