RE: auth from cisco to freeradius msql

2004-12-07 Thread Lim Han Shyong
Hi: Haha, never mind.. i also just a newbie... just feel your situation i also face before last time. Just try to share... haha.. ok lah, sorry for cant help. C yeah. HSL -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Frog Sent: Tuesday,

RE: Check Multiple Calling-Station-Id in mysql

2004-12-07 Thread Lim Han Shyong
Hi: There might be other better method, me use a simple stupid method, maybe can have a try. +++++--+ | id | GroupName | Attribute | op | Value|

Re: authentication fails with peap when proxied

2004-12-07 Thread Andree Toonk
Alan, .-- My secret spy satellite informs me that at 6-12-2004 21:06 Alan DeKok wrote: rlm_realm: Looking up realm test.nl for User-Name = [EMAIL PROTECTED] rlm_realm: Found realm test.nl rlm_realm: Adding Stripped-User-Name = test Why are you stripping the username AGAIN? I thought

Index on MCC/MNC

2004-12-07 Thread Phil Reilly
Hi there, Does anybody know how to configure free radius to return attributes based on the 3GPP-SGSN-MCC-MNC parameter. Thanks Phil

Re: ADSL Accounting

2004-12-07 Thread Mike Smith
I am having trouble with usage based statistics because freeradius stores its Acct-Input-Octets and Acct-Output-Octets octets in an integer. The RFC's specifiy that those attributes go into a 32-bit integer in the RADIUS packet. FreeRADIUS is therefore limited by the RFC's. Understood.

Re: ADSL Accounting

2004-12-07 Thread Kostas Kalevras
On Tue, 7 Dec 2004, Mike Smith wrote: Anyone know a way round it other than me writing a daemon that collects the data and then passes it to freeradius afterward. Collects *what* data? You just said that the provider wasn't sending Gigawords attributes to you. Why would another daemon be

Re: ADSL Accounting

2004-12-07 Thread Mike Smith
Anyone know a way round it other than me writing a daemon that collects the data and then passes it to freeradius afterward. Collects *what* data? You just said that the provider wasn't sending Gigawords attributes to you. Why would another daemon be able to do something that FreeRADIUS

Undefined symbol with eaptls / freeradius 1.0.1 (debian)

2004-12-07 Thread Julien CABESSUT
Hello, I'm trying to set up a freeradius server on a debian box to authenticate wireless users. The current debian (sid) package for 1.0.1 doesn't include eap_tls, eap_ttls, nor eap_peap due to licensing issues - yet I needed them. So I downloaded the source package, removed the three lines in

RE: Check Multiple Calling-Station-Id in mysql

2004-12-07 Thread Anson Rinesmith
-Original Message- From: [EMAIL PROTECTED] [mailto:freeradius- [EMAIL PROTECTED] On Behalf Of Nurul Faizal M.Shukeri Sent: Tuesday, December 07, 2004 4:52 PM To: [EMAIL PROTECTED] Subject: Check Multiple Calling-Station-Id in mysql Hi to all, I'm using freeradius 1.0.1. I'm

Experience of use

2004-12-07 Thread Neil Craig
Hi Can anyone who has Freeradius running in a production environment comment on how stable it is with 100's (1000's?) of users? Do you see a marked degradation of service when lots of people are authenticating and accounting being sent? I have a system set up in a test environment which is

Re: Undefined symbol with eaptls / freeradius 1.0.1 (debian)

2004-12-07 Thread Paul Hampson
On Tue, Dec 07, 2004 at 03:16:47PM +0100, Julien CABESSUT wrote: I'm trying to set up a freeradius server on a debian box to authenticate wireless users. The current debian (sid) package for 1.0.1 doesn't include eap_tls, eap_ttls, nor eap_peap due to licensing issues - yet I needed them.

