Re: Getting DD-WRT to work with FreeRadius and LEAP authentication

2013-06-04 Thread Jouni Malinen
to test. Huh.. LEAP should not really be used for number of reasons (not secure, not a compliant EAP method).. Does anyone have experience getting LEAP to work with DD-WRT and FreeRadius? Assuming DD-WRT uses hostapd as the authenticator, it does not support LEAP. The LEAP design is a horrible

Getting DD-WRT to work with FreeRadius and LEAP authentication

2013-06-02 Thread Kostya
different configurations but nothing seems to help. Basically nothing happens after the Access-Challenge message is sent to the router. Does anyone have experience getting LEAP to work with DD-WRT and FreeRadius? Thanks in advance. Below is the log: --- SNIP -- rad_recv: Access-Request packet

Re: Getting DD-WRT to work with FreeRadius and LEAP authentication

2013-06-02 Thread Alan DeKok
don't. Does anyone have experience getting LEAP to work with DD-WRT and FreeRadius? FreeRADIUS sends LEAP to the DD-WRT, which forwards it to the client PC. If the client PC doesn't respond, then FreeRADIUS and DD-WRT aren't responsible. Alan DeKok. - List info/subscribe/unsubscribe? See http

Re: Getting DD-WRT to work with FreeRadius and LEAP authentication

2013-06-02 Thread Kostya
after the Access-Challenge message is sent to the router. Then the issue isn't FreeRADIUS. It's the client PC. Are you sure it supports LEAP? Most don't. Does anyone have experience getting LEAP to work with DD-WRT and FreeRadius? FreeRADIUS sends LEAP to the DD-WRT, which forwards

sql checkval Operator which work with Value comma (,)

2013-04-10 Thread EasyHorpak.com
and many NAS to check. I setup multi hotspot. so I have 10 hotspot and have 10 billing plans (GroupName) per Hotspot. I try to use Operators += but it is not work. Thank in advance to all expert. -- EasyZone Hotspot Billing

Re: sql checkval Operator which work with Value comma (,)

2013-04-10 Thread Arran Cudbard-Bell
On 10 Apr 2013, at 08:15, EasyHorpak.com i...@easyhorpak.com wrote: Dear All Jesus Fuck, what the hell are those hideously coloured blinking things at the bottom of your email. You're trying to advertise using your signature?! Have you any idea how completely inappropriate that is on a

Re: sql checkval Operator which work with Value comma (,)

2013-04-10 Thread EasyHorpak.com
On 10/04/2556 19:20, Arran Cudbard-Bell wrote: On 10 Apr 2013, at 08:15, EasyHorpak.com i...@easyhorpak.com wrote: Dear All Jesus Fuck, what the hell are those hideously coloured blinking things at the bottom of your email. You're trying to advertise using your signature?! Have you any idea

Re: help:freeradius + ldap + cisco ap can not work

2012-11-09 Thread Matthew Newton
, is not clear text. You need clear text passwords or NTLM (NT-Password) for mschap to work. http://deployingradius.com/documents/protocols/compatibility.html Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester

Privileges cisco-avpair = shell:priv-lvl=10 doesn't work

2012-10-12 Thread Ruben Blendeman
Hi, I want assign different privileges to users, these are my users: admin Cleartext-Password := admin cisco-avpair = shell:priv-lvl=15 user1Cleartext-Password := user1 cisco-avpair = shell:priv-lvl=10 user2Cleartext-Password := user2

Re: Privileges cisco-avpair = shell:priv-lvl=10 doesn't work

2012-10-12 Thread Øystein Gyland
work on later versions of IOS without the latter attribute though). [0] http://www.cisco.com/en/US/tech/tk59/technologies_configuration_example09186a0080178a51.shtml -- Øystein Gyland - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

suffix not work for me

2012-09-27 Thread Tony Peña
hi again... i try to get suffix work but i guess missing something... here some debugs and confs rad_recv: Access-Request packet from host 10.10.64.67 port 16829, id=53, length=208 Framed-Protocol = PPP User-Name = *usert...@my.domain.cu* User-Password = *secret

Re: suffix not work for me

2012-09-27 Thread alan buxey
Hi,         User-Name = [1]usert...@my.domain.cu okay.. [preprocess]   hints: Matched DEFAULT at 36 ++[preprocess] returns ok and what is in your hints file? ++- policy filter_username returns ok and what is in this policy? alan - List info/subscribe/unsubscribe? See

