yes, and I can confirm that dynamic vlaning works like a charm ! Thank you
OpenWrt ! :D

On Thu, Dec 1, 2011 at 12:03 PM, Helmut Schaa
<[email protected]>wrote:

> On Thu, Dec 1, 2011 at 3:57 AM, Ashkanull <[email protected]> wrote:
> > freeradius -X output:
> >>
> >>
> >> [peap] Got tunneled reply RADIUS code 2
>
> This is the tunneled reply that contains the VLAN attributes.
>
> >> Tunnel-Type:0 = VLAN
> >> Tunnel-Medium-Type:0 = IEEE-802
> >> Tunnel-Private-Group-Id:0 := "10"
> >> MS-MPPE-Encryption-Policy = 0x00000001
> >> MS-MPPE-Encryption-Types = 0x00000006
> >> MS-MPPE-Send-Key = 0xfa4b6928402162dc75ca3c5d3633a544
> >> MS-MPPE-Recv-Key = 0xdbaf38647954a65f8ff3bd457640aa33
> >> EAP-Message = 0x03450004
> >> Message-Authenticator = 0x00000000000000000000000000000000
> >> User-Name = "ashkan"
> >> [peap] Tunneled authentication was successful.
> >> [peap] SUCCESS
> >> ++[eap] returns handled
> >> Sending Access-Challenge of id 12 to 192.168.1.1 port 56950
> >> EAP-Message =
> >>
> 0x0146002b1900170301002005105d3df33ceaaa611dee9999d6ef7ebea0a52aa5a306448fc819ac6b864fb3
> >> Message-Authenticator = 0x00000000000000000000000000000000
> >> State = 0x84bc4e3b83fa57e7caa19a8619269cb1
> >> Finished request 268.
> >> Going to the next request
> >> Waking up in 0.5 seconds.
> >> rad_recv: Access-Request packet from host 192.168.1.1 port 56950, id=13,
> >> length=199
> >> User-Name = "ashkan"
> >> NAS-Port = 1
> >> Called-Station-Id = "F4-EC-38-FC-11-C8:OpenWrt"
> >> Calling-Station-Id = "78-E4-00-6C-2F-EB"
> >> Framed-MTU = 1400
> >> NAS-Port-Type = Wireless-802.11
> >> Connect-Info = "CONNECT 54Mbps 802.11g"
> >> EAP-Message =
> >>
> 0x0246002b190017030100204569670443a923b680717450c026917c7fe46b678375ddf9bb4ee0fc34a5a81b
> >> State = 0x84bc4e3b83fa57e7caa19a8619269cb1
> >> Message-Authenticator = 0x24ef8ecd74b9236f51ff3dd17e4dc93c
> >> # Executing section authorize from file
> >> /etc/freeradius/sites-enabled/default
> >> +- entering group authorize {...}
> >> ++[preprocess] returns ok
> >> ++[chap] returns noop
> >> ++[mschap] returns noop
> >> ++[digest] returns noop
> >> [suffix] No '@' in User-Name = "ashkan", looking up realm NULL
> >> [suffix] No such realm "NULL"
> >> ++[suffix] returns noop
> >> [eap] EAP packet type response id 70 length 43
> >> [eap] Continuing tunnel setup.
> >> ++[eap] returns ok
> >> Found Auth-Type = EAP
> >> # Executing group from file /etc/freeradius/sites-enabled/default
> >> +- entering group authenticate {...}
> >> [eap] Request found, released from the list
> >> [eap] EAP/peap
> >> [eap] processing type peap
> >> [peap] processing EAP-TLS
> >> [peap] eaptls_verify returned 7
> >> [peap] Done initial handshake
> >> [peap] eaptls_process returned 7
> >> [peap] EAPTLS_OK
> >> [peap] Session established.  Decoding tunneled attributes.
> >> [peap] Peap state send tlv success
> >> [peap] Received EAP-TLV response.
> >> [peap] Success
> >> [eap] Freeing handler
> >> ++[eap] returns ok
> >> # Executing section post-auth from file
> >> /etc/freeradius/sites-enabled/default
> >> +- entering group post-auth {...}
> >> ++[exec] returns noop
> >> Sending Access-Accept of id 13 to 192.168.1.1 port 56950
> >> MS-MPPE-Recv-Key =
> >> 0x6398fd9d9561ea47fa64bf536de9c865b49d11ae9e40ad97653424747c433085
> >> MS-MPPE-Send-Key =
> >> 0x1e5eefc46a70bb8704f9b8bf92eab52609af6e5c695a1e24fcedbe91f7ed2ec3
> >> EAP-Message = 0x03460004
> >> Message-Authenticator = 0x00000000000000000000000000000000
> >> User-Name = "ashkan"
> >> Finished request 269.
>
> And this is the access accept that doesn't contain the VLAN attributes
> but hostapd
> expects them to be here instead of in the tunneled reply.
>
> I don't know exactly anymore but freeradius has a eap config option
> "use_tunneled_reply" to force this behavior AFAIK ...
>
> HTH,
> Helmut
>
_______________________________________________
openwrt-devel mailing list
[email protected]
https://lists.openwrt.org/mailman/listinfo/openwrt-devel

Reply via email to