Re: Setting Acct-Interim-Interval for all users

2012-01-31 Thread Alan DeKok
Nataniel Klug wrote: Is it possible to setup this parameter as a default for all clients using my Radius? See raddb/acct_users Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: How to Restrict All Users from Certain APs

2012-01-31 Thread Alan DeKok
White III, Joe wrote: Based on the debug output down below, could I do the following in the users file?: DEFAULT User-Password == letmelook Airespace-Wlan-Id = 4 Fall-Through = No No. Put the Airespace attribute on the first line. See man users And use

Decoding complex CableLabs-Event-Message

2012-01-31 Thread Laurent Debacker
Hi, We would like to use FreeRadius to decode Cablelabs accounting messages, as specified in http://www.cablelabs.com/packetcable/downloads/specs/PKT-SP-EM-I12-05812.pdf . FreeRadius has a CableLabs dictionary, which works fine, but... The value of one of the AVP, CableLabs-Event-Message, is

Re: Decoding complex CableLabs-Event-Message

2012-01-31 Thread Alan DeKok
Laurent Debacker wrote: We would like to use FreeRadius to decode Cablelabs accounting messages, as specified in http://www.cablelabs.com/packetcable/downloads/specs/PKT-SP-EM-I12-05812.pdf. Why do people do that? It's ridiculous. FreeRadius has a CableLabs dictionary, which works fine,

Re: Decoding complex CableLabs-Event-Message

2012-01-31 Thread Alan DeKok
Laurent Debacker wrote: We would like to use FreeRadius to decode Cablelabs accounting messages, as specified in http://www.cablelabs.com/packetcable/downloads/specs/PKT-SP-EM-I12-05812.pdf. After reading that spec... those guys are crazy. They invented their own format, and didn't even use

Question about WARNING in rlm_sql_mysql

2012-01-31 Thread Krzysztof Grobelak
Hello all, Can somebody shed some light what the 'You probably need to lower min' means. I just installed fresh freeradius from git. All my settings are the same as in the last version but apart from the radiusd -X not working (but the radiusd -lxx -l stdout is) radius.log displays this

Re: Question about WARNING in rlm_sql_mysql

2012-01-31 Thread Fajar A. Nugraha
On Tue, Jan 31, 2012 at 4:31 PM, Krzysztof Grobelak kgrobe...@airspeed.ie wrote: Hello all, Can somebody shed some light what the 'You probably need to lower min' means. I just installed fresh freeradius from git. All my settings are the same as in  the last version but apart from the radiusd

Re: Question about WARNING in rlm_sql_mysql

2012-01-31 Thread Alan DeKok
Krzysztof Grobelak wrote: Can somebody shed some light what the 'You probably need to lower min' means. See raddb/modules/sql in the latest git repository. The values and functionality are documented there. I just installed fresh freeradius from git. All my settings are the same as in

RE: Mixed Environment Question

2012-01-31 Thread Paul Stewart
The user session authenticates and receives their IP address, accounting packets start etc - all part of a normal session. but the Juniper MX logs an entry such as this: Jan 30 13:12:19 lab-mx80 jpppd: NACK received for profile request with id=3f55d50 from dcd daemon: Generic conf read

RES: Setting Acct-Interim-Interval for all users

2012-01-31 Thread Nataniel Klug
Thank you Alan. -- -Mensagem original- De: freeradius-users-bounces+listas.nata=cnett.com...@lists.freeradius.org [mailto:freeradius-users- bounces+listas.nata=cnett.com...@lists.freeradius.org] Em nome de Alan DeKok Enviada em: terça-feira, 31 de janeiro de 2012 04:37

Re: Question about WARNING in rlm_sql_mysql

2012-01-31 Thread Alan DeKok
Krzysztof Grobelak wrote: I did lower it, as it recommends but i did not have to do it in previous versions and I wanted to understand what has changed in the new release. Read raddb/mods-available/sql Really. You managed to edit that file. This means you saw the comments in that file

Joining Active Directory Domain

2012-01-31 Thread Gilmour, Scott
Hi, I am following the FreeRadius Beginners Guide book on how to join a domain. I keep on getting this error when running the command. root@FreeRadius:/etc# net ads join -U Administrator Enter Administrator's password: Using short domain name -- SQA Joined 'FREERADIUS' to realm 'SQA.net'

