send accounting data

2010-12-07 Thread Sokvantha YOUK
Dear All, I would like to configure freeradius server to send accounting data to other server. Could any one advice me or show me how can I achieve this method? -- YOUK Sokvantha Tell: (855) 89896589 email: sokvan...@gmail.com - List info/subscribe/unsubscribe? See

Voip database

2010-12-07 Thread miha-
Hello, I need a little help:) I am setting radius for voip. I comment sql in default file (authorize, Authentication) and I enable voip-postpaid for postgresql. I have import filw for databases in /etc/raddb/sql/postgresql/shema.sql. Please help me out! thanks! I have put users in table but I

Re: Voip database

2010-12-07 Thread Fajar A. Nugraha
On Tue, Dec 7, 2010 at 5:27 PM, miha- miha_zou...@hotmail.com wrote: Hello, I need a little help:) I am setting radius for voip. I comment sql in default file (authorize, Authentication) what do you mean you comment sql? You DO know that for it to be used, the sql module needs to be

Re: Voip database

2010-12-07 Thread miha-
I have uncomment only this # Cisco VoIP specific bulk accounting pgsql-voip under accounting section. I have not found it under authorize and authenticate. Must I put it there? Thanks! -- View this message in context:

Re: Voip database

2010-12-07 Thread Fajar A. Nugraha
On Tue, Dec 7, 2010 at 9:17 PM, miha- miha_zou...@hotmail.com wrote: I have uncomment only this #  Cisco VoIP specific bulk accounting pgsql-voip under accounting section. I have not found it under authorize and authenticate. Must I put it there? On second thought, you might not need it in

Re: Voip database

2010-12-07 Thread Fajar A. Nugraha
On Tue, Dec 7, 2010 at 9:24 PM, Fajar A. Nugraha w...@fajar.net wrote: On Tue, Dec 7, 2010 at 9:17 PM, miha- miha_zou...@hotmail.com wrote: I have uncomment only this #  Cisco VoIP specific bulk accounting pgsql-voip under accounting section. I have not found it under authorize and

Re: Need help Configuring Radius and Ldap

2010-12-07 Thread James Winter
Oh dear. A lot of the online info is out-of-date or plain wrong. If you've made a lot of changes, and you're not sure exactly what youve changed and why, my advice would be to start again from scratch. Restore the default configs, and use the following system: 1. Check the config into

Re: Attribute not passing to NAS?

2010-12-07 Thread mikal
Rob, In your eap.conf set use_tunneled_reply = yes. Assuming that it's currently set to no. Working here now after that change. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Attribute-not-passing-to-NAS-tp3289418p3295956.html Sent from the FreeRadius - User mailing

EAP-Type = SIM

2010-12-07 Thread Wagner D4rkGl0be Andre
Hi everybody, I'm trying to configure EAP-SIM test on my FreeRADIUS server, and I would like to know if is possible to validate the parameters by database as setting in the radcheck? I tested validating with the users file and all sounds good, but I'm not having the same results with just

Re: Voip database

2010-12-07 Thread Fajar A. Nugraha
On Tue, Dec 7, 2010 at 9:39 PM, Miha Zoubek miha_zou...@hotmail.com wrote: I put it there but still the same problem: No, it's not. It's a different problem. Look at the debug log you posted and you'll see it's a different problem altogether. [pgsql-voip]    expand: %{User-Name} - 081609000

Re: Attribute not passing to NAS?

2010-12-07 Thread Rob Yamry
Ive changed that setting previously and it does not work for a client connection. However, I didnt have the eapol_test util before. If I test it with the eapol_test utility now with ttls-eap-mschapv2.conf config file it works. It passes it on Filter-Id in the Access-Accept. If I use the

Re: Attribute not passing to NAS?

2010-12-07 Thread mikal
Rob, I'm doing PEAP here, and I'm assuming that your clients are also? Maybe post the output from a client connection attempt from radiusd -X. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Attribute-not-passing-to-NAS-tp3289418p3296090.html Sent from the FreeRadius

Re: Attribute not passing to NAS?

2010-12-07 Thread Rob Yamry
Just figured it out. In eap.conf under the peap section 'use_tunneled_reply = yes' needs to be set there as well. I only had it set under the ttls section before. I just tested a client and its working fine now. Thanks for all your help Mikkal! - List info/subscribe/unsubscribe? See

Re: Attribute not passing to NAS?

2010-12-07 Thread mikal
Yep, that's the file I meant. You're welcome. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Attribute-not-passing-to-NAS-tp3289418p3296126.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See

One virtual server for MS-chapv2 against AD w/ ntlm_auth, the other one against ldap ntpasswd hash possible?

