Re: radiusExpiration attirbute declared in the LdapGroup

2009-10-09 Thread aangles
Hello, In which file i configure the Ldap-Group Expiration? thanks Ivan Kalik wrote: I would Like to know if there is a way to define an expiration time for all those users which belong to an LDAP Group, instead of defining this attribute for each of those users? if(Ldap-Group ==

Re: radiusExpiration attirbute declared in the LdapGroup

2009-10-09 Thread Alexander Clouter
Hi, aangles aav_1...@hotmail.com wrote: I would Like to know if there is a way to define an expiration time for all those users which belong to an LDAP Group, instead of defining this attribute for each of those users? Moreover, after expiration time , RADIUS send an access-reject to the

Re: when to use exec / echo external script query

2009-10-09 Thread Alexander Clouter
Hi, c...@gateway.net.au wrote: freeradius 1.1.3-1.1 freeradius mysql Redhat Linux Fedora 6 A fine vintage... :-/ I was looking for information on at what point i would fire an external script. What i wish to do is once a client is authenticated and a framed-ip address allocated

Adding vendor specific attributes to dictionary

2009-10-09 Thread Patric
Hi all :) Hope someone can point me in the right direction once again! freeradius v 2.1.3 I am attempting to add vendor specific attributes to my dictionary without success :( I was given the following information to add: Class Number Attribute Value Type VENDORATTR

acct_postgresql+auth_ldap

2009-10-09 Thread José Johnny RANDRIAMAMPIONONA
Hi all, I d like to know if someone has already tried to do the accounting (only accounting) thing with postgres and authentication with OpenLdap? There is nothing on wiki ... I am wondering if I have to write some scripts to save the user id, his connection duration ect ...in postgres database.I

Re: acct_postgresql+auth_ldap

2009-10-09 Thread Rakotomandimby Mihamina
10/09/2009 01:58 PM, José Johnny RANDRIAMAMPIONONA:: Hi all, I d like to know if someone has already tried to do the accounting (only accounting) thing with postgres and authentication with OpenLdap? I am going to try that. Not yet, but I will. and I think it's globally about: auth {

Re: acct_postgresql+auth_ldap

2009-10-09 Thread Ivan Kalik
I am wondering if I have to write some scripts to save the user id, his connection duration ect ...in postgres database. No. Just configure postgre in sql.conf and uncoment sql entries in radiusd.conf and accounting section of default virtual server. Schema for the database is provided. I

Re: radiusExpiration attirbute declared in the LdapGroup

2009-10-09 Thread aangles
I'm sorry man, i am new with this. Exactly in which file I configure ,and in which section of that file: radiusd.conf, or expiration module, or ldap module, users file? Because I know that in the users file radius can check ittems stored in the LDAP, only in a per user basis. But i would like to

Re: radiusExpiration attirbute declared in the LdapGroup

2009-10-09 Thread Ivan Kalik
I'm sorry man, i am new with this. Exactly in which file I configure ,and in which section of that file: radiusd.conf, or expiration module, or ldap module, users file? None of the above. In authorize section of default or inner-tunnel virtual server depending on the protocol used. Because

Re: Adding vendor specific attributes to dictionary

2009-10-09 Thread Ivan Kalik
I am attempting to add vendor specific attributes to my dictionary without success :( I was given the following information to add: Class Number Attribute Value Type VENDORATTR 12345 Vendor-Attribute-A 1 string VENDORATTR 12345 Vendor-Attribute-A 2

Re: acct_postgresql+auth_ldap

2009-10-09 Thread José Johnny RANDRIAMAMPIONONA
Thank u guys! 2009/10/9 Ivan Kalik t...@kalik.net I am wondering if I have to write some scripts to save the user id, his connection duration ect ...in postgres database. No. Just configure postgre in sql.conf and uncoment sql entries in radiusd.conf and accounting section of default

