HELP! EAP-TLS: how can I install a cert on a workstation so that it works for all users

2009-07-14 Thread john
been authenticated by Freeradius. However when I log in to the computer under a different windows profile authentication fails. How should I create this file and where do I place this cert so that it's available for any user logging on? Please help me figure this out! Thanks! John -

Help required in defining new string Attribute

2009-07-14 Thread Ila Palanisamy
Hi, I'm new to free radius. I'm trying to assign a new string attribute for a user, but the radius server is not coming up. Can someone help me in defining new string Attribute in freeradius. I have added a new attribute Foundry-INM-Role-AOR-List as string in dictionary and I&#

Help required in defining new Attribute

2009-07-11 Thread Ila Palanisamy
Hi, I need a help in defining new Attribute in freeradius. I have added a new attribute Foundry-INM-Role-AOR-List as string in dictionary and I'm trying to set this attribute for a user. With the below configuration radius server is not coming up. Any help in resolving this issue wi

RE: Pls help: realm based proxy setting

2009-07-05 Thread ST Wong (ITSC)
>> Hi all, >> >> I'm using freeradius 2.1.3 and setting up a realm-based proxy server. >> In users file, I add line like following: >> >> >> DEFAULT Aruba-Essid-Name == "NewSSID", Realm == >> "realm1.my.domain", Proxy-to-realm := "test1.my.domain", >> aruba-user-vlan := 191 >>

Re: Pls help: realm based proxy setting

2009-07-05 Thread Ivan Kalik
> Hi all, > > I'm using freeradius 2.1.3 and setting up a realm-based proxy server. > In users file, I add line like following: > > > DEFAULT Aruba-Essid-Name == "NewSSID", Realm == > "realm1.my.domain", Proxy-to-realm := "test1.my.domain", aruba-user-vlan > := 191 > Fall-Th

Re: RadRelay help

2009-07-05 Thread Alan DeKok
Jihad Jaafar wrote: > Thank for that ok > > that's the listen part where is the part that send the acct record to > the billing server It's a normal server policy. You will need to create it. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Pls help: realm based proxy setting

2009-07-04 Thread ST Wong (ITSC)
Hi all, I'm using freeradius 2.1.3 and setting up a realm-based proxy server. In users file, I add line like following: DEFAULT Aruba-Essid-Name == "NewSSID", Realm == "realm1.my.domain", Proxy-to-realm := "test1.my.domain", aruba-user-vlan := 191 Fall-Through = 1 And t

Re: RadRelay help

2009-07-04 Thread Jihad Jaafar
Thank for that ok that's the listen part where is the part that send the acct record to the billing server Alan DeKok wrote: Jihad Jaafar wrote: reading the doc of 2.1.6 thinks have changed but I can't see what's going on please can any one help on what I need t

Re: RadRelay help

2009-07-04 Thread Alan DeKok
Jihad Jaafar wrote: > reading the doc of 2.1.6 thinks have changed but I can't see what's > going on > > please can any one help > > on what I need to do in version 2.x.x to do the same thing You need to configure a "listen" section that reads the detai

RadRelay help

2009-07-04 Thread Jihad Jaafar
I any one can Help We just upgraded from 1.1.3 to 2.1.6 and I use radrelay to pass the accounts data to my billing server using this command "radrelay -a /var/log/radius/radacct/192.168.26.251 -s ZZ -r ds9.xxx.net:1646 detailfile" reading the doc of 2.1.6 thinks have c

Re: Need help no of users and capacity load

2009-07-02 Thread parsa123
List info/subscribe/unsubscribe? See > http://www.freeradius.org/list/users.html > > > > > - > List info/subscribe/unsubscribe? See > http://www.freeradius.org/list/users.html > -- View this message in context: http://www.nabble.com/Need-help-no-of-users-and-capa

Re: Need help no of users and capacity load

2009-07-02 Thread Padam J Singh
Hello Ramesh, Capacity depends a lot on how the RADIUS server is accessing authentication stores. Are you storing these users in a LDAP or a DB? It is these resources that generally become the bottle-neck first rather than the RADIUS Server. Also, are you doing authentication and accounting (

