FreeRADIUS - no service!

2010-12-15 Thread Александр Чурсин
Hi to all! We have an issue with a FreeRADIUS server (FreeRADIUS server and Oracle Database). Sometimes it fails and stops to process the AAA requests (only complete server reboot helps)! Here is the log output during the time of a failed situation: [r...@aaa0 ~]# tailf

RE: FreeRADIUS - no service!

2010-12-15 Thread Ramon Escriba
Sorry, no idea about Oracle, but: Mon Dec 13 20:09:51 2010 : Error: There appears to be another RADIUS server running on the authentication port 1812 Seems the radius proces is still running, so does not stops properly. Maybe the former rasiusd process was hanged. Do an xxradius stop look

Re: FreeRADIUS - no service!

2010-12-15 Thread Fajar A. Nugraha
2010/12/15 Александр Чурсин achursi...@gmail.com: Hi to all! We have an issue with a FreeRADIUS server (FreeRADIUS server and Oracle Database).  Sometimes it fails and stops to process the AAA requests (only complete server reboot helps)! Here is the log output during the time of a failed

RE: FreeRADIUS - no service!

2010-12-15 Thread Александр Чурсин
Thanks for the replies! We'll try to kill the process manually, but it is still unclear what is the core reason of the service fall ? The logs should speak for itself. To fix this one you need to coordinate with network/dba guys. Sometimes its simply because oracle s dead or too busy to respond

Re: FreeRADIUS - no service!

2010-12-15 Thread Fajar A. Nugraha
2010/12/15 Александр Чурсин achursi...@gmail.com: The logs should speak for itself. To fix this one you need to coordinate with network/dba guys. Sometimes its simply because oracle s dead or too busy to respond to anything. Other times in can be firewall issues. There were no network changes

Re: FreeRADIUS - no service!

2010-12-15 Thread Alan Buxey
Hi, We have an issue with a FreeRADIUS server (FreeRADIUS server and Oracle Database). Sometimes it fails and stops to process the AAA requests (only complete server reboot helps)! Here is the log output during the time of a failed situation: from the log 1) no connection to the DB. thats

Re: Freeradius/Oracle compilation

2010-12-15 Thread alexandre.chapellon
It works here, is indeed smarter and lighter. Hope it's ok. --- /tmp/configure.in.orig 2010-12-14 23:24:40.019101002 -1000 +++ /tmp/configure.in 2010-12-14 23:18:25.875101003 -1000 @@ -86,32 +86,37 @@ if test x$oracle_lib_dir != x ; then

Re: FreeRADIUS - no service!

2010-12-15 Thread Alan Buxey
Hi, There were no network changes before and during the RADIUS outage (no firewall). Dba guys say that the Oracle is Ok, and no significant issues were placed on record according to oracle logs. Then do a simple test. When radius says can't reconnect, connect manually from the radius

query

2010-12-15 Thread karnik jain
Hi, I have downloaded the free radius server and successfully installed on linux machine.. Can you please tell me that does your this implimentation supports the US-ASCII to UTF-8 conversion as you are saying this is compliant to RFC 2865 ? thanks and regards, karnik jain - List

Proxying CoA

2010-12-15 Thread Zsolt Tripolszky
Hello, I'm trying to figure out how to proxy CoA packets. I have read through a similar thread on this list ( http://lists.freeradius.org/mailman/htdig/freeradius-users/2010-July/msg00335.html ), but somehow I cannot get it to work. My setup is the following: In my proxy.conf: home_server

Re: FreeRADIUS - no service!

2010-12-15 Thread Александр Чурсин
Alan, please, clarify some things: 1) in the accounting {} sectin of your server, instead of just calling SQL, wrapper it: if (Acct-Session-Time != 0) { sql } else { ok } Where can I put this wrapper, sql.conf or in some source file and

Re: FreeRADIUS - no service!

2010-12-15 Thread Alan Buxey
Hi, Alan, please, clarify some things: 1) in the accounting {} sectin of your server, instead of just calling SQL, wrapper it: if (Acct-Session-Time != 0) { sql } else { ok } Where can I put this wrapper, sql.conf or in some

Re: query

2010-12-15 Thread Alan DeKok
karnik jain wrote: Hi, I have downloaded the free radius server and successfully installed on linux machine.. Can you please tell me that does your this implimentation supports the US-ASCII to UTF-8 conversion They are compatible. No conversion is required. as you are saying this is

RE: FreeRADIUS - no service!

2010-12-15 Thread Александр Чурсин
Ok, thanks for explanation. The RADIUS version is 1.1.0 In the accounting section of the radiusd.conf we have: accounting { #detail #acct_unique # # Vladikavkaz OSE Acct-Type OSE { acct_unique

Re: query

2010-12-15 Thread karnik jain
Hello Sir, Thank you so much for spending valuable time of yours for the reply. As per my understanding of RFC 2865, It is clearly written in section 5.0 of RFC 2865 that “text 1-253 octets containing UTF-8 encoded 10646 [7] characters. Text of length zero (0) MUST NOT be sent; omit

Re: query

2010-12-15 Thread karnik jain
Hello, Thank you so much for spending valuable time of yours for the reply. As per my understanding of RFC 2865, It is clearly written in *section 5.0 of RFC 2865* that, *“text 1-253 octets containing UTF-8 encoded 10646 [7] characters. Text of length zero (0) MUST NOT be sent; omit the

Re: query

2010-12-15 Thread John Dennis
On 12/15/2010 10:00 AM, karnik jain wrote: Hello Sir, Thank you so much for spending valuable time of yours for the reply. As per my understanding of RFC 2865, It is clearly written in section 5.0 of RFC 2865 that “text 1-253 octets containing UTF-8 encoded 10646 [7]characters. Text

