Thanks for the reply Kostas!

Kostas Kalevras wrote:
On Mon, 21 Feb 2005, Mitchell, Michael J wrote:


Latest cvs versions of rlm_preprocess do huntgroup processing.

Great! I'll take a look at the latest rlm_preprocess!

I am not sure you need to run rlm_ldap again in pre-accounting. You could probably add a Class attribute in the home server access-accept (if you get an access-accept that probably means the ldap server already contains the username) and also use that in acct_users when deciding on whether to proxy the request.



Yep, I've considered using the Class attribute, which I will do. However, we do not have control over some of the NAS's and proxies in between them and our radius servers, and I've been told that I should not rely on them being "well behaved". Maybe the 80% solution is good enough though to reduce the number of lookups on ldap for pre-accounting to an acceptable level. Who knows, it may even turn out to be 100%..

If anyone has any other thoughts, please keep them coming!

regards,
Mike


- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to