Question about mac address auth / dot1x / vlan assignement.

2005-10-21 Thread Didier CONTIS
I apologize if the subject is a little bit off topic. I have what seems now to be a classic scenario where I am trying to do mac address auth / vlan assignment using Windows XP / Cisco Catalyst switch running IOS / FreeRadius 1.0.5 After reading several posts on the mailing list about the subj

Re: Radlast and radwho fails

2005-10-21 Thread Kevin Capwell
Mr. DeKok I give you my sincere apologies, I was replying to Mr. Ori's message - I saw his first and relied to that _before_ I saw your message. I did not mean to give offence. - The views, opinions and statements contained in this transmission are not

Re: Radlast and radwho fails

2005-10-21 Thread Alan DeKok
Kevin Capwell <[EMAIL PROTECTED]> wrote: > OK, so here is the _full_ story: ... > rad_recv: Access-Request packet from host 192.168.zz.zz:1239, id=46, length=68 That's not an accounting packet. See my previous response. If you're not going to read it, then there's no point in continuing to a

Re: Radlast and radwho fails

2005-10-21 Thread Kevin Capwell
OK, so here is the _full_ story: Module: Loaded radutmp radutmp: filename = "/usr/local/var/log/radius/radutmp" radutmp: username = "%{User-Name}" radutmp: case_sensitive = no radutmp: check_with_nas = yes radutmp: perm = 384 radutmp: callerid = yes Module: Instantiated radutmp (radutmp) Li

Re: Radlast and radwho fails

2005-10-21 Thread Zoltan Ori
> ... > Module: Loaded radutmp > radutmp: filename = "/usr/local/var/log/radius/radutmp" > radutmp: username = "%{User-Name}" > radutmp: case_sensitive = no > radutmp: check_with_nas = yes > radutmp: perm = 384 > radutmp: callerid = yes > Module: Instantiated radutmp (radutmp) > Listen

Re: ldap filter question

2005-10-21 Thread Alan DeKok
Markus Krause <[EMAIL PROTECTED]> wrote: > i assume that i have to > define something like 'filter = "dhcpHWAddress=%u" ', but how to strip of > "ethernet"? Regular expressions. See doc/variables.txt Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.htm

Re: Radlast and radwho fails

2005-10-21 Thread Alan DeKok
Kevin Capwell <[EMAIL PROTECTED]> wrote: > GIVEN: I can use both the test account and a laptop with an access > point to access our wireless network via freeradius. However, I can > not see who is currently online through radlast and radwho. The data in radwho & radlast come from accounting p

Radlast and radwho fails

2005-10-21 Thread Kevin Capwell
GIVEN: I can use both the test account and a laptop with an access point to access our wireless network via freeradius. However, I can not see who is currently online through radlast and radwho. Authentication Style: MAC address using the ${sysconfdir}/raddb/users file DETAILS Server OS: Mac

Re: PEAP Machine Authentication

2005-10-21 Thread Michael Griego
The second function is the one you want to change... rpccli_netlogon_sam_network_logon. On line 803, change it from: 0, /* param_ctrl */ to: 0x800, /* param_ctrl */ --Mike Jérémy Cluzel wrote: Hi, I looked in the samba 3.0.20 source code and I only found 2 calls to the "init_id_info2()"

ldap filter question

2005-10-21 Thread Markus Krause
hi all! to verify some network devices which want to connect to a switch we want to use radius and store the mac-addresses in ldap. the switch passes the ethernet-mac-address to radius which should then be checked against the ldap entry for dhcp, there is an attribte dhcpHWAddress we already use s

Session Timeout Questions

2005-10-21 Thread Curt LeCaptain
Say I've got two login locations to log in from, NAS1 and NAS2. I'm wondering, how would I go about making it so that anyone that logs in from NAS1 would not get a session timeout, but anyone logging in from NAS2 would? Thanks, Curt LeCaptain - List info/subscribe/unsubscribe? See http://www

