Re: No User-Password or CHAP-Password attribute in the request

2010-03-03 Thread omega bk
hello all, My version of freeradius is Version 2.1.0 here is my result in debug mode: rad_recv: Access-Request packet from host 192.168.20.253 port 1645, id=112, length=131 User-Name = linatest Service-Type = Framed-User Framed-MTU = 1500 Called-Station-Id =

Re: No User-Password or CHAP-Password attribute in the request

2010-03-03 Thread Alan Buxey
Hi, My version of freeradius is Version 2.1.0 upgrade to 2.1.8 [files] users: Matched entry linatest at line 11 ++[files] returns ok WARNING: Please update your configuration, and remove 'Auth-Type = Local' WARNING: Use the PAP or CHAP modules instead. FreeRADIUS doesnt lie i don't have

Re: No User-Password or CHAP-Password attribute in the request

2010-03-03 Thread omega bk
hi alan, thanks for your help. i use ubuntu as radius server all configuration file is under /etc/freeradius/* as client i use winxp wired without certificate. just EAP-MSCHAP v2 as authentication method. in my users file i put one user like this: ## linatest

Re: No User-Password or CHAP-Password attribute in the request

2010-03-03 Thread Alan DeKok
omega bk wrote: hi alan, thanks for your help. i use ubuntu as radius server all configuration file is under /etc/freeradius/* as client i use winxp wired without certificate. just EAP-MSCHAP v2 as authentication method. in my users file i put one user like this:

Re: No User-Password or CHAP-Password attribute in the request

2010-03-03 Thread Alan Buxey
Hi, i use ubuntu as radius server all configuration file is under /etc/freeradius/* as client i use winxp wired without certificate. just EAP-MSCHAP v2 as authentication method. in my users file i put one user like this: ## linatestAuth-Type = CHAP

Re: No User-Password or CHAP-Password attribute in the request

2010-03-03 Thread omega bk
yeah i really messed things up. i got my radius from apt-get i downloaded from source the latest version. i removed the odl one with apt-get remove freeradius i did a dpkg-bildpackage -b -uc but messd in: /home/omega/freeradius-server-2.1.8/src/main/modules.c:1358: undefined reference to

Re: No User-Password or CHAP-Password attribute in the request

2010-03-03 Thread omega bk
oh great i compiled the latest = and tryed new configuration great , it works with my client wired Thank u so much 2010/3/3 omega bk omeg...@gmail.com yeah i really messed things up. i got my radius from apt-get i downloaded from source the latest version. i removed the odl one with

Multiple Home Server for authentication

2010-03-03 Thread Rosario Lumia
Hi to all. I'm tryng to use Freeradius 2.x for managing a complex architecture. I use the 802.1x standard for wireless authentication. I need to authenticate users that have passwords in different authentication server whit different protocol (TTLS/PAP or PEAP/MSCHAPv2) and i'd want to proxy the

Re: Multiple Home Server for authentication

2010-03-03 Thread Alan Buxey
Hi, I'm tryng to use Freeradius 2.x for managing a complex architecture. I use the 802.1x standard for wireless authentication. I need to authenticate users that have passwords in different authentication server whit different protocol (TTLS/PAP or PEAP/MSCHAPv2) and i'd want to proxy the

Re: No User-Password or CHAP-Password attribute in the request

2010-03-03 Thread Alan Buxey
Hi, oh great i compiled the latest = and tryed new configuration great , it works with my client wired Thank u so much congratulations - and thanks. alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

vlan and freeradius

2010-03-03 Thread omega bk
Hello, so i would like to redirect my winxp authenticated to VLAN1 and if not authenticated , this client must be in vlan2 i got a switch cisco so how to handla this with freeradius? thank u - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: rlm_perl behavior

2010-03-03 Thread Alexandr Kovalenko
On Wed, Apr 22, 2009 at 12:23 PM, Alan DeKok al...@deployingradius.com wrote: Apostolos Pantsiopoulos wrote: If any changes are to be made to the current implementation to support multiple interpreters (one per thread) would they show up in a 2.1.x release or a future one (2.2.x or something)?