Re: suffix not work for me

2012-09-27 Thread Tony Peña
i put the hint file more below after radiusd -X.. check again please... i miss policyfilter... i send again both. /etc/freeradius/hints DEFAULT Suffix == @my.domain.cu, Strip-User-Name = Yes Hint = userdefault, Service-Type = Framed-User, Framed-Protocol = PPP, /etc/freeradius/policy.conf

Re: suffix not work for me

2012-09-27 Thread Fajar A. Nugraha
On Thu, Sep 27, 2012 at 10:34 PM, Tony Peña emperor...@gmail.com wrote: hi again... i try to get suffix work but i guess missing something... here [preprocess] hints: Matched DEFAULT at 36 [suffix] No '@' in User-Name = usertest, looking up realm NULL ---why not found '@' if is coming

Re: suffix not work for me

2012-09-27 Thread alan buxey
Hi, DEFAULT Suffix == @[1]my.domain.cu, Strip-User-Name = Yes there you go. strip-user-name = yes this means that u...@blahblah.com becomes just user do you WANT or intend to strip the user-name? If you are trying to use the suffix for other things then stripping it isnt going

Re: suffix not work for me

2012-09-27 Thread Tony Peña
I want when username is user@my.domain the suffix out @my.domain to only get: user that only need. 2012/9/27 alan buxey a.l.m.bu...@lboro.ac.uk Hi, DEFAULT Suffix == @[1]my.domain.cu, Strip-User-Name = Yes there you go. strip-user-name = yes this means that

Re: suffix not work for me

2012-09-27 Thread Tony Peña
anyway... my problem is exactly at monthlycounter because i need stripped-user-name and module stripped when try to use but in the queries use username complete including realm. 2012/9/27 Tony Peña emperor...@gmail.com I want when username is user@my.domain the suffix out @my.domain to only

Re: suffix not work for me

2012-09-27 Thread Phil Mayers
On 27/09/12 17:06, Tony Peña wrote: i put the hint file more below after radiusd -X.. check again please... i miss policyfilter... i send again both. /etc/freeradius/hints DEFAULT Suffix == @my.domain.cu, Strip-User-Name Don't do this. It doesn't work reliably, because you modify

Re: suffix not work for me

2012-09-27 Thread Tony Peña
please... i miss policyfilter... i send again both. /etc/freeradius/hints DEFAULT Suffix == @my.domain.cu, Strip-User-Name Don't do this. It doesn't work reliably, because you modify the username, which breaks some things. Stop using the hints file, and instead do something like

Re: suffix not work for me

2012-09-27 Thread alan buxey
Hi, key = User-Name     use the if { your patch} ??? either change this to Stripped-User-Name insteador if you ONLY want this to be the full realm when its NOT the realm of interest, then create a new SQL query and then wrap unlang around it eg if (%{User-Name} =~

Re: suffix not work for me

2012-09-27 Thread Tony Peña
ok.. I do some testing about new sql... and with your unlang if idea.. could be thanxs to all 2012/9/27 alan buxey a.l.m.bu...@lboro.ac.uk Hi, key = User-Name use the if { your patch} ??? either change this to Stripped-User-Name insteador if you ONLY want

Re: EAP does not work with realms

2012-06-29 Thread Iliya Peregoudov
Hello Chris, Local realms should be defined as empty in raddb/proxy.conf. E.g.: myrealm { } Your current erroneous setting realm myrealm { auth_pool = mypool } leads to stripping realm part from User-Name and proxying request to 127.0.0.1. If you want to completely ignore realm

EAP does not work with realms

2012-06-28 Thread Christopher Manigan
Hi, I am trying to get EAP MSCHAPv2 working with realms. When I authenticate without using a realm prefix, MSCHAPv2 works ok. Once I add a realm prefix in to the mix, I get radius rejection. Below is radius running in debug with a user failing to authenticate. I see this buried in the debug

FreeRadius2(certos)+cisco2950+wpa_supplicant(win7) can't work with EAP-TLS

2012-06-24 Thread 关旭
Hi! Just like the title,it work fine when I use MSCHAPV2 or MD5, But PEAP and EAP-TLS not works. I test Radius with eapol_test,It also work fine. Who can tell me the reason? WPA_supplicant config file ,Radius log, WPA_supplicant log as follow

