Re: Error with radiusd -X

2006-10-05 Thread Collen Blijenberg
comment out : including file: /usr/local/etc/raddb/sql.conf including file: /usr/local/etc/raddb/sqlippool.conf or install mysql and lib's.. cheers Collen Abel Monzon wrote: Hello list, I have problem at the time to debug my radiusd, this is the log #radiusd -X Starting - reading

RE: Any luck with 802.1x authentication using TTLS with MSCHAPv2 ?

2006-10-05 Thread Mak Moussa
Hi, I would appreciate any insight into the 802.1x authentication using TTLS with MSCHAPv2. Such auth scheme is constantly failing in my wireless setup with FreeRadius. I tried 3 versions v1.0.5, v1.1.2 and v1.1.3 with not much luck. The following authentication schemes worked fine: 1. TTLS w/

ethereal log for vlan assignment

2006-10-05 Thread fhcom
Hi every body, I use Freeradius 1.0.5 under cygwin-XP with cisco switch 3550. I'd like to assign my users under vlans. I search logs caught with ethereal to compare with mine (because I don't see any information about vlan with my ethereal which can prove that vlan assignment was made).

RE: Accepting any login attempt

2006-10-05 Thread John Williams
Ok so Accept doesn't work for MS-CHAP. And I know I can grab the rejected usernames and drop them into the DB so the next time they try to auth it works. I did want to try and avoid rejecting the users and them getting fed up. Someone did mention to me that you can auth a NAS so any auth

Re: Acmepacket SBC

2006-10-05 Thread Peter Nixon
On Wed 04 Oct 2006 11:48, Pradeep Kumar wrote: Hi Everyone, I would like to configure freeRADIUS server with Acmepacket SBC (Session Border Controller). Could you please let me know whether is it possible or not? You should ask whoever makes your SBC. FreeRADIUS should work with any device

Re: Windows Vista doing PEAP

2006-10-05 Thread A . L . M . Buxey
Hi, I created the vista.patch file by pasting the file you referenced into a vi session. I moved it into freeradius-1.1.3 I used the command: patch -p0 vista.patch Which gave me a success. (Well two of them for each file) I recreated my .deb file and installed it. Let me know if I did

lots of duplicated user logins via cisco aironet

2006-10-05 Thread Michael Messner
hey freeRADIUS users, [EMAIL PROTECTED] ~]# radwho -r ISALAB.local\\mmessner,ISALAB.local\\mmessner,shell,S31005,Thu 12:15,141.201.43.115, mmessnerO,mmessnerO,shell,S310,Wed 11:33,141.201.43.118, mmessnerO,mmessnerO,shell,S279,Tue 12:45,141.201.43.118, mmessnerO,mmessnerO,shell,S453,Thu

Re: syslog - 1.1.2

2006-10-05 Thread Michael Messner
hey kenneth, Kenneth Grady wrote: try ... log_destination = syslog log { syslog_facility = daemon } not working :-( mIke - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

IPV6 support

2006-10-05 Thread sujata.gaddemane
Title: Message Hi, I am using FreeRADIUS 2.0.0 ; $Date: 2006/08/15 20:46:48 Will this server work on a host configured with IPV6 address and clients will still be able to authenticate using this server? I am currently not able to use this radius server. Using tcpdump I could see

Re: IPV6 support

2006-10-05 Thread Michael Schwartzkopff
Am Donnerstag, 5. Oktober 2006 15:39 schrieb [EMAIL PROTECTED]: Hi, I am using FreeRADIUS 2.0.0 ; $Date: 2006/08/15 20:46:48 Will this server work on a host configured with IPV6 address and clients will still be able to authenticate using this server? I am currently not

Re: syslog - 1.1.2

2006-10-05 Thread Kevin Bonner
On Thursday 05 October 2006 08:07, Michael Messner wrote: hey kenneth, Kenneth Grady wrote: try ... log_destination = syslog log { syslog_facility = daemon } not working :-( mIke I don't believe it was added to the 1.1.X branch, so the CVS head and nightly snapshots

Re: Freeradius users

2006-10-05 Thread Adrián Leonardo Acuña Rodríguez
Nick, Thank you for your answer! How I can test that user?Any way I will try to use MySQL Thank you again My regards Adrián Acuña 2006/10/2, Nick Larsen [EMAIL PROTECTED]: Hi Adrian,Have you looked in the 'users' file in the raddb/ directory? There's some examples in there (user 'steve'). You

Deploying radius page comment

2006-10-05 Thread King, Michael
Just reading thru the deployingradius.com pages On page: http://deployingradius.com/documents/configuration/active_directory.html You reference the krb5.conf file like this: [realms] ... realm.company.com = { kdc = nt-server-hostname.company.com } ... However, someone on the list

Re: Any luck with 802.1x authentication using TTLS with MSCHAPv2 ?