Need help no of users and capacity load

2009-07-02 Thread ramesh p
We are going to have up to 3 million users in our radius setup in the next month. At present we are using freeradius1.1.6 in linux platform and over 1 million users. we are planning to upgrade to latest version. How the performance matter with 3 million users. Please suggest interms of load balanci

Re: Accounting help please

2009-07-02 Thread David Hobley
That would be it. Sorry to waste your time - I have asked our Cisco guy to set this up for us. Cheers, David - Original Message - From: "Chris" Still don't see any accounting packets. Did you configure a RADIUS accounting server in your NAS? You usually have to set both authentic

Re: Accounting help please

2009-06-30 Thread Chris
On Jun 30, 2009, at 10:43 PM, David Hobley wrote: Chris, When you put it like that, it does make rather a large amount of sense. Sorry about that. Login details attached. Cheers, David Still don't see any accounting packets. Did you configure a RADIUS accounting server in your NAS? Yo

Re: Accounting help please

2009-06-30 Thread David Hobley
he output from radiusd -X, any > pointers anyone could give me, I would appreciate. Might help if you included debug output which included processing of an accounting packet. Preferably a start and a stop. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html FreeRA

Re: Accounting help please

2009-06-30 Thread Chris
le or directory [r...@samba raddb]# radlast last: /var/log/radius/radwtmp: No such file or directory Might help if you included debug output which included processing of an accounting packet. Preferably a start and a stop. - List info/subscribe/unsubscribe? See http://www.freeradius.org

Accounting help please

2009-06-30 Thread David Hobley
Hello, I have freeradius2 configured and authenticating properly. I would like to be able to get radwho and radlast working properly, but for some reason the files do not get created (permission are correct in that directory). I thought I have set up accounting correctly, but obviously haven't

Re: Unlang authentication help

2009-06-25 Thread Ivan Kalik
> I'm trying to use unlang to limit LDAP user's access to different > network > devices. Here is what I have so far in the site-enable/default: > > Auth-Type LDAP { > ldap > > if(NAS-IP-Address == 10.1.1.1 && LDAP-Group == > 'RouterAdmin') { >

Unlang authentication help

2009-06-25 Thread Scott Angus
} else { reject } } How would i do that? And how would list the IP address in the files? Thanks for your help, Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Help needed : dynamic pooling not working properly

2009-06-23 Thread josgeorge thaikudathil
Hi , i am getting dynamic ip's but ip is not assigned from the pool i given .Can you please give me some suggestion i had given *ippool main_pool {* *# range-start,range-stop: The start and end ip # addresses for the ip pool range-s

Re: Please help me (Ivan Kalik)

2009-06-22 Thread josgeorge thaikudathil
Hi , Thank you very much for the response but still i am getting same error can you please suggest accordingly .I had done 3 different tries in my user file those tries and output is given below Also i more think i remember while my installation db.ippool file and db.index file

Re: Please help me

2009-06-22 Thread Ivan Kalik
> in users file > > steve Auth-Type := Local, User-Password == "testing" > Service-Type = Framed-User, > Framed-Protocol = PPP, > Framed-IP-Address = 172.16.3.33, > Framed-IP-Netmask = 255.255.255.0, > Framed-Routing = Broadcast-Listen, > Framed-Fi

Please help me

2009-06-22 Thread josgeorge thaikudathil
auth for request 0 rlm_ippool: Could not find Pool-Name attribute. modcall[post-auth]: module "main_pool" returns noop for request 0 rlm_ippool: Could not find Pool-Name attribute. I am suspecting some problem with users file ... Can you please help me to find out what is missing

Re: Cannot Authenticate - Help!

2009-06-19 Thread Filipe Scalioni
Thanks a lot Alan, I checked your site and "bob" is authenticating through RADIUS with EAP and mschapv2. That's already enough to finish my graduation work! I'll try to use your site to configure it to talk to the LDAP (Linux) that's installed on the same server. - List info/subscribe/unsubscribe?

Re: Cannot Authenticate - Help!

2009-06-18 Thread Alan DeKok
Filipe Scalioni wrote: > .. I read through it and I think that the fail is on EAP, > but I can't figure out what it is... Here is a portion of the log, cut > a little bit above where the errors begin ... > [eap] Request found, released from the list > [eap] EAP/mschapv2 > [eap] processing type msch

Re: Cannot Authenticate - Help!