PEAP Machine Authentication

2005-10-21 Thread Jérémy Cluzel
Hi, I looked in the samba 3.0.20 source code and I only found 2 calls to the "init_id_info2()" function in the "samba/source/rpc_client/cli_netlogon.c" file: In the "cli_netlogon_sam_logon()" function: 701 init_id_info2(&ctr.auth.id2, lp_workgroup(), 702

Re: recommended restart-wrapper for freeradius

2005-10-21 Thread Nicolas Baradakis
Tariq Rashid wrote: > but from the doc/supervide-radiusd.txt we have > > "Note: The radwatch script that used to be part of this distribution, > is depreciated and SHOULD NOT BE USED." > > is it still safe to use? I think it is. For example, it's used in the initscript from Gentoo. htt

Re: recommended restart-wrapper for freeradius

2005-10-21 Thread Alan DeKok
"Tariq Rashid" <[EMAIL PROTECTED]> wrote: > "Note: The radwatch script that used to be part of this distribution, > is depreciated and SHOULD NOT BE USED." > > is it still safe to use? Probably, but it's no longer maintained. Alan DeKok. - List info/subscribe/unsubscribe? See http

Re: Malformed RADIUS packet. Invalid attribute 0

2005-10-21 Thread Alan DeKok
Ramon Barquier <[EMAIL PROTECTED]> wrote: > When I test the authentication utility from a linux client I don't have > response by the server. Looking into /var/log/freeradius/radius.log, > Error: WARNING: Malformed RADIUS packet from host www.xxx.yyy.zzz: > Invalid attribute 0. "0" is not a

RE: recommended restart-wrapper for freeradius

2005-10-21 Thread Tariq Rashid
but from the doc/supervide-radiusd.txt we have "Note: The radwatch script that used to be part of this distribution, is depreciated and SHOULD NOT BE USED." is it still safe to use? tariq -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Nicola

Re: recommended restart-wrapper for freeradius

2005-10-21 Thread Nicolas Baradakis
Tariq Rashid wrote: > hi - we're having the freeradius 1.0.2 daemon dying occasionally for > mysterious reasons - we're still investuigating the cause. You should upgrade to 1.0.5. http://freeradius.org/security.html > running in the foreground in an infinite loop is also not ideal as > this mea

SV: recommended restart-wrapper for freeradius

2005-10-21 Thread Svein Hansen
I have the same problem.. I made a simple shell script that runs every 5 min.(crontab) #! /bin/bash if ! [ -n "`radtest username passwd localhost 10 secret | grep TRAPEZE`" ]; then service radiusd restart fi "TRAPEZE" i s the name of the user-assigned vlan.. rad_recv: Access-Accept pack

Re: accounting scripts ?

2005-10-21 Thread Frank Bonnet
Miguel wrote: Frank Bonnet wrote: Hello I'm searching for scripts that are able to parse the radacct/xxx.xxx.xxx.xxx/detail-xxx file to perform some simple statistics ? Thanks - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html what do you mean with pars

Re: accounting scripts ?

2005-10-21 Thread Frank Bonnet
Alan DeKok wrote: Frank Bonnet <[EMAIL PROTECTED]> wrote: I'm searching for scripts that are able to parse the radacct/xxx.xxx.xxx.xxx/detail-xxx file to perform some simple statistics ? radiusreport. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/lis

recommended restart-wrapper for freeradius

2005-10-21 Thread Tariq Rashid
hi - we're having the freeradius 1.0.2 daemon dying occasionally for mysterious reasons - we're still investuigating the cause. however - when it dies the radiusd.pid file is not removed. this causes problems for most restart-wrappers ... running in the foreground in an infinite loop is also n

Re: mac address auth question

2005-10-21 Thread kdr akm
Hi Mr N White   Thanks for replying and i do what u said but it not success this is my /etc/raddb/users file if u can take a look to see if i do it right plz and notice me if there's something wrong :     cut-

Malformed RADIUS packet. Invalid attribute 0

2005-10-21 Thread Ramon Barquier
Hi, I have installed freeradius 1.0.4-2 in a Debian sarge and I have install php-radius 1.2-1 (Radius protocol implementation in PHP from Roberto Lumbreras) for authenticate users. When I test the authentication utility from a linux client I don't have response by the server. Looking into /v