Re: Experience of use

2004-12-07 Thread Kostas Kalevras
On Tue, 7 Dec 2004, Neil Craig wrote: Hi Can anyone who has Freeradius running in a production environment comment on how stable it is with 100's (1000's?) of users? Do you see a marked degradation of service when lots of people are authenticating and accounting being sent? I have a system set up

Re: Experience of use

2004-12-07 Thread Dustin Doris
I use freeradius to authenticate about 200,000 users for various services, all connecting to an ldap backend. We use radrelay on our 4 radius servers to send a copy of all accounting data to one server that stores it in sql. Its been incredibly stable, we've actually never touched our failover

Re: Experience of use

2004-12-07 Thread Jason Frisvold
On Tue, 07 Dec 2004 14:44:47 +, Neil Craig [EMAIL PROTECTED] wrote: Hi Can anyone who has Freeradius running in a production environment comment on how stable it is with 100's (1000's?) of users? Do you see a marked degradation of service when lots of people are authenticating and

Re: Index on MCC/MNC

2004-12-07 Thread Alexander Serkin
Phil Reilly wrote: Hi there, Does anybody know how to configure free radius to return attributes based on the 3GPP-SGSN-MCC-MNC parameter. this param is not defined in any dictionary file. If you know its format, then add it to the dictionary and enjoy. Is it described anywhere? Thanks

RE: Experience of use

2004-12-07 Thread Anson Rinesmith
I have it running in a production environment as both actual RADIUS and a PROXY server. 10,000 users and I see no difference from when I had it in a test environment with 10 users. P3 667 w/256Mb RAM. -Original Message- From: [EMAIL PROTECTED] [mailto:freeradius- [EMAIL PROTECTED] On

RE: Index on MCC/MNC

2004-12-07 Thread Phil Reilly
Hi I have defined it in the 3GPP dictionary file attribute 18, but I am unsure on how to configure the check on this parameter Phil -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alexander Serkin Sent: 07 December 2004 14:55 To: [EMAIL PROTECTED]

Re: Index on MCC/MNC

2004-12-07 Thread Alexander Serkin
What's the problem with check? Something like 3GPP-SGSN-MCC-MNC == blahblah or 3GPP-SGSN-MCC-MNC =~ ^startswith or 3GPP-SGSN-MCC-MNC =~ endswith$ should work if this a string attribute. It depends on what you want. -- als Phil Reilly wrote: Hi I have defined it in the 3GPP dictionary file

RE: Index on MCC/MNC

2004-12-07 Thread Phil Reilly
I have this in radiusd.conf checkval { item-name = 3GPP-SGSN-MCC-MNC check-name = 3GPP-SGSN-MCC-MNC data-type = string notfound-reject = yes } -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

Re: authentication fails with peap when proxied

2004-12-07 Thread Stefan . Neis
Hi, Andree Toonk schrieb: Don't strip the username. Doing so will break EAP, and MS-CHAP, as you are discovering. But how should I fix this? User are know as test and not as [EMAIL PROTECTED] Then change that. If the user uses [EMAIL PROTECTED], any change you make to the

Re: PEAP-EAP-MSCHAPv2

2004-12-07 Thread Alan DeKok
Bilal Shahid [EMAIL PROTECTED] wrote: 1- I keep getting the following error rlm_eap_mschapv2: Response contains contradictory length 0 54 while using PEAP-EAP-MSCHAPv2 to authenticate the XSupplicant with FreeRADIUS. Following is the partial lof from FreeRADIUS run in debug mode: You

Re: Experience of use

2004-12-07 Thread Alan DeKok
Neil Craig [EMAIL PROTECTED] wrote: Can anyone who has Freeradius running in a production environment comment on how stable it is with 100's (1000's?) of users? It is deployed today in multiple sites with millions of users. Do you see a marked degradation of service when lots of people are

sql_groupcmp called as an accounting query?