2009-06-18 Thread Filipe Scalioni
conf but I was unsuccessful. Everything, except for ipaddr and port on radiusd.conf was left untouched initially. I tried to use the "NT_domain_hack" from the mschap config but it was no good too... Thanks for any help! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Cannot Authenticate - Help!

2009-06-17 Thread Ivan Kalik
> So, it works... But then I put the AP to work (Linksys wrt54g), > configured like this: > It nevers authenticates... No matter what I do. I tried everything I > could find on the list or FAQ before registering. Here goes the log This is a very old version. You shouldn't be using 1.x with EAP for

Re: [rad] Cannot Authenticate - Help!

2009-06-17 Thread Charles Gregory
thenticate]: module "unix" returns invalid for request 0 modcall: leaving group authenticate (returns invalid) for request 0 auth: Failed to validate the user. Login incorrect: [backup/] (from client Linksys port 1 cli 00-15-AF-CF-FE-DB) Delaying request 0 for 1 seconds Finished request

Cannot Authenticate - Help!

2009-06-17 Thread Filipe Scalioni
ired for authentication.   modcall[authenticate]: module "unix" returns invalid for request 0 modcall: leaving group authenticate (returns invalid) for request 0 auth: Failed to validate the user. Login incorrect: [backup/] (from client Linksys port 1 cli 00-15-AF-CF-FE-DB) Delaying re

RE: radclient: no response from server ... please help newbe.

2009-06-17 Thread Gregory Machin
response from server ... please help newbe. > I'm using the following stack FreeRADIUS Version 2.1.3 with > coova-chilli-1.0.13 with Daloradius . > > > I'm having issues with sending POD from Daloradius and radclient via the > command line Send it to NAS (coova-chill

Re: radclient: no response from server ... please help newbe.

2009-06-17 Thread Ivan Kalik
> I'm using the following stack FreeRADIUS Version 2.1.3 with > coova-chilli-1.0.13 with Daloradius . > > > I'm having issues with sending POD from Daloradius and radclient via the > command line Send it to NAS (coova-chilli), not radius server. Ivan Kalik Kalik Informatika ISP - List info/subs

Re: radclient: no response from server ... please help newbe.

2009-06-17 Thread Nicolas Goutte
Am 17.06.2009 um 13:43 schrieb Gregory Machin: Hi Please could someone help a newbe ... I'm using the following stack FreeRADIUS Version 2.1.3 with coova- chilli-1.0.13 with Daloradius . I'm having issues with sending POD from Daloradius and radclient via the command

radclient: no response from server ... please help newbe.

2009-06-17 Thread Gregory Machin
Hi Please could someone help a newbe ... I'm using the following stack FreeRADIUS Version 2.1.3 with coova-chilli-1.0.13 with Daloradius . I'm having issues with sending POD from Daloradius and radclient via the command line [r...@localhost ~]# echo "User-Name='TC-Demo

Re: NTLM Auth Help

2009-06-04 Thread Rupert Finnigan
heoretical sense and works for my environment, it needs more testing... I've attached a patch based on the diff of my two source files. Many thanks to Alan Buxey and John Dennis for your help. Rupert rlm_mschap.patch Description: Binary data - List info/subscribe/unsubscribe? See http:

Re: help HMAC-MD5

2009-06-04 Thread Alan DeKok
Marco De Magistris wrote: > Sorry, but I’m confused about HMAC-MD5 method. > > I’m working on Radius Proxy Implementation. If it's based on FreeRADIUS, then FreeRADIUS gets it right. If it's not based on FreeRADIUS, then we are *not* the global help desk for RADIUS ques

Re: help HMAC-MD5

2009-06-04 Thread Nicolas Goutte
Am 04.06.2009 um 13:39 schrieb Marco De Magistris: Hi all, Sorry, but I’m confused about HMAC-MD5 method. I’m working on Radius Proxy Implementation. The scenario is the following RADIUS Client -> Radius Proxy -> Radius Server. Radius Client sends a Radius Packet towards Radius Proxy (Mes

help HMAC-MD5

2009-06-04 Thread Marco De Magistris
Hi all, Sorry, but I'm confused about HMAC-MD5 method. I'm working on Radius Proxy Implementation. The scenario is the following RADIUS Client -> Radius Proxy -> Radius Server. Radius Client sends a Radius Packet towards Radius Proxy (Message-Authenticator not used). Radi

