radiusd.conf[9] Failed to link to module 'rlm_eap'

2005-11-11 Thread Daniel Frankovic
Hi, I have a problem: radiusd.conf[9] Failed to link to module 'rlm_eap': /usr/local/lib/ rlm_eap-1.0.2.so: cannot make segment writable for relocation: Permission denied I have tried with freeradius 1.0.5 same problem Can anyone help me? Daniel - List info/subscribe/unsubscribe? See

Freeradius for securing wlan in big installation

2005-11-11 Thread Thomas Widhalm
Hi everyone! I'm searching for a way to secure our wireless Lan with encryption, but we don't want any sort of authentication. This is, because we have another way of authenticating our users (a webportal, they have to log in, before getting access to the wlan) What we want is an encrypted wlan

Re: Freeradius for securing wlan in big installation

2005-11-11 Thread Josh Howlett
Hi Thomas, What you're asking for is not possible, with any combination of existing technologies. Drop the web portal, and use an 802.1X supplicant. FreeRADIUS does this well :-) best regards, josh. Thomas Widhalm wrote: Hi everyone! I'm searching for a way to secure our wireless Lan

RE: Freeradius for securing wlan in big installation

2005-11-11 Thread Jonathan De Graeve
Its possible with SSL-VPN Just use your SSL-VPN appliance as the captive-portal page (with help from a router) In this way, clients with different oses can login (you always need authentication) and have a ssl-vpn where all traffic goes over J. -- Jonathan De Graeve Network/System

virtual domains as realms

2005-11-11 Thread Marko Dinic
Hello, I have the following setup on my system: In LDAP i have: dc=mydomain,dc=com | |---ou=Virtual Domains || |---dc=domain1.com || ||---uid=john ||---uid=mike ||---uid=peter | |---dc=domain2.com

RE: freeradius wont let realms based auth

2005-11-11 Thread Andres Pazos
thanks again!. I already understand the diference between accounting and authentication. I have a freeradius server (1.0.5), a MySQL server and an SQL server (with different databases). what i need to do is, i.e.: User sends radius request (i.e.: radtest [EMAIL PROTECTED] password server

How to allow user login only from one ip?

2005-11-11 Thread Tarasov Alexey
Hello! I'm using FreeRadius for accounting. For example we have user: testAuth-Type:=Local, User-Password == test How to allow user login only from one ip? -- Best regards, Tarasov Alexey. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius wont let realms based auth

2005-11-11 Thread Alan DeKok
Andres Pazos [EMAIL PROTECTED] wrote: I already understand the diference between accounting and = authentication. Your earlier messages did not make that clear, which is why I asked. if realm is wireless, i want radius to authenticate the user using MySQL. if realm is dhcp, i want radius

Re: virtual domains as realms

2005-11-11 Thread Alan DeKok
Marko Dinic [EMAIL PROTECTED] wrote: and add each of these virtual domains to proxy.conf as realms, it works like a charm... However, You don't need to add the realms to proxy.conf. You should be able to use hints, instead: DEFAULT User-Name =~ @(.*)$ Realm := ${1} Remove the

Re: radiusd.conf[9] Failed to link to module 'rlm_eap'

2005-11-11 Thread Alan DeKok
Daniel Frankovic [EMAIL PROTECTED] wrote: I have a problem: radiusd.conf[9] Failed to link to module 'rlm_eap': /usr/local/lib/ rlm_eap-1.0.2.so: cannot make segment writable for relocation: Search google. The answer is there. Alan DeKok. - List info/subscribe/unsubscribe? See

RE: freeradius wont let realms based auth

2005-11-11 Thread Andres Pazos
thanks again. im really sorry about mistakes i've made. i was trying to say authorize instead of authenticate, then: if realm is wireless, i want radius to authorize the user using MySQL. if realm is dhcp, i want radius to authorize the user using the SQL server. - users file # Except

Re: freeradius wont let realms based auth

2005-11-11 Thread Alan DeKok
Andres Pazos [EMAIL PROTECTED] wrote: My problem is that after reading the users file and getting a Match, when Radius enters the authorize seccion it never read the subsection autz-Type SQL2 { sql2 }. what's wrong with that?. thanks alan! I think the problem is that your story keeps

