Re: Is there a simple way to activate accounts on demand ?

2009-11-18 Thread Goke M Aruna
Play around with sql that works for radcheck and radgroupcheck(incase its a group account), create a row called acct_enable_disable. Edit your sql.conf to check the row created before authorizing user. On 11/18/09, Alan DeKok wrote: > Mazzz86 wrote: >> I'm using Freeradius on a MySQL database wi

Re: pptp + perl + freeradius???

2009-11-18 Thread Oguzhan Kayhan
>> Hello, I am using a perl script to authenticate my users for hotspots >> with >> freeradius. >> I got no problem regarding to it. >> Now i planned to move my existing vpn server to freeradius also.. >> Read some howtos about it (with poptop mostly) > > Perhaps reading freeradius documentation if

how to configure realm in freeradius

2009-11-18 Thread shivashankar
hi, sample configurations for realm in freeradius 2.1.6 regard;s shiv -- View this message in context: http://old.nabble.com/how-to-configure-realm-in-freeradius-tp26420475p26420475.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See

chap authentication problem

2009-11-18 Thread shivashankar
hi, i am new to useing Freeradius 2.1.6 and soalris 10. users file entry "moto" Auth-Type := CHAP, Cleartext-Password := "shiva" Reply-Message = "Hello shiva , %u" and what about Auth-Type := MS-CHAP. trying chap authentication.but it is showing below as Listening on au

Re: Expanding run-time variables and checking access_attr for allow

2009-11-18 Thread tnt
> The second question. > > If I put, ONLY FOR CHECK, the base_filter = > "(uniquemember=cn=nicolas.velazq...@uam.es,cn=users,dc=uam,dc=es)" the > LDAP > replies with No Such Object. But the radius authorization sends ok. > The misconfiguration of LDAP is not the question here. > The question here i

Re: pptp + perl + freeradius???

2009-11-18 Thread tnt
> Ok, I am updating my question. > I tried to make vpn work with inner-tunnel and it works via mysql without > any problems. > As i understand ms-chap asks the username to mysql. > > So, how can i use perl script instead of using mysql to authenticate??? "Just" translate rlm_mysql code to perl.

Re: Combine Proxy Answer with Local Information

2009-11-18 Thread tnt
> My problem is that the response I send to our LAC has to contain extra > information depending on the domain. Is it possible to query a local > mysql database for this extra information (these are cisco av pairs > needed to establish the tunnels between the LAC and LNS) Yes. See man unlang. > a

Re: pptp + perl + freeradius???

2009-11-18 Thread tnt
> Hello, I am using a perl script to authenticate my users for hotspots with > freeradius. > I got no problem regarding to it. > Now i planned to move my existing vpn server to freeradius also.. > Read some howtos about it (with poptop mostly) Perhaps reading freeradius documentation if you are to

Re: Unexpected "Exiting normally" 2.1.8?

2009-11-18 Thread Craig Campbell
st info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Information from ESET Smart Security, version of virus signature database 4618 (20091118) __ The message was checked by ESET Smart Security. http://www.eset.com __ Information fr

Re: Other authentication method installation after

2009-11-18 Thread Alan DeKok
Wagner Pereira wrote: > Alan, > > What I got from your website, Deploying Radius, was I can choose other > authentication method after I install freeradius using PAP. Am I right? I think the answer is "yes". > In that case, what would be the impact in a server running? What does that mean?

Re: DHCP in FR

2009-11-18 Thread Alan DeKok
Kassai Istvan wrote: > I can see in the log, the assigned client ip (rad.log), but somehow the > client doesn't use it. I think I done wrong something, but what? I don't know. Try using tcpdump on the client && server to see where the packets are going. > But it is only the first step. The nex

Re: Unexpected "Exiting normally" 2.1.8?

2009-11-18 Thread Alan DeKok
Craig Campbell wrote: > Ok, >I hope this is helpful. Below please find the git bisect log. > There were a number of iterations with make errors which I then > skipped. I suspect the errors were OS specific and were clearly fixed > in later iterations. > > -bash-3.2$ git bisect log > git bise

Re: Book About Free-Radius Configurations

2009-11-18 Thread Wagner Pereira
My apologyze to all! I swear don't write in Portuguese no more. By the way, there is service, Google Translator, that can solve this idiomatic thing : ) -- Wagner Pereira PoP-SP/RNP - Ponto de Presença da RNP em São Paulo CCE/USP - Centro de Computação Eletrônica da Universidade de São Paul

Re: Book About Free-Radius Configurations

2009-11-18 Thread Alisson
Vamos fazer o seguinte, coloquem todos os emails do pessoal que é do Brasil aqui. alisson...@gmail.com 2009/11/18 Johan Meiring > Wagner Pereira wrote: > >> Respeito sua opinião, yahmamotto. >> >> Talvez meu erro tenha sido apenas não informar o idioma que usei. Se o >> tivesse informado, era