Re: NTLM Auth Help

2009-06-03 Thread Rupert Finnigan
Hi, Following up from this, I think I've discovered what the real problem here is. I think there's a problem with the MS-CHAP module The module looks in the username to find "host/" at the beginning, and if it does then handles it differently. Whilst it sets the "username" section correctly,

Re: NTLM Auth Help

2009-06-02 Thread A . L . M . Buxey
Hi, > Sounds good - I'll give this logic a go... Where best to place this bit of > Unlang? In the inner-tunnel Authorization stanza, before ms-chap? Would I > need to repeat in the Authentication MS-CHAP bit too, or does it get set at > the beginning of the "request session" and follow all the way

Re: NTLM Auth Help

2009-06-02 Thread Rupert Finnigan
best to place this bit of Unlang? In the inner-tunnel Authorization stanza, before ms-chap? Would I need to repeat in the Authentication MS-CHAP bit too, or does it get set at the beginning of the "request session" and follow all the way though. Suppose I could just get on and try it out! Many thanks for your help. Rupert - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: NTLM Auth Help

2009-06-02 Thread A . L . M . Buxey
Hi, > If I follow the logic as supplied by Neil, and remove the "--domain" option > then this works fine for all users in all domains, and machines in same > domain that winbind was joined to, but not machines from remote domains. If ah! multiple remote domains - not in a forest of trust? > I c

Re: NTLM Auth Help

2009-06-02 Thread Rupert Finnigan
Hi, 2009/6/2 > why? with recent versions of FreeRADIUS this just works(tm) with no > rewriting needed > - just ensure that the ntlm_auth line has the correct arguments and > you have the ntdomain stuff turned on . > > I've tried, and can't make the default work. I've got three domains with use

RE: NTLM Auth Help

2009-06-02 Thread Garber, Neal
> why? with recent versions of FreeRADIUS this just works(tm) with no > rewriting needed > - just ensure that the ntlm_auth line has the correct arguments and > you have the ntdomain stuff turned on . > > we used to have all kinds of hacky stuff in our config...almost all > of it is now wiped a

Re: NTLM Auth Help

2009-06-02 Thread A . L . M . Buxey
Hi, > We pass hostname$ to ntlm_auth by rewriting the User-Name attribute as > follows: > > > > attr_rewrite machine_UserName { > >attribute = User-Name > >searchin = packet > >searchfor = "^host/(.*).domain.name" > >re

RE: NTLM Auth Help

2009-06-02 Thread Garber, Neal
ctions before mschap. From: freeradius-users-bounces+neal.garber=energyeast@lists.freeradius.org [mailto:freeradius-users-bounces+neal.garber=energyeast@lists.freera dius.org] On Behalf Of Rupert Finnigan Sent: Monday, June 01, 2009 2:59 PM To: FreeRadius users mailing list Sub

NTLM Auth Help

2009-06-01 Thread Rupert Finnigan
Hi All, Wander if someone can help me resolve a problem I'm experiencing I'm using FreeRADIUS to provide AAA for 802.1X for wireless in a number of sites. It doesn't need to be 100% up all the time, and so I've got one server back in our central site that handles all t

Re: Unable to implement huntgroups--pls help

2009-05-23 Thread Ivan Kalik
> I want to implement huntgroup for Radius server. In this respect I want to > give access to user name test1, which authenticated via LDAP, to only one > NAS with IP 172.16.0.150. For this I have modified /etc/raddb/users file > with following data: > > > kmcuser Auth-Type :=LDAP, Huntgroup-Name =

Unable to implement huntgroups--pls help

2009-05-23 Thread Parashar Singh
I want to implement huntgroup for Radius server. In this respect I want to give access to user name test1, which authenticated via LDAP, to only one NAS with IP 172.16.0.150. For this I have modified /etc/raddb/users file with following data: kmcuser Auth-Type :=LDAP, Huntgroup-Name == "kmc1"