Re: Adding vendor specific attributes to dictionary

2009-10-09 Thread Patric
Ivan Kalik wrote: ... File dictionary.myvendor: - VENDOR MyVendor 12345 BEGIN-VENDOR MyVendor ATTRIBUTE Vendor-Attribute-A 1 string ATTRIBUTE Vendor-Attribute-B 2 string END-VENDOR MyVendor That looks OK. As always thank you for your reply Ivan

Re: Adding vendor specific attributes to dictionary

2009-10-09 Thread Alan DeKok
Patric wrote: I have narrowed the problem down to the number field. The actual number I have been given to use is 32768, Install 2.1.7. See doc/ChangeLog Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Adding vendor specific attributes to dictionary

2009-10-09 Thread Ivan Kalik
File dictionary.myvendor: - VENDOR MyVendor 12345 BEGIN-VENDOR MyVendor ATTRIBUTE Vendor-Attribute-A 1 string ATTRIBUTE Vendor-Attribute-B 2 string END-VENDOR MyVendor That looks OK. I have narrowed the problem down to the number field. The

Re: Adding vendor specific attributes to dictionary

2009-10-09 Thread Patric
Alan DeKok wrote: Patric wrote: I have narrowed the problem down to the number field. The actual number I have been given to use is 32768, Install 2.1.7. See doc/ChangeLog Aaah, 2.1.7 Changelog: * Allowed vendor IDs to be be higher than 32767. Fantastic, upgrading now,

errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alisson
Hi, I have a dedicated server with freeradius 2.05 i'm getting 2 errors Error: Discarding conflicting packet from client net port 25000 - ID: 100 due to recent request 7343. There are no DB handles to use! skipped 0, tried to connect 0 I'm searching on the forums and a lot of people has this

Re: radiusExpiration attirbute declared in the LdapGroup

2009-10-09 Thread aangles
Like this? DEFAULT guests-Ldap-Group == cn=wlanguests,ou=Groups,dc=CELLS,dc=ES, Expiration := 09 Oct 2009 17:00, Auth-Type = LDAPGUESTS Because with this radius says: /etc/raddb/users[65]: Parse error (check) for entry DEFAULT: Expected end of line or comma and i tried to add a comma at the

Problems with radutmp

2009-10-09 Thread Gerardo Contreras
Hi. I'm having some problems with radutmp. I'm using an Aruba Mobility Controller which has radauth and radacct configured to this freeradius server. In fact, I've tried with freeradius both on centOS and ubuntu with same results. When a user logs in, a corresponding entry is added to

Re: Problems with radutmp

2009-10-09 Thread Gerardo Contreras
It even happens without using Simultaneous-use. Even if the same user authenticates, radius will delete the previous entry from the radutmp. It only keeps the last logged in user. By the way, radlast shows the previous users like if there were logged out, but they are indeed still logged

Re: Problems with radutmp

2009-10-09 Thread Gerardo Contreras
I've been watching the log records from users sessions, and I noted that every access from the NAS comes from the same NAS-Port. Could it be the reason? If so, is there any way so radutmp registers all of the entries even if the nas port is the same? Gerardo Contreras wrote: It even

Re: Problems with radutmp

2009-10-09 Thread Craig Campbell
://www.freeradius.org/list/users.html __ Information from ESET Smart Security, version of virus signature database 4493 (20091009) __ The message was checked by ESET Smart Security. http://www.eset.com __ Information from ESET Smart Security, version of virus signature database

Re: radiusExpiration attirbute declared in the LdapGroup

2009-10-09 Thread Alan DeKok
aangles wrote: Like this? DEFAULT guests-Ldap-Group == cn=wlanguests,ou=Groups,dc=CELLS,dc=ES, Expiration := 09 Oct 2009 17:00, Auth-Type = LDAPGUESTS No. Because with this radius says: /etc/raddb/users[65]: Parse error (check) for entry DEFAULT: Expected end of line or comma and i

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alan DeKok
Alisson wrote: Hi, I have a dedicated server with freeradius 2.05 i'm getting 2 errors Error: Discarding conflicting packet from client net port 25000 - ID: 100 due to recent request 7343. There are no DB handles to use! skipped 0, tried to connect 0 Your database is broken. Fix it.