Re: accounting question

2005-11-11 Thread Alan DeKok
Chuck [EMAIL PROTECTED] wrote: would it also do the same thing if I removed the simultaneous-use=1 check statement from the user group? No. That's enforcement, not accounting. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: freeradius wont let realms based auth

2005-11-11 Thread Andres Pazos
thanks anyway!. -Original Message- From: [EMAIL PROTECTED] on behalf of Alan DeKok Sent: Fri 11/11/2005 4:18 PM To: FreeRadius users mailing list Subject: Re: freeradius wont let realms based auth Andres Pazos [EMAIL PROTECTED] wrote: My problem is that after reading the users file

Ascend-Data-Filters

2005-11-11 Thread Eric Gregory
I am having an issue that hopefully someone can help with. I am trying to configure my radius server to send liethe following reps Ascend-Data-Filterwhen a user authenticates. Ascend-Data-Filter = ip in forward tcp est Ascend-Data-Filter = ip in forward dstip xxx.xxx.xxx.4/32

Announce: ARA v.0.3 released.

2005-11-11 Thread Dawid Ciężarkiewicz
ARA is OpenSource web application written in PHP. It's goal is to create simple but convenient solution for managing the FreeRADIUS server. It resides on web server and connects to FreeRADIUS' database to allow easy and efficient manipulation of users, groups, network access servers and more.

Proxy replies not getting to/past proxy

2005-11-11 Thread Kristina Pfaff-Harris
Hi, all. First, let me say that if the answer to this is in the lists or the docs or rlm_whatever.c, please let me know. I've been searching for a few days, but either I'm not using the right queries to find my answer, or it's not there. (Ain't that always the way?) :-) We recently upgraded

Re: Proxy replies not getting to/past proxy

2005-11-11 Thread Alan DeKok
Kristina Pfaff-Harris [EMAIL PROTECTED] wrote: The problem is that with FR 0.8.1, our custom Radius attributes were getting sent back to the proxy and applied to the user. As soon as we implemented 1.0.5, this does not happen and all users are assigned a generic PPP profile regardless of

Re: Proxy replies not getting to/past proxy

2005-11-11 Thread Kristina Pfaff-Harris
On Fri, 11 Nov 2005, Alan DeKok wrote: Are the attributes being received by the proxy? If so, which module is deleting them? Debug mode should tell you more... Hrm. Good question. I guess I assumed they were since they were before. I'll see if I can get with the MegaPOP folks and find

possible bug in rlm_preprocess parsing of huntgroups?

2005-11-11 Thread Christopher Carver
The scenario is complicated. I will try to keep this as short and simple as possible. We are experiencing odd and different behavior when we modify just the order of the huntgroups being built in raddb/huntgroups. Nothing else is changed, just the ordering. FreeBSD 5.3-RELEASE w/

assigning a vlan-id after successful authentication

2005-11-11 Thread Sven Juergensen
hello people, how does the above mentioned work? i am not quite sure where to start. is it embedded in the 'Reply-Message' or does it have to do with the tunnel-types? i'm trying to supply a vlan-id to an hp2626 with mac-based authentication. couldn't find this in the faq or relevant conf-files

Re: Ascend-Data-Filters

2005-11-11 Thread Bill Brunton
I have in my default section: Ascend-Data-Filter = ip in forward tcp dstip 2xx.2xx.4x.x/32 dstport = 25, Ascend-Data-Filter = ip in forward tcp dstip 2xx.2xx.4x.x/32 dstport = 25, Ascend-Data-Filter = ip in forward tcp dstip 2xx.2xx.4x.xx/32 dstport = 25,

Re: Ascend-Data-Filters

2005-11-11 Thread Christopher Carver
You need to be using the += operator. man 5 users in the operators section. Ascend-Data-Filter += ip in forward tcp dstip 2xx.2xx.4x.x/32 dstport = 25, Ascend-Data-Filter += ip in forward tcp dstip 2xx.2xx.4x.x/32 dstport = 25, Ascend-Data-Filter += ip in forward tcp