Re: vlan and freeradius

2010-03-03 Thread Jens Link
omega bk omeg...@gmail.com writes: Hi, so i would like to redirect my winxp authenticated to VLAN1 and if not authenticated , this client must be in vlan2 i got a switch cisco so how to handla this with freeradius? Depends on how you do the authentication: Using certificates (either

Re: vlan and freeradius

2010-03-03 Thread Michael Schwartzkopff
Am Mittwoch, 3. März 2010 15:34:56 schrieb Jens Link: omega bk omeg...@gmail.com writes: Hi, so i would like to redirect my winxp authenticated to VLAN1 and if not authenticated , this client must be in vlan2 i got a switch cisco so how to handla this with freeradius? Depends on

Re: rlm_perl behavior

2010-03-03 Thread Apostolos Pantsiopoulos
I think yes. In my current config (2.1.8) it works fine. -- --- Apostolos Pantsiopoulos Kinetix Tele.com R D email: r...@kinetix.gr --- On 3/3/2010 4:26 μμ, Alexandr Kovalenko wrote: On Wed, Apr 22, 2009 at 12:23

Re: vlan and freeradius

2010-03-03 Thread omega bk
in fact, i got my client wired with winxp and authentication works well in 802.1x this client is connected directly in my switch trough vlan3 i would like dynamically assign a successfull authentication trough vlan2 and faillure authentication to vlan1 autthentication is based in users file

Re: vlan and freeradius

2010-03-03 Thread Alan Buxey
Hi, Hello, so i would like to redirect my winxp authenticated to VLAN1 and if not authenticated , this client must be in vlan2 i got a switch cisco so how to handla this with freeradius? read the cisco docs on dealing with 802.1X. you should never use VLAN1 for users - most would

Re: vlan and freeradius

2010-03-03 Thread Michael Schwartzkopff
Am Mittwoch, 3. März 2010 15:45:56 schrieb omega bk: in fact, i got my client wired with winxp and authentication works well in 802.1x this client is connected directly in my switch trough vlan3 i would like dynamically assign a successfull authentication trough vlan2 and faillure

Re: vlan and freeradius

2010-03-03 Thread omega bk
2) set the switch to use RADIUS return attributes for VLAN (and for session time etc) and set the fail VLAN and guest VLAN to Y = that's really what i want to do so in my users file myuser Cleartext-Password := user Tunnel-type = VLAN,

Checkrad.pl MIB

2010-03-03 Thread J Brandon Polley
Does anyone know the MIB OID we need to put in checkrad.pl in order for it to work with Cisco 4404 wireless controller? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Wiki

2010-03-03 Thread Peter Nixon
On Sun 28 Feb 2010, Doug Hardie wrote: A week ago I tried to update the wiki to correct an interpretation error that was pointed out by one of the freeradius users. I can log into the wiki fine, but even though the save says the update was saved, it is not. I then posted the necessary change

Logging

2010-03-03 Thread James Devine
Is there a way to enable full debugging while still having it write to the log file and not push into the foreground? We are seeing radius packets coming in that I can locate via tcpdump but not via the logs. We have a custom module which dumps the radius packet almost immediately to logs which

Re: Logging

2010-03-03 Thread Alan DeKok
James Devine wrote: Is there a way to enable full debugging while still having it write to the log file and not push into the foreground? $ man raddebug It requires 2.1.7 or 2.1.8 (IIRC). We are seeing radius packets coming in that I can locate via tcpdump but not via the logs. We have

Re: Multiple Home Server for authentication

2010-03-03 Thread Rosario Lumia
Thank you Alan, your help was precious and (I hope) needful. In the next days I will send my (hopefully) configuration, if you consider it appropriate. Thanks. Rosario L. 2010/3/3 Alan Buxey a.l.m.bu...@lboro.ac.uk Hi, I'm tryng to use Freeradius 2.x for managing a complex architecture. I

freeradius 1.1.8 hangs in rlm_perl on 64bit

2010-03-03 Thread Olivier Bilodeau
Hi, We have been using freeradius 1.1.8 with a lot of success on a lot of our deployments. Lately we deployed a freeradius 1.1.8 on a 64 bit environment for the first time. On that setup we have been experiencing segfaults and hanging processes once a month maybe. When hanged, gdb points

Re: vlan and freeradius

2010-03-03 Thread Phil Mayers
On 03/03/2010 03:01 PM, omega bk wrote: 2) set the switch to use RADIUS return attributes for VLAN (and for session time etc) and set the fail VLAN and guest VLAN to Y = that's really what i want to do so in my users file myuser Cleartext-Password := user Tunnel-type

Re: Wiki

2010-03-03 Thread Doug Hardie
Works now. Update to instantiate description is now there. Thanks. On 3 March 2010, at 07:19, Peter Nixon wrote: On Sun 28 Feb 2010, Doug Hardie wrote: A week ago I tried to update the wiki to correct an interpretation error that was pointed out by one of the freeradius users. I can log

Hardware NAT

2010-03-03 Thread Коньков Евгений
Hello, FreeRadius. GE Intelligent Platforms - 10GE. Does FreeBSD support that? -- Коньков mailto:kes-...@yandex.ru - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Hardware NAT

2010-03-03 Thread Eugen Konkov
Здравствуйте, Коньков. Вы писали 3 марта 2010 г., 21:43:10: КЕ Hello, FreeRadius. КЕ GE Intelligent Platforms - 10GE. КЕ Does FreeBSD support that? Another interesting thing http://www.netfpga.org/ -- С уважением, Коньков mailto:kes-...@yandex.ru - List

Re: Can a wpa_supplicant talk to a Free Radius server without a NAS in between?