Re: FreeRadius2(certos)+cisco2950+wpa_supplicant(win7) can't work with EAP-TLS

2012-06-24 Thread Alan DeKok
关旭 wrote: Just like the title,it work fine when I use MSCHAPV2 or MD5, But PEAP and EAP-TLS not works. I test Radius with eapol_test,It also work fine. Who can tell me the reason? The debug log you posted has the answer. In big bold letters. Read

Re: FreeRadius2(certos)+cisco2950+wpa_supplicant(win7) can't work with EAP-TLS

2012-06-24 Thread 关旭
: !! ? I don't think is this,beause my client is wpa_supplicant not MS client, and eapol_test work fine. On wpa_supplicant log,we can see: EAP-TLS: Start SSL: (where=0x10 ret=0x1) SSL: (where=0x1001 ret=0x1) SSL: SSL_connect:before/connect

Re: FreeRadius2(certos)+cisco2950+wpa_supplicant(win7) can't work with EAP-TLS

2012-06-24 Thread Alan DeKok
: !! ? I don't think is this,beause my client is wpa_supplicant not MS client, and eapol_test work fine. I guess you know better than me. Good luck solving the problem. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Can't get accounting radacct to work?

2012-04-04 Thread Tim Tyler
Freeradius experts, I am running Freeradius 2.1.10 on two different Redhat 6.2 systems. Both of them work fine. We are using ldap back end and we have no problem with client connections on either server. The problem I have is that one of my servers (64 bit on vmware) won’t give me

Re: Can't get accounting radacct to work?

2012-04-04 Thread Matthew Newton
Hi, On Wed, Apr 04, 2012 at 04:26:44PM -0500, Tim Tyler wrote: The problem I have is that one of my servers (64 bit on vmware) won’t give me accounting records for client connections in the radacct directory. The log directory is /var/log/radius/radacct. Nothing gets written in it. Check

Freeradius stopped to work

2012-02-20 Thread dorje2007
Hi after more then year my freeradius 2.1.9 stopped to work in log I have a lot of the following info: Feb 20 13:11:55 radius radiusd[12006]: WARNING: Child is hung for request 35 in component accounting module radutmp. Feb 20 13:11:56 radius radiusd[12006]: WARNING: Child is hung

Re: Freeradius stopped to work

2012-02-20 Thread Marinko Tarlać
radutmp file became to large... But to be sure, check you radius in debug mode... /usr/local/var/log/radius/radutmp On 20.2.2012 13:25, dorje2...@seznam.cz wrote: Hi after more then year my freeradius 2.1.9 stopped to work in log I have a lot of the following info: Feb 20 13:11:55

Re: Freeradius stopped to work

2012-02-20 Thread dorje2007
radutmp is not big, it has only 700kB However radwtmp has almost 700MB pet Původní zpráva Od: Marinko Tarlać mangi...@gmail.com Předmět: Re: Freeradius stopped to work Datum: 20.2.2012 13:37:16 radutmp file became to large

Re: Freeradius stopped to work

2012-02-20 Thread Alan Buxey
Hi, However radwtmp has almost 700MB are you using it - ie any of the features that require it? If not, then turn off the calls to it in accounting etc - alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius stopped to work

2012-02-20 Thread dorje2007
hi yes, i;m using accounting, but i don't know for what is the radwtmp file responsible thanks Původní zpráva Od: Alan Buxey a.l.m.bu...@lboro.ac.uk Předmět: Re: Freeradius stopped to work Datum: 20.2.2012 13:46:43 Hi

Re: Freeradius stopped to work

2012-02-20 Thread Fajar A. Nugraha
. As Alan suggested, comment-out radutmp in your sites-available/default (or whatever other virtual server you might use) -- Fajar Původní zpráva Od: Alan Buxey a.l.m.bu...@lboro.ac.uk Předmět: Re: Freeradius stopped to work Datum: 20.2.2012 13:46:43

Re: Freeradius stopped to work

2012-02-20 Thread dorje2007
Původní zpráva Od: Fajar A. Nugraha l...@fajar.net Předmět: Re: Freeradius stopped to work Datum: 20.2.2012 14:05:19 2012/2/20 dorje2...@seznam.cz: hi yes, i;m using accounting, but i don't know for what is the radwtmp

