RE: Source IP address for proxy requests

2006-09-27 Thread Angel L. Mateo
El mar, 26-09-2006 a las 10:00 +0200, Sebastien Cantos escribió: I've you seen my post or are you just ignoring it ? :) I've seen your post. I already know I could reconfigure routes. -- Angel L. Mateo Martínez Sección de Telemática Área de Tecnologías de la Información _o) y

MS-CHAPv2 error, clues ?

2006-09-27 Thread Apu islam
Here is the error message I am getting when I am trying to authenticate, Processing the authenticate section of radiusd.conf modcall: entering group MS-CHAP for request 1 rlm_mschap: Told to do MS-CHAPv2 for apu with NT-Password rlm_mschap: FAILED: MS-CHAP2-Response is

multiple MAC in calling-station-id

2006-09-27 Thread Collen Blijenberg
Just a question... we use 'Calling-Station-Id' for authenticate agains MAC address (and username and passwd) can i use multiple 'Calling-Station-Id' if some user account has, let's say 3 laptops.. ?? or is there an other way to link multiple mac addresses to a user account ? --- users

Re: Source IP address for proxy requests

2006-09-27 Thread Peter Nixon
On Tue 26 Sep 2006 22:03, Alan DeKok wrote: Phil Mayers [EMAIL PROTECTED] wrote: All IP protocol servers should offer each type of socket a configurable bind address (or list of such). That is quite aside from the specifics of this issue - that is, it solves other, much much harder to solve

Re: Show Groups in dialup_admin

2006-09-27 Thread Evert
Is no-one else bothered by this error? Or am I the only one experiencing it...? ;-) Regards, Evert Evert wrote: Hi all! This question has been asked (but not answered?) before: http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg11278.html I do the following: *

Re: multiple MAC in calling-station-id

2006-09-27 Thread James Wakefield
Collen Blijenberg wrote: Just a question... we use 'Calling-Station-Id' for authenticate agains MAC address (and username and passwd) can i use multiple 'Calling-Station-Id' if some user account has, let's say 3 laptops.. ?? or is there an other way to link multiple mac addresses to a

Accounting issues in Oracle solved

2006-09-27 Thread Guilherme Franco
Hello, I had to modify oracle-dialup.conf to make accounting on/off to work. In AcctSessionTime, the original query would generate expected NUMBER, got INTERVAL error. Here is the original: accounting_onoff_query = UPDATE ${acct_table1} SET AcctStopTime=TO_DATE('%S','-mm-dd hh24:mi:ss'),

dumb humble question about sqlippool

2006-09-27 Thread Guilherme Franco
Hi, I know you guys must be angry with all the questions I'm posting here. In Devel-List, I found this: Is it usefull to community? (SQLIPPOOL and NASCATS) by Roman M. Bibikov on Thu, 16 Oct 2003 17:36:26 +1100. He says that created a sucessfull ip pool in Oracle (exactly what I'm trying to

Re: Show Groups in dialup_admin

2006-09-27 Thread Christian Hahn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Evert, this works for me with the CVS version 2.0.0pre0. regards, Christian Evert wrote: Is no-one else bothered by this error? Or am I the only one experiencing it...? ;-) Regards, Evert Evert wrote: Hi all! This question has

RE: assigning vlan based on LDAP attribute

2006-09-27 Thread Matt Ashfield
I'm a bit confused on this one. I want my users vlan'd based on their affiliation (ie, staff, student) In my radiusd.conf file, under ldap, I've put: groupmembership_attribute = eduPersonPrimaryAffiliation Do I need to do more in my radiusd.conf file than that? I assume this means assign them

RE : assigning vlan based on LDAP attribute

2006-09-27 Thread Thibault Le Meur
I'm a bit confused on this one. I want my users vlan'd based on their affiliation (ie, staff, student) In my radiusd.conf file, under ldap, I've put: groupmembership_attribute = eduPersonPrimaryAffiliation That's a good start, but sending the whole ldap configuration section would

RE: RE : assigning vlan based on LDAP attribute

2006-09-27 Thread Matt Ashfield
My ldap section from radiusd.conf looks like: ldap { server = ldapserver.net.org identity = uid=name,dc=net,dc=org password = password basedn = ou=stuffdc=net,dc=org filter = (uid=%{Stripped-User-Name:-%{User-Name}})

RE : RE : assigning vlan based on LDAP attribute

2006-09-27 Thread Thibault Le Meur
My ldap section from radiusd.conf looks like: ldap { server = ldapserver.net.org identity = uid=name,dc=net,dc=org password = password basedn = ou=stuffdc=net,dc=org filter =

Re: RADIUS + MySQL + decisionmaking?

