Heikki Vatiainen wrote:

> My suggestion is this:
>
> <Handler TunnelledByTTLS=1, ExistsInRequest=EAP-Message>
>   # Send EAP to Windows
> </Handler>
>
> <Handler TunnelledByTTLS=1>
>   # Handle non-EAP here
> </Handler>

Thanks. That pointed me to the right direction.

It appears, that in our case the MSCHAPv2 part didn't have any EAP
headers. So, instead I used MS-CHAP-Challenge=/.+/. That worked.

For some reason, I haven't managed to get TTLS+EAP-MSHCAPv2 working so
far . I've yet to debug this further. Luckily, very small part (if any)
of our users use that combination

Cheers,

Matti
_______________________________________________
radiator mailing list
[email protected]
https://lists.open.com.au/mailman/listinfo/radiator

Reply via email to