Re: query

2010-12-15 Thread Alan DeKok
karnik jain wrote: As per my understanding of RFC 2865, It is clearly written in *section 5.0 of RFC 2865* that, *“text 1-253 octets containing UTF-8 encoded 10646 [7] characters. Text of length zero (0) MUST NOT be sent; omit the entire attribute instead.” * So, It has to be

Re: wifi ip allocation

2010-12-15 Thread pauvre
Thank you Alexandre for your analysis and more precision on your thread! It is very helpul and appreciate!! -- View this message in context: http://freeradius.1045715.n5.nabble.com/wifi-ip-allocation-tp3286614p3306442.html Sent from the FreeRadius - User mailing list archive at Nabble.com. -

mysql huntgroups Access-Reject

2010-12-15 Thread GeneTitus
Greetings from Texas. I'm setting up freeradius to authenticate/authorize network engineers to log into cisco and juniper devices. Some devices we share with other organizations. I need to be able to allow some engineers access to some devices and not others. I'm running on redhat with Mysql as

Re: FreeRADIUS - no service!

2010-12-15 Thread Alan Buxey
1.1.0 ? And this is your ONLY problem? At least upgrade to 1.1.8 - but if you want my help you'll need to be running the current release 2.1.x train Alan - Reply message - From: Александр Чурсин achursi...@gmail.com Date: Wed, Dec 15, 2010 14:29 Subject: FreeRADIUS - no service! To:

RE: FreeRADIUS - no service!

2010-12-15 Thread Sallee, Stephen (Jake)
To be fair the fact that he is able to get along running such an ancient release of FreeRADIUS is a testament to the quality of the software...however it is dangerous to run antiquated versions of well know software, the security implications are horrendous. Jake Sallee Godfather Of Bandwidth

RE: Reals Based Upon Port

2010-12-15 Thread Brian Carpio
So I am still a bit confused by this (I'm just now getting back to this issue). So I have the following setup: - Radiusd Server -- 2 home_servers listening on 1812 and 1813 -- 2 home_servers listening on 1815 and 1816 In my proxy.conf I have the following: proxy server {

RE: FreeRADIUS - no service!

2010-12-15 Thread Александр Чурсин
Honestly and as you have already understood the system is an inheritance from the previous system administrator. Now we try to fix some current issues on it... Ok, I see the best way is an upgrade to a later version. But what about the Oracle database? How can we make an upgrade with a

Re: PEAP/EAP-GTC proxy?

2010-12-15 Thread mgmitch
OK, upgraded to 2.1.10 as suggested. Thanks. However, I have a different issue now -- seems that the passcode is not being proxied over to the home server. I only see a username, nas IP address and proxy state being proxied in the access-request packet but no user-password. Also get a

Password oddity

2010-12-15 Thread discgolfer72
Set up FreeRadius on SLES 10. Using the NTRadPing utility we can authenticate to our back end LDAP server (eDirectory) w/o problem. However, when we enabled Radius authentication on two separate Wireless access points (Linksys WRT54 and DLink WBR 1310), they both fail authentication because the

RE: Password oddity

2010-12-15 Thread Gary Gatten
Someone will for SURE yell at you for using something that old. Or, they'll just ignore you. That is a weird a$$ problem for sure! Why can't you upgrade? At LEAST to the latest 1.x version? -Original Message- From: freeradius-users-bounces+ggatten=waddell@lists.freeradius.org

RE: Password oddity

2010-12-15 Thread discgolfer72
I guess that would be my next step. Anyone else out there seen this particular issue? -- View this message in context: http://freeradius.1045715.n5.nabble.com/Password-oddity-tp3307174p3307212.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List

RE: Password oddity

2010-12-15 Thread John Tabasz (jtabasz)
Where do you play disc golf? -Original Message- From: freeradius-users-bounces+jtabasz=cisco@lists.freeradius.org [mailto:freeradius-users-bounces+jtabasz=cisco@lists.freeradius.org] On Behalf Of discgolfer72 Sent: Wednesday, December 15, 2010 3:36 PM To:

RE: Password oddity

2010-12-15 Thread Ben Lewis
Mainly Tennessee. You? Sent via DROID on Verizon Wireless -Original message- From: John Tabasz (jtabasz) jtab...@cisco.com To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Thu, Dec 16, 2010 00:12:43 GMT+00:00 Subject: RE: Password oddity Where do you play

RE: Password oddity

2010-12-15 Thread John Tabasz (jtabasz)
Nice. I have switched to basketball for the time being but DeLaveaga is my home course in Santa Cruz CA. Love it. From: freeradius-users-bounces+jtabasz=cisco@lists.freeradius.org [mailto:freeradius-users-bounces+jtabasz=cisco@lists.freeradius.org] On Behalf Of Ben Lewis Sent:

multiple usergroups failing; freeradius 2.1.10 + Cisco-AVPairs

2010-12-15 Thread michael
Hi, During a rebuild of our Radius servers from an old freeradius 1.x install to 2.1.10, we've lost ability to push multiple usergroups to our Cisco LNS: MySQL: radcheck: id UserNameAttribute op Value 9791t...@realm Password:= {clear}somepass

Re: multiple usergroups failing; freeradius 2.1.10 + Cisco-AVPairs

2010-12-15 Thread michael
SQL log attached: rlm_sql (sql): Reserving sql socket id: 4 rlm_sql_mysql: query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 't...@realm' ORDER BY id rlm_sql_mysql: query: SELECT id, username, attribute, value, op FROM