RE: duplicate sessions

2010-03-01 Thread Santiago Balaguer García
I think you need to analyse more the accounting request because the MAC and IP address would be different. Check the attributes framedipaddress and calledstationid in Accountig request. Date: Sun, 28 Feb 2010 20:56:16 +0400 From: na...@ultel.net To: freeradius-users@lists.freeradius.org

RE: framedipaddress

2010-05-12 Thread Santiago Balaguer García
We worked with Meru as Access Point, but not as NAS. If you want to autrhenticate users, then it is not the correct device; use another one. Anyway I think there is other better devices in the market at he same cost. Date: Tue, 11 May 2010 17:16:31 +0200 From: al...@deployingradius.com

RE: plpgsql freeradius authentication function

2010-10-18 Thread Santiago Balaguer García
In which statement do you implement this query? Date: Sat, 16 Oct 2010 11:49:36 -0400 Subject: plpgsql freeradius authentication function From: kak...@gmail.com To: freeradius-users@lists.freeradius.org Hi I have a plpgsql function being called from freeradius to do authentication but i

RE: Redundant SQL

2010-10-19 Thread Santiago Balaguer García
Hi Chester, I think for a good behaviour of SQL server, all of them have to be working in a normal startup of a freeradius service. Try to repair why your SQL server are down. You have to have a stable system. Regards, Santiago From:

RE: Mikrotik-Xmit-Limit - Not enforced on first logon but is on subsequent logons...

2010-12-02 Thread Santiago Balaguer García
Hi, I normally use MK for lots of things. The Mikrotik-Xmit-Limit attribute is recognize for MK as a limitation, so when the limit arrives, the MT cuts the user account. You can write a exec program to modify the Mikrotik-Xmit-Limit attribute or insert a trigger in the DB or use

RE: Radius Load-Balancing concept

2008-01-04 Thread Santiago Balaguer García
People, I have several radius severs who have configurated the same databases. As you said radius service has a fail-over when they connect to DB and the first one fails. However, the main problem that I see in your configuration is the concurrency of database access. If you, at least, has

RE: alan's book, or anything new on the horizon

2008-01-16 Thread Santiago Balaguer García
I have been following you since three years and I trust you, so I will buy your book. Date: Tue, 15 Jan 2008 17:03:52 +0100 From: [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Subject: Re: alan's book, or anything new on the horizon Duane Cox wrote: I wonder if Alan ever

RE: 1.1.7 and rlm_sql_mysql duplicated query

2008-02-17 Thread Santiago Balaguer García
The answer is not totally correct. Because a microcuts in the connectibity of hotspot cause that hotspot re-sends the acct request. In that case, you have to desactivate: - accounting_start_query_alt - accounting_stop_query_alt Maybe It can cause that some requests do not register, and it

[no subject]

2008-03-11 Thread Santiago Balaguer García
Hi, I have two radius server since three years ago. They are my two production AAA servers and can authenticate until 300.000 accounts. So my RADIUS database (PostgreSQL) grew up enough and I realize that my SQL queries slow down. I know that I have four table with almost 500.000 registers

RADIUS database growing up

2008-03-11 Thread Santiago Balaguer García
Hi, I have two radius server since three years ago. They are my two production AAA servers and can authenticate until 300.000 accounts. So my RADIUS database (PostgreSQL) grew up enough and I realize that my SQL queries slow down. I know that I have four table with almost 500.000 registers

RE: Database performance (was Re: )

2008-03-11 Thread Santiago Balaguer García
I usually execute VACUMM. But the time of the queries does not decrease. PostgreSQL 7.4 Date: Tue, 11 Mar 2008 10:39:47 + From: [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Subject: Re: Database performance (was Re: ) Hi,Any suggestion for improving the throughput and

RE: Postgres SQL Alarm on duplicated record

2008-03-18 Thread Santiago Balaguer García
HI, I supposed you have in radiusd.conf file this code: # Create a unique accounting session Id. Many NASes re-use or# repeat values for Acct-Session-Id, causing no end of# confusion.# # This module will add a (probably) unique session id# to an

RADIUS ports

2008-03-27 Thread Santiago Balaguer García
Hi, Recently I have just configured another RADIUS server and I use /etc/services for radius service ports. I use auth port 1645 and acct port 1646. But, are these ports better than auth port 1812 and act port 1813 ? What ports are more standart ? Santiago