Re: help me: proxing towards 2 different networks

2009-05-19 Thread Alan DeKok
Marco De Magistris wrote: >1. Radius Client sends packets towards Radius Proxy (from 192.168.1.2 > to 192.168.1.3) >2. Radius proxy listen on 192.168.1.3 for authentication packet and > forwarding them towards two different network (192.168.14.4 and > 192.168.24.4) > > Ca

help me: proxing towards 2 different networks

2009-05-19 Thread Marco De Magistris
Hi all, Thanks in advance for your help. Here is our Scenario which is working now: 1. Radius Client sends packets towards Radius Proxy (from 192.168.1.2 to 192.168.1.3) 2. Radius proxy listen on 192.168.1.3 for authentication packet and forwarding them towards two

Re: Problems with IP address allocation, help needed

2009-05-15 Thread Ramm-Ericson, Johannes
a.l.m.bu...@lboro.ac.uk wrote: >Hi, > >> OK, fair enough, I can agree that that is what it looks like. Trouble is >> though that CBJN is listed together with GLANA in the post-auth section >> where the ippools are configured. So, for some reason the server is not >> acknowledging that part of the c

Re: freeradius packets thresholds | help

2009-05-15 Thread ramesh p
cond > >> using > >> MySQL. > >> > >> > >> > >> Tim > >> > >> > >> > >> *From:* freeradius-users-bounces+tim.sylvesteretworkradius.com@ > >> lists.freeradius.org > >> [mailto:freeradius-users-bounces+tim.syl

Re: freeradius packets thresholds | help

2009-05-15 Thread Ivan Kalik
org >> [mailto:freeradius-users-bounces+tim.sylvester >> etworkradius@lists.freeradius.org] *On Behalf Of *ramesh p >> *Sent:* Thursday, May 14, 2009 9:18 PM >> *To:* FreeRadius users mailing list >> *Subject:* freeradius packets thresholds | help >>

Re: freeradius packets thresholds | help

2009-05-15 Thread ramesh p
ists.freeradius.org >> [mailto:freeradius-users-bounces+tim.sylvester >> =networkradius@lists.freeradius.org] *On Behalf Of *ramesh p >> *Sent:* Thursday, May 14, 2009 9:18 PM >> *To:* FreeRadius users mailing list >> *Subject:* freeradius packets threshold

Re: Help Regarding Freeradius Server Inactivity and client access

2009-05-15 Thread pushpraj nimbalkar
On Thu, May 14, 2009 at 6:58 PM, Ivan Kalik wrote: >>    I have working  Freeradius(freeradius-2.1.3-1.fc10.i386) server >> with Mysql and chillispot. I just want to know what should happen when >> user is authenticated and after few time freeradius server stops >> working(due to any reason). In m

Re: freeradius packets thresholds | help

2009-05-14 Thread ramesh p
dius.com@ > lists.freeradius.org > [mailto:freeradius-users-bounces+tim.sylvester > =networkradius@lists.freeradius.org] *On Behalf Of *ramesh p > *Sent:* Thursday, May 14, 2009 9:18 PM > *To:* FreeRadius users mailing list > *Subject:* freeradius packets thresholds | help >

Re: freeradius packets thresholds | help

2009-05-14 Thread Alan DeKok
ramesh p wrote: > Hi All, > > Does anybody have an idea , how many transactions the FreeRADIUS server > can handle on a per second, minute, and hourly basis. How fast can a car go? That depends... See doc/performance-testing Alan DeKok. - List info/subscribe/unsubscribe? See http://ww

RE: freeradius packets thresholds | help

2009-05-14 Thread Tim Sylvester
: freeradius-users-bounces+tim.sylvester=networkradius@lists.freeradius.or g [mailto:freeradius-users-bounces+tim.sylvester=networkradius@lists.freer adius.org] On Behalf Of ramesh p Sent: Thursday, May 14, 2009 9:18 PM To: FreeRadius users mailing list Subject: freeradius packets thresholds | help

freeradius packets thresholds | help

2009-05-14 Thread ramesh p
Hi All, Does anybody have an idea , how many transactions the FreeRADIUS server can handle on a per second, minute, and hourly basis. Thanks in advance. Thanks, Rams. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radius help

