two user authentication groups for one AS

2010-01-04 Thread Eric
My users differ in ldap attributes and all come from one AS. I want session-timeout of some users to be the value of counter and for others the session-timeout that I define in freeradius for them. How should I distinct them? - List info/subscribe/unsubscribe? See

Re: Default reply for username incorrect-s

2010-01-04 Thread Alex M
Ok I think i got the idea, will no go and try it out! thank you! as to 2nd reply, yes my NAS supports Reply-Messages 2010/1/4 Charles (KOL-Goma) char...@goma.kivu-online.com Does your NAS support the option? - Original Message - *From:* EasyHorpak.com i...@easyhorpak.com *To:*

2.1.8 proxy zombie/dead/alive loops

2010-01-04 Thread Craig Campbell
craig.campb...@ccraft.ca CampbellCraft Consulting Inc 2 Kenny Court Whitby, Ontario Canada L1R 2L8 905 922-2789 __ Information from ESET Smart Security, version of virus signature database 4743 (20100104) __ The message was checked by ESET Smart Security. http

Re: 2.1.8 proxy zombie/dead/alive loops

2010-01-04 Thread Alan DeKok
Craig Campbell wrote: There are 2 radius servers (radius-a and radius-b). Each server will relay packets it receives to the other server. (Currently only accounting packets are being received) The packets are collected in detail-relay file. The packets are then relayed via the

RE: MAC authentication bypass --- How amIsupposedto?edit?theusersfileto include multiple MAC addresses??

2010-01-04 Thread Difan Zhao
Hey guys, I am still waiting for a possible solution for this problem that I have... Please let me know even there is no easy fix. To refresh your memory, I am doing MAC address authentication bypass. It looks to me that the users file takes precedence than sites-available/default.

Freeradius and memory usage part deux

2010-01-04 Thread Roy Kartadinata
Greetings, I started this email few months back but due to other projects that took priority, I had to put this troubleshooting on hold. To recap: 1. Our radius servers are having some memory issue where its memory usage would increase by 1% every 30 - 45 minutes until it crashes and restarts.

Re: Freeradius and memory usage part deux

2010-01-04 Thread Alan DeKok
Roy Kartadinata wrote: 1. Our radius servers are having some memory issue where its memory usage would increase by 1% every 30 - 45 minutes until it crashes and restarts. 2. I created a script that will temporarily fix the issue by monitoring its memory usage and restart after it reaches

Re: MAC authentication bypass --- How amIsupposedto?edit?theusersfileto include multiple MAC addresses??

2010-01-04 Thread Alan DeKok
Difan Zhao wrote: To refresh your memory, I am doing MAC address authentication bypass. It looks to me that the “users” file takes precedence than “sites-available/default”. No. You are setting Auth-Type = ... in the users file, and then trying to se Auth-Type = ... *again* elsewhere.

RE: MAC authentication bypass ---How amIsupposedto?edit?theusersfileto include multiple MAC addresses??

2010-01-04 Thread Difan Zhao
Lol Alan you found the problem again! I just read the manual of users and unlang again and now I know clearly what the problem was... Thank you very much for the help! So radiusd -X won't show whether a check attribute was updated or not? Here is my radiusd -X output. It's the same no

Proxy-Accounting problems

2010-01-04 Thread Phil Pierotti
I've configured Freradius (2.1.7) to proxy certain realms to another box, and generally things are working as expected. Running TCPDUMP, I see: 11:54:26.205736 IP (tos 0x0, ttl 64, id 19359, offset 0, flags [none], proto UDP (17), length 518) blah.blah.blah.foo.1814 blah.blah.blah.bar.1813:

Re: Managing the RADIUS database

2010-01-04 Thread Steve Bertrand
Steve Bertrand wrote: Hi all, I'm curious to know what you use to manage your RADIUS database, particularly the accounting tables. For quite some time, I was using severely hacked versions of the dialup_admin scripts. Since then, I've written (ie. been writing) an ISP mgmt/accounting

how to use RSA instead of DH?

2010-01-04 Thread kachin Agarwal
Hi,     I m using freeradius-server 2.1.7. I ve created an openssl engine for doing all the RSA calculations and it is quite fast. But when i use the try to authenticate something it uses DH algorithm also. so how can i make use of only RSA so that my authentication rate is high. What part of

Re: Proxy-Accounting problems

2010-01-04 Thread Alan DeKok
Phil Pierotti wrote: I've configured Freradius (2.1.7) to proxy certain realms to another box, and generally things are working as expected. Running TCPDUMP, I see: sigh Accounting request proxied to foreign server, Accounting response received from foreign server. Response packet was

Re: how to use RSA instead of DH?

2010-01-04 Thread Alan DeKok
kachin Agarwal wrote: I m using freeradius-server 2.1.7. I ve created an openssl engine for doing all the RSA calculations and it is quite fast. But when i use the try to authenticate something it uses DH algorithm also. so how can i make use of only RSA so that my authentication rate is

Re: Managing the RADIUS database

2010-01-04 Thread Alan DeKok
Steve Bertrand wrote: Again, I'm not a programmer, so the real developers will likely laugh. Why? If it works... ship it. :) The radacct table in the RADIUS database grows at an enormously fast rate. Regardless of server resources, trying to search or perform actions on this table can be