RE: Mikrotik as NAS with PPPoE - checkval

2008-08-20 Thread Santiago Balaguer García
Yes, you needn't. What you need is to create a normal user account and add these attributes in radreply: Framed-Protocol = PPP, Framed-IP-Address = 10.0.0.x, Framed-IP-Netmask = 255.255.255.0, Be carefull because you have to modify the ppp profiles in the Mikrotik client in the option /ppp

Re: Double entries in Radacct - FreeRadius + MT

2007-03-27 Thread Santiago Balaguer García
Yes, what Alan says is true, in part . I have undred of MT and in some locatios I have the same problem. But I arrive to one conclusion for this affair: the main problem is the lack of conectivity to the Radius server and NAS. From:Alan DeKok [EMAIL PROTECTED]Reply-To:FreeRadius users mailing

realms in my Postgres DB

2007-04-03 Thread Santiago Balaguer García
Hi people, I have several roaming agreements and usually add a new entry in proxy.conf file when I sign a new one. I realize that I my DB about radius appears the realms table. Do you know it this table is useful? Can I put my realm from proxy.conf file to realm table? Thanks, SantiagoBusca a

RE: RE : FreeRadius + Freetds + unixodbc

2007-04-18 Thread Santiago Balaguer García
so by starting radiusd -X i have this error:rlm_sql (sql): Driver rlm_sql_unixodbc (module rlm_sql_unixodbc) loaded and linkedrlm_sql (sql): Attempting to connect to [EMAIL PROTECTED]:/radiusrlm_sql (sql): starting 0rlm_sql (sql): Attempting to connect rlm_sql_unixodbc #0rlm_sql_unixodbc: SQL

Re: Proxy.conf regex

2007-05-07 Thread Santiago Balaguer García
DEFAULT User-Name =~ "(([a-zA-Z]+\.)*foo.com", Proxy-To-Realm := "foo.com" Will cause the following to be proxied to "foo.com": [EMAIL PROTECTED] [EMAIL PROTECTED] [EMAIL PROTECTED] ... How can I integrate this entryof user file in a DB? Must I put this entries in radcheck table or in radreply

RE: Multiple shared secrets?

2007-06-12 Thread Santiago Balaguer García
I think there is no problem. I have in my nas table (or clients.conf): 80.45.78.12/32 and 80.45.78.0/24 with diferent secret and I do not have any conflict. From:Mark J Elkins [EMAIL PROTECTED]Reply-To:FreeRadius users mailing list freeradius-users@lists.freeradius.orgTo:FreeRadius users

Re: Problem with NULL realm..

2007-07-10 Thread Santiago Balaguer García
But, can Freeradius 2.x.x read a realm table instead of proxy.conf file? I guess FreeRadius 2.xx will make things easier? Éxitos, grandes clásicos y novedades. Un millón de canciones en MSN Music. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

accounting exec when Acct-Status-Type == Stop

2007-07-10 Thread Santiago Balaguer García
hello all, i have added the following lines in acct_users file DEFAULT Acct-Status-Type == Start Exec-Program-Wait = "/usr/local/start.sh" DEFULT Acct-Status-Type == Stop Exec-Program-Wait = "/usr/lcal/stop.sh" started radius in debug mode and i haven't seen Exec-Program-Wait executing those

RE: accounting exec when Acct-Status-Type == Stop

2007-07-11 Thread Santiago Balaguer García
Nobody understood my question. I want to know how to custom a specific account with an specific sh exec. One different for each group of accounts. And I want to do using my database. From: Santiago Balaguer García[EMAIL PROTECTED]Reply-To: FreeRadius users mailing list freeradius-users

RADIUS attributes: acctoutputoctects and acctinputoctect in mikrotik

2007-07-24 Thread Santiago Balaguer García
Hi, Iam working with freeradius and mirkrotik routers since two years. However, I have never realized that the radius attributes acctoutputoctects and acctinputoctects are intechanged in mikrotik. Does anyone know ths mikrotik bug? SantiagoÉxitos, grandes clásicos y novedades. Un millón de

Re: RADIUS attributes: acctoutputoctects and acctinputoctect inmikrotik

2007-07-25 Thread Santiago Balaguer García
nputoctect inmikrotikDate:Tue, 24 Jul 2007 20:16:10 +0100I have RouterOSv2.9 and input is input and output is output.Ivan KalikKalik Informatika ISPDana 24/7/2007, "Santiago Balaguer García" [EMAIL PROTECTED]pi¹e: Hi, I am workingwith freeradiusand mirkrotik routers since two years. However, I

RE: Re[2]: Adding a NAS via SQL

2007-07-31 Thread Santiago Balaguer García
I have one question to this, you suposed that RADIUS and DataBase services are in the same machine, what happens if these services are in severa or there are replicate servers? My advice is to create a database trigger on INSERTs, UPDATEs,DELETEs.For example, my postgresql trigger written in

RE: healthcheck?

