Re: Bridging RADIUS Servers

2006-12-19 Thread Phil Mayers
Jack Jackson wrote: Dear All- Excuse my ignorance. Our company uses RADIUS today for network (802.1x) authentication. We're merging with another company who also uses RADIUS for the same purpose. Is there a config document which shows how I can configure Free Radius to proxy 2 completely

ntlm fall-through

2006-12-19 Thread Stieven . Struyf
All, Does anyone know how i can configure ntlm fall-through, eg. try to authenticate the user local (via password entry in users file) and if the user isn't found use ntlm-auth(or first ntlm and afterwards userfile is also ok)? If i comment out the ntlm-auth line in the mschap section of

need help

2006-12-19 Thread Zion Somech
Subject: help Hi Team I need your help to set the following setup: Machine 1: freeradius server --- working and running freeradius OS sled 10 (Suse) Machine 2: pam server --- pam module foe radius install under /lib64/security I need your help to configure the files which file I need to

freeradius brake down

2006-12-19 Thread S.L.
Hi all,I have built an Access Point with hostapd, and want to authenticate with FreeRADIUS via users file.I wnat to use MSCHAPv2 with PEAP and TLS. my eap.conf: eap { default_eap_type = peap timer_expire = 60 ignore_unknown_eap_types = no md5{ } leap{

Re: Long authentication times

2006-12-19 Thread Stefan Winter
Hi, Good morning Stefan, perhaps the solution you proposed could work in my case. Could you suggest me the way to check if the lag depends on the DHCP service? Do you know if there is any way to configure the DHCP service timing (we are using freeradius + Chillispot on the server side) so to

User authentication using Mysql table - radacct

2006-12-19 Thread N S
I have the radacct table populated with a few users. But the radius is not checking this table for user info. The only users being allowed/authenticated are those that are in the users.conf file.How do I make the radius look for the user info in the mysql database. Thanks.

RE: User authentication using Mysql table - radacct

2006-12-19 Thread N S
I have the radacct table populated with a few users. But the radius is not checking this table for user info. The only users being allowed/authenticated are those that are in the users.conf file.How do I make the radius look for the user info in the mysql database. The freeradius version is

RE: User authentication using Mysql table - radacct

2006-12-19 Thread Cory Robson
a customized station.  Try MSN Radio powered by Pandora. http://radio.msn.com/?icid=T002MSN03A07001 - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ NOD32 1928 (20061219) Information __ This message was checked by NOD32 antivirus system. http

Re: User authentication using Mysql table - radacct

2006-12-19 Thread romero.cl
Hi. Check your radiusd.conf to include sql.conf You can check my How To at http://turing.udp.cl/~dromero/freeradius May the source be with you. - Original Message - From: N S [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Sent: Tuesday, December 19, 2006 1:13 PM Subject:

Re: User authentication using Mysql table - radacct

2006-12-19 Thread Dennis Skinner
N S wrote: I have the radacct table populated with a few users. But the radius is not checking this table for user info. The only users being allowed/authenticated are those that are in the users.conf file.How do I make the radius look for the user info in the mysql database. For starters,

RE: User authentication using Mysql table - radacct

2006-12-19 Thread Cory Robson
info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ NOD32 1928 (20061219) Information __ This message was checked by NOD32 antivirus system. http://www.eset.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: radius hosting

2006-12-19 Thread normalboy
Yes, it works. Thank you. But the problem is that SSID: The SSID for every Radiuz router must be set to www.radiuz.net. But I cannot share my connection for entire neighborhood ;), my ISP forbids me to. Is there something else? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

Re: freeradius brake down

2006-12-19 Thread Alan DeKok
S.L. wrote: I have built an Access Point with hostapd, and want to authenticate with FreeRADIUS via users file. I wnat to use MSCHAPv2 with PEAP and TLS. ... freeradius: relocation error: /usr/lib/freeradius/rlm_eap_peap-1.0.2.so: undefined symbol: eaptls_process It looks like you built

Re: ntlm fall-through

2006-12-19 Thread Alan DeKok
[EMAIL PROTECTED] wrote: All, Does anyone know how i can configure ntlm fall-through, eg. try to authenticate the user local (via password entry in users file) No, the users file doesn't authenticate anyone. It just adds a known good password to the request. Some other module takes care

