RE: Redundant SQL

2010-10-19 Thread Santiago Balaguer GarcĂ­a
Hi Chester, I think for a good behaviour of SQL server, all of them have to be working in a normal startup of a freeradius service. Try to repair why your SQL server are down. You have to have a stable system. Regards, Santiago From:

Re: Matching a value within an IP subnet

2010-10-19 Thread Brian Candler
On Mon, Oct 18, 2010 at 02:51:25PM +0200, Alan DeKok wrote: Brian Candler wrote: DEFAULT NAS-IP-Address =~ 192.0.2.0/27, NAS-Group := ADSL-BRAS I've had a look at paircmp() in src/lib/valuepair.c and can't see any logic which might do this. Nope. Write a regex to do the

Re: Matching a value within an IP subnet

2010-10-19 Thread Alan DeKok
Brian Candler wrote: Indeed it is not. But NAS-IP-Address is (natively) not a string in RADIUS either, it's a 4-byte integer. To be pedantic: an IPv4 address. Does FreeRADIUS let me treat it as if it were a string? The operator you have chosen to use is: =~. That is defined as doing

Freeradius 1.2.3 and Windows 7

2010-10-19 Thread Krzysztof Srokowski
Hello, Before I ask detailed question I have one simple. Can Freeradius 1.2.3 cooperate successfully with Windows 7 ? I Mean in configuration WPA2-Enterprise (AES) + EAP-PEAP(MSCHAPv2) ? I cant get no information about it. Actually my configuration works fine with Windows XP, so after hours

Re: LDAP authentication failed

2010-10-19 Thread snowman5840
Hi thx for this hint. I have activated realm ntdomain modul but ldap search dosen't work?? Maybe my used filter is wrong? Debug: +- entering group authorize {...} ++[chap] returns noop ++[mschap] returns noop ++[unix] returns notfound [ntdomain] Looking up realm FIRMA1 for User-Name =

Re: Freeradius 1.2.3 and Windows 7

2010-10-19 Thread Alan DeKok
Krzysztof Srokowski wrote: Before I ask detailed question I have one simple. Can Freeradius 1.2.3 What's that? There is no version 1.2.3. cooperate successfully with Windows 7 ? I Mean in configuration WPA2-Enterprise (AES) + EAP-PEAP(MSCHAPv2) ? I cant get no information about it.

Re: Authentication failing when using *...@domain.com

2010-10-19 Thread Ryan Garrett
Alan, There must be something I am not understanding, as I am unclear on what I need to be adding to proxy.conf. And from what I can tell, inner-tunnel doesn't need to be touched with the way I am configuring, or is that incorrect? If my realm is testlab.net, do I just need an entry that is:

Re: plpgsql freeradius authentication function

2010-10-19 Thread Kafui Akyea
I have not changed the order of the default queries. Because for users in radcheck table it authenticates perfectly but for users who are not thats when i need to get an Access-Reject but i dont get anything at all. On Tue, Oct 19, 2010 at 1:18 AM, Alan DeKok al...@deployingradius.comwrote:

Re: Matching a value within an IP subnet

2010-10-19 Thread Brian Candler
On Tue, Oct 19, 2010 at 02:11:06PM +0200, Alan DeKok wrote: Does FreeRADIUS let me treat it as if it were a string? The operator you have chosen to use is: =~. This was more of a wish than an actual usage. The question I meant was: is there any sort of operator to match an IP address

AD authenication issue with machine authentication

2010-10-19 Thread Cannady, Mike
I'm having a problem with XP (and windows 7) machine authentication from a Procurve switch (802.1x and eap-radius) and the supplicant using PEAP to an AD domain. The FreeRadius version is 2.1.7. My configuration works for the following style authentication requests: jmct...@htc.com