Re: Authenticate Many Sites on dynamic IPs through One Freeradius Server

2009-11-18 Thread Johan Meiring
Alan DeKok wrote: Charles (KOL) Goma wrote: I have test-configured freeradius to work on my hotspot. It works fine and I am happy. I am planning to have about 17 of my sites authenticate through one freeradius server. These 17 HOTSPOTS are in different parts of the country and have dynamic IP

Re: Book About Free-Radius Configurations

2009-11-18 Thread Johan Meiring
Wagner Pereira wrote: Respeito sua opinião, yahmamotto. Talvez meu erro tenha sido apenas não informar o idioma que usei. Se o tivesse informado, era só copiar e colar no Google Translator pra saber o que eu disse. Mas, concordo que o Inglês é a melhor opção. Am I missing something I

Expanding run-time variables and checking access_attr for allow

2009-11-18 Thread Nicolás Velázquez
Hi all, We are running 2.1.3 and we'll upgrade soon for several reasons. Two of them can be the questions I'll explain now. We need to search the authorize check for users in one place of LDAP tree and the user password must be checked in another place. My config file is as follows: dictionary_m

Re: pptp + perl + freeradius???

2009-11-18 Thread Oguzhan Kayhan
Ok, I am updating my question. I tried to make vpn work with inner-tunnel and it works via mysql without any problems. As i understand ms-chap asks the username to mysql. So, how can i use perl script instead of using mysql to authenticate??? > Hello, I am using a perl script to authenticate my

Re: Is there a simple way to activate accounts on demand ?

2009-11-18 Thread Alan DeKok
Mazzz86 wrote: > I'm using Freeradius on a MySQL database with DialupAdmin web interface. > I would like to activate/desactivate users account on demand but i didnt > find any easy way to do it. After reading some forums, I saw some tricks > like updating the 'radcheck' table by putting "Reject" in

Re: solution---Re: Re: help--- IPsec VPN on radius

2009-11-18 Thread Bjørn Mork
Alan DeKok writes: > Yagnesh Dave wrote: >> Found the solution from one of the previous posts. >> >> http://lists.cistron.nl/pipermail/freeradius-users/2005-July/msg00273.html >> >> I just the did the same, added the below line in the dictionary file at >> /usr/local/share/freeradius/dictionary

Re: Authenticate Many Sites on dynamic IPs through One Freeradius Server

2009-11-18 Thread Alan DeKok
Charles (KOL) Goma wrote: > I have test-configured freeradius to work on my hotspot. It works fine > and I am happy. > > I am planning to have about 17 of my sites authenticate through one > freeradius server. These 17 HOTSPOTS are in different parts of the > country and have dynamic IPs. > > 1

Re: Unexpected "Exiting normally" 2.1.8?

2009-11-18 Thread Craig Campbell
__ Information from ESET Smart Security, version of virus signature database 4617 (20091118) __ The message was checked by ESET Smart Security. http://www.eset.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Combine Proxy Answer with Local Information

2009-11-18 Thread Dan Fisher | Fluidata
Hi all, I am wondering if someone will be able to point me in the correct direction with a setup I am trying to achieve. Basically we are rolling out a new offering to our customers where we want to have our LAC's query our radius servers which will then proxy requests on to our customer's r

Re: solution---Re: Re: help--- IPsec VPN on radius

2009-11-18 Thread Alan DeKok
Yagnesh Dave wrote: > Found the solution from one of the previous posts. > > http://lists.cistron.nl/pipermail/freeradius-users/2005-July/msg00273.html > > I just the did the same, added the below line in the dictionary file at > /usr/local/share/freeradius/dictionary > > VALUE Service-Type outb

Is there a simple way to activate accounts on demand ?

2009-11-18 Thread Mazzz86
Hye guys, I'm using Freeradius on a MySQL database with DialupAdmin web interface. I would like to activate/desactivate users account on demand but i didnt find any easy way to do it. After reading some forums, I saw some tricks like updating the 'radcheck' table by putting "Reject" instead of th

Re: Book About Free-Radius Configurations

2009-11-18 Thread Wagner Pereira
Respeito sua opinião, yahmamotto. Talvez meu erro tenha sido apenas não informar o idioma que usei. Se o tivesse informado, era só copiar e colar no Google Translator pra saber o que eu disse. Mas, concordo que o Inglês é a melhor opção. -- Wagner Pereira PoP-SP/RNP - Ponto de Presença da