2004-12-07 Thread Jason Lixfeld
I've been messing around with trying to get huntgroup access working with SQL. I've made some headway, but I'm seeing something mighty strange. Specifically, the line below which reads: rlm_sql (sql_acct): - sql_groupcmp I have my sql.conf configured to check accounting on one sql server

the client must send it

2004-12-07 Thread Luiz Gustavo Anflor Pereira
Hello all I want o verify if my client is sending some attributes. If it is not, the request must be rejected. I want the client always to send its NAS-Port-Type, I have tried with the checkval option in radiusd.conf, but it has not worked. So I am trying to change the code. I was looking in

Max-Monthly-Session

2004-12-07 Thread Neil Craig
Hi If I use Max-Monthly-Session - does it reset on the 1st of every month or a month from when applied? Sorry if the answer is really obvious :/ Thanks Neil - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

migrating external programs from xtradius to freeradius

2004-12-07 Thread L.C. \(Laurentiu C. Badea\)
As the subject says, I am currently using xtradius in production with external programs for authentication and accounting. Freeradius is very similar in its handling of external scripts, but has its own peculiarities which made things a bit more complicated than they should be: Xtradius puts

Re: the client must send it

2004-12-07 Thread Alan DeKok
Luiz Gustavo Anflor Pereira [EMAIL PROTECTED] wrote: I want the client always to send its NAS-Port-Type, I have tried with the checkval option in radiusd.conf, but it has not worked. Why not use the users file? So I am trying to change the code. I was looking in auth.c, maybe using the

Re: Max-Monthly-Session

2004-12-07 Thread Alan DeKok
Neil Craig [EMAIL PROTECTED] wrote: If I use Max-Monthly-Session - does it reset on the 1st of every month or a month from when applied? The first of every month. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: migrating external programs from xtradius to freeradius

2004-12-07 Thread Alan DeKok
L.C. (Laurentiu C. Badea) [EMAIL PROTECTED] wrote: Freeradius converts the attribute names to make them more like standard sh variables. It also wraps the string values in double quotes, such that echo ${USER_NAME} yields username. The first issue is a result of deciding that '-' is a magic

Re: Max-Monthly-Session

2004-12-07 Thread Neil Craig
[EMAIL PROTECTED] 07/12/2004 21:34:20 Neil Craig [EMAIL PROTECTED] wrote: If I use Max-Monthly-Session - does it reset on the 1st of every month or a month from when applied? The first of every month. Alan DeKok. Thank you!!! - List info/subscribe/unsubscribe? See

RE: Experience of use

2004-12-07 Thread Mitchell, Michael
Yeah, I don't think you'll have any problem. In our development environment (Solaris 9 on a V240) I've had freeRADIUS with an openLDAP backend (500,000 users in LDAP) handling close to 500 authentication requests per second. The limiting factor in that case was my client software, which could only

Re: sql_groupcmp called as an accounting query?

2004-12-07 Thread Jason Lixfeld
Figured it out and have it all working now. I'm going to contribute some documentation revisions in the next few days on the huntgroup interoperability with mysql as well as how to use multiple mysql servers for purposes other than for configurable failover. On Dec 7, 2004, at 12:36 PM,

Re: migrating external programs from xtradius to freeradius

2004-12-07 Thread Paul Hampson
On Tue, Dec 07, 2004 at 12:40:41PM -0800, L.C. (Laurentiu C. Badea) wrote: Xtradius uses Auth-Type = External, freeradius appears to need Auth-Type = Accept with an external script. Not a big deal, just thought I should mention it because it is somewhat less intuitive (since after all, you

installaion problem

2004-12-07 Thread Spades
While installing Freeradius 1.0.1, i managed to run ./configure, however.. I'm unable to run 'make' in my Fedora Core 2. gives me error Any idea what went wrong? -- gmake[6]: Entering directory `/home/software/freeradius-1.0.1/src/modules/rlm_ippool' gmake[6]: Leaving directory

Re: installaion problem

2004-12-07 Thread Paul Hampson
On Wed, Dec 08, 2004 at 12:53:48PM +0800, Spades wrote: While installing Freeradius 1.0.1, i managed to run ./configure, however.. I'm unable to run 'make' in my Fedora Core 2. gives me error Any idea what went wrong? -- Making static dynamic in rlm_krb5... gmake[6]: Entering directory

Freeradius installation problem

2004-12-07 Thread vamsikv
I have tried to install freeradius version freeradius-snapshot-20040607.tar.gz in two Linux 8.0 versions .I have been able to install in one system but in another system i got error after giving make .Below i am printing just a part of the error message .My doubt is why the problem did not occur