Re: Freeradius stopped to work

2012-02-20 Thread dorje2007
Původní zpráva Od: Fajar A. Nugraha l...@fajar.net Předmět: Re: Freeradius stopped to work Datum: 20.2.2012 14:05:19 2012/2/20 dorje2...@seznam.cz: hi yes, i;m using accounting, but i don't know for what

Re: Freeradius stopped to work

2012-02-20 Thread Alan Buxey
Hi, unfortunately , radius wend down again. The log is not very precise: Feb 20 14:22:44 radius radiusd[12700]: WARNING: Child is hung for request 988 in component module . Feb 20 14:22:44 radius radiusd[12700]: WARNING: Child is hung for request 990 in component module . Feb 20

Re: Freeradius stopped to work

2012-02-20 Thread Alan DeKok
the system is receiving more requests than it can handle. You need to fix it so that it can handle high volumes of traffic. Upgrade the machine, add DB indexes, do less processing work per packet. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius stopped to work

2012-02-20 Thread dorje2007
handle high volumes of traffic. Upgrade the machine, add DB indexes, do less processing work per packet. Hi, how i can fix it ? The server is virtual , 2GB RAM, 1x 3.33 GHZ CPU The server is doing almost nothing, load averaga less then one: Here is the top command: top - 17:49:36 up 25 days, 6

Re: Freeradius stopped to work

2012-02-20 Thread Alan DeKok
dorje2...@seznam.cz wrote: Hi, how i can fix it ? I don't know. It's your system. Something is blocking it. Also as i said, nothing happend more then one year, and suddenly today it has started to crash Well... find out what it's doing. Use your OS debugging tools. There could be

Re: 2.1.12 bug/change in behaviour - un-named server {} blocks no longer work?

2011-09-30 Thread Fred MAISON
Ho Phil, Could you explain the interest of un-named server ? Best regards, Fred - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: 2.1.12 bug/change in behaviour - un-named server {} blocks no longer work?

2011-09-30 Thread Alan DeKok
Fred MAISON wrote: Ho Phil, Could you explain the interest of un-named server ? The authorize, etc. sections should really be inside of a server block. It will make future functionality easier to add. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: 2.1.12 bug/change in behaviour - un-named server {} blocks no longer work?

2011-09-30 Thread Arran Cudbard-Bell
On 30 Sep 2011, at 07:58, Fred MAISON wrote: Ho Phil, Could you explain the interest of un-named server ? It's the default server for anything in clients.conf and the listen section in radiusd.conf. It's mainly in there for backwards compatibility... -Arran Arran Cudbard-Bell

Re: 2.1.12 bug/change in behaviour - un-named server {} blocks no longer work?

2011-09-29 Thread Alan DeKok
... Removing the un-named: server { } enclosing blocks makes everything work again. I haven't had time to hunt down the commit which might have changed this, but just a heads-up. I've pushed a fix sigh Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

2.1.12 bug/change in behaviour - un-named server {} blocks no longer work?

2011-09-27 Thread Phil Mayers
this is a change from 2.1.10/11 (although I was always running a pre-release i.e. a known-good commit) Removing the un-named: server { } enclosing blocks makes everything work again. I haven't had time to hunt down the commit which might have changed this, but just a heads-up. - List info

Re: Freeradius 2 + MySQL + MD5 hash don't work

2011-03-18 Thread joao...@gmail.com
Okay folks, I appreciate the help. Already managed to solve. Basically there were two details, the first was as the supplicant was trying to authenticate, it was either use MSCHAPv2, but the passwords were encrypted at the base with MD5, just like CHAP authentication would not work . By forcing

Freeradius 2 + MySQL + MD5 hash don't work

2011-03-17 Thread joao...@gmail.com
Hello, Someone already has implemented two freeradius with mysql I'm using version 2.1.10 of freeradius on a debian 6 If I try a plaintext based authentication, everything works. But if I try to do an authentication with an MD5 password, I get the message seguite: *[pap] ERROR: You set

Re: Freeradius 2 + MySQL + MD5 hash don't work

2011-03-17 Thread Phil Mayers
On 03/17/2011 08:01 PM, joao...@gmail.com wrote: *[pap] ERROR: You set 'Auth-Type = PAP' for a request that does not contain a User-Password attribute!* This is very clear: mysql select * from radgroupcheck; +++---++---+ | id | groupname | attribute | op