2009-05-14 Thread jon jon
I restarted server and ran radtest but still getting access reject packet. anything else I should check? Am I at least doing this the right way using the users file to make a user and see if I can get a access accept message? On Thu, May 14, 2009 at 3:34 PM, John Dennis wrote: > jon jon wrote:

Re: radius help

2009-05-14 Thread jon jon
because of this. ++[pap] returns noop no authenticate method (Auth-type) configuration found for the request: Rejecting the user Failed to authenticate the user. Using Post- Auth-Type Reject that is why I thought maybe the password was not matching. Does this help any? On Thu, May 14, 2009 at 3:2

Re: radius help

2009-05-14 Thread John Dennis
jon jon wrote: > I have am using slackware 12.1 and installed freeradius version 2.1.5. I > have read the Install and the Readme me file. I am trying the radtest > program out and I start the radius server in debugging mode in one > virtual screen and do a "radtest test test localhost 0 testing123

Re: radius help

2009-05-14 Thread Ivan Kalik
> I have am using slackware 12.1 and installed freeradius version 2.1.5. I > have read the Install and the Readme me file. I am trying the radtest > program out and I start the radius server in debugging mode in one virtual > screen and do a "radtest test test localhost 0 testing123" from another

radius help

2009-05-14 Thread jon jon
I have am using slackware 12.1 and installed freeradius version 2.1.5. I have read the Install and the Readme me file. I am trying the radtest program out and I start the radius server in debugging mode in one virtual screen and do a "radtest test test localhost 0 testing123" from another virtual

Re: help on OpenSUSE installation

2009-05-14 Thread Marcos López
Thanks Bruno, I really appreciate your help. Let me try and will let you know. Marcos Lopez - Original Message - From: Bruno Noronha To: FreeRadius users mailing list Sent: Thursday, May 14, 2009 7:06 AM Subject: Re: help on OpenSUSE installation mx5450

Re: Help Regarding Freeradius Server Inactivity and client access

2009-05-14 Thread Ivan Kalik
>I have working Freeradius(freeradius-2.1.3-1.fc10.i386) server > with Mysql and chillispot. I just want to know what should happen when > user is authenticated and after few time freeradius server stops > working(due to any reason). In my case user stays on-line even though > freeradius serve

Re: Help Regarding Freeradius Server Inactivity and client access

2009-05-14 Thread Alan DeKok
pushpraj nimbalkar wrote: >I have working Freeradius(freeradius-2.1.3-1.fc10.i386) server > with Mysql and chillispot. I just want to know what should happen when > user is authenticated and after few time freeradius server stops > working(due to any reason). Version 2.1.6 will be released

Help Regarding Freeradius Server Inactivity and client access

2009-05-14 Thread pushpraj nimbalkar
Hello All, I have working Freeradius(freeradius-2.1.3-1.fc10.i386) server with Mysql and chillispot. I just want to know what should happen when user is authenticated and after few time freeradius server stops working(due to any reason). In my case user stays on-line even though freeradius serv

Re: help on OpenSUSE installation

2009-05-14 Thread Bruno Noronha
ibmysqlclient-devel is needed by freeradius-server-2.1.4-0.x86_64 > mar...@win-219e0010bba:~> > > I read about this and regarding the dependencies it seems that some > "features" are not installed and that I need the OpenSUSE disk to load them > from the YAST. > >

Re: Problems with IP address allocation, help needed

2009-05-14 Thread A . L . M . Buxey
Hi, > OK, fair enough, I can agree that that is what it looks like. Trouble is > though that CBJN is listed together with GLANA in the post-auth section > where the ippools are configured. So, for some reason the server is not > acknowledging that part of the configuration. Sure, I may definitely

Re: Problems with IP address allocation, help needed

2009-05-14 Thread Ramm-Ericson, Johannes
Alan de Kok wrote: >Ramm-Ericson, Johannes wrote: > As (nearly) always, the debug output is instructive: > >> Following are extracts from the debug log that exemplify a working >> instance with GLANA and a failing instance with CBJN: >... >> Failing instance with CBJN

Re: Problems with IP address allocation, help needed debugging...