2007-08-20 Thread Santiago Balaguer García
Use: Auth-Type := reject From:Kevin J [EMAIL PROTECTED]Reply-To:FreeRadius users mailing list freeradius-users@lists.freeradius.orgTo:freeradius-users@lists.freeradius.orgSubject:healthcheck?Date:Thu, 16 Aug 2007 09:40:56 -0700 (PDT) We want to reject slb health checks immediately. What is

RE: access only particular website through RADIUS

2007-08-31 Thread Santiago Balaguer García
Yes, it forbit the access to some site it is easy if you have the correct NAS. You need for instance a mikrotik device where in the walled garden you can allow some site but you can ban others. ;) From:"Parham Beheshti" [EMAIL PROTECTED]Reply-To:FreeRadius users mailing list

RE: FreeRADIUS and iODBC

2007-09-24 Thread Santiago Balaguer García
What is the question? Perfectly You can use a MS SQL server using iodbc. From:"Josh Howlett" [EMAIL PROTECTED]Reply-To:FreeRadius users mailing list freeradius-users@lists.freeradius.orgTo:"FreeRadius users mailing list" freeradius-users@lists.freeradius.orgCC:Josh Howlett [EMAIL

accept or deny users depending on the realm

2007-11-22 Thread Santiago Balaguer García
Hi, I use freeradius for a long time and now we are authenticating users of roaming partners. I normally allow all the users of a domain. For example: trustive/johndoeor teo/maria and I use mydomain realm. realm trustive { type= radiusauthhost =

RE: Dynamic Realm

2007-11-28 Thread Santiago Balaguer García
Is there any way to put all domains in a table and when freeradius start up, it read this table and recognizes them? I do not understand the realm table in radius DB. Any suggestion? From: [EMAIL PROTECTED] To: [EMAIL PROTECTED]; freeradius-users@lists.freeradius.org Subject: Re: Dynamic Realm

RE: Dynamic Realm

2007-11-28 Thread Santiago Balaguer García
Thanks for the aclaration about realms. It is my repeated question. Now I am waiting to freeradius 2.0 and try it. By the way, I usually write in plain text. It was a browser bug. From: [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Subject: Re: Dynamic Realm Date: Wed, 28

Distributed Data Base

2004-11-10 Thread Santiago Balaguer García
I have to replicate my RADIUS databases, one in my central office and the another in another city. I prepare my RADIUS server to support that. As it is usual I have a MySQL database. Do you know if MySQL can fucntion as Distributed DataBase ? Santiago

Execute a script at the end of a session

2004-12-10 Thread Santiago Balaguer García
Hi, I am using RADIUS for more than 9 months and for each client a initial script is executed since the radreply table in MySQL has a field: * id *UserName * Attribute * OP *

Attribute Name of end of session

2004-12-10 Thread Santiago Balaguer García
Hi, I am using Radius for more than 9 months. I am using the attribute Exec-Program-Wait in radreply as initial script. Is there another attibute to add in radreply to specify the path of a script of end of session? _ Un amor,

Re: Execute a script at the end of a session

2004-12-10 Thread Santiago Balaguer García
10, 2004 at 09:23:12AM +, Santiago Balaguer García wrote: Hi, I am using RADIUS for more than 9 months and for each client a initial script is executed since the radreply table in MySQL has a field: * id

Re: Execute a script at the end of a session

2004-12-10 Thread Santiago Balaguer García
I read acct_users and others files, but what I want to do is to add some register in the MySQL DB and can execute a different script to each user. This is my idea but I don't know if it is possible. On Fri, Dec 10, 2004 at 09:23:12AM +, Santiago Balaguer García wrote: Hi, I am using

Re: Execute a script at the end of a session

2004-12-16 Thread Santiago Balaguer García
/finish_script.sh %u %n | I locate the accounting section, but I unknown what I must modify. So I attach my radius.conf. Subject: Re: Execute a script at the end of a session Date: Sat, 11 Dec 2004 15:26:18 +1100 On Fri, Dec 10, 2004 at 04:38:05PM +, Santiago Balaguer García wrote: I read acct_users

Re: Exec-Program

2004-12-29 Thread Santiago Balaguer García
You should have something like this in radiusd.conf: files { usersfile = ${confdir}/users acctusersfile = ${confdir}/acct_users compat = no } And you also should have something like this in radiusd.conf: preacct { preprocess

Primary key in radacct table

2008-10-06 Thread Santiago Balaguer García
Hi, I am using a freeradius 1.1.7 + postgres since 3 years ago. The AAA service works fine, however my radacct table has sonetimes duplicate registers. I realize that it happens when a NAS does not have a realiable Internet conection, so NAS send the accounting packets several times.

