Re: Change of network adapters in radius server

2011-12-02 Thread Johan Meiring

On 2011/12/02 09:52 AM, Alan DeKok wrote:


   I've done tests with 50K requests/s for days straight.  My smartphone
could do 200 requests/s.



I must say, freeradius running on a smartphone is quite cool!

--


Johan Meiring
Cape PC Services CC
Tel: (021) 883-8271
Fax: (021) 886-7782


Before acting on this email or opening any attachments
you should read Cape PC Service's email disclaimer at:

http://www.pcservices.co.za/disclaimer.html

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Change of network adapters in radius server

2011-12-02 Thread Fajar A. Nugraha
On Fri, Dec 2, 2011 at 3:28 PM, Johan Meiring jmeir...@pcservices.co.za wrote:
 On 2011/12/02 09:52 AM, Alan DeKok wrote:


   I've done tests with 50K requests/s for days straight.  My smartphone
 could do 200 requests/s.


 I must say, freeradius running on a smartphone is quite cool!

Yes, it is :)

Although more practical users will opt for smart (i.e.
flashable-with-custom-linux-firmware) AP or *plugs instead, which
should be more affordable and better suited for embedded server tasks.

-- 
Fajar

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re[2]: configuration freeradius for no simultaneous use

2011-12-02 Thread tolik_shavlov...@mail.ru
Dear Alan,

i added  Simultaneous-Use = 1 to user profile in users file.


02 декабря 2011, 11:49 от Alan DeKok-2 [via FreeRadius] 
ml-node+s1045715n5040921...@n5.nabble.com:
 
  
  
 [hidden email] wrote:
 i need your help in configuration freeradius for no simultaneous use. 

  doc/Simultaneous-Use  See also the Wiki.

  Have you read that documentation and followed the instructions there?

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
 
 
 
--
 
 
If you reply to this email, your message will be added to the discussion below: 
http://freeradius.1045715.n5.nabble.com/configuration-freeradius-for-no-simultaneous-use-tp5040887p5040921.html
  
 To unsubscribe from configuration freeradius for no simultaneous use, click 
here.
 NAML 












   


--
View this message in context: 
http://freeradius.1045715.n5.nabble.com/configuration-freeradius-for-no-simultaneous-use-tp5040887p5041046.html
Sent from the FreeRadius - User mailing list archive at Nabble.com.-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Re[2]: configuration freeradius for no simultaneous use

2011-12-02 Thread Fajar A. Nugraha
On Fri, Dec 2, 2011 at 3:37 PM, tolik_shavlov...@mail.ru
tolik_shavlov...@mail.ru wrote:
 Dear Alan,

 i added  Simultaneous-Use = 1 to user profile in users file.

Did you read the doc? Or the reply I sent earlier?

It requires MORE than just that.

-- 
FAN

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re[4]: configuration freeradius for no simultaneous use

2011-12-02 Thread Толик Шавловский
Dear Alan,

i am not good acquainted with freeradius. So, from doc/Simultaneous-use i 
understood that freeradius requres script, which will connect to NAS and check 
user session. Am i right? 


02 декабря 2011, 12:43 от Fajar A. Nugraha l...@fajar.net:
 On Fri, Dec 2, 2011 at 3:37 PM, tolik_shavlov...@mail.ru
 tolik_shavlov...@mail.ru wrote:
  Dear Alan,
 
  i added  Simultaneous-Use = 1 to user profile in users file.
 
 Did you read the doc? Or the reply I sent earlier?
 
 It requires MORE than just that.
 
 --
 FAN
 
 -
 List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
 

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Getting NT_STATUS_WRONG_PASSWORD: Wrong Password (0xc000006a) when using ntlm_auth

2011-12-02 Thread Alan Buxey
Hi,

[ntlm_auth] expand: --username=%{mschap:User-Name} - --username=testuser
 
[ntlm_auth] expand: --password=%{User-Password} - --password=
 ^^

look. blank!

use the correct attribute in that --password argument 

alan
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Re[4]: configuration freeradius for no simultaneous use

2011-12-02 Thread Fajar A. Nugraha
2011/12/2 Толик Шавловский tolik_shavlov...@mail.ru:
 Dear Alan,

I assume you want help from anyone, not just Alan, so I'll add some
comments here.


 i am not good acquainted with freeradius. So, from doc/Simultaneous-use i 
 understood that freeradius requres script, which will connect to NAS and 
 check user session. Am i right?

