Re: FreeRadius going through ISA to reach federation

2011-12-17 Thread Phil Mayers
On 12/16/2011 09:20 PM, Rui Ribeiro wrote: Eh? Who suggested that? Another freeradius-IAS thread in this list. Well, it's not a very useful suggestion in this instance. Setting Reply-Message won't magically make something work. Perhaps the original thread had some context that explains why

Re: I need your help!!!!

2011-12-17 Thread Guillermo William Llanes Suárez
Hola Fajar y amigos. Lo que necesito es, que una ves que un usuario se encuentre ya autenticado no pueda otra persona (robo de identidad) usar ese mismo usuario para autenticarse en otro equipo. Lo que quiero hacer, es, cuando esto suceda, que el intento de autenticacion por segunda ves sea

Re: I need your help!!!!

2011-12-17 Thread Guillermo William Llanes Suárez
Hi Fajar and friends. What I need is that one you see that a user is authenticated and can not be another person (identity theft) use the same user to authenticate to another machine. What I do is, when this happens, the authentication attempt is rejected for second time, or only the user may

Re: radrelay: cross-replication of accounting records between two redundant freeradius servers

2011-12-17 Thread Alan DeKok
Arch Mangle wrote: I've got radrelay replicating accounting packets from a primary radius server to a secondary radius server. The secondary radius server is capable of handling radius accounting/auth requests if NASes cannot reach the primary or the primary fails. ... However, when I test

Re: FreeRADIUS 2.1.12 rlm_sqlcounter bug?

2011-12-17 Thread Alan DeKok
ben beneke wrote: rlm_expr doesn't seem to have extensive documentation, nor was I able to find an example similar to what I want to achieve. It does math. That's it. However, if I understand everything correctly, my solution would be something like the following: rlm_expr is needed to

Always Login incorrect: Could not extract EAP-Message from RADIUS message

2011-12-17 Thread Sergio Belkin
Hi, Sorry I resend the message because of original message was bounced because it was too big. I have a really weird problem. We have a lot of NAS'es and no one of them had this problem, except only one! It gets always login incorrect. If I run eapol_test it complains saying. I've tried

Re: I need your help!!!!

2011-12-17 Thread Alan Buxey
Hi, Hi Fajar and friends. What I need is that one you see that a user is authenticated and can not be another person (identity theft) use the same user to authenticate to another machine. What I do is, when this happens, the authentication attempt is rejected for second time, or only the

Re: FreeRadius going through ISA to reach federation

2011-12-17 Thread Alan Buxey
Hi, In the debug logs, I have:Â ad_recv: Access-Reject packet from host 10.10.66.18 port 1812, id=251, length=24 Â Â Â ÂProxy-State = 0x3137 reject is reject - you need to check the logs of the IAS to see what it thought it was doing (event viewer - IAS events) - you may also

Re: Always Login incorrect: Could not extract EAP-Message from RADIUS message

2011-12-17 Thread Alan DeKok
Sergio Belkin wrote: I have a really weird problem. We have a lot of NAS'es and no one of them had this problem, except only one! It gets always login incorrect. Throw the NAS in the garbage. If I run eapol_test it complains saying. I've tried replacing the nas a few times What does

Re: Always Login incorrect: Could not extract EAP-Message from RADIUS message

2011-12-17 Thread Sergio Belkin
2011/12/17 Alan DeKok al...@deployingradius.com: Sergio Belkin wrote: I have a really weird problem. We have a lot of NAS'es and no one of them had this problem, except only one! It gets always login incorrect.  Throw the NAS in the garbage. If I run eapol_test it complains saying. I've

Re: Always Login incorrect: Could not extract EAP-Message from RADIUS message

2011-12-17 Thread Alan DeKok
Sergio Belkin wrote: Ooops, sorry it says could not extract EAP-Message from RADIUS message That's a message on the NAS. Ask the NAS manufacturer what it means. Hmmm, so it should something wrong in the network, because I've tried from 2 differentes Access Points, with differents firmware

Re: Always Login incorrect: Could not extract EAP-Message from RADIUS message

2011-12-17 Thread Sergio Belkin
2011/12/17 Alan DeKok al...@deployingradius.com: Sergio Belkin wrote: Ooops, sorry it says could not extract EAP-Message from RADIUS message  That's a message on the NAS.  Ask the NAS manufacturer what it means. Hmmm, so it should something wrong in the network, because I've tried from 2

Re: FreeRadius going through ISA to reach federation

2011-12-17 Thread Rui Ribeiro
Message: 5 Date: Sat, 17 Dec 2011 10:51:42 + From: Phil Mayers p.may...@imperial.ac.uk Subject: Re: FreeRadius going through ISA to reach federation To: freeradius-users@lists.freeradius.org Message-ID: 4eec743e.5000...@imperial.ac.uk Content-Type: text/plain; charset=ISO-8859-1;