Re: Blank Password Problem

2010-01-23 Thread Satyam Mathura
a little help here guys??? On Fri, Jan 22, 2010 at 9:58 AM, Satyam Mathura satz...@gmail.com wrote: OK i'm back to my original question. How do i get FreeRadius working with a MySQL back-end to do the following: a. Reject a user if that user is in a group which is not allowed to access

Re: Blank Password Problem

2010-01-22 Thread Satyam Mathura
to access a nas once their username is correct even if they supply a blank password. There must be a way around this. What am i doing wrong? On Thu, Jan 21, 2010 at 7:28 PM, Satyam Mathura satz...@gmail.com wrote: Quick update. Although the radius server no longer accepts blank passwords, i now

Blank Password Problem

2010-01-21 Thread Satyam Mathura
Guys, I'm experiencing a strange problem. I use FreeRadius to control cmd line access to my routers and switches and I've configured FreeRadius to use a MySQL back-end and thus far it works fine except for one condition. If i supply a blank password when authenticating, FreeRadius allows the

Re: Blank Password Problem

2010-01-21 Thread Satyam Mathura
Line 204 in my users file is the following: DEFAULT Auth-Type := Reject My MySQL databse also stores huntgroup information for the FreeRadius server. I want to reject authentication by default on all my nas devices unless the usergroup which the user belongs to is allowed to access that

Re: Blank Password Problem

2010-01-21 Thread Satyam Mathura
or needs updating? Thanks for the help guys. On Thu, Jan 21, 2010 at 6:58 PM, Bjørn Mork bj...@mork.no wrote: Satyam Mathura satz...@gmail.com writes: Line 204 in my users file is the following: DEFAULT Auth-Type := Reject You don't want that. It removes the server's ability

Re: Blank Password Problem

2010-01-21 Thread Satyam Mathura
Quick update. Although the radius server no longer accepts blank passwords, i now have a problem where users who belong to groups which are not allowed to access nas devices in certain huntgroups can now do so. Any ideas? On Thu, Jan 21, 2010 at 7:14 PM, Satyam Mathura satz...@gmail.com wrote

Re: Lock Out Users

2009-12-03 Thread Satyam Mathura
Thanks, i'll give it a try. On Wed, Dec 2, 2009 at 7:52 PM, t...@kalik.net wrote: With FreeRadius, is it possible to lock out users after a specified number of failed login attempts? Can someone please point me in the right direction. Use perl to count the number of failed attempts (and

Downloadable Access List Not Getting Applied

2009-12-03 Thread Satyam Mathura
Guys, I currently have FreeRadius working with a MySQL back-end to authenticate VPN users on my 2800 Cisco router. I have been trying to get the download-able access list feature working but am hitting a brick wall. If i enable cisco-avpair:=ipsec:inacl=185 i can see the radius server responding

Lock Out Users

2009-12-02 Thread Satyam Mathura
Hey Guys, With FreeRadius, is it possible to lock out users after a specified number of failed login attempts? Can someone please point me in the right direction. Thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html