SV: SV: SV: No known good password

2009-03-04 Thread Ove Fagerheim
Thank you Ivan, I figured that out after actually *reading* your post, unfortunately I'm a little bit stressed at the moment. After uncommenting the entry, FreeRadius does not start. Errors: E:\FreeRADIUS.net\binradiusd -X Starting - reading configuration files ... reread_config: reading

Re: SV: SV: SV: No known good password

2009-03-04 Thread Alan DeKok
Ove Fagerheim wrote: After uncommenting the entry, FreeRadius does not start. Errors: E:\FreeRADIUS.net\binradiusd -X Ah freeradius.net. That's a cygwin build of a *very* old version of the server. I'd suggest running it instead on a Linux machine. You can run a *new* version of

Re: eap-tls configuration not running...

2009-03-04 Thread fabien.crettaz
Hello My server is now accepting the eap authentication, but is sending after this accept an access challenge to the client. It seems that the client ignores the access challenge sent by the server !! Any idea ?? Fabien rad_recv: Access-Request packet from host 10.166.42.30:1024, id=3,

Freeradius with CoA

2009-03-04 Thread M K
Hello all! I have freeradius 2.1.3 installed on my FreeBSD 7.1 OS. And i have cisco 7201 with ISG module. When i try to send CoA (Change of authorization) account-logon request like this /bin/echo

SV: SV: SV: SV: No known good password

2009-03-04 Thread Ove Fagerheim
Hmm, that gives me a policy problem, my company *does not* use Linux. Is there any Windows ports out there? I've checked http://download.opensuse.org/repositories/network:/aaa/;, but I'm uncertain which folder to select and which files to download Ove -Opprinnelig melding- Fra:

Re: Freeradius with CoA

2009-03-04 Thread tnt
There's cisco debug: And this is freeradius list. Feel free to send this to your friendly Cisco support people. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: SV: SV: SV: SV: No known good password

2009-03-04 Thread tnt
Hmm, that gives me a policy problem, my company *does not* use Linux. And they are in Internet business? Not for long. Is there any Windows ports out there? freeradius.net (this is support for versions from freeradius.org). Not a real port but it works. It has support for mysql, but not for

Re: SV: SV: SV: No known good password

2009-03-04 Thread Laurent Besson
Le Wednesday 04 March 2009 11:21:38 t...@kalik.net, vous avez écrit : Oh, this is Windows. Uninstall the whole thing. You can download that version in default configuration from freeradius.net. Do fresh install. Just edit clients.conf and users file. Maybe, installing Virtual Machine could

Re: SV: SV: SV: SV: No known good password

2009-03-04 Thread Nicolas Goutte
Am 04.03.2009 um 11:24 schrieb Ove Fagerheim: Hmm, that gives me a policy problem, my company *does not* use Linux. If you do not mean only Windows, see the other options, like for examples MacOS, BSD, Solaris: http://wiki.freeradius.org/Platforms Is there any Windows ports out there?

Re: SV: SV: SV: No known good password

2009-03-04 Thread tnt
Oh, this is Windows. Uninstall the whole thing. You can download that version in default configuration from freeradius.net. Do fresh install. Just edit clients.conf and users file. Windows version supports mysql but not much more. You are far better of with current (Linux) version. Ivan Kalik

Re: OT: Implementing RSA's SecurID

2009-03-04 Thread Mike O'Connor
Greg Vickers wrote: Hi, (Apologies for an OT post) I was wondering if anyone know of any user list that would contain a community of people who implement systems like RSA's SecurID? The reason is that I am researching who else has implemented SecurID and am trying to find if there is

Re: Freeradius with CoA

2009-03-04 Thread Evgeniy Kozhuhovskiy
M K wrote: Hello all! I have freeradius 2.1.3 installed on my FreeBSD 7.1 OS. And i have cisco 7201 with ISG module. When i try to send CoA (Change of authorization) account-logon request like this /bin/echo

Re: SV: SV: SV: SV: No known good password

2009-03-04 Thread Alan DeKok
Ove Fagerheim wrote: Hmm, that gives me a policy problem, my company *does not* use Linux. Is there any Windows ports out there? I've checked http://download.opensuse.org/repositories/network:/aaa/;, but I'm uncertain which folder to select and which files to download

Re: eap-tls configuration not running...

2009-03-04 Thread Alan DeKok
fabien.cret...@novelis.com wrote: My server is now accepting the eap authentication, but is sending after this accept an access challenge to the client. It seems that the client ignores the access challenge sent by the server !! Any idea ?? Have you tried reading the FAQ? Alan DeKok. -

Please can someone help I'm new on the list

2009-03-04 Thread Gustavo Román
I'm trying to install Radius EAP/TLS but when I enable the EAP module, I get the following Error: rlm_eap: Failed to link EAP-Type/tls: rlm_eap_tls.so: cannot open shared object file: No such file or directory radiusd.conf[10]: eap: Module instantiation failed. radiusd.conf[1960] Unknown module

Re: Please can someone help I'm new on the list

2009-03-04 Thread Alan DeKok
Gustavo Román wrote: I'm trying to install Radius EAP/TLS but when I enable the EAP module, I get the following Error: rlm_eap: Failed to link EAP-Type/tls: rlm_eap_tls.so: cannot open shared object file: No such file or directory radiusd.conf[10]: eap: Module instantiation failed.