Re: Freeradius 2 + MySQL + MD5 hash don't work

2011-03-17 Thread joao...@gmail.com
Dear Phil, By removing this option, it tries to authenticate with EAP/MSCHAPv2, and also fails. Authentication is what I'm doing wireless network. Below is the result of debugging when I removed the Auth-Type PAP table radgroupcheck: [sql_visitantes] expand: %{Stripped-User-Name} - usql2

Re: Freeradius 2 + MySQL + MD5 hash don't work

2011-03-17 Thread Alan Buxey
Hi, [pap] ERROR: You set 'Auth-Type = PAP' for a request that does not contain a User-Password attribute! its fair enough. you've set Auth-Type = PAP why? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius 2 + MySQL + MD5 hash don't work

2011-03-17 Thread Alan Buxey
and then the password will be exposed in the EAP tunnel...et voila, it will work(tm) alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

authentication work but i got no access to the protected network

2011-01-06 Thread rogge
have any hints for me or do you need more information about the setup? thx Chris -- View this message in context: http://freeradius.1045715.n5.nabble.com/authentication-work-but-i-got-no-access-to-the-protected-network-tp3330913p3330913.html Sent from the FreeRadius - User mailing list archive

Re: authentication work but i got no access to the protected network

2011-01-06 Thread Alan Buxey
hi, you cant just do an ACCEPT or plain MD5 password with 802.1X WPA/WPA2 enterprise alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Authentication doesn't work anymore

2010-11-07 Thread snowman5840
with timestamp +2802 Ready to process requests. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authentication-doesn-t-work-anymore-tp3253866p3253866.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http

Re: Authentication doesn't work anymore

2010-11-07 Thread Alan DeKok
snowman5840 wrote: I'm going crazy with my RADIUS configuration. For some days all works. But now i can't authenticate with xp client, linux still works. It seams that it is a problem with the EAP configuration or with the certificates, but i doesn't find any error in the debug output!? See

Re: Authentication doesn't work anymore

2010-11-07 Thread snowman5840
ok i've found my failure. for testing purpose i changed the domain user und had forgotten to add the certificate to this user also. damn stupid failure. sry. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Authentication-doesn-t-work-anymore-tp3253866p3253991.html Sent

Free Radius , how to make it work with dynamic clients

2010-10-06 Thread Rajendra Hegde
Hello, I want to make free radius work with dynamic set of clients - Clients will have specific range (not just any client) - Clients will have some shared secret. Can it do 2 objectives listed above? I know there is a macro WITH_DYNAMIC_CLIENTS, But after compiling it with having

Re: Free Radius , how to make it work with dynamic clients

2010-10-06 Thread Peter Lambrechtsen
pools. On Thu, Oct 7, 2010 at 9:09 AM, Rajendra Hegde rajendra.he...@cryptocard.com wrote: Hello, I want to make free radius work with dynamic set of clients - Clients will have specific range (not just any client) - Clients will have some shared secret. Can it do 2 objectives listed

Getting groups to work, from a group file

2010-07-15 Thread Madsen.Jan JMD
Hello FreeRadius users I'm trying to get some group stuff working in freeradius I want to check a group file for witch group a user is member off, and after that send specific commands back to the radius client, on behalf of witch group the client is a member of. I can't get freeradius

Re: Getting groups to work, from a group file

2010-07-15 Thread Alan DeKok
Madsen.Jan JMD wrote: I want to check a group file for witch group a user is member off, and after that send specific commands back to the radius client, on behalf of witch group the client is a member of. I can’t get freeradius to do the correct check on my Group variable in my users file,

SV: Getting groups to work, from a group file

2010-07-15 Thread Madsen.Jan JMD
: Re: Getting groups to work, from a group file Madsen.Jan JMD wrote: I want to check a group file for witch group a user is member off, and after that send specific commands back to the radius client, on behalf of witch group the client is a member of. I can’t get freeradius to do the correct

Re: SV: Getting groups to work, from a group file

2010-07-15 Thread Alan DeKok
Madsen.Jan JMD wrote: I did change the variable to the following Etc_group module file ... Added the following to dictionary file ... Changed the users file DEFAULT NAS-IP-Address == 172.31.254.4, Radius1-Group == wcs-superadmin Cisco-AVPair +=