2006-10-05 Thread Alan DeKok
Mak Moussa [EMAIL PROTECTED] wrote: I would appreciate any insight into the 802.1x authentication using TTLS with MSCHAPv2. Such auth scheme is constantly failing in my wireless setup with FreeRadius. I tried 3 versions v1.0.5, v1.1.2 and v1.1.3 with not much luck. OK... The following

Re: Accepting any login attempt

2006-10-05 Thread Alan DeKok
John Williams [EMAIL PROTECTED] wrote: Someone did mention to me that you can auth a NAS so any auth requests coming from that NAS will be authenticated. Is this right? Sort of, but for your purposes, no. You *can* do: DEFAULT Client-IP-Address == 1.2.3.4, Auth-Type := Accept Which is

Re: Accepting any login attempt

2006-10-05 Thread Phil Mayers
John Williams wrote: Ok so Accept doesn't work for MS-CHAP. And I know I can grab the rejected usernames and drop them into the DB so the next time they try to auth it works. I did want to try and avoid rejecting the users and them getting fed up. Someone did mention to me that you can auth a

Re: W2K doesn't ask FreeRadius with EAP

2006-10-05 Thread Alexandros Gougousoudis
Hi me, Alexandros Gougousoudis schrieb: But there are two W2K clients which doesn't want to register over radius, the radius server even doesn't get a request. It seems the problem was, that the netbios name of the PC was to long (16 characters). I took a short one and it worked immediately.

Re: syslog - 1.1.2

2006-10-05 Thread Michael Messner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 hey Kevin, Kevin Bonner wrote: On Thursday 05 October 2006 08:07, Michael Messner wrote: hey kenneth, Kenneth Grady wrote: try ... log_destination = syslog log { syslog_facility = daemon } not working :-( mIke I don't believe

MYSQL

2006-10-05 Thread Abel Monzon
Hello, I need know when compile my freeradius to support mysql, at the time of ./configure or make? And what is the sintax.. Tanx for all, Abel - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

FreeRADIUS user Survey

2006-10-05 Thread Alan DeKok
In order to better understand the needs of people using FreeRADIUS, I've set up a survey with 12 questions. The goal is to understand who's using FreeRADIUS, how they're using it, and what the users needs are. The page is: http://gs-survey.com/s.asp?s=1651 Please take a few minutes

Re: FreeRADIUS user Survey

2006-10-05 Thread Guilherme Franco
Hello, Survey Not Found Sorry but this survey is no longer available. Please contact us if you require any further information. For more information on GroupSurveys, you can visit our site at http://www.group-surveys.com On 10/5/06, Alan DeKok [EMAIL PROTECTED] wrote: In order to better

Nortel Shasta BSN

2006-10-05 Thread Keith Woodworth
Anyone using a Nortel Shasta with FreeRadius? I'd like to cutover the PPPoE customers on the Shasta from an old Livingston radius server to our FR server. Thanks, Keith - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: MYSQL

2006-10-05 Thread A . L . M . Buxey
Hi, Hello, I need know when compile my freeradius to support mysql, at the time of ./configure or make? ./configure And what is the sintax.. none. ./configure will detect the mysql development and include environment and compile in the support. UNLESS you have such libraries/includes

Re: FreeRADIUS user Survey

2006-10-05 Thread Jan Mulders
404 On 05/10/06, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Don't know why it shows me - Sorry but this survey is no longer available. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] g] On Behalf Of Alan DeKok Sent: Thursday, October 05, 2006 11:39 AM To:

freeradius bug?

2006-10-05 Thread Abel Monzon
Hello, why ifI have in my clients.conf this configuration: clientlocalhost { secret = testing123 nastype = other shortname = localhost login =test password = test} andI try #radtest test test localhost testing123 say: Sending Access-Request of id 231 to 201.220.197.66 port

Re: FreeRADIUS user Survey

2006-10-05 Thread Alan DeKok
Guilherme Franco [EMAIL PROTECTED] wrote: Survey Not Found Whoops... the make active link didn't work. I poked it again. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See

Re: freeradius bug?

2006-10-05 Thread Alan DeKok
Abel Monzon [EMAIL PROTECTED] wrote: Why is Access-Reject? There is a bug of freeradius? Run the server in debugging mode and it will tell you why it's sending a reject. This is documented in the README, FAQ, INSTALL, and daily on this list. Alan DeKok. -- http://deployingradius.com

Re: FreeRADIUS user Survey

2006-10-05 Thread Dennis Skinner
Alan DeKok wrote: Guilherme Franco [EMAIL PROTECTED] wrote: Survey Not Found Whoops... the make active link didn't work. I poked it again. Still Survey Not Found as of right now. -- Dennis Skinner Systems Administrator BlueFrog Internet http://www.bluefrog.com - List

Re: FreeRADIUS user Survey

2006-10-05 Thread Guilherme Franco
Hello, The problem persists: http://gs-survey.com/s.asp?s=1651 Survey Not Found Sorry but this survey is no longer available. Please contact us if you require any further information. For more information on GroupSurveys, you can visit our site at http://www.group-surveys.com On 10/5/06,

RE: Any luck with 802.1x authentication using TTLS with MSCHAPv2 ?