Re: Rejections

2009-03-04 Thread Alan DeKok
Jack D. Martin Jr. wrote: I am using freeradius 2.1.3 using MySQL for my IP pool and user auth tables in my small ISP. What I need to do is have customers that get rejected with a bad password assigned to a particular IP pool. I am sure this is possible, but can't find it. I assume I

Re: SV: SV: SV: SV: No known good password

2009-03-04 Thread John Dennis
Ove Fagerheim wrote: Hmm, that gives me a policy problem, my company *does not* use Linux. What a marvellous opportunity for you to become a respected and valued employee of your company by educating your peers on the many benefits of open source operating systems. Perhaps the money you

Re: OT: Implementing RSA's SecurID

2009-03-04 Thread Nick Owen
On Tue, Mar 3, 2009 at 11:38 PM, Greg Vickers g.vick...@qut.edu.au wrote: Hi, (Apologies for an OT post) I was wondering if anyone know of any user list that would contain a community of people who implement systems like RSA's SecurID?  The reason is that I am researching who else has

reply messages in access-reject

2009-03-04 Thread Hegedus Gabor
Hi I have a question. How can I send attributes(for example reply-message, cvpn3000, ...) in access-reject packet. I tried to put my exec to the post-auth section Post-Auth-Type REJECT{}, but in this section radius dosen't send the attribs in the reject packet. Radius send only if i run the

Re: Rejections

2009-03-04 Thread Jack D. Martin Jr.
What about using a fall through? Could it be that the last option to auth, even if the password is incorrect - they get assigned to a particular group? Jack Martin Magic Wireless Internet Service Providers LLC P.O. Box 278 104 W. Main Oilton, OK 74052 www.magicwisp.com Jack D. Martin Jr.

Re: Can freeradius do a CoA Push.

2009-03-04 Thread Marlon Duksa
I thought that this can already be done with radclient , no?:radclient -x -t 20 -c 1 -f /home/coa.txt 114.0.1.1:3799 coa test On Tue, Mar 3, 2009 at 11:43 PM, Alan DeKok al...@deployingradius.comwrote: Simon Herriotts wrote: New user to freeradius, nice little bit of work. Wondering if

Re: Rejections

2009-03-04 Thread Alan DeKok
Jack D. Martin Jr. wrote: What about using a fall through? Could it be that the last option to auth, even if the password is incorrect - they get assigned to a particular group? As I said: The server can't turn a reject into an accept. Doing so will require source code patches. I

Re: Can freeradius do a CoA Push.

2009-03-04 Thread Alan DeKok
Marlon Duksa wrote: I thought that this can already be done with radclient , no? Yes. But integrating that into the server policies cannot currently be done well. i.e. When the server receives an accounting packet, you can check if they're over a bandwidth quota, and if so, run radclient

Re: Can freeradius do a CoA Push.

2009-03-04 Thread Marlon Duksa
ok. I see. Thanks.The NAS did exactly what I wanted it to do in my case (disconnect a user and also change the SLA parameters) Marlon On Wed, Mar 4, 2009 at 7:55 AM, Alan DeKok al...@deployingradius.comwrote: Marlon Duksa wrote: I thought that this can already be done with radclient , no?

Re: Rejections

2009-03-04 Thread tnt
This kind of handling of rejected users should be handled by your NAS. Radius server is suposed to reject users with bad passwords. You can make policy on your NAS to place them in a restricted VLAN instead of dropping the connection. Ivan Kalik Kalik Informatika ISP Dana 4/3/2009, Jack D.

Re: Rejections

2009-03-04 Thread Jack D. Martin Jr.
I wasn't questioning your skills - trust me. I have read many of your responses on the list, you helped me deploy my server without ever talking to me. I am just looking for a solution. Basically what I have is a billing solution that automatically suspends customers by scrambling their

Re: Rejections

2009-03-04 Thread Thibault Le Meur
Jack D. Martin Jr. a écrit : I wasn't questioning your skills - trust me. I have read many of your responses on the list, you helped me deploy my server without ever talking to me. I am just looking for a solution. Basically what I have is a billing solution that automatically suspends

Re: Rejections

2009-03-04 Thread Alan DeKok
Jack D. Martin Jr. wrote: I wasn't questioning your skills - trust me. I have read many of your responses on the list, you helped me deploy my server without ever talking to me. I am just looking for a solution. Basically what I have is a billing solution that automatically suspends

Re: Can freeradius do a CoA Push.

2009-03-04 Thread Simon Herriotts
Marlon, This looks like the item I am looking for. What is the syntax example in the coa.txt. Looks like I need to do more research into radclient usage. Cheers Simon Marlon Duksa wrote: I thought that this can already be done with radclient , no? : radclient -x -t 20 -c 1 -f

Re: Can freeradius do a CoA Push.

2009-03-04 Thread Marlon Duksa
Simon - I think there is a man on radclient. But the file you are asking about usually contains the attributes that you want to change. I was doing this on JNPR so the syntax was this in my particular example: user-Name = circuit:3.remote:3 Acct-Session-ID = 3 ERX-CoS-Parameter-Type = T02 800k I

Re: Can freeradius do a CoA Push.

2009-03-04 Thread Simon Herriotts
Perfect, thanks I will play with the radclient and see about the man tool. Cheers Simon Marlon Duksa wrote: Simon - I think there is a man on radclient. But the file you are asking about usually contains the attributes that you want to change. I was doing this on JNPR so the syntax