SV: SV: Getting groups to work, from a group file

2010-07-15 Thread Madsen.Jan JMD
meddelelse- Fra: freeradius-users-bounces+jmd=kmd...@lists.freeradius.org [mailto:freeradius-users-bounces+jmd=kmd...@lists.freeradius.org] På vegne af Alan DeKok Sendt: 15. juli 2010 14:28 Til: FreeRadius users mailing list Emne: Re: SV: Getting groups to work, from a group file Madsen.Jan JMD

Re: radius dont work

2010-07-08 Thread Alan DeKok
Aziz YÜCELEN wrote: I am setup freeradius again and not edit default configuration, I am trying configure inner-tunnel but result didn't change. How to configure inner-tunnel file for ttls thanks. You don't configure it. The default installation of the server configures it. The debug log

RE: radius dont work

2010-07-08 Thread Aziz YÜCELEN
Aziz YÜCELEN wrote: I am setup freeradius again and not edit default configuration, I am trying configure inner-tunnel but result didn't change. How to configure inner-tunnel file for ttls thanks. You don't configure it. The default installation of the server configures it.

Re: radius dont work

2010-07-08 Thread Alan DeKok
installation. Binaries, libraries, configuration files, the whole raddb/ directory. Then re-install, and don't mangle the configuration again. It's really not that hard. The documentation and web pages give *explicit* instructions for getting TTLS and PEAP to work. You have ignored those

RE: radius dont work

2010-07-08 Thread Aziz YÜCELEN
You need to delete *everything* from the current installation. Binaries, libraries, configuration files, the whole raddb/ directory. Then re-install, and don't mangle the configuration again. Alan DeKok. hi radtest is ok and output below but pc is not ; maybe pc 8021x configration

Re: radius dont work

2010-07-08 Thread Alan DeKok
Aziz YÜCELEN wrote: radtest is ok and output below but pc is not ; maybe pc 8021x configration is incorrect. How do I configure correctly it Thanks If you are not going to follow the instructions on this list, there is no point in asking questions. You have been told multiple times what

radius dont work

2010-07-07 Thread Aziz YÜCELEN
one # more byte than it should. # # We can work around it by configurably adding an extra # zero byte. cisco_accounting_username_bug = no # # Help prevent DoS attacks by limiting the number

Re: radius dont work

2010-07-07 Thread Alan DeKok
. Follow the instructions on http://deployingradius.com/. TTLS *will* work. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: radius dont work

2010-07-07 Thread Aziz YÜCELEN
Hi Sorry for my carelessness. Debug output is here and I am using eap TTLS but login not success.Please help me thanks. rad_recv: Access-Request packet from host 10.1.1.252 port 1206, id=20, length=183 User-Name = denemeNAS-IP-Address = 10.1.1.252 NAS-Port = 0

Re: radius dont work

2010-07-07 Thread Alan DeKok
. } # server inner-tunnel You have edited the default configuration and broken it. Don't do that. You need the inner-tunnel virtual server for TTLS to work. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: radius dont work

2010-07-07 Thread Aziz YÜCELEN
server for TTLS to work. I am setup freeradius again and not edit default configuration, I am trying configure inner-tunnel but result didn't change. How to configure inner-tunnel file for ttls thanks

Re: Getting PAP to work with ntlm_auth

2010-06-16 Thread Neil Prockter
On 15/06/10 07:51, Alan DeKok wrote: Neil Prockter wrote:w I want to authenticate users against Active Directory for EAP-MSCHAPv2 and PAP. PAP is for a wireless web authentication redirection service that authenticates using PAP and its PAP I'm trying to debug not MSCHAP at present. For

Re: Getting PAP to work with ntlm_auth

2010-06-15 Thread Alan DeKok
Neil Prockter wrote:w I want to authenticate users against Active Directory for EAP-MSCHAPv2 and PAP. PAP is for a wireless web authentication redirection service that authenticates using PAP and its PAP I'm trying to debug not MSCHAP at present. For that, you can configure Active

Getting PAP to work with ntlm_auth

2010-06-14 Thread Neil Prockter
Hello I want to authenticate users against Active Directory for EAP-MSCHAPv2 and PAP. PAP is for a wireless web authentication redirection service that authenticates using PAP and its PAP I'm trying to debug not MSCHAP at present. I've been following

dynamic assignment of VLANs from LDAP via freeradius to WLAN-Clients doesn't work properly

