Thanks Umar -
I have copied this to Mike so he can add an entry to the FAQ.
In any case, I can't see any reason for not doing what they suggest.
Add a username to your database of ACC_DEFAULT with the password being the
shared secret that is in use between the ACC and Radiator. The reply
attributes can be something innocuous like a default Session-Timeout if you
don't want to send a real set of defaults.
regards
Hugh
NB - I'm travelling for a couple of weeks ...
--
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald,
Platypus, Freeside, Interbiller, TACACS+, PAM, external, etc, etc.
Available on Unix, Linux, FreeBSD, Windows 95/98/2000, NT, MacOS X.
----- Original Message -----
From: "Umar Goldeli" <[EMAIL PROTECTED]>
To: "Hugh Irvine" <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>
Sent: Friday, March 31, 2000 9:31 AM
Subject: Re: (RADIATOR) "New" radius changes?
> The page is up again (although it's password protected - for XSI's
> customers) here's a snippet:
>
> Radius Update for 11.5.3.x code
>
> Please read this if you are having any difficulties with your radius since
> going to 11.5.3.x code stream. There has been some changes in the RFC for
> radius, and the new code incorporates these
> changes. If your radius server hasn't been updated recently then it will
> not support these changes, but there is a simple workaround located here.
>
>
>
> and the link leads to:
>
> Radius Update from 11.5.x
> *As of Tigris Software Version 11.5.x there are some RADIUS Modifications
> that have been made to allow the Tigris to support new RADIUS standards.
> This will cause the Tigris not to be
> able to see some RADIUS Servers because it cannot file particular RADIUS
> Attributes that it needs to be able to perform RADIUS Authentication. the
> Tell Tale sign of this error in 11.5.x code
> is This error Message in the TRAP via telnet or Console.
>
> *** TRAP from local agent at 31-Aug-1999 11:05:09 uptime 0 Days, 00:00:03
> *** RADIUS (Auth-1): Access denied for user "ACC_DEFAULT"
>
> OR / AND
>
> *** TRAP from local agent at 31-Aug-1999 10:15:02 uptime 0 Days, 00:00:00
> *** RADIUS (Auth-1): Operational state changed from DISABLED to UNKNOWN
>
> The Work Around :
> *Add a Radius user entry by the name of "ACC_DEFAULT". The password for
> this user account is the same as the shared secret for the Radius
> Authentication server entry. Note that the
> authentication is sent using PAP. Set the return list attributes to those
> values which will be used as default by your user base.
>
> ACC_DEFAULT Password = "secret"
> Framed-Protocol = PPP,
> Service-Type = Framed-User,
> Framed-IP-Address = 255.255.255.254,
> Framed-Compression = Van-Jacobson-TCP-IP
>
> *This should allow RADIUS to work perfectly with Tigris software 11.5.x
> and beyond..
>
>
>
>
> file://umar.
>
>
> On Mon, 27 Mar 2000, Hugh Irvine wrote:
>
> > Hello Umar -
> >
> > Can you send us any more information on this?
> >
> > ie. what has changed and why and some reference to the documentation?
> >
> > thanks
> >
> > Hugh
> >
> > NB - I'm travelling for a couple of weeks ...
> >
> > --
> > Radiator: the most portable, flexible and configurable RADIUS server
> > anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald,
> > Platypus, Freeside, Interbiller, TACACS+, PAM, external, etc, etc.
> > Available on Unix, Linux, FreeBSD, Windows 95/98/2000, NT, MacOS X.
> >
> >
> > ----- Original Message -----
> > From: "Umar Goldeli" <[EMAIL PROTECTED]>
> > To: <[EMAIL PROTECTED]>
> > Sent: Monday, March 27, 2000 1:48 PM
> > Subject: (RADIATOR) "New" radius changes?
> >
> >
> > > Greetings,
> > >
> > > After having setup a new ACC Tigris box and pointed it to Radiator -
it
> > > failed to authenticate... so I looked up an FAQ and lo' and behold -
it
> > > said that the radius code on the Tigris has been changed in accord
with
> > > some changes to the radius specs..
> > >
> > > The workaround was to add a user to the SUBSCRIBERS table with
username:
> > > DEFAULT and the password as the shared secret etc.. and the
> > > replyattributes as the ones to be given to all dialup users etc...
> > >
> > > This doesn't exactly appeal to me as you may imagine.. as I believe
that
> > > this may be contributing to some other problems I'm having (i.e.
> > > Framed-IP-Address attributes aren't being honoured and only pool IP's
are
> > > being assigned)...
> > >
> > > Is there a patch to radiator that will "update it" to comply with
these
> > > new mysterious radius protocol changes? (I'm running 2.14 atm)..
> > >
> > > Thanks in advance..
> > >
> > > cheers,
> > > Umar.
> > >
> > >
> > >
> > > ===
> > > Archive at http://www.starport.net/~radiator/
> > > Announcements on [EMAIL PROTECTED]
> > > To unsubscribe, email '[EMAIL PROTECTED]' with
> > > 'unsubscribe radiator' in the body of the message.
> > >
> >
> >
> > ===
> > Archive at http://www.starport.net/~radiator/
> > Announcements on [EMAIL PROTECTED]
> > To unsubscribe, email '[EMAIL PROTECTED]' with
> > 'unsubscribe radiator' in the body of the message.
> >
>
>
>
>
===
Archive at http://www.starport.net/~radiator/
Announcements on [EMAIL PROTECTED]
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.