No dynamic IP address after authentication

2004-04-13 Thread Roemen, J.
Title: No dynamic IP address after authentication Hi guys, Where are using the latest Freeradius CVS snapshot. After succesfull authentication with EAP-TTLS de client doesn't get an IP address from our DHCP server. This problem only occurs with PCMCIA cards (3com and SMC). Another PC with

Thank you !I have a problem :about freeradius

2004-04-13 Thread zhang linbao
First ,Thanks you for seeing it ! Now ,I have a problem my version is openssl-0.9.7c + freeradius-snapshot-20031124 to implement PPTP ,TLS/TTLS . NOW ,tls/ttls has work well ,but when pptp client choose 128 bit encrypt ,it can sucessed to be authenticated ,it can have a virtual IP address .but

EAP/TLS general question

2004-04-13 Thread Rinaldo Bergamini
Hi everbody! I have a freeradius eap/tls working setup and now my sake is having different routing for different users-classes. By example, I need that a student of my campus isn't able to access subnets accessible by professors. I need to differentiate policies by the content of certificates

Re: Authentication only with username and password

2004-04-13 Thread Alan DeKok
Robert Baron [EMAIL PROTECTED] wrote: Yesterday I asked list if there is a way to setup a radius authentication without encrytion stuff. I have no clue what that means. Maybe you could be more specific. The aim is to get a authentication process validated only through username and

Re: EAP/TLS will not load on FreeBSD

2004-04-13 Thread Alan DeKok
Mike Newell [EMAIL PROTECTED] wrote: The error says that it fails to load ttls, not tls. When I look at the modules in the modules directory I see that mschapv2, peap, and ttls are not there; in fact even though the radius config file has them in it they don't appear to exist in the source

RE: Dynamic VLAN

2004-04-13 Thread Stadler Karel
Is attribute Tunnel-Private-Group-ID really supported by Cisco ? Please see this link ? http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuratio n_guide_chapter09186a008014ee11.html#53974 -Original Message- From: Alan DeKok [mailto:[EMAIL PROTECTED] Sent: Dienstag,

Re: Dynamic VLAN

2004-04-13 Thread Frederic . EVRARD
[EMAIL PROTECTED] wrote: Thx David, i've tried your config, but freeradius doesn't accept IEEE-802 value attibute for Tunnel-Medium-Type, it needs only 802. No. It will interpret the 802 as a number. Use IEEE-802. Sorry Alan, but here's the log when conf is Tunnel-Medium-Type =

RE: Dynamic VLAN

2004-04-13 Thread Frederic . EVRARD
yes this attribute is accepted an needed by Cisco switch : http://www.cisco.com/en/US/products/hw/switches/ps646/products_configuration_guide_chapter09186a008014f342.html It's for IOS 12.1 on cisco 3550. Your link is for IOS 12.2 Is attribute Tunnel-Private-Group-ID really supported by Cisco ?

Re: EAP/TLS will not load on FreeBSD

2004-04-13 Thread Mike Newell
On Tue, 13 Apr 2004, Alan DeKok wrote: aland Mike Newell [EMAIL PROTECTED] wrote: aland The error says that it fails to load ttls, not tls. When I look at aland the modules in the modules directory I see that mschapv2, peap, and aland ttls are not there; in fact even though the radius config

Re: Proxying PEAP/MSCHAP

2004-04-13 Thread Bob McCormick
/10.140.24.12/pre-proxy-detail -20040413' rlm_detail: /usr/local/var/log/radius/radacct/%{Client-IP-Address}/pre-proxy- detail-%Y%m%d expands to /usr/local/var/log/radius/radacct/10.140.24.12/pre-proxy-detail -20040413 modcall[pre-proxy]: module pre_proxy_log returns ok for request 0 modcall

Re: problems with ldap + ssl + eap-ttls

2004-04-13 Thread David Hart
[EMAIL PROTECTED] 4/9/2004 9:37:16 PM David Hart [EMAIL PROTECTED] wrote: I assume this is due to an openssl problem, so as an experiment I compiled freeradius to use the current openssl libraries for all modules (configure --with-openssl-libraries=... --with-openssl-includes=...). Did you

Session/User Limits Per Profile

2004-04-13 Thread David Barker - 4d Hosting
Hi, It is possible to limit the maximum number of users (or sessions) allowed online in each profile? For example, we have Profile 1 with a user limit of 10 and Profile 2 with a user limit of 5 - So that when there are 10 users online (or 10 sessions open) for Profile 1 it'll just reject the

Re: Proxying PEAP/MSCHAP

2004-04-13 Thread Bob McCormick
Sorry, I guess my description was a little vague. I want to handle on EAP types on the proxy radius server, but send the inner MS-CHAP request to another radius server. PEAP is the only one listed in my config right now just because it's the only one I've been testing with (I'm trying to

random generated prepaid accounts management

2004-04-13 Thread Milver S. Nisay
anyone here could give advise on an open source software that would be helpful on generating random dialup accounts to be used as prepaid accounts, that would be done in a single click? the open source software might work together with my running MySQL+freeradius under FC1? (just to avoid the

Re: random generated prepaid accounts management

2004-04-13 Thread Guy Fraser
That would depend on what you intend on clicking. If it was a mouse button on a website or application, then it would be possible. If it was a button on a POS terminal, then it may be possible. If it was a ball point pen, then probably not. :-) Milver S. Nisay wrote: anyone here could give

Re: Converting Detail and Auth Detail file in Mysql Format

2004-04-13 Thread Guy Fraser
I have a program written in C, that produces configurable CVS output from detail files. I developed it for an ISP, so it is not free, but if you are interested contact me directly and we can discuss the details. Julien freeradius wrote: Hello, I have got a problem with an hard drive, some

client.conf and proxy.conf

2004-04-13 Thread Htin Hlaing
Hi, I assume we need to bounce the FreeRadius server when changes are made to any config files. I am interested more in the config files which might be changed frequently such as client.conf and proxy.conf. Has anyone got expereince in this area, so the changes can take place dynamic without

Re: client.conf and proxy.conf

2004-04-13 Thread Alan DeKok
Htin Hlaing [EMAIL PROTECTED] wrote: I assume we need to bounce the FreeRadius server when changes are made to any config files. I am interested more in the config files which might be changed frequently such as client.conf and proxy.conf. Has anyone got expereince in this area, so the

exec-program-wait - scripts are not executing

2004-04-13 Thread mel
A simple test script: echo hello rad.txt acct_users: testuser Password == test123 Exec-Program = sh /home/radius/test.sh It does not produce the rad.txt. tesh.sh has the correct permission and it is executable. Leaving out the sh to just /home/radius/test.sh also gives no result. radiusd in

Re: exec-program-wait - scripts are not executing

2004-04-13 Thread Doug Hardie
Are you sure you are looking in the right directory? Since you didn't specify the full path, it uses whatever it has as a working path at that point. It may not be one that is obvious. Try specifying the complete path. Also run it by hand to be sure the permissions are correct. On Apr 13,

Re: exec-program-wait - scripts are not executing

2004-04-13 Thread mel
Doug Hardie wrote: Are you sure you are looking in the right directory? Since you didn't specify the full path, it uses whatever it has as a working path at that point. It may not be one that is obvious. Try specifying the complete path. Also run it by hand to be sure the permissions are

VoIP emulator

2004-04-13 Thread mel
My apologies if this is not the correct list to ask: May I know if there's any any VoIP emulator software the will emulate the behavior of VoIP gateways for testing purposes? I'm looking for something like NTRadPing, but one that can send VSAs that are used for VoIP. Regards, --mel - List