2010-05-27 Thread Meister, Frank
) after reboot of the accesspoint it doesn't work anymore. after assign all three VLANs again, one after the other, it works. has anybody an idea about what I'm doing wrong ? the command aaa authorization network default group radius from the Cisco-site I tried, but it didn't help further. Thanks

Re: dynamic assignment of VLANs from LDAP via freeradius to WLAN-Clients doesn't work properly

2010-05-27 Thread Alan DeKok
with RADIUS. after reboot of the accesspoint it doesn't work anymore. after assign all three VLANs again, one after the other, it works. This has nothing to do with RADIUS. has anybody an idea about what I'm doing wrong ? the command aaa authorization network default group radius from

Re: dynamic assignment of VLANs from LDAP via freeradius to WLAN-Clients doesn't work properly

2010-05-27 Thread Michael Schwartzkopff
it works fine. (I mean manual assigning VLANs using web-interface) after reboot of the accesspoint it doesn't work anymore. after assign all three VLANs again, one after the other, it works. Besides that this question doesn't have anything to do with this list, did you try: copy running-config

RADIUS_CLIENT_MAX_WAIT does not work

2010-03-17 Thread R C
Hi, I am testing my radius server with eapol_test that comes with the wpa_supplicant. If the radius server is down, I want the eapol_test to not give up trying to talk to the radius server. So, i set the parameter RADIUS_CLIENT_MAX_WAIT to 9 seconds and the eapol_test timeout to 1.

Re: can't get simultaneous login to work Part 1

2010-02-23 Thread J Brandon Polley
Yes I read doc/Simultaneous-Use what makes a session unique? What does the perl script need to know from the controller? We may be able to work with the script to pull that information out. We think its looking through for a cisco VPN device by default and not a wireless controller. Alan

Re: can't get simultaneous login to work Part 1

2010-02-23 Thread Alan DeKok
J Brandon Polley wrote: Yes I read doc/Simultaneous-Use what makes a session unique? The fields in the radutmp file, or the simul_count_query and simul_verify_query in the SQL configuration. What does the perl script need to know from the controller? Huh? We may be able to work

can't get simultaneous login to work Part 1

2010-02-19 Thread J Brandon Polley
get simultaneous login to work. We are trying to restrict simultaneous use to allow only one user to be logged at once. (1) Some things that we have picked up on are that the checkrad.pl perl script is not able to access the Cisco 4400 wireless controller's data properly to access

Re: can't get simultaneous login to work Part 1

2010-02-19 Thread Alan DeKok
J Brandon Polley wrote: We can't get simultaneous login to work. We are trying to restrict simultaneous use to allow only one user to be logged at once. OK... you've posted rather a lot of information. Did you read doc/Simultaneous-Use? I don't see any session aections being executed

RE: STILL Trying to get tunneling to work

2010-02-04 Thread Mike Bernhardt
Alan, A few days ago I sent you a private email to your deployingradius address. I attached a bunch of config files and log output so you could see the issues in my working 2.1.4 vs non-working 2.1.8 installations. I did not scrub the config files since it was a private email. If you want the

Re: STILL Trying to get tunneling to work

2010-02-04 Thread Alan DeKok
Mike Bernhardt wrote: I never got a response to that email, so I wanted to make sure you know I sent it. If it should go elsewhere, let me know. I received it. I'll take a look and see if I can figure out what's going on. Alan DeKok. - List info/subscribe/unsubscribe? See

RE: STILL Trying to get tunneling to work- resolved, and a question

2010-02-01 Thread Mike Bernhardt
It doesn't work referred to the original question I posted with the same subject a few weeks ago. At that time I provided debug output. I tried this configuration with 2.1.7 and 2.1.8 but it didn't work in that the request never left freeradius for the downstream server. After I installed 2.1.4

Re: STILL Trying to get tunneling to work- resolved, and a question

2010-02-01 Thread Alan DeKok
Mike Bernhardt wrote: It doesn't work referred to the original question I posted with the same subject a few weeks ago. At that time I provided debug output. Ah... that's the failed creating proxy socket issue. Weird. I tried this configuration with 2.1.7 and 2.1.8 but it didn't work