2006-09-27 Thread Guy Fraser
On Wed, 2006-09-27 at 02:47 +0100, Jan Mulders wrote: Hello, I am trying to set up some decision-making logic into FreeRADIUS, to assign users a different speed of service depending on how much bandwidth they've used since their billing started. I want to issue 512k speed to users in

How to deny user with changed username when using EAP-TLS

2006-09-27 Thread Marcos González
Hello, my name is Marcos and I'm developing an access control solution using FreeRADIUS+MySQL+Web frontend. I use check attributes in table 'radusercheck ' to allow or deny access on a per user basis. The problem is, if an user changes his 'UserName' in his wireless network adapter configuration,

syslog.conf

2006-09-27 Thread sean
Hi, I've been running a trouble free Radius server for over a year. Last weekend a local power company substation went on fire. This resulted in a massive power surge and a major system crash. Since then Radius has been validating users from MySQL no problem. However it is not updating its log

Re: ULTRA IMPORTANT! Proxy - Assertion failed in listen.c, line 558 error

2006-09-27 Thread Guilherme Franco
Thank you very much! On 9/27/06, Alan DeKok [EMAIL PROTECTED] wrote: Guilherme Franco [EMAIL PROTECTED] wrote: Sending duplicate proxied request to home server foo.com port 1645 - ID: 16 Assertion failed in listen.c, line 558 This is now fixed in CVS. You'll have to do a cvs update

Re: ULTRA IMPORTANT! Proxy - Assertion failed in listen.c, line 558 error

2006-09-27 Thread Guilherme Franco
By the way, http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/ does not work: Internal Server Error The server encountered an internal error or misconfiguration and was unable to complete your request. Please contact the server administrator, [EMAIL PROTECTED] and inform them of the time the

RE: RE : RE : assigning vlan based on LDAP attribute

2006-09-27 Thread Thibault Le Meur
I think part of my problem is that I do not have the vlans defined in the Access Point. I incorrectly assumed that the AP would receive the vlan info from the Radius server, and tag all outgoing packets from the wireless client with that tag. However, I'm starting to think that that is

Re: RADIUS + MySQL + decisionmaking?

2006-09-27 Thread Jan Mulders
Thanks for your help. I ended up pulling the accounting counter part out completely and did it via a cronjob that changed the user's group - and have implemented the detail log as suggested. Thank you, Jan On 27/09/06, Guy Fraser [EMAIL PROTECTED] wrote: On Wed, 2006-09-27 at 02:47 +0100, Jan

Re: RE : assigning vlan based on LDAP attribute

2006-09-27 Thread A . L . M . Buxey
Hi, You asked: * is your AP accepting Tunnel-Private-Group-Id=2 (I've got AP which uses other format). How do I check that? easiest way is to set up a dumb user in your users files which returns the attributes you want (check with radtest) and then run that against your AP - and check that

Re: How to deny user with changed username when using EAP-TLS

2006-09-27 Thread Alan DeKok
=?ISO-8859-1?Q?Marcos_Gonz=E1lez?= [EMAIL PROTECTED] wrote: Is there any way to allow known users (those whose UserName appears in radcheck) access, but deny unknown (all other) users? Huh? If the user password aren't known to the server, the default *is* to reject them. If that isn't

CRITICAL! NFS/ SQLIPPOOL :~(

2006-09-27 Thread Guilherme Franco
Hello, I'm in a situation where I have 2 freeradius servers, working perfectly with rlm_sql_oracle (the entire AAA is done in Oracle, except the ippool). It's not possible to have the same pool configured the same way in the 2 servers, and also It's totally out of question to configure range1