Hi, > 1. If the server sends access-accept, then proxy the message back to the > client (like it is being done at the moment) > 2. If the server sends access-reject, then do not proxy, just drop the > packet.
eerr, why? that is horribly broken and will cause lots of issues with clients - making them believe, for example , that the RADIUS server (proxy) is dead and stop sending ANY packets to the RADIUS server (proxy) alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

