different secret keys per APN

2004-06-17 Thread Pedro Sousa
Hello, hope you can help me on this, I'm new freeradius, but I have set-up different secret keys for different GGSNs going to the same Radius server. Is it possible to have different secret key on APN level? to have different secret keys for two different APNs going from the same GGSN to the

cdr

2004-06-17 Thread Gulen Buyukbayram
Hi, I need to configure free radius so that I can generate CDR and send them to an external database. Does anyone have any idea about how I can do this? thanks in advance Gulen - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Trouble with IP Address Allocation

2004-06-17 Thread Kostas Kalevras
On Thu, 17 Jun 2004, Dave Shepherd wrote: All, I've got a problem that I currently can't seem to solve, through the docs or google that I hope you can help me with. I'm in the process of setting up a freeradius server which is currently acting as a proxy from an unknown BT radius

RE: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Kostas Kalevras
On Thu, 17 Jun 2004, Pate Mark-marpate1 wrote: -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alexander Serkin Sent: 17 June 2004 09:01 To: [EMAIL PROTECTED] Subject: Re: rlm_ippool and NAS-Port missing in access-request There is a

Re: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Alexander Serkin
Kostas Kalevras wrote: On Thu, 17 Jun 2004, Pate Mark-marpate1 wrote: rlm_ippool needs the nas-port-id to work. In the future the search key will be configurable. For now you could configure your NAS to also send the accounting-session-id in the access-request: radius-server attribute 44

Solution for Auth-Problem

2004-06-17 Thread Markus Ebel
Hi, i tried but i can´t find a solution of my auth-problem. i try to connect to our Ascend Max2000 by a Windows-Client with username and password and i´cant get it working Here is the debug. -- freeradius Debug -- rad_recv: Access-Request packet from host

Re: cdr

2004-06-17 Thread Thor Spruyt
- Original Message - From: Gulen Buyukbayram [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Thursday, June 17, 2004 1:56 PM Subject: cdr Hi, I need to configure free radius so that I can generate CDR and send them to an external database. Does anyone have any idea about how I can do

Re: Solution for Auth-Problem

2004-06-17 Thread Thor Spruyt
My best guess is that the passwords are stored encrypted at the radius server, which will never work since CHAP is one-way encyption. You have 2 options: - use CHAP and store passwords unencrypted at the radius server - use PAP and store passwords encrypted at the radius server. Regards, Thor.

Re: cdr

2004-06-17 Thread Gulen Buyukbayram
Hi again, I think I could not make myself clear. Let me explain my problem further. I do not have VoIP, instead, I want to simulate it and create CDRs, then observe their formats and write a billing algorithm.Hence, I need to have a test tool which creates dummy CDRs. Then, I think I can see the

Re: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Alexander Serkin
Alexander Serkin wrote: ... Thank you, Kostas. that's what i was looking for. Can you give an example of attr_rewrite block to copy attributes? The explanations in radiusd.conf are not quite clear for me :) My acct-session-id comes with value D47761550033DDC3 for example. I've also copied CLID

Re: copying accounting

2004-06-17 Thread Alan DeKok
Alexander Serkin [EMAIL PROTECTED] wrote: Ok. I can use radrelay. But. I do not understand the reason why the replicate-to-realm is being removed from server. It made the server more complicated and prone to failure. There are two operators now wich we have roaming agreements with. But

Re: different secret keys per APN

2004-06-17 Thread Alan DeKok
Pedro Sousa [EMAIL PROTECTED] wrote: hope you can help me on this, I'm new freeradius, but I have set-up different secret keys for different GGSNs going to the same Radius server. Is it possible to have different secret key on APN level? GGSN? APN? English? Alan DeKok. - List

Re: Solution for Auth-Problem

2004-06-17 Thread Alan DeKok
Markus Ebel [EMAIL PROTECTED] wrote: users: Matched DEFAULT at 5 modcall[authorize]: module files returns ok So... what's that DEFAULT? rlm_chap: Could not find clear text password for user testuser Yup. It couldn't find a password. It seems that the freeradius can't read the

Re: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Alan DeKok
Alexander Serkin [EMAIL PROTECTED] wrote: My acct-session-id comes with value D47761550033DDC3 for example. I've also copied CLID (15 digits) into NAS-Port attribute because it's missing in request. 15 digits is more than 2^32, so it won't fit into a the integer value for NAS-Port.