2006-10-05 Thread Mak Moussa
Dear Alan, Thank you for the quick reply. Indeed, on WinXP I was using the Funk Odyssey client as it offered a good debug log. However, I tested using different supplicants like IntelPROSet on WinXP and the OSX 10.4 built-in supplicant with consistent results. I even tried a LinkSys WAP54G Fat

Huntgroups, Realms, MySQL

2006-10-05 Thread Brad McAllister
Sorry if this has already been addressed. I has been searching all day and haven't found the solution to my problem. I am attempting to setup multiple huntgroups to limit the types of connections that clients can make. Along with this I have a list of realms that are authenticated locally

RE: FreeRADIUS user Survey

2006-10-05 Thread King, Michael
Still a 404 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Thursday, October 05, 2006 3:59 PM To: FreeRadius users mailing list Subject: Re: FreeRADIUS user Survey Guilherme Franco [EMAIL PROTECTED] wrote: Survey Not Found

Re: FreeRADIUS user Survey

2006-10-05 Thread Alan DeKok
Dennis Skinner [EMAIL PROTECTED] wrote: Still Survey Not Found as of right now. Ok. I logged out of their system, logged back in, and poked the button again. It's now telling me Survey online, so let's see if it works. Sorry for the problems. Alan DeKok. -- http://deployingradius.com

1.1.3 or 2.0?

2006-10-05 Thread Roberto Greiner
Hi, I have a server running GNU-Radius 1.3, and was preparing to migrate it to FreeRadius 1.1.3, but on recent messages I noticed that 2.0 is being developed. My doubt is, should I go ahead and install 1.1.3, or wait and go straight for 2.0? The GNU-Radius machine is not giving me troubles for

Re: IPV6 support

2006-10-05 Thread Alan DeKok
[EMAIL PROTECTED] wrote: time (currently) and ALSO there is a bug. :: (listen on any address) causes a segmentation fault. WTF? types madly Ah. 'struct sockaddr' isn't big enough to hold IPv6 addresses. We have to use 'struct sockaddr_storage'. Thanks, it's now fixed. Alan

Re: Any luck with 802.1x authentication using TTLS with MSCHAPv2 ?

2006-10-05 Thread Alan DeKok
Mak Moussa [EMAIL PROTECTED] wrote: Thank you for the quick reply. Indeed, on WinXP I was using the Funk Odyssey client as it offered a good debug log. Ok... However, I tested using different supplicants like IntelPROSet on WinXP and the OSX 10.4 built-in supplicant with consistent

rewriting Frame-IP-Netmask

2006-10-05 Thread Apu islam
I am having problems rewriting the IP Netmask attribure. I am using mysql for my user authorization. the IP address seems to get set right, but the Netmask does not. I have specified it specifically and even changed the default, but could not get this to work. Its a PPP framed connection. What

Re: FreeRADIUS user Survey

2006-10-05 Thread Nicholas Hall
On 10/5/06, Alan DeKok [EMAIL PROTECTED] wrote: Guilherme Franco [EMAIL PROTECTED] wrote: Survey Not FoundWhoops... the make active link didn't work.I poked it again. I was now able to successfully complete the survey.-- Nick HallAlexssa Enterprisesp: 262.338.3742m: 262.208.6271Never lose your

Re: FreeRADIUS user Survey

2006-10-05 Thread Alan DeKok
The survey is up now, and results are coming in. Thanks for everyone's help. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS user Survey

2006-10-05 Thread Doug Hardie
On Oct 5, 2006, at 14:12, King, Michael wrote: Still a 404 -Original Message- From: [EMAIL PROTECTED] [mailto:freeradius-users-bounces [EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Thursday, October 05, 2006 3:59 PM To: FreeRadius users mailing list Subject: Re: FreeRADIUS user

Re: Huntgroups, Realms, MySQL

2006-10-05 Thread James Wakefield
Brad McAllister wrote: If I removed the huntgroups out of the picture, is works fine. The problem seems to be that the realm is not being stripped off of the username when it checks it against the usergroup table. If more information is needed, please let me know. I would really like to get

Re: rewriting Frame-IP-Netmask

2006-10-05 Thread James Wakefield
Apu islam wrote: I am having problems rewriting the IP Netmask attribure. I am using mysql for my user authorization. the IP address seems to get set right, but the Netmask does not. I have specified it specifically and even changed the default, but could not get this to work. Its a PPP framed

RE: IPV6 support

2006-10-05 Thread sujata.gaddemane
Title: RE: IPV6 support Hi, Thanks for the help. Now radiusd is receiving the packets. But it is ignoring the packat saying it is from unknow client. rad_recv: Access-Request packet from host 2001:888:1941::3 port 30407, id=101, length=88 Ignoring request from unknown client