That's one way to do that (and possibly the most accurate way). But
not the ONLY way.

You can make it work without the script, if you store accounting data
in sql. See (for example) raddb/sql/mysql/dialup.conf, look for
simul_count_query and simul_verify_query. But again, you need to
store accounting data for it to work.

-- 
Fajar



 02 декабря 2011, 12:43 от Fajar A. Nugraha l...@fajar.net:
 On Fri, Dec 2, 2011 at 3:37 PM, tolik_shavlov...@mail.ru
 tolik_shavlov...@mail.ru wrote:
  Dear Alan,
 
  i added  Simultaneous-Use = 1 to user profile in users file.

 Did you read the doc? Or the reply I sent earlier?

 It requires MORE than just that.


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re[6]: configuration freeradius for no simultaneous use

2011-12-02 Thread tolik_shavlov...@mail.ru
Fajar,

thanks. I understand how to search.


02 декабря 2011, 13:53 от Fajar A. Nugraha-2 [via FreeRadius] 
ml-node+s1045715n5041277...@n5.nabble.com:
 
  
  
 2011/12/2 Толик Шавловский [hidden email]:
 Dear Alan,

I assume you want help from anyone, not just Alan, so I'll add some
comments here.


 i am not good acquainted with freeradius. So, from doc/Simultaneous-use i 
 understood that freeradius requres script, which will connect to NAS and 
 check user session. Am i right?

That's one way to do that (and possibly the most accurate way). But
not the ONLY way.

You can make it work without the script, if you store accounting data
in sql. See (for example) raddb/sql/mysql/dialup.conf, look for
simul_count_query and simul_verify_query. But again, you need to
store accounting data for it to work.

-- 
Fajar



 02 декабря 2011, 12:43 от Fajar A. Nugraha [hidden email]:
 On Fri, Dec 2, 2011 at 3:37 PM, [hidden email]
 [hidden email] wrote:
  Dear Alan,
 
  i added  Simultaneous-Use = 1 to user profile in users file.

 Did you read the doc? Or the reply I sent earlier?

 It requires MORE than just that.














-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
 
 
 
--
 
 
If you reply to this email, your message will be added to the discussion below: 
http://freeradius.1045715.n5.nabble.com/configuration-freeradius-for-no-simultaneous-use-tp5040887p5041277.html
  
 To unsubscribe from configuration freeradius for no simultaneous use, click 
here.
 NAML 
























   


--
View this message in context: 
http://freeradius.1045715.n5.nabble.com/configuration-freeradius-for-no-simultaneous-use-tp5040887p5041322.html
Sent from the FreeRadius - User mailing list archive at Nabble.com.-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Minor change to the WIki

2011-12-02 Thread Alan DeKok
  We've removed Facebook authentication from the Wiki.  About 50% of the
edits to the wiki are nonsense.  People creating empty pages, or pages
with text of how do I do..., or pages with sxwdxx

  The hope is that removing facebook means that those kind of edits will
go away.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: AK Timeout

2011-12-02 Thread Johan Meiring

Hi,

Reading between the lines

I suspect the NAS notes means:
re-authentiaction timer (aka life time)

i.e.
re-autentication time (also known as life time)

I supect the Nas will re-authenticate ever hour.
Freeradius must not consider the session closed if the reauthentication does 
not arrive (for at least an hour).


As Freeradius will not consider the session closed (until it receives an 
accounting stop).  All should be fine.


Cheers,

Johan




On 2011/12/02 01:41 AM, David Peterson wrote:

Sigh, I wish I knew.  I was hoping it would make sense to someone on this list.

I will bug the NAS manufacturer for clarification.

David

-Original Message-
From: 
freeradius-users-bounces+davidp=wirelessconnections@lists.freeradius.org 
[mailto:freeradius-users-bounces+davidp=wirelessconnections@lists.freeradius.org]
 On Behalf Of Alan DeKok
Sent: Thursday, December 01, 2011 3:52 PM
To: FreeRadius users mailing list
Subject: Re: AK Timeout

David Peterson wrote:

In one of my NAS release notes it mentions:

“In the external AAA, the re-authentication timer (AK Life time)
should be set to a value higher than 1hour.”

Where would I set this?


   What's an AK life time ?

   Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html




--


Johan Meiring
Cape PC Services CC
Tel: (021) 883-8271
Fax: (021) 886-7782


Before acting on this email or opening any attachments
you should read Cape PC Service's email disclaimer at:

http://www.pcservices.co.za/disclaimer.html

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Daily accounting

2011-12-02 Thread hiteshvinzoda
Hi David,

Thanks for the post. I have a question about Updating sql.conf section, I
was unable to locate Replace accounting_update_query in sql.conf

FR version 2.1.7,

Please advise.