(no subject)

2004-06-17 Thread Maqbool Hashim
Is it possible to get a Windows Domain Controller to authenticate via radius? Has anyone got this working? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

dialup_admin/sql using postgresql

2004-06-17 Thread apellido jr., wilfredo p.
mysql -h mysql.host.com -u username -p radius badusers.sql this is for MYSQL. what about POSTGRESQL? i tried this cat mtotacct.sql | psql radius and i got this : ERROR: syntax error at or near "(" at character 44 thanks

authentication based on caller-id

2004-06-17 Thread Gene Cohen
Hi, I am a new user so forgive my ignorance on this issue Is there a method of authorization based on caller-id (ANI) ? I can see that the ani get's to the server in the debug logs. Any advice would be appreciated, gene - List info/subscribe/unsubscribe? See

Re: authentication based on caller-id

2004-06-17 Thread Aquiles Cohen Llanes
Gene Cohen wrote: Yes You may use Calling-Station-Id Attibute Aquiles Cohen Hi, I am a new user so forgive my ignorance on this issue Is there a method of authorization based on caller-id (ANI) ? I can see that the ani get's to the server in the debug logs. Any advice would be appreciated, gene

LDAP groups send reply

2004-06-17 Thread Rivera, Denis
Hello, I would like to know if this is possible Send a Class or Filter-Id attribute to the NAS, with the content being the names of the LDAP groups to which the user belongs. Thank you, denis - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: LDAP groups send reply

2004-06-17 Thread Dustin Doris
Hello, I would like to know if this is possible Send a Class or Filter-Id attribute to the NAS, with the content being the names of the LDAP groups to which the user belongs. Thank you, denis How does the NAS expect the group to come back? Class: - List info/subscribe/unsubscribe?

Re: LDAP groups send reply

2004-06-17 Thread Dustin Doris
Hello, I would like to know if this is possible Send a Class or Filter-Id attribute to the NAS, with the content being the names of the LDAP groups to which the user belongs. Thank you, denis How does the NAS expect the group to come back? Class: Sorry, I guess I hit send

Newbie

2004-06-17 Thread Juan Antonio Ibañez Santorum
Hello!   Ive been reading FreeRadius documentation but I dont understand meaning of users file. If we have: 1234567890  Auth-Type := Local, Password ==1234567890   h323-credit-amount=10,   h323-return-code=0, What is the meaning of h323 attributes? Do they tell that answers

Re: Newbie

2004-06-17 Thread Alan DeKok
=?iso-8859-1?Q?Juan_Antonio_Iba=F1ez_Santorum?= [EMAIL PROTECTED] wrote: What is the meaning of h323 attributes? Do they tell that answers to radius client will carry these attributes with 10 and 0 values? Yes. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: LDAP groups send reply

2004-06-17 Thread Kenneth Grady
That's probably a bad idea. It would take to long to authenticate if you have a lot of groups. You can send a reply item: users file ... DEFAULT (your check items here) Filter-Id = profile=switch_profile_name, ... On Thu, 2004-06-17 at 11:16, Rivera, Denis wrote: Hello, I would like to

web interface

2004-06-17 Thread Marco Marques
Hello all , I am using freeradius with mysql , is there any web interface that i can use to add and delete ( manage ) the user accounts in the sql server? Best regards Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: web interface

2004-06-17 Thread Joel Eddy
webmin url http://www.webmin.com Sincerely, Joel Eddy Iowa Connect, Inc. http://www.iowaconnect.com Ph. 641-456-5964 Fax 641-456-5912 - Original Message - From: Marco Marques [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Thursday, June 17, 2004 4:22 PM Subject: web interface Hello

Re: dialup_admin/sql using postgresql

2004-06-17 Thread Guy Fraser
Check the mailing list archives, or google for dialup admin postgres schema I have supplied postgres compliant commands for dialup admin a number of times in the past. I currently have my development machine in pieces so I can't provide the information anew. apellido jr., wilfredo p. wrote:

eap tls configuration problem

2004-06-17 Thread Heath Partington
Has the issue where freeradius crashes when tls is enabled due to the lack of ability to find ssl libraries and includes at configuration time been fixed?  I have hit this issue recently with both the 1.0.0 pre1 and 1.0.0 pre2 source.   I know of the workaround posted by Tarun Bhushan 3/21/04 -

Re: Rate limit radius requests

2004-06-17 Thread Guy Fraser
Matthew Schumacher wrote: Alan DeKok wrote: Gary McKinney [EMAIL PROTECTED] wrote: From following this thread I am wondering how many transactions a second can a DB handle successfully perform before the system starts to lose information??? That depends on the DB. Oracle is fast, PostGreSQL is

cvs latest does not compile

2004-06-17 Thread Htin Hlaing
Hi, I just downloaded the cvs latest and did configure successfully, but make would fail from the first step going into libltdl. Htin gmake[1]: Entering directory `/data/home/hhlaing/FreeRadius/buildversion/radiusd/libltdl' gmake[1]: *** No rule to make target `all'. Stop. gmake[1]: Leaving