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alisson
ok.. but what I need to do on my DB? Repair? Create another DB? alter some variable? 2009/10/9 Alan DeKok al...@deployingradius.com Alisson wrote: Hi, I have a dedicated server with freeradius 2.05 i'm getting 2 errors Error: Discarding conflicting packet from client net port 25000 -

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Roberto Greiner
http://forums.mysql.com/ Alisson wrote: ok.. but what I need to do on my DB? Repair? Create another DB? alter some variable? 2009/10/9 Alan DeKok al...@deployingradius.com mailto:al...@deployingradius.com Alisson wrote: Hi, I have a dedicated server with freeradius 2.05

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alisson
somebody have this same problem? 2009/10/9 Roberto Greiner mrgrei...@gmail.com http://forums.mysql.com/ Alisson wrote: ok.. but what I need to do on my DB? Repair? Create another DB? alter some variable? 2009/10/9 Alan DeKok al...@deployingradius.com mailto: al...@deployingradius.com

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alan DeKok
Alisson wrote: ok.. but what I need to do on my DB? Repair? Create another DB? alter some variable? Ask the people who wrote and support the DB. Asking DB questions on a RADIUS list isn't the best way to solve the problem. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Craig Campbell
(20091009) __ The message was checked by ESET Smart Security. http://www.eset.com __ Information from ESET Smart Security, version of virus signature database 4494 (20091009) __ The message was checked by ESET Smart Security. http://www.eset.com - List info

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alisson
but this problem is on radius or db? 2009/10/9 Alan DeKok al...@deployingradius.com Alisson wrote: ok.. but what I need to do on my DB? Repair? Create another DB? alter some variable? Ask the people who wrote and support the DB. Asking DB questions on a RADIUS list isn't the best

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Craig Campbell
-- - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Information from ESET Smart Security, version of virus signature database 4494 (20091009) __ The message was checked by ESET Smart Security. http://www.eset.com

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alisson
de Informação - UFGD -- - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Information from ESET Smart Security, version of virus signature database 4494 (20091009) __ The message was checked by ESET Smart

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Ivan Kalik
ok.. but what I need to do on my DB? Is your database server/process running? Is database IP/port/user/password correct in sql.conf? Is correct type of database selected? Is your database configured to recieve queries from radius server (ie. not localhost) if they are not on the same machine?

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Ivan Kalik
but this problem is on radius or db? 2009/10/9 Alan DeKok al...@deployingradius.com Alisson wrote: ok.. but what I need to do on my DB? Repair? Create another DB? alter some variable? Ask the people who wrote and support the DB. Asking DB questions on a RADIUS list isn't the best

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Ivan Kalik
but this problem is on radius or db? Database, network between radius and sql or incorrect data in sql.conf. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Ivan Kalik
the radius DB is working with user root the Users are authenticanting, and everything is working but i have this 2 errors and I tried do fix altering some variables from mysql and radius, but still appearing the message Do debug (radiusd -X) and see what causes the error. Maybe some

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alisson
Hi, Answering your questions 1) Is your database server/process running? R: Yes 2) Is database IP/port/user/password correct in sql.conf? R:Yes 3) Is correct type of database selected? R:Yes Radchecks=Innodb and the another tables are MyIsam 4) Is your database configured to recieve queries

Re: Problems with radutmp

2009-10-09 Thread Alan DeKok
Gerardo Contreras wrote: I've been watching the log records from users sessions, and I noted that every access from the NAS comes from the same NAS-Port. Could it be the reason? Yes. If so, is there any way so radutmp registers all of the entries even if the nas port is the same? Use

