At FR2.1.9 this is possible?

2010-05-31 Thread ziyen
Hi at one auth request happen then FR Act as like { first check remote1 radius Server if fail second chek remote 2 radius Server if fail third check local DB of file fi fi } is't a another multi auth check method? Thaks! - List info/subscribe/unsubscribe? See

Re: At FR2.1.9 this is possible?

2010-05-31 Thread Alan DeKok
ziyen wrote: Hi at one auth request happen then FR Act as like { first check remote1 radius Server if fail second chek remote 2 radius Server See fail-over. This works only if the server is down. You *cannot* re-proxy a request if the first server returned reject. Alan

Re: Your maximum never usage time has been reached

2010-05-31 Thread Alan Buxey
Hi, Maybe it's time to read the source code for the counter module :( the documentation should be more than enough.if the rest of the config is fine, then the issue is that you are setting some attribute as a comparison ... := which would always be true. you need to set it as a value

badusers issues

2010-05-31 Thread Robert Wilkinson
i get this message from the bad users page: Database query failed: Unknown column 'incidentdate' in 'where clause' Is this something that is critical or concerning? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

freeradius-dialupadmin

2010-05-31 Thread Robert Wilkinson
Freeradius-dialupadmin Check Server page only shows: (test user dummy) Does this indicate that it isn't working correctly? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Using rml_perl to modify calling_station_id and set as sql_user_name

2010-05-31 Thread blaqb0x
Hi, I'm trying to get mac authentication to a mysql database where the mac addresses are stripped of all special characters. If I add this line to the /sql/mysql/dialup.conf file sql_user_name = %{Calling-Station-Id} the calling-station-id (username passed to mysql) is the correct mac

Re: Fwd: SSL issues

2010-05-31 Thread Martin v. Wittich
I am using a radius-openldap-EAP/TTLS|EAP/PEAP scheme and often I've got the following error from a Windows 7 client trying to connect using EAP/PEAP. Client lacked CA cert, but I've found clients that are able to import it. Finally client connected using EAP/TTLS with SecureW2. But I wonder

Re:Re: How long is the nas-table cached by freeradius?

2010-05-31 Thread Rameshbabu Ragothaman
Is this fix available now ? (freeradius server to read the change in nas-table without restart) Thanks. Evert Meulie ev...@witelcom.com wrote: Just wondering about the following: If a change is made in the nas-table of the radius-db, how long does it take for the freeradius daemon to start using

Re: Using rml_perl to modify calling_station_id and set as sql_user_name

2010-05-31 Thread Alexander Clouter
blaq...@netscape.net wrote: I'm trying to get mac authentication to a mysql database where the mac addresses are stripped of all special characters. If I add this line to the /sql/mysql/dialup.conf file sql_user_name = %{Calling-Station-Id} the calling-station-id (username passed to

EAP_TLS

2010-05-31 Thread dorra aa
hello freeradius. I used my radius by using authentication type EAP-MD5, which is based on the use of login and password. Then I tried to use EAP-TLS. So I created the certificates and I modified the file eap.con as follows:eap{ default_eap_type = tls}tls {

RE: Re: How long is the nas-table cached by freeradius?

2010-05-31 Thread Tim Sylvester
FreeRADIUS starts in seconds. I have restarted FreeRADIUS in very large production environments without a problem. If you are concerned about availability, use multiple FreeRADIUS servers and/or a load balancer (F5, Cisco, lvs, etc.). Tim From:

Re: peap/eap/mschapv2 + MySQL

2010-05-31 Thread Matt Madrid
Ok, well like I said, mysql wasn't being queried by the inner-tunnel server. Still not clear on why that was happening, but I worked around it by commenting out inner-tunnel as the virtual server to use for peap. So the default server is being used and working. er, it wasnt working when

Qugestion about Vendor-Specific Attr in EAP TTLS

2010-05-31 Thread WWF
Hello, all! I use fr 2.1.9 on ubuntu 10.04, installed from source code. Use mysql as database. Now I add a VSA in radreply, then, if a user passes the auth, the VSA will be returned back to NAS. I find that for other auth types like PAP/EAPMD5/EAPTLS, this VSA VALUE is returned in ACCESS-ACCEPT