Re: Unknown Clients

2004-06-17 Thread prabhdeep
Hi, Could you please post your configuration file... as its not working for me its only in clients.conf? is there any change in radius.conf? I am using 0.93 version. Thanks Prabh [EMAIL PROTECTED] (Alan DeKok) wrote in message news:[EMAIL PROTECTED]... Timothy Tan [EMAIL PROTECTED] wrote:

Re: computer authentication from windows

2004-06-17 Thread Michael Griego
With EAP-TLS, the machine will attempt to use a certificate that resides in the Local Computer's Personal Certificates store. With PEAP, the machine will attempt to use the machine credentials as negotiated with the domain controller. --Mike On Thu, 2004-06-17 at 18:26, Brian Craft wrote: Can

DHCP using rlm_ippool and Cisco 2500 Series NAS.

2004-06-17 Thread Shannon Sariman
Hi Folks, I'd like to know the process involved in setting up DHCP on my FreeRadius server instead of using a Cisco 2500 NAS to do the dynamic IP assignment. At the moment I am using a Cisco 2500 NAS to do the dynamic IP assignment. If I am going to use rlm_ippools in my radiusd.conf file,

RE: eap tls configuration problem

2004-06-17 Thread Sathish Challa
Heath, Here are it may be possible solution. Please follow as it is the EAP-TLS HOW-TO guide, that is available at www.freeradius.org. Once you are done with that you can install new free-radius version- pre2 too and able to run that. I have done in the same way. And got

Re: rlm_sqlcounter query parameter

2004-06-17 Thread nsinit
Hello it is possible to define the query parameter in sqlcounter.conf? %k = %b = I just want to specify the date where the AcctSessionTime will be compute(SUM). I think i will be ok. I have modified the accounting_stop_query in sql.conf, instead of '%S' for a static

rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Alexander Serkin
hello again. The problem is that Cisco PDSN (NAS for 3G CDMA networks) does not send any NAS-Port attributes in its Access-Request: RADIUS(0022F081): Send to unknown id 21797/240 212.119.96.62:1812, Access-Request, len 131 RADIUS: authenticator C4 5F D4 5B EB C5 68 69 - 16 78 96 A7 5B A7 69 C3

RE: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Pate Mark-marpate1
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alexander Serkin Sent: 17 June 2004 08:30 To: Freeradius-Users Subject: rlm_ippool and NAS-Port missing in access-request hello again. The problem is that Cisco PDSN (NAS for 3G CDMA networks)

Re: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Alexander Serkin
There is a command. Something like radius-server attribute nas-port, but it does not work for now. The IOS Release is the last for this kind of hardware. And i'll definitely open a case with Cisco regarding this problem. But this is not a subject for the freeradius-users. I wonder if i could fix

RE: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Pate Mark-marpate1
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alexander Serkin Sent: 17 June 2004 09:01 To: [EMAIL PROTECTED] Subject: Re: rlm_ippool and NAS-Port missing in access-request There is a command. Something like radius-server attribute

RE: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Pate Mark-marpate1
Hi Alexander, Presumably you'll be moving to the 7609? My understanding is that FreeRadius uses the NAS-Port-ID as an increment to a base IP address to provide the client IP address. The Cisco GGSN has a constant NAS-Port-ID, so it would make sense that when you raise this with Cisco,

RE: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Pate Mark-marpate1
I used only NAS-PortNAS-IP-Address with radclient and it seem enough to allocate an IP from the pool: Sending Access-Request of id 69 to 127.0.0.1:1812 User-Name = [EMAIL PROTECTED] User-Password = xx Calling-Station-Id = 25009702749 Framed-Protocol =

Re: rlm_ippool and NAS-Port missing in access-request

2004-06-17 Thread Alexander Serkin
Pate Mark-marpate1 wrote: I used only NAS-PortNAS-IP-Address with radclient and it seem enough to allocate an IP from the pool: Sending Access-Request of id 69 to 127.0.0.1:1812 User-Name = [EMAIL PROTECTED] User-Password = xx Calling-Station-Id = 25009702749 Framed-Protocol = PPP

Trouble with IP Address Allocation

2004-06-17 Thread Dave Shepherd
All, I've got a problem that I currently can't seem to solve, through the docs or google that I hope you can help me with. I'm in the process of setting up a freeradius server which is currently acting as a proxy from an unknown BT radius server to a Microsoft IAS server authenticating