TIA

Hitesh

--
View this message in context: 
http://freeradius.1045715.n5.nabble.com/Daily-accounting-tp2754814p5041721.html
Sent from the FreeRadius - User mailing list archive at Nabble.com.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re[7]: configuration freeradius for no simultaneous use

2011-12-02 Thread Толик Шавловский
Hi again,

as i found naslist and naspass are old configuration files, now their 
functionality is used in clients.conf file.

So, i indicated nastype = cisco

will freeradius connect to nas in this case?


02 декабря 2011, 14:39 от tolik_shavlov...@mail.ru tolik_shavlov...@mail.ru:
 
  
  
Hi,

according to doc:
===
3. IMPLEMENTATION

  The server keeps a list of logged-in users in the /var/log/radutmp file.
  This is also called the session database. When you execute radwho,
  all that radwho really does is list the entries in this file in a pretty
  format. Only when someone tries to login who _already_ has an active
  session according to the radutmp file, the server executes the perl
  script /usr/local/sbin/checkrad (or /usr/sbin/checkrad, it checks for
  the presence of both and in that order). This script queries the terminal
  server to see if the user indeed already has an active session.

  The script uses SNMP for Livingston Portmasters and Ciscos, finger for
  Portslave, Computone and Ascend, and Net::Telnet for USR/3Com TC.

  Since the script has been witten in perl, it's easy to adjust for
  any type of terminal server. There are implementations in the script for
  checks using SNMP, finger, and telnet, so it should be easy to add
  your own check routine if your terminal server is not supported yet.

  You can find the script in the file src/checkrad.pl.

  You need to set the correct type in the file /etc/raddb/naslist so that
  checkrad KNOWS how it should interrogate the terminal server. At this
  time you can define the following types:
=

my  /usr/local/etc/raddb doesn't has naslist ans naspassword files.

If i configure them manually, so freeradius will connect to NAS (we use cisco) 
via snmp and check user session? So, in such way i don't need script?

thanks.


02 декабря 2011, 13:53 от Fajar A. Nugraha-2 [via FreeRadius] [hidden 
email]:
 
 
  
 2011/12/2 Толик Шавловский [hidden email]:
 Dear Alan,

I assume you want help from anyone, not just Alan, so I'll add some
comments here.


 i am not good acquainted with freeradius. So, from doc/Simultaneous-use i 
 understood that freeradius requres script, which will connect to NAS and 
 check user session. Am i right?

That's one way to do that (and possibly the most accurate way). But
not the ONLY way.

You can make it work without the script, if you store accounting data
in sql. See (for example) raddb/sql/mysql/dialup.conf, look for
simul_count_query and simul_verify_query. But again, you need to
store accounting data for it to work.

-- 
Fajar



 02 декабря 2011, 12:43 от Fajar A. Nugraha [hidden email]:
 On Fri, Dec 2, 2011 at 3:37 PM, [hidden email]
 [hidden email] wrote:
  Dear Alan,
 
  i added  Simultaneous-Use = 1 to user profile in users file.

 Did you read the doc? Or the reply I sent earlier?

 It requires MORE than just that.













-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
 
 
 
--
 
 
If you reply to this email, your message will be added to the discussion below: 
http://freeradius.1045715.n5.nabble.com/configuration-freeradius-for-no-simultaneous-use-tp5040887p5041277.html
  
 To unsubscribe from configuration freeradius for no simultaneous use, click 
here.
 NAML 
























   
 
--
View this message in context: Re[6]: configuration freeradius for no 
simultaneous use
Sent from the FreeRadius - User mailing list archive at Nabble.com.



 
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

   
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: configuration freeradius for no simultaneous use

2011-12-02 Thread Alan DeKok
Толик Шавловский wrote:
 So, i indicated nastype = cisco
 
 will freeradius connect to nas in this case?

  Only if the server receives accounting packets, AND a user session is
still open, AND that user tries to log in a second time from a different
location.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Radacct update at 3 hours

2011-12-02 Thread Hitesh Vinzoda
Hi,

We want to have accounting records created every 3 hours in case the users are 
not disconnected to create daily/weekly/monthly report.