Re: Logging additional attributes into sql backend

2006-12-19 Thread Alan DeKok
Cory Robson wrote: My upstream provider sends me an account terminate cause in a stop packet in the format Ascend-Disconnect-Cause, how do I get freeradius to map and log this into the sql field 'AcctTerminateCause' I have checked and it is in my dictionary file. Edit sql.conf to include

Re: realms and local user file processing question

2006-12-19 Thread Alan DeKok
Michael Hare wrote: However, I'd like to provide a different Framed-IP-Address based on the supplied realm. The goal that we are trying to implement are IP groups in a VPN server. I'm trying to hammer this out with radius because I don't want a vendor specific solution. Can you think of a

Re: radius hosting

2006-12-19 Thread Dennis Skinner
normalboy wrote: Yes, it works. Thank you. But the problem is that SSID: The SSID for every Radiuz router must be set to www.radiuz.net. But I cannot share my connection for entire neighborhood ;), my ISP forbids me to. Is there something else? Read closer Radiuz lets you

RE: User authentication using Mysql table - radacct

2006-12-19 Thread N S
for request 0 modcall: group preacct returns ok for request 0 Processing the accounting section of radiusd.conf modcall: entering group accounting for request 0 radius_xlat: '/var/log/radius/radacct/127.0.0.1/detail-20061219' rlm_detail: /var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands

freeradius brake down

2006-12-19 Thread S.L.
Hi all,Thanks for the reply Alan.You suggested version 1.1.3 - it's ok - and said that it's peap configuration...so I think I am disconcerted a little...If I want PEAP I have to configure tls section in eap.conf too, otherwise the server fails like this:rlm_eap: Unable to load

Re: freeradius brake down

2006-12-19 Thread Alan DeKok
S.L. wrote: You suggested version 1.1.3 - it's ok - and said that it's peap configuration...so I think I am disconcerted a little... No, I didn't say the problem as PEAP. I said it was TLS. Then I configure tls section and the message is this: rlm_eap: Failed to link EAP-Type/tls:

FreeRADIUS SQLite support

2006-12-19 Thread Fenn Bailey
Hi All, This may be a silly question, but are there any plans/is it possible (or even a good idea) to build in SQLite support to FreeRADIUS? To me it seems like a nice lightweight in-between for SQL DB and local file DB type auth - The convenience of integration of SQL with things like PHP/Perl

Re: FreeRADIUS SQLite support

2006-12-19 Thread Alan DeKok
Fenn Bailey wrote: This may be a silly question, but are there any plans/is it possible (or even a good idea) to build in SQLite support to FreeRADIUS? Maybe. The main problem with SQLite is that it's really only for one reader/writer at a time. I think it works with multiple readers and

Send atributes to the client

2006-12-19 Thread fjlagos
Hello: What file i must set for send some atributes to a Radius client, for example, how can i send the VLAN for some user as soon as he was authenticated? In whish file i must set the attributes for a specific vendor like Juniper ERX atributes? Saludos y Gracias Francisco - List

Re: Send atributes to the client

2006-12-19 Thread James Wakefield
[EMAIL PROTECTED] wrote: Hello: What file i must set for send some atributes to a Radius client, for example, how can i send the VLAN for some user as soon as he was authenticated? In whish file i must set the attributes for a specific vendor like Juniper ERX atributes? Saludos y Gracias

modify sql table structure for additional logging

2006-12-19 Thread Cory Robson
Is it possible to modify the existing radacct table with some extra fields for logging. My upstream also sends Attr-151 X-Ascend-Session-Svr-Key which I would also like logged (its used for terminating a user if need be). I could use it in the unique session server key field instead of the

Re: modify sql table structure for additional logging

2006-12-19 Thread Alan DeKok
Cory Robson wrote: Is it possible to modify the existing radacct table with some extra fields for logging. Yes. You can add anything you want to the SQL schema, and then edit the queries/inserts to write the appropriate data. My upstream also sends Attr-151 X-Ascend-Session-Svr-Key which

RE: modify sql table structure for additional logging

2006-12-19 Thread Cory Robson
://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ NOD32 1929 (20061219) Information __ This message was checked by NOD32 antivirus system. http://www.eset.com - List info/subscribe/unsubscribe? See http