Re: Joining Active Directory Domain

2012-01-31 Thread Alan DeKok
Gilmour, Scott wrote: I have checked the clock, added the dns forward lookup zone to the AD Doman. Add the AD Server to the resolv.conf and etc/hosts files. I am able to ping both servers. Weird. Try following my guide: http://deployingradius.com/ I haven't heard of any

Segmentation Fault in 2.1.12 - rlm_eap-2.1.12.so

2012-01-31 Thread DaveA
FreeRadius has been stable for about a month, up until yesterday, and I have not changed the configuration of the server. I began seeing segmentation faults as seen below: #grep radiusd /var/log/messages Jan 30 15:53:03 radius1 kernel: radiusd[14764]: segfault at 70 ip 7fb9d4ba81ed sp

Using different realm in the same server

2012-01-31 Thread Gabriele Brosulo
Hi all, I'm trying to use different realm into the same server, but I probably miss something. I just want to check my users in radcheck table as user@realm, but I can't get it working. here you are my radcheck table mysql select * from radcheck where username like 'tesths%';

Re: Segmentation Fault in 2.1.12 - rlm_eap-2.1.12.so

2012-01-31 Thread Alan DeKok
DaveA wrote: FreeRadius has been stable for about a month, up until yesterday, and I have not changed the configuration of the server. I began seeing segmentation faults as seen below: See doc/bugs for how to help debug problems. I have not included my radiusd -X because it will need to be

Re: Joining Active Directory Domain

2012-01-31 Thread Phil Mayers
On 01/31/2012 03:32 PM, Gilmour, Scott wrote: Hi, I am following the FreeRadius Beginners Guide book on how to join a domain. I keep on getting this error when running the command. root@FreeRadius:/etc# net ads join -U Administrator Enter Administrator's password: Using short domain name --

Re: Joining Active Directory Domain

2012-01-31 Thread Alan Buxey
And your system time is too far from that of the AD. Ensure you are sync'd eg with ntpdate or ntpd alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Newbie and Sqlippool

2012-01-31 Thread Antonio Modesto
Hi, I am trying to test sqlippool on freeradius, but i've found that the documentation explains very well how to implement it, but it doesn't explain very well how I can set a user or a group to use this pool. Can someone explain me how can I do this? i've set up a pool called 'main_pool' in

Joining Active Directory Domain

2012-01-31 Thread Gilmour, Scott
Hi, I am following the FreeRadius Beginners Guide book on how to join a domain. I keep on getting this error when running the command. root@FreeRadius:/etc# net ads join -U Administrator Enter Administrator's password: Using short domain name -- SQA Joined 'FREERADIUS' to realm

Re: Newbie and Sqlippool

2012-01-31 Thread Alan DeKok
Antonio Modesto wrote: I am trying to test sqlippool on freeradius, but i've found that the documentation explains very well how to implement it, but it doesn't explain very well how I can set a user or a group to use this pool. Set: update control { Pool-Name :=

Verifying you are Joining the Active Directory Domain

2012-01-31 Thread Gilmour, Scott
Hi, Still can't figure out why the clock is skewed since both my Ubuntu and Active Directory server are showing the same time and Date. My Ubuntu server is an NTP Server but when I issue the command net time system I get this error Can't contact server (null). Error

Re: Verifying you are Joining the Active Directory Domain

2012-01-31 Thread Alan DeKok
Gilmour, Scott wrote: Hi, Still can't figure out why the clock is skewed since both my Ubuntu and Active Directory server are showing the same time and Date. My Ubuntu server is an NTP Server but when I issue the command net time system I get this error Can't contact server (null).

Re: Verifying you are Joining the Active Directory Domain

2012-01-31 Thread Matthew Newton
On Tue, Jan 31, 2012 at 08:54:40PM +, Gilmour, Scott wrote: It looks like it joined the domain # net ads testjoin will tell you if you're joined or not - you should get Join is OK. but when I do a wbinfo -u it gives me an error message: Error looking up domain users.

Member of Group Check Else REJECT

2012-01-31 Thread Neville Collins
Hi, I'm trying to check if a user coming from a particular NAS, then check in that user is also a member of a GROUP associated to that NAS, else REJECT access. Authorise sectionŠ.. if(NAS-Identifier == 'OpenVPN' SQL-GROUP == 'openvpn') { update reply { Reply-Message :=