I have gone through all the steps involved till modifying the accounting 
queries in sql.conf, i realized that my sql.conf is different from one listed 
at http://freeradius.org/radiusd/raddb/sql.conf

Now i stalled that whether to modify. I am using FR 2.1.10.

LNS is setup to send periodic updates every 3 hours and FR is updating the 
records but the acctstarttime is unchanged and acctstoptime is set to null 
but i can see that the acctinoctets and output octets are updated. We need to 
have separate record created in MYSQL radacct table once received update from 
the LNS.

Any help on this would be appreciated.

Thanks in advance
 
Hitesh Vinzoda
Network Administrator
+91-9924117399
www.vinzoda.in

There are 10 types of people in this world.
One who can understand binary and other's can't.-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Radacct update at 3 hours

2011-12-02 Thread Francois Gaudreault
Maybe my way of doing things is not the right one, but I had to solve 
the same issue a while ago.  What I did is I changed the simple update 
in sql.conf to a stored procedure call, and in my stored proc, I update 
the radacct entry, but I also insert another record into a log table.  
That way I can do my stats easily.


I am sure there is an easiest way of doing it.

On 11-12-02 10:22 AM, Hitesh Vinzoda wrote:

Hi,

We want to have accounting records created every 3 hours in case the 
users are not disconnected to create daily/weekly/monthly report.


I have gone through all the steps involved till modifying the 
accounting queries in sql.conf, i realized that my sql.conf is 
different from one listed at http://freeradius.org/radiusd/raddb/sql.conf


Now i stalled that whether to modify. I am using FR 2.1.10.

LNS is setup to send periodic updates every 3 hours and FR is updating 
the records but the acctstarttime is unchanged and acctstoptime is set 
to null but i can see that the acctinoctets and output octets are 
updated. We need to have separate record created in MYSQL radacct 
table once received update from the LNS.


Any help on this would be appreciated.

Thanks in advance
Hitesh Vinzoda
Network Administrator
+91-9924117399
www.vinzoda.in

There are 10 types of people in this world.
One who can understand binary and other's can't.



-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html



--
Francois Gaudreault, ing. jr
fgaudrea...@inverse.ca  ::  +1.514.447.4918 (x130) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (www.sogo.nu) and PacketFence 
(www.packetfence.org)

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Radacct update at 3 hours

2011-12-02 Thread Hitesh Vinzoda
Hi,

Thanks for your prompt response. Could you please let me know where to include 
in sql.conf file to call the procedures.

P.S. : we are using freeradius 2.1.10

Thanks
 
Hitesh Vinzoda
Network Administrator
+91-9924117399
www.vinzoda.in

There are 10 types of people in this world.
One who can understand binary and other's can't.






 From: Francois Gaudreault fgaudrea...@inverse.ca
To: freeradius-users@lists.freeradius.org 
Sent: Friday, 2 December 2011 9:32 PM
Subject: Re: Radacct update at 3 hours
 

Maybe my way of doing things is not the right one, but I had to solve the same 
issue a while ago.  What I did is I changed the simple update in sql.conf to a 
stored procedure call, and in my stored proc, I update the radacct entry, but I 
also insert another record into a log table.  That way I can do my stats 
easily.

I am sure there is an easiest way of doing it.

On 11-12-02 10:22 AM, Hitesh Vinzoda wrote: 
Hi,


We want to have accounting records created every 3 hours in case the users are 
not disconnected to create daily/weekly/monthly report.


I have gone through all the steps involved till modifying the accounting 
queries in sql.conf, i realized that my sql.conf is different from one listed 
at http://freeradius.org/radiusd/raddb/sql.conf


Now i stalled that whether to modify. I am using FR 2.1.10.


LNS is setup to send periodic updates every 3 hours and FR is updating the 
records but the acctstarttime is unchanged and acctstoptime is set to null 
but i can see that the acctinoctets and output octets are updated. We need to 
have separate record created in MYSQL radacct table once received update from 
the LNS.


Any help on this would be appreciated.


Thanks in advance
 
Hitesh Vinzoda
Network Administrator
+91-9924117399
www.vinzoda.in

There are 10 types of people in this world.
One who can understand binary and other's can't.




-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html 


-- 
Francois Gaudreault, ing. jr fgaudrea...@inverse.ca ::  +1.514.447.4918 (x130) 
:: www.inverse.ca Inverse inc. :: Leaders behind SOGo (www.sogo.nu) and 
PacketFence (www.packetfence.org) 
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Radacct update at 3 hours

2011-12-02 Thread Hitesh Vinzoda
My current sql.conf looks like below and it does not have accounting sections 
at all.

