Radius CDR'S

2006-07-06 Thread ravi reddy
Hi FreeRadius users, Presently Iam using FreeRadius-1.1.1 with SER iam getting all account start account stop details in to the Radius database This is a Raw data what I mean is iam gettting two or three messages for one call . So , in order to get them like a CDR per customer what is the way to

Re: Defining different Service-Types for different equipment for the same user

2006-07-06 Thread Nuno Cervaens
Alan DeKok wrote: Nuno Cervaens [EMAIL PROTECTED] wrote: My problem is that when a user logs in to an Enterasys SSR with the Service-Type = Administrative, it goes immediately to the configure mode, and I dont want that, just the enable mode. I presume this is a documented

Re: Framed-IP-Address accounted in Hex

2006-07-06 Thread Graeme Hinchliffe
On 4 Jul 2006, at 17:01, Alan DeKok wrote: Graeme Hinchliffe [EMAIL PROTECTED] wrote: Further to this, I have just noticed that this doesn't seem to just be restricted to the IP address, but also the Session ID field. Instead of displaying the session ID as say 020268001A6C-44A618FF I

Re: problem in configuring PEAP on freeRADIUS1.1.2

2006-07-06 Thread sukhvinder kumar
Generate certificates and then Configure eap.conf, it'll work. Regards. sukhvinder --- Pradeep Sengar [EMAIL PROTECTED] wrote: Hi, I m running freeRADIUS 1.1.2. Trying to run it for PEAP authentication and made few changes in radiusd.conf,eap.conf users files in /usr/local/etc/raddb/

multiple Auth-Type

2006-07-06 Thread Rohaizam Abu Bakar
I've mutiple Auth-Type and Autz-Type to use for LDAP backend From below setting, i'm trying NOT to set Auth-Type as suggested... So i let Freeradius detecting Auth-Type by itself... It only working for OCE line coz it's EAP type. Other line not working unless the password is stored in

Re: Framed-IP-Address accounted in Hex

2006-07-06 Thread Graeme Hinchliffe
On 6 Jul 2006, at 09:58, Graeme Hinchliffe wrote: On 4 Jul 2006, at 17:01, Alan DeKok wrote: Graeme Hinchliffe [EMAIL PROTECTED] wrote: Further to this, I have just noticed that this doesn't seem to just be restricted to the IP address, but also the Session ID field. Instead of displaying

unknown module eap error

2006-07-06 Thread simon
Hello, I was running freeRadius version 1.1.1, and everything was working smoothly. I then had to reformat my server, so I saved my entire raddb config directory so that I would not need to start completely from scratch. However, I have now installed version 1.1.2, and I cannot get it

Re: unknown module eap error

2006-07-06 Thread Stefan Winter
Hi, rlm_eap: Failed to link EAP-Type/tls: file not found radiusd.conf[10]: eap: Module instantiation failed. radiusd.conf[1894] Unknown module eap. radiusd.conf[1841] Failed to parse authenticate section. you want to use TLS or TTLS or PEAP, but have compiled the server without TLS support.

module install

2006-07-06 Thread Cihan DEMÄ°R
Hi all, Im new to radius and im searching authentication without username/password but calling number about a week. After all, i find rlm_checkval module. We are using version 0.9.3 and rlm_checkval module doesnt exist. I want to install it but its not in stable list. So, here is the

Re: Listening on proxy*: 1814

2006-07-06 Thread Alan DeKok
Giuseppe Parlato [EMAIL PROTECTED] wrote: I upgraded freeradius but when it starts at the end of debug I don't get the usual Listening on proxy*: 1814 , where can I configure it.. You don't. If you're not proxying packets, then that port won't be used. Alan DeKok. - List

Re: module install

2006-07-06 Thread Alan DeKok
=?iso-8859-9?Q?Cihan_DEM=DDR?= [EMAIL PROTECTED] wrote: in 1.1.2 version, it is in stable list. If i want to install rlm_checkval module which exists in 1.1.2 version to 0.9.3 , what happens? I think there is no difference. You can't do it. Upgrade to 1.1.2. Alan DeKok. - List

Re: CHAP and Windows 2003 AD LDAP

2006-07-06 Thread Luke
Alan DeKok wrote: Luke [EMAIL PROTECTED] wrote: Unfortunately I need to support CHAP because it is used by an external global Dial-Up provider which the freeradius machine is authenticating for. If the passwords are in AD your ONLY choice is to use IAS, and even then, only if ALL of

cisco 3550

2006-07-06 Thread fhcom
hi, I am using freeradius 1.0.5 on cygwin in eap-tls mode. My switch is a cisco 3550. I hope to affect a user under a vlan and modified my users file in adding these attributes: Tunnel-Type = 13,Tunnel-Medium-Type = 6,Tunnel-Private-Group-Id = vlan number the user is authenticated, but it

Radius ip pool service !!

