Hi Alan...
Thanx for the info.
Basically, you can't do these checks until after the RADIUS authentication has succeeded, which means that you can't use the checks to change the RADIUS response.
Is there any post-authentication mechanism I could use in FreeRadius to revoke the authentication....i.e. allow the user to authenticate long enough to make the checks over IP via an Exec-Program-Wait and if they fail the checks, freeradius 'tells' (?) the access point to disconnect the client?
Thanx in advance.
Chris.
_________________________________________________________________
Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail
- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