=

[root@br-radius01 raddb]# cat sql.conf
# -*- text -*-
##
## sql.conf -- SQL modules
##
##      $Id$

##
#
#  Configuration for the SQL module
#
#  The database schemas and queries are located in subdirectories:
#
#       sql/DB/schema.sql       Schema
#       sql/DB/dialup.conf      Basic dialup (including policy) queries
#       sql/DB/counter.conf     counter
#       sql/DB/ippool.conf      IP Pools in SQL
#       sql/DB/ippool.sql       schema for IP pools.
#
#  Where DB is mysql, mssql, oracle, or postgresql.
#

sql {
        #
        #  Set the database to one of:
        #
        #       mysql, mssql, oracle, postgresql
        #
        database = mysql

        #
        #  Which FreeRADIUS driver to use.
        #
        driver = rlm_sql_${database}

        # Connection info:
        server = localhost
        #port = 3306
        login = radius
        password = radpass

        # Database table configuration for everything except Oracle
        radius_db = radius
        # If you are using Oracle then use this instead
        # radius_db = 
(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=localhost)(PORT=1521))(CONNECT_DATA=(SID=your_sid)))

        # If you want both stop and start records logged to the
        # same SQL table, leave this as is.  If you want them in
        # different tables, put the start table in acct_table1
        # and stop table in acct_table2
        acct_table1 = radacct
        acct_table2 = radacct

        # Allow for storing data after authentication
        postauth_table = radpostauth

        authcheck_table = radcheck
        authreply_table = radreply

        groupcheck_table = radgroupcheck
        groupreply_table = radgroupreply

        # Table to keep group info
        usergroup_table = radusergroup

        # If set to 'yes' (default) we read the group tables
        # If set to 'no' the user MUST have Fall-Through = Yes in the radreply 
table
        # read_groups = yes

        # Remove stale session if checkrad does not see a double login
        deletestalesessions = yes

        # Print all SQL statements when in debug mode (-x)
        sqltrace = no
        sqltracefile = ${logdir}/sqltrace.sql

        # number of sql connections to make to server
        num_sql_socks = 5

        # number of seconds to dely retrying on a failed database
        # connection (per_socket)
        connect_failure_retry_delay = 60

        # lifetime of an SQL socket.  If you are having network issues
        # such as TCP sessions expiring, you may need to set the socket
        # lifetime.  If set to non-zero, any open connections will be
        # closed lifetime seconds after they were first opened.
        lifetime = 0

        # Maximum number of queries used by an SQL socket.  If you are
        # having issues with SQL sockets lasting too long, you can
        # limit the number of queries performed over one socket.  After
        # max_qeuries, the socket will be closed.  Use 0 for no limit.
        max_queries = 0

        # Set to 'yes' to read radius clients from the database ('nas' table)
        # Clients will ONLY be read on server startup.  For performance
        # and security reasons, finding clients via SQL queries CANNOT
        # be done live while the server is running.
        #
        #readclients = yes

        # Table to keep radius client info
        nas_table = nas

        # Read driver-specific configuration
        $INCLUDE sql/${database}/dialup.conf
}



Thanks
 
Hitesh Vinzoda
Network Administrator
+91-9924117399
www.vinzoda.in

There are 10 types of people in this world.
One who can understand binary and other's can't.






 From: Hitesh Vinzoda hiteshvinz...@yahoo.com
To: FreeRadius users mailing list freeradius-users@lists.freeradius.org 
Sent: Friday, 2 December 2011 9:57 PM
Subject: Re: Radacct update at 3 hours
 

Hi,

Thanks for your prompt response. Could you please let me know where to include 
in sql.conf file to call the procedures.

P.S. : we are using freeradius 2.1.10

Thanks
 
Hitesh Vinzoda
Network Administrator
+91-9924117399
www.vinzoda.in

There are 10 types of people
 in this world.
One who can understand binary and other's can't.






 From: Francois Gaudreault fgaudrea...@inverse.ca
To: freeradius-users@lists.freeradius.org 
Sent: Friday, 2 December 2011 9:32 PM
Subject: Re: Radacct update at 3 hours
 

Maybe my way of doing things is not the right one, but I had to solve the same 
issue a while ago.  What I did is I changed the simple update in sql.conf to a 
stored procedure call, and in my stored proc, I update the radacct entry, but I 
also insert another record into a log table. 