2006-07-06 Thread Emerson
Hi, I read about ip pool service in freeradius. I need to deliver ip to my clients postauth. I need to know if ip pool is the tool for this. Thank's Emerson - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Radius ip pool service !!

2006-07-06 Thread Stefan Winter
Hi, I read about ip pool service in freeradius. I need to deliver ip to my clients postauth. I need to know if ip pool is the tool for this. That depends on who your clients are. If you have 802.1X secured networks, you will need a DHCP server. 802.1X does not support passing arguments

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-06 Thread Stefan Winter
Quite new to radius and struggling to get my head around things so forgive me if my assumptions are wrong. I appear to have the setup working but i'm concerned it's not doing what it think it is. I don't think the authentication requests are actually going over an encrypted channel. You need

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-06 Thread A . L . M . Buxey
Hi, I'm using freeradius-1.1.2 on a freebsd server and i've compiled it against openldap-2.3.24 which all went well. I'm attempting to set up secure wireless with WPA2 using our ldap directory for authentication. We have a replica of our directory running on the freeradius server. Originally

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-06 Thread John Allman
Stefan Winter wrote: You need to differentiate two parts of the link: a) the data that is passed between the client device and the RADIUS server and b) the backend communication between RADIUS server and LDAP. a) is encrypted when using EAP-TTLS b) may or may not be encrypted, depending

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-06 Thread John Allman
[EMAIL PROTECTED] wrote: captive portal - there are several software tools that will do this... eg http://en.wikipedia.org/wiki/Captive_portal most people seem to be moving away from this method as it is riddled with possible security compromises. Thanks for the heads-up. I'll take a

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-06 Thread A . L . M . Buxey
Hi, The EAP-Message doesn't appear to be encrypted on the initial packet from the ap to the server. Inside i see Type and Identity (containing my username. The username is also in the User-Name attribute) that'll be your outer identity... which, as it is plain to see (pun definately intended

Mysql Authentication

2006-07-06 Thread Max Clark
Hi all, We are migrating from an old installation of Radiator onto Freeradius. Local test accounts work fine, however I am getting an error on mysql based authentication. I am sure I'm missing something basic, here is the output from the radiusd process. Thanks, Max Ready to process requests.

Re: Mysql Authentication

2006-07-06 Thread Francois-Xavier GAILLARD
Le Thu, Jul 06, 2006 at 10:48:03AM -0700, Max Clark ecrivait: Hi all, We are migrating from an old installation of Radiator onto Freeradius. Local test accounts work fine, however I am getting an error on mysql based authentication. I am sure I'm missing something basic, here is the output

Re: Mysql Authentication

2006-07-06 Thread Max Clark
It was actually much more of a basic problem - dialupadmin uses crypt passwords by default and the default radius configuration looks for clear text. Thanks, Max On 7/6/06, Francois-Xavier GAILLARD [EMAIL PROTECTED] wrote: Le Thu, Jul 06, 2006 at 10:48:03AM -0700, Max Clark ecrivait: Hi all,

Re: Mysql Authentication

2006-07-06 Thread Alan DeKok
Max Clark [EMAIL PROTECTED] wrote: We are migrating from an old installation of Radiator onto Freeradius. Local test accounts work fine, however I am getting an error on mysql based authentication. I am sure I'm missing something basic, here is the output from the radiusd process. You still

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-06 Thread John Allman
[EMAIL PROTECTED] wrote: The EAP-Message doesn't appear to be encrypted on the initial packet from the ap to the server. Inside i see Type and Identity (containing my username. The username is also in the User-Name attribute) that'll be your outer identity... which, as it is plain to

Re: Framed-IP-Address accounted in Hex

2006-07-06 Thread Alan DeKok
Graeme Hinchliffe [EMAIL PROTECTED] wrote: What would cause FreeRADIUS to output in this manner, we have summized that if it sees a none ASCII byte in the field it would convert the whole field into a hex representation to stop trying to write binary to the db. No, it should print out

Re: Defining different Service-Types for different equipment for the same user

2006-07-06 Thread Alan DeKok
Nuno Cervaens [EMAIL PROTECTED] wrote: Here's an example for what it would be a perfect solution: userOne Crypt-Password == $1$GYuKhumy$wUkW0ZvClTCi86kkkgJBw. Service-Type = 6 Service-Type = 7 (for the SSRs) I don't think that will work. You're allowed ONE Service-Type in

802.1x authentication

2006-07-06 Thread Jin Fan
Hi, All: I need some pointers on how to set up 802.1x (PEAP/MSCHAP v.2) authentication in freeradius. Generating certificates? Modifying configurations? Jin - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html