Re: Book About Free-Radius Configurations

2009-11-18 Thread yahmamotto yahmamotto
Acho que é um pouco má onda estar a enviar mensagens para uma lista international numa lingua que só alguns entendem. Se calhar o melhor seria trocarem mensagens entre vocês apenas. Mas isto é apenas a minha opinião... 2009/11/18 Wagner Pereira > Olá, Inácio. > > Eu gostaria de encontrar um liv

solution---Re: Re: help--- IPsec VPN on radius

2009-11-18 Thread Yagnesh Dave
Hi All, Found the solution from one of the previous posts. http://lists.cistron.nl/pipermail/freeradius-users/2005-July/msg00273.html I just the did the same, added the below line in the dictionary file at /usr/local/share/freeradius/dictionary VALUE Service-Typeoutboun

Re: Crash due to fr_packet_cmp

2009-11-18 Thread Alan DeKok
Padam J Singh wrote: > Could this be some sort of a compiler optimization that may be causing > this? May be some memory barrier is required? I don't see why. All of the lookups, insertions, and deletions into the hash occur in the main processing thread. The child threads process packets th

Re: help--- IPsec VPN on radius

2009-11-18 Thread Yagnesh Dave
Hi, Found the problem, it is with the service type attribute. I am getting this error on the freeradius /usr/local/etc/raddb/users[24719]: Parse error (reply) for entry tatablue-vpn.vsnl.net: Unknown value outbound for attribute Service-Type How to rectify this problem of "outbound" service ty

Re: Algum brasileiro nessa lista?

2009-11-18 Thread Wagner Pereira
Inácio, Minha primeira experiência com freeradius foi instalá-lo junto com mysql e até consegui fazer com que ele se autenticasse na base de dados, mas não consegui me autenticar quando acessei um Cisco 6500. Desisti desse modelo e agora estou escolhendo outro. -- Wagner Pereira PoP-SP/RNP

Re: Book About Free-Radius Configurations

2009-11-18 Thread Wagner Pereira
Olá, Inácio. Eu gostaria de encontrar um livro bom sobre RADIUS também. Estou com essa responsabilidade de implementá-lo, mas tem sido difícil, já que não existe uma documentação tão bom na Internet. Um abraço, -- Wagner Pereira PoP-SP/RNP - Ponto de Presença da RNP em São Paulo CCE/USP -

pptp + perl + freeradius???

2009-11-18 Thread Oguzhan Kayhan
Hello, I am using a perl script to authenticate my users for hotspots with freeradius. I got no problem regarding to it. Now i planned to move my existing vpn server to freeradius also.. Read some howtos about it (with poptop mostly) Here is how my perl script works.. When it gets a username/pass i

help--- IPsec VPN on radius

2009-11-18 Thread Yagnesh Dave
Hi, I am trying to configure this on Free Radius; # setup for IPSec VPDN, ezvpn Password := "cisco" Service-Type = outbound, Cisco-Avpair = "ipsec:tunnel-password=cisco123", Cisco-Avpair="ipsec:tunnel-type*esp", Cisco-Avpair="ipsec:group-lock=1", Cisco-Avp

Re: Freeradius-Users Digest, Vol 55, Issue 80

2009-11-18 Thread Gilbert Lo
Thank you for your message. I am away until Nov 19th. I will respond to your message on my return . For urgent matters, please contact helpd...@stgeorges.bc.ca . Cheers, Gilbert Lo - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Crash due to fr_packet_cmp

2009-11-18 Thread Padam J Singh
Alan, Could this be some sort of a compiler optimization that may be causing this? May be some memory barrier is required? Padam Alan DeKok wrote: > fabiana marvani wrote: > >> Why is not there a protection for "null pointer" to avoid this kind of >> problem? >> > > Because the design

Re: Crash due to fr_packet_cmp

2009-11-18 Thread Alan DeKok
fabiana marvani wrote: > Why is not there a protection for "null pointer" to avoid this kind of > problem? Because the design of the server means that this crash *should* be impossible. The request packet has been placed in a hash table. The crash comes because the request data structure is

RE:Crash due to fr_packet_cmp

2009-11-18 Thread fabiana marvani
Hello Alan, Thanks so much for your answer. Below, you can find the additionally information about us problem : - which OS && CPU (32 / 64-bit) ---> CentOs 5.2 - CPU: 32 bits - which version of the server - --> 2.1.6 - which command l

Re: Book About Free-Radius Configurations

2009-11-18 Thread Alan DeKok
INACIO ALVES wrote: > I think that I saw in your blog that you is writting a book about > RADIUS. The project continues? Slowly, but I am making progress. > And about the book > http://www.amazon.com/Radius-Jonathan-Hassell/dp/0596003226/ref=pd_sim_b_3 > do you know it? I'm need to buy some boo

Re: Accessing a second AV Pair

2009-11-18 Thread Alan DeKok
Robert White wrote: > No problem! > > Anyone else have any thoughts? $ man unlang See the section on VARIABLES Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html