2010-12-07 Thread schilling
We got ntlm_auth against AD working for PEAP, we also got separate server for PEAP against ldap ntPassword hash. in latest etc/raddb/modules/mschap # The module can perform authentication itself, OR # use a Windows Domain Controller. This configuration # directive tells

thread pools in 2.1.10

2010-12-07 Thread Keven Smith-Worthylake
Hi all, We just upgraded from freeRADIUS 1.1.7 to 2.1.10, and we're having issues getting freeRADIUS to work with a thread pool (see debug logs below). The thread pool config was working in version 1.1.7. Were there major changes on how threads were implemented from 1.1.7 to 2.1.10? Why

Re: One virtual server for MS-chapv2 against AD w/ ntlm_auth, the other one against ldap ntpasswd hash possible?

2010-12-07 Thread Alan DeKok
schilling wrote: We got ntlm_auth against AD working for PEAP, we also got separate server for PEAP against ldap ntPassword hash. ... Is there any way to have a virtual server(1812/1813) for mschapv2-ntlm_auth-AD and another virtual server(1814/1815) for mschapv2-ldap ntPassword hash?

Re: thread pools in 2.1.10

2010-12-07 Thread Alan DeKok
Keven Smith-Worthylake wrote: We just upgraded from freeRADIUS 1.1.7 to 2.1.10, and we're having issues getting freeRADIUS to work with a thread pool (see debug logs below). The thread pool config was working in version 1.1.7. I don't see a problem with thread pools. And it would be

RE: thread pools in 2.1.10

2010-12-07 Thread Keven Smith-Worthylake
When we start radiusd with a thread pool configured, none of the requests from the pam-radius-auth proxy client are serviced/processed. The client never gets a reply from the server. From the server logs, the request is never seen. I noticed that when the server is started without the thread

Re: thread pools in 2.1.10

2010-12-07 Thread Alan DeKok
Keven Smith-Worthylake wrote: When we start radiusd with a thread pool configured, none of the requests from the pam-radius-auth proxy client are serviced/processed. The client never gets a reply from the server. From the server logs, the request is never seen. Because it's not

Re: One virtual server for MS-chapv2 against AD w/ ntlm_auth, the other one against ldap ntpasswd hash possible?

2010-12-07 Thread schilling
Hi Alan, Thanks for the hint. Just to be sure. Both user(username and usern...@foo.edu) will use eap, mschapv2 to authenticate. But there is only one mschap module in etc/raddb/modules/? Regards, Schilling On Tue, Dec 7, 2010 at 3:41 PM, Alan DeKok al...@deployingradius.com wrote: schilling

Oracle OID and FreeRadius

2010-12-07 Thread Robert Masters
Okay, so we've got the whole ancient version thing sorted out, and we now have things working - sort of. To recap: We've been working on using Freeradius on RHEL5.4 to link a Motorola RFS6000 with Oracle OID. We now have the following situation - and fair warning this is something of an

Re: Oracle OID and FreeRadius

2010-12-07 Thread Fajar A. Nugraha
On Wed, Dec 8, 2010 at 9:50 AM, Robert Masters rmast...@bunnings.com.au wrote: An alternate path would be to convince FreeRadius to obtain the user-supplied password via EAP-GTC *before* connecting to OID to authenticate the user, if that is possible. (None of the doco I have read to date

RE: Oracle OID and FreeRadius

2010-12-07 Thread Robert Masters
I had forgotten about that - thanks, I'll try giving that a go. -Rob -Original Message- From: freeradius-users-bounces+rmasters=bunnings.com...@lists.freeradius.org [mailto:freeradius-users-bounces+rmasters=bunnings.com...@lists.freeradi us.org] On Behalf Of Fajar A. Nugraha Sent:

Re: One virtual server for MS-chapv2 against AD w/ ntlm_auth, the other one against ldap ntpasswd hash possible?

2010-12-07 Thread Alan DeKok
schilling wrote: Just to be sure. Both user(username and usern...@foo.edu) will use eap, mschapv2 to authenticate. But there is only one mschap module in etc/raddb/modules/? So... configure another mschap module. See raddb/modules/files for examples of configuring two instances of the

RE: Voip database

2010-12-07 Thread Miha Zoubek
I have replace voip-postpaid.conf with new one but still the same. I this configuration file (voip-postpaid.conf) is written: uthcheck_table = radcheckauthreply_table = radreply groupcheck_table = radgroupcheckgroupreply_table = radgroupreply usergroup_table =