Re: Radacct update at 3 hours

2011-12-02 Thread Alan DeKok
Hitesh Vinzoda wrote:
 My current sql.conf looks like below and it does not have accounting
 sections at all.

  That's nice.  We know.  We're familiar with the default configuration
files.

  Now read it.  It *tells you* where the rest of the configuration is
located.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Change of network adapters in radius server

2011-12-02 Thread Roland Pinches
On 12/02/2011 08:52 PM, Alan DeKok wrote:
 Roland Pinches wrote:
 Is there something I have missed that binds radius to a specific MAC
 address?
   No.

   It *does* bind to a specific IP address, if you've configured it to do
 that.

 Can anyone offer suggestions? I can provide the output from radiusd -X
 if needed but will take me a day or two to get it since this is on a
 production server that can only be worked on at 3am!
   You can run the server in debugging mode on a different port.
Ah, I didn't know that. I'll grab the debug output as soon as I can, thanks.
 The VM is configured with 2 vCPU and 4GB RAM. The cisco NAS is reporting
 approx 2000 requests a minute, so not exactly super busy. I've seen
 other posts in the mailing list suggesting FreeRADIUS can cope with
 1000's per second!
   I've done tests with 50K requests/s for days straight.  My smartphone
 could do 200 requests/s.

   Alan DeKok.
 -
 List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re[6]: configuration freeradius for no simultaneous use

2011-12-02 Thread tolik_shavlov...@mail.ru
Hi,

according to doc:
===
3. IMPLEMENTATION

  The server keeps a list of logged-in users in the /var/log/radutmp file.
  This is also called the session database. When you execute radwho,
  all that radwho really does is list the entries in this file in a pretty
  format. Only when someone tries to login who _already_ has an active
  session according to the radutmp file, the server executes the perl
  script /usr/local/sbin/checkrad (or /usr/sbin/checkrad, it checks for
  the presence of both and in that order). This script queries the terminal
  server to see if the user indeed already has an active session.

  The script uses SNMP for Livingston Portmasters and Ciscos, finger for
  Portslave, Computone and Ascend, and Net::Telnet for USR/3Com TC.

  Since the script has been witten in perl, it's easy to adjust for
  any type of terminal server. There are implementations in the script for
  checks using SNMP, finger, and telnet, so it should be easy to add
  your own check routine if your terminal server is not supported yet.

  You can find the script in the file src/checkrad.pl.

  You need to set the correct type in the file /etc/raddb/naslist so that
  checkrad KNOWS how it should interrogate the terminal server. At this
  time you can define the following types:
=

my  /usr/local/etc/raddb doesn't has naslist ans naspassword files.

If i configure them manually, so freeradius will connect to NAS (we use cisco) 
via snmp and check user session? So, in such way i don't need script?

thanks.


02 декабря 2011, 13:53 от Fajar A. Nugraha-2 [via FreeRadius] 
ml-node+s1045715n5041277...@n5.nabble.com:
 
  
  
 2011/12/2 Толик Шавловский [hidden email]:
 Dear Alan,

I assume you want help from anyone, not just Alan, so I'll add some
comments here.


 i am not good acquainted with freeradius. So, from doc/Simultaneous-use i 
 understood that freeradius requres script, which will connect to NAS and 
 check user session. Am i right?

That's one way to do that (and possibly the most accurate way). But
not the ONLY way.

You can make it work without the script, if you store accounting data
in sql. See (for example) raddb/sql/mysql/dialup.conf, look for
simul_count_query and simul_verify_query. But again, you need to
store accounting data for it to work.

-- 
Fajar



 02 декабря 2011, 12:43 от Fajar A. Nugraha [hidden email]:
 On Fri, Dec 2, 2011 at 3:37 PM, [hidden email]
 [hidden email] wrote:
  Dear Alan,
 
  i added  Simultaneous-Use = 1 to user profile in users file.

 Did you read the doc? Or the reply I sent earlier?

 It requires MORE than just that.














-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
 
 
 
--
 
 
If you reply to this email, your message will be added to the discussion below: 
http://freeradius.1045715.n5.nabble.com/configuration-freeradius-for-no-simultaneous-use-tp5040887p5041277.html
  
 To unsubscribe from configuration freeradius for no simultaneous use, click 
here.
 NAML 
























   


--
View this message in context: 
http://freeradius.1045715.n5.nabble.com/configuration-freeradius-for-no-simultaneous-use-tp5040887p5041384.html
Sent from the FreeRadius - User mailing list archive at Nabble.com.-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html