Re: acct_postgresql+auth_ldap

2009-10-09 Thread Alan DeKok
José Johnny RANDRIAMAMPIONONA wrote: I d like to know if someone has already tried to do the accounting (only accounting) thing with postgres and authentication with OpenLdap? Yes. Configure SQL and LDPA. Uncomment ldap in authorize authenticate. Uncomment sql in accounting. There is

Re: over 30 radiusd processes

2009-10-09 Thread Alan DeKok
Craig Campbell wrote: radius-a seems to be getting the bulk of the radius records. Normally, it has a single process. Last night it spawned a bunch of children that seem to be loitering... Are you forking shell scripts via exec? radius-b and radius-c don't have more than a single radiusd

Re: Proxy/Realm problem in 2.1.7

2009-10-09 Thread Alan DeKok
Palmer J.D.F. wrote: There are three servers in the auth and acct pools, but unless I comment two of them out (as below) I receive a 'Request Denied' message back in response to the first access-request packet that is proxied to one of the auth servers. ? The only way that happens is if

Re: Problems with radutmp

2009-10-09 Thread Gerardo Contreras
https://lists.freeradius.org/pipermail/freeradius-users/2009-September/msg00809.html Oh! I see... thanks. Alan DeKok wrote: Gerardo Contreras wrote: I've been watching the log records from users sessions, and I noted that every access from the NAS comes from the same NAS-Port.

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Alan DeKok
Alisson wrote: but this problem is on radius or db? What part of fix your database is hard to understand? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Proxy/Realm problem in 2.1.7

2009-10-09 Thread Alan DeKok
Alan Buxey wrote: there does seem to be an issue with 2.1.7 - I've had a couple of reports stating that the proxy doesnt seem to 'stick' to one remote proxy during EAP (eg with client-balance or client-ip-balance methods). not sure what has changed since 2.1.6 - but a rollback to 2.1.6 with

Re: Manage IPv6 pools using freeradius

2009-10-09 Thread Alan DeKok
Ram Akuka wrote: I want to manage my ipv6 users using ip_pool from FreeRadius. And I have few question regarding this. 1. how can I use ip_pool to allocate ipv6 address to a users? That isn't currently supported. 2. How can I assign ipv6 address to client based on the NAS he

Re: over 30 radiusd processes

2009-10-09 Thread Craig Campbell
/list/users.html __ Information from ESET Smart Security, version of virus signature database 4494 (20091009) __ The message was checked by ESET Smart Security. http://www.eset.com __ Information from ESET Smart Security, version of virus signature database 4494

Re: errors There are no DB handles to use and Discarding conflicting packet from client

2009-10-09 Thread Marinko Tarlac
This is not database list but here what you can do: - install sysbench and do some tests with your current settings - tunning-primer.sh (http://www.day32.com/MySQL/tuning-primer.sh), - mytop, - mysqlreport (http://hackmysql.com/mysqlreport) and - mysqltuner.pl

Re: when to use exec / echo external script query

2009-10-09 Thread Marinko Tarlac
post-auth ? c...@gateway.net.au wrote: freeradius 1.1.3-1.1 freeradius mysql Redhat Linux Fedora 6 I was looking for information on at what point i would fire an external script. What i wish to do is once a client is authenticated and a framed-ip address allocated to fire an external

Enabling ldap causes freeradius server to not start up.

2009-10-09 Thread Jesper Klit Jensen
Freeradius: 2.1.6 OS: Open Suse 11.0 LDAP 2.4.9 Problem is when running radiusd in forground with logging: Thread spawned new child 1. Total threads in pool: 1 Thread 1 waiting to be assigned a request Thread pool initialized radiusd: Opening IP addresses and Ports listen { type

Re: over 30 radiusd processes

2009-10-09 Thread Alan DeKok
4494 (20091009) __ The message was checked by ESET Smart Security. http://www.eset.com __ Information from ESET Smart Security, version of virus signature database 4494 (20091009) __ The message was checked by ESET Smart Security. http://www.eset.com