IPv6 deployment howto

2007-10-08 Thread Mark J Elkins
Hi, I'm looking for some assistance on deploying IPv6. I'm currently using FreeRADIUS Version 1.1.6. I have for testing a Cisco 3640 running C3640-IK9S-M. The cisco has properly routable IPv6 addresses on its Ethernet and Loopback. I currently allow clients to dial to this device using the E1

Re: IPv6 deployment howto

2007-10-08 Thread Alan DeKok
Mark J Elkins wrote: I'm looking for some assistance on deploying IPv6. I'm currently using FreeRADIUS Version 1.1.6. I have for testing a Cisco 3640 running C3640-IK9S-M. The cisco has properly routable IPv6 addresses on its Ethernet and Loopback. Version 1.1.6 doesn't support IPv6. I

Re: IPv6 deployment howto

2007-10-08 Thread Matthias Cramer
What magic lines would I need to add to my Cisco and what magic to add to FreeRadius? Anyone have Dialup clients being issued IPv6 addresses yet? 1 - I expect to add some sort of IPv6 field to MySQL (ie - for a static IPv6 address or to signify the NAS to use a Dynamic address) 2 - I

Re: IPv6 deployment howto

2007-10-08 Thread Mark J Elkins
Alan DeKok wrote: Mark J Elkins wrote: I'm looking for some assistance on deploying IPv6. I'm currently using FreeRADIUS Version 1.1.6. I have for testing a Cisco 3640 running C3640-IK9S-M. The cisco has properly routable IPv6 addresses on its Ethernet and Loopback. Version

EAP/TLS certificate Security question

2007-10-08 Thread satish patel
Dear all I have installed EAP/TLS base authentication in my wirless network i have some question about security issue i have installed certificate on every laptop of wirless client machine now thing is that is some one will installed that certificate on unknow client

Re : Freeradius Billing Account Management

2007-10-08 Thread Eshun Benjamin
You may want to use phpMyPrepaidhttp://sourceforge.net/project/showfiles.php?group_id=127438 == Benjamin K. Eshun - Message d'origine De : Pratchaya Chatuphian [EMAIL PROTECTED] À : freeradius-users@lists.freeradius.org Envoyé le :

Re: EAP/TLS certificate Security question

2007-10-08 Thread tnt
You can't prevent someone with a valid certificate logging on (you can revoke it and then that user and whoever has duplicate certificate will not be able to log on). But you can stop unknown mac addresses associating with your AP. Read AP documentation. Or, if you have AD, use machine

Freeradius with TTLS support

2007-10-08 Thread José Antonio Olivera Ortega
Hello, I am trying to set up a freeradius server with EAP-TTLS authentication, Which are the steps to build freeradius with EAP-TTLS support? Can anybody help me? Thanks in advance regards! -- José Antonio Olivera Ortega Automóvil Conectado - Telefónica I+D Teléfono: 913340330 Ext. 1000

Re: Freeradius with TTLS support

2007-10-08 Thread Alan DeKok
José Antonio Olivera Ortega wrote: I am trying to set up a freeradius server with EAP-TTLS authentication, Which are the steps to build freeradius with EAP-TTLS support? $ ./configure $ make $ make install It would also help if you said what OS you are running. Alan DeKok. - List

Re: Freeradius with TTLS support

2007-10-08 Thread José Antonio Olivera Ortega
Hello Alan, I am using Debian GNU/Linux. I saw at http://wiki.freeradius.org/Build#Building_Debian_packages the steps but I don't know if all the steps are included. May be I have to modify more things like freeradius-1.1.7/debian/rules, freeradius-1.1.7/debian/control or somethig like that

Re: Freeradius with TTLS support

2007-10-08 Thread Alan DeKok
José Antonio Olivera Ortega wrote: I am using Debian GNU/Linux. I saw at http://wiki.freeradius.org/Build#Building_Debian_packages the steps but I don't know if all the steps are included. May be I have to modify more things like freeradius-1.1.7/debian/rules, freeradius-1.1.7/debian/control

freeradius 1.0.2 with oracle backend

2007-10-08 Thread Sam Gibbs
I've setup freeradius by following the Using Oracle as a Backend DB for a Radius Server document at www.ceta.ufm.edu.gt. The server will load the rlm_sql_oracle module and start. It is also communicating with the database properly. However, It will not authenticate users from that database. I get

Re: freeradius 1.0.2 with oracle backend

2007-10-08 Thread tnt
1. Update - 1.0.2 is years out of date. 2. Delete (comment out) DEFAULT entry setting Auth-Type System from the users file (if you don't plan to use it). 3. Post the debug from the request. Ivan Kalik Kalik Informatika ISP Dana 8/10/2007, Sam Gibbs [EMAIL PROTECTED] piše: I've setup

Re: freeradius 1.0.2 with oracle backend

2007-10-08 Thread Sam Gibbs
On 10/8/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: 1. Update - 1.0.2 is years out of date. Thanks, I will update. The doc I followed specified 1.0.2. 2. Delete (comment out) DEFAULT entry setting Auth-Type System from the users file (if you don't plan to use it). I've commented out these

access rejected

2007-10-08 Thread 翔 李
Hi, I added FreeRADIUS-EAP-TNC-Patch on FreeRADIUS which is developed by [EMAIL PROTECTED] so that eap-tnc can be supported by FreeRADIUS.Then I entered radiusd -X command but some error occured , which indicated that access was rejected and the debug info is Could not open file

Re: access rejected

2007-10-08 Thread tnt
I added FreeRADIUS-EAP-TNC-Patch on FreeRADIUS which is developed by [EMAIL PROTECTED] Don't you think that you should put this question to the people who made the patch? Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: access rejected

2007-10-08 Thread Alan DeKok
翔 李 wrote: I added FreeRADIUS-EAP-TNC-Patch on FreeRADIUS which is developed by [EMAIL PROTECTED] Please ask them questions about EAP-TNC support. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

AAA for cisco management

2007-10-08 Thread German Garay
Hi: - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

radius for cisco management

2007-10-08 Thread German Garay
Hi I want to do per user command authorization in a cisco network to replace a tacacs+ server. But I can´t find a how to in a page, can you send me the link? Thanks Germán - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radius for cisco management

2007-10-08 Thread tnt
http://wiki.freeradius.org/Cisco Ivan Kalik Kalik Informatika ISP Dana 8/10/2007, German Garay [EMAIL PROTECTED] piše: Hi I want to do per user command authorization in a cisco network to replace a tacacs+ server. But I can´t find a how to in a page, can you send me the link? Thanks

Re: radius for cisco management

2007-10-08 Thread Phil Mayers
On Mon, 2007-10-08 at 17:00 -0300, German Garay wrote: Hi I want to do per user command authorization in a cisco network to replace a tacacs+ server. But I can´t find a how to in a page, can you send me the link? Can't be done. The best you can do is use Radius to assign a privilege

Re: IPv6 deployment howto

2007-10-08 Thread Alan DeKok
Mark J Elkins wrote: My reading of this is that I can use FreeRADIUS 1.1.6 to store and transport IPv6 Radius attributes so I can use 1.1.6 ??? Yes. There's Framed-IPv6-prefix, where you can assign Ip's to a client. I think this is for static allocations only. I don't know what

CAR cisco radius replace freeradius

2007-10-08 Thread satish patel
Dear all I have CAR cisco radius server with MPLS attribites but there is no Accouting option for users so is it possible to replace CAS radius with freeradius server ?? $ cat ~/satish/url.txt http://www.linuxbug.org