2010-03-03 Thread R C
Sorry, again. I didn't mean not to lookup eapol_test. This is what happened. 1. Initially, I thought I will work without NAS and required information about how to get the wpa_supplicant to talk with the Free radius server directly. You suggested eapol_test for this. 2. When I resent my

RE: Dialup admin error

2010-03-03 Thread Michael J Humphries
radiusd: FreeRADIUS Version 1.1.8, for host i686-pc-linux-gnu, built on Mar 3 2010 at 18:01:19 here is the exact error I am getting Warning: import_request_variables() [function.import-request-variables]: Numeric key detected - possible security hazard. in

Re: Can a wpa_supplicant talk to a Free Radius server without a NAS in between?

2010-03-03 Thread R C
Hi, I ran eapol_test with reauthentication = 100. It went through fine. Thanks for that. 1. But, since these reauthentications are serial and not parallel, and even if i run 5-6 eapol_test processes at the same time, there will be only 5-6 parallel sessions at any given time. 2. Since there

Re: Can a wpa_supplicant talk to a Free Radius server without a NAS in between?

2010-03-03 Thread Peter Lambrechtsen
On Thu, Mar 4, 2010 at 1:29 PM, R C rc_w...@yahoo.com wrote: Hi, I ran eapol_test with reauthentication = 100. It went through fine. Thanks for that. 1. But, since these reauthentications are serial and not parallel, and even if i run 5-6 eapol_test processes at the same time, there will

Re: vlan and freeradius

2010-03-03 Thread Matt Hite
On Wed, Mar 3, 2010 at 10:44 AM, Phil Mayers p.may...@imperial.ac.uk wrote: but how to set the fail VLAN and guest VLAN to Y ??? Setting the Fail and Guest VLAN by radius doesn't make any sense. The Fail vlan is what to use when the radius server is unavailable. The Guest vlan is what to do

special query for authentication

2010-03-03 Thread mwarren
I am trying to setup something where I can have multiple NAS devices where users can roam. Some NAS devices people will be able to have the first level of service free(sponsored NAS). I need to be able to identify and authenticate people who sign up to the free service to only be allowed to use

Re: LDAP groups and attributes

2010-03-03 Thread Jethro Carr
On Mon, 2010-03-01 at 17:42 -0500, John Dennis wrote: If I understand correctly what you would like to do then check out profiles in the ldap_howto.txt. A profile is a way to associate a set of attributes (e.g. the profile) with a user. thanks John, Robert and off-listers, Looking at the

Re: LDAP groups and attributes

2010-03-03 Thread Peter Lambrechtsen
Jethro The eaist way is as per what I e-mailed to you. http://lists.freeradius.org/mailman/htdig/freeradius-users/2009-November/msg1.html This means you only need to create groups in your LDAP directory. It also means you don't need to extend the LDAP Schema to do this. And use the

Lost and confused

2010-03-03 Thread jin jin
This is the first time that I'm trying to set up a freeRADIUS server (Ver 2.1.0) using Ubuntu 9.10 and I'm running into walls. I used the debug mode and this is the output Failed binding to socket: Address already in use /etc/freeradius/radiusd.conf[236]: Error binding to port for 0.0.0.0

Re: Can a wpa_supplicant talk to a Free Radius server without a NAS in between?

2010-03-03 Thread Alan DeKok
R C wrote: and even if i run 5-6 eapol_test processes at the same time, there will be only 5-6 parallel sessions at any given time. So... run more processes on more machines. 2. Since there are no free wpa supplicants that can generate multiple separate sessions at the same time, do you

Re: freeradius 1.1.8 hangs in rlm_perl on 64bit

2010-03-03 Thread Alan DeKok
Olivier Bilodeau wrote: Any ideas on what it could be? perl? freeradius? 64bit? our perl code? shrug That code is about 3 years old at this point, and no longer actively maintained. We haven't switched to 2.x because of day to day activity overload but that could be a good reason for us to

Re: vlan and freeradius

2010-03-03 Thread Alan DeKok
Jens Link wrote: @Alan: I would document VMPS in some more detail in the wiki if my access would be working. ;-) It seems to be fine now. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Lost and confused

2010-03-03 Thread Alan DeKok
jin jin wrote: This is the first time that I'm trying to set up a freeRADIUS server (Ver 2.1.0) using Ubuntu 9.10 and I'm running into walls. I used the debug mode and this is the output Failed binding to socket: Address already in use /etc/freeradius/radiusd.conf[236]: Error binding to