2009-05-14 Thread Alan DeKok
Ramm-Ericson, Johannes wrote: > There are several NASes from various vendors / service providers > connecting to my Freeradius server. I have instances of IP address > allocation managed by the vendors equipment and in some cases IP address > allocation is managed by my server. IP address managemen

Problems with IP address allocation, help needed debugging...

2009-05-14 Thread Ramm-Ericson, Johannes
Hi Freeradius-users! I've run into a problem with my Freeradius 2.1.3 installation (on Suse Linux 10 - I'll be upgrading freeradius & migrating to Ubuntu Linux server during the weekend) that I'm hoping maybe someone on this list can help me with. There are several NASes f

help on OpenSUSE installation

2009-05-12 Thread mx5450
quot;sh: apxs2-prefork: command not found" message is about or how to fix that. I'm stuck again. Could you help with this? Thanks in advance - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Please help me ...thanks in advance

2009-05-05 Thread Ivan Kalik
ed in > several > groups but did not work.Tried through PAM module. > > If some body can help me out in this matter or point to some good > links,will > be helpful to > me. http://freeradius.org/pam_radius_auth/ Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe

Please help me ...thanks in advance

2009-05-04 Thread praveen saxena
as published in several groups but did not work.Tried through PAM module. If some body can help me out in this matter or point to some good links,will be helpful to me. Best Regards Praveen - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius upgrade help

2009-04-30 Thread ramesh p
Thanks alot for your replies. On Thu, Apr 30, 2009 at 6:51 PM, Ivan Kalik wrote: > > Appreciate if some one can please forward any docs/details about the > > upgrade > > from old freeradius version 1.1.6 to 2.1.4 in linux. > > > > All the information is right there - in the configuration files.

Re: freeradius upgrade help

2009-04-30 Thread A . L . M . Buxey
Hi, > Appreciate if some one can please forward any docs/details about the upgrade > from old freeradius version 1.1.6 to 2.1.4 in linux. copy the old config to somewhere safe install version 2.1.4 now configure 2.1.4 to match the requirements you used to use in 1.1.6 - although some things have

Re: freeradius upgrade help

2009-04-30 Thread Doug Hardie
On 30 April 2009, at 06:21, Ivan Kalik wrote: Appreciate if some one can please forward any docs/details about the upgrade from old freeradius version 1.1.6 to 2.1.4 in linux. All the information is right there - in the configuration files. If parts of radiusd.conf have been moved somewhe

Re: freeradius upgrade help

2009-04-30 Thread Ivan Kalik
> Appreciate if some one can please forward any docs/details about the > upgrade > from old freeradius version 1.1.6 to 2.1.4 in linux. > All the information is right there - in the configuration files. If parts of radiusd.conf have been moved somewhere - there will be comments in radiusd.conf exp

freeradius upgrade help

2009-04-30 Thread ramesh p
Appreciate if some one can please forward any docs/details about the upgrade from old freeradius version 1.1.6 to 2.1.4 in linux. Thanks, Ramesh. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

help in radius

2009-04-30 Thread Basant Agarwal
Hello, I am installing freeradius .it is showing the error Undefined symbol "cbtls_password" . what is the problem ..?? i have installed openssl by apt-get install openssl. /usr/local/sbin/radiusd -X Starting - reading configuration files ... reread_config: reading radiusd.conf Config: includ

Re: Help with Freeradius + OpenLDAP/Samba + 802.1x WLan auth for Windows

2009-04-29 Thread Albrecht Dreß
Am 24.04.09 23:23 schrieb(en) Ivan Kalik: > rlm_eap: Identity does not match User-Name, setting from EAP Identity. Username was altered. Got it - Win sends the domain in uppercase, and I had conversion to lowercase enabled. Works fine now. Thanks, Albrecht. pgp85LHExAchz.pgp Descripti

Re: radius process dying help

2009-04-29 Thread ramesh p
Sorry for typos. One more question: how much traffic can freeradius server can manage/afford? if there are calls more than 1 lakh in number per day, will it afford? My radius server process 'radiusd' is dying due to more traffic these days frequently . That's why i want to know. On Wed, Apr 29, 2