Re: STILL Trying to get tunneling to work- resolved, and a question

2010-01-29 Thread Mike Bernhardt
I found the major problem that caused my configuration to not work. This was in regards to getting freeradius to proxy EAP/PEAP to IAS servers as standard CHAP. I was using freeradius 2.1.7, and then 2.1.8 as recommended by someone. Neither worked. The solution was to back down to 2.1.4

Re: STILL Trying to get tunneling to work- resolved, and a question

2010-01-29 Thread Alan DeKok
Mike Bernhardt wrote: I found the major problem that caused my configuration to not work. This was in regards to getting freeradius to proxy EAP/PEAP to IAS servers as standard CHAP. ? That's impossible. PEAP uses a MD4 hash of the password, and CHAP uses an MD5 hash of the password. You

RE: STILL Trying to get tunneling to work- resolved, and a question

2010-01-29 Thread Mike Bernhardt
Just to clarify my questions: If one of the servers I'm proxying to is dead, is there a way to reduce the number of times freeradius tries before failing over to the next one? 2. Are there any ways to make this process more efficient, given that status check currently doesn't work

Re: STILL Trying to get tunneling to work- resolved, and a question

2010-01-29 Thread Alan DeKok
that status check currently doesn't work with the downstream servers? Since that isn't a given... I'm not sure what else to say. Testing for 2.1.8 involved *billions* of packets go through it in prixying non-proxying setups, with status checks enabled and disabled, with home servers going up

My Static IP Client conf. not work

2010-01-13 Thread Tevfik Ceydeliler
, January 12, 2010 2:15 AM To: freeradius-users@lists.freeradius.org Subject: My Static IP Client conf. not work Hi Adrian, I change the operator for Framed IP Address and Netmask. But nothing changed. Client get Access-Accept but no IP address assigned. I check it with ipconfig Regards... Tevfik

My Static IP Client conf. not work

2010-01-13 Thread Tevfik Ceydeliler
=dsl4u...@lists.freeradius.org [mailto:freeradius-users-bounces+adrian=dsl4u...@lists.freeradius.org] On Behalf Of Tevfik Ceydeliler Sent: Tuesday, January 12, 2010 2:15 AM To: freeradius-users@lists.freeradius.org Subject: My Static IP Client conf. not work Hi Adrian, I change the operator

RE: My Static IP Client conf. not work

2010-01-12 Thread Adrian Boros
Subject: My Static IP Client conf. not work Hi Adrian, I change the operator for Framed IP Address and Netmask. But nothing changed. Client get Access-Accept but no IP address assigned. I check it with ipconfig Regards...  Tevfik Ceydeliler    -Original Message- From: freeradius

My Static IP Client conf. not work

2010-01-12 Thread Tevfik Ceydeliler
-users-bounces+adrian=dsl4u...@lists.freeradius.org [mailto:freeradius-users-bounces+adrian=dsl4u...@lists.freeradius.org] On Behalf Of Tevfik Ceydeliler Sent: Tuesday, January 12, 2010 2:15 AM To: freeradius-users@lists.freeradius.org Subject: My Static IP Client conf. not work Hi Adrian, I change

My Static IP Client conf. not work

2010-01-11 Thread Tevfik Ceydeliler
Hi, I have a client, when I put this client into an IP pool everything is ok. But when I move him for framed-Ip (static IP),he can't get that IP address. Note: I use a secovid as realm and NAS is Telecom Operator (For APN) I dont know what i should check. Can you help me to start?

RE: My Static IP Client conf. not work

2010-01-11 Thread Adrian Boros
@lists.freeradius.org Subject: My Static IP Client conf. not work Hi, I have a client, when I put this client into an IP pool everything is ok. But when I move him for framed-Ip (static IP),he can't get that IP address. Note: I use a secovid as realm and NAS is Telecom Operator (For APN) I dont know what i should

My Static IP Client conf. not work

2010-01-11 Thread Tevfik Ceydeliler
: My Static IP Client conf. not work (Adrian Boros) 2. Re: rlm_sqlippool required? (John Dennis) 3. NT/LM password from LDAP (PAP works, MSCHAP doesn't). (Lech Karol Paw?aszek) -- Message: 1 Date: Mon, 11 Jan 2010 09

  1   2   3   4   5   6   >