Re: radius process dying help

2009-04-29 Thread ramesh p
One more question: how much traffic can efford freeradius version? if there are calls morethan 1 lakh in number per day will it afford? My radius server process 'radiusd' is dying due to more traffic these days. That's why i want to know. Thank you. Rams. On Wed, Apr 29, 2009 at 10:20 PM, ramesh

Re: radius process dying help

2009-04-29 Thread ramesh p
Thanks Ivan. So am stopped the server using following command: /usr/local/etc/init.d/radiusd stop Then added the supervision using inittab file. This started process as *radiusd -f -s * automatically and radiusd.pid will not updated. Any issues with this? Thanks, Ramesh. On Wed, Apr 29, 2009 a

Re: radius process dying help

2009-04-29 Thread Ivan Kalik
> I'm using freeradius version 1.1.6. My radius process 'radiusd' is dying > frequently due to mysterious reasons. So is it safe to use 'radwatch' > script > to monitor? doc/supervise-radiusd.txt Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/li

radius process dying help

2009-04-29 Thread ramesh p
I'm using freeradius version 1.1.6. My radius process 'radiusd' is dying frequently due to mysterious reasons. So is it safe to use 'radwatch' script to monitor? Thanks. Rams. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius upgrade help

2009-04-29 Thread A . L . M . Buxey
Hi, > I'm currently using freeradius version 1.1.6, planning to upgrdate to a > stable version. Please suggest a version which is stable. My radius box > running linux. compared to 1.1.6 any of the 2.1.x are more stable ;-) alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/lis

freeradius upgrade help

2009-04-28 Thread ramesh p
I'm currently using freeradius version 1.1.6, planning to upgrdate to a stable version. Please suggest a version which is stable. My radius box running linux. Thanks in advance. Regards, Rams. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread Borislav Dimitrov
Hi, As far as I can see, the people on the list have provided you with a lot of very useful suggestions on what could cause the problem. As I said earlier (let me clarify) and to help you narrow things a little bit - it's probably due to the RADIUS response timing out hence the

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, > Same box. and you do live accounting database insertions? This sounds to me very much like the classic 'tables have now grown just too big' - everything works fine then barfs one day. the request isnt getting serviced in time therefore its marking as dead..check your query times...remove wr

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
Same box. On Mon, Apr 27, 2009 at 4:57 PM, wrote: > Hi, > > Accounting server was alive and receving packets till yesterday. And > > suddenly got receiving dead alive messages. So restarted radiusd process > > then it got resolved. > > are we talking about the same box? I'm not talking about thi

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, > Accounting server was alive and receving packets till yesterday. And > suddenly got receiving dead alive messages. So restarted radiusd process > then it got resolved. are we talking about the same box? I'm not talking about this FreeRADIUS box you gave logs from, I'm talking about the box t

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
Accounting server was alive and receving packets till yesterday. And suddenly got receiving dead alive messages. So restarted radiusd process then it got resolved. However it repeating frequently once a week Unable to findout the exact reason for this. On Mon, Apr 27, 2009 at 4:38 PM, wrote

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, are you sure that the accounting server was ever alive and handling accounting packets? Those logs look exactly like they would if , for example, you were sending auth+acct to an IAS RADIUS server not configured for accounting. the RADIUS server attempts to send an accounting packet to it...

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread ramesh p
Thanks alot for providing very good suggestions. On Mon, Apr 27, 2009 at 4:12 PM, Ivan Kalik wrote: > Well, has it? Servers don't just go dead and back alive just like that. > It's much more likely that server was never dead at all. Stop looking at > NAS messages and examine why radius server di

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread Ivan Kalik
Well, has it? Servers don't just go dead and back alive just like that. It's much more likely that server was never dead at all. Stop looking at NAS messages and examine why radius server didn't respond: - did it get the request at all? Maybe your network is loosing packets. - did something else

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread Borislav Dimitrov
Why do you think that the process is stopped? It's probably sleeping which is its normal state if you're looking at the `ps`s output. About the thread pool, check the documentation. Anyways, here's what it looks like: # THREAD POOL CONFIGURATION thread pool { start_servers = 1

<    4   5   6   7   8   9   10   11   12   13   >