RE: Primary key in radacct table

2008-10-07 Thread Santiago Balaguer García
and it will be rejected. you will see this in your log files.Another idea is to change NAS or you can create cron script to delete duplicated entries. MT On Mon, Oct 6, 2008 at 5:35 PM, Santiago Balaguer García [EMAIL PROTECTED] wrote: Hi,I am using a freeradius 1.1.7 + postgres since 3 years ago. The AAA

RE: Primary key in radacct table

2008-10-08 Thread Santiago Balaguer García
with duplicated session is very strange. My NAS (Mtik 2.9.x and Mtik 3.x) sends duplicated session ids but almost in the same time. For example one session is started now and the second one is transfered 1 second later. On Tue, Oct 7, 2008 at 8:54 AM, Santiago Balaguer García [EMAIL

xDSL with dynamic addressing

2008-10-29 Thread Santiago Balaguer García
Hi, I am using freeradius since four years and I used PPTP/L2TP tunnel for autenticating users against my RADIUS servers with one of my NAS has a dynamic IP (xDSL). However, I can not rely on these connections and the connectivity sometimes fall down and the tunnel, too. I have some

accounting bug in Mikrotik

2008-12-11 Thread Santiago Balaguer García
Hi, I am working with freeradius and mikrotik gateway for a long time, but recently I detect in my PostgreSQL database, in radacct table some inconsistencies. First af all, I say that I have the standard configuration file (postgres.sql) for accounting queries. My problem is sometimes

RE: accounting bug in Mikrotik

2008-12-11 Thread Santiago Balaguer García
It is what I thought: Accounting Stop packet should be the only thing that inserts dates. Thanks. To: freeradius-users@lists.freeradius.org Subject: Re: accounting bug in Mikrotik Date: Thu, 11 Dec 2008 10:59:26 +0100 From: [EMAIL PROTECTED] I am working with freeradius and mikrotik gateway

Repeated accopunting packets

2008-12-11 Thread Santiago Balaguer García
Hi, In a normal revision of detail file of radius logs I see: - Wed Dec 10 18:27:04 2008Acct-Status-Type = AliveNAS-Port-Type = Wireless-802.11Calling-Station-Id = 00:15:AF:09:5E:B5 Called-Station-Id = hs-AKIWIFINAS-Port-Id = br-AKIWIFI

RE: Best Config

2009-01-26 Thread Santiago Balaguer García
If you have these figures, yours database has to be GOOD DB server and a GOOD machine. To: freeradius-users@lists.freeradius.org Subject: Re: Best Config Date: Sat, 24 Jan 2009 11:08:53 +0100 From: t...@kalik.net From experience, what would be the best server configuration for 200,000 users

Custom error messages

2009-02-12 Thread Santiago Balaguer García
Hi, I use freeradius 1.1.7 for autenticate users to provide Internet connectivity. I have groups of usernames who has access from anywhere. However, I have others groups which only has access from one NAS (promotional codes). I know how to block these accounts from my Postgres Database:

Implementing 'Invalid before' feature

2009-03-02 Thread Santiago Balaguer García
Good morning, I am working with FR some years ago, and I have implemented a prepaid card system. I want to get an account which are not valid until some date. I am looking for some freeradius attribute which means 'account invalid until 15th march 2009'. I do not know if I have

RE: stop old open session and star new..

2009-03-09 Thread Santiago Balaguer García
You have to implement some (perl, PHP, shell) code to remove the 'stale session' from your database. Date: Fri, 6 Mar 2009 20:33:05 -0300 From: alexan...@ondainternet.com.br To: freeradius-users@lists.freeradius.org Subject: stop old open session and star new.. Hello, How i can solve

Correct operator in radcheck

2009-03-23 Thread Santiago Balaguer García
Hi, I am several years working woth freeradius, bit recently I surgeg me a question: I do not want that johndoe account never connect from NASES with Client IP: * 195.56.53.23 * 96.53.26.59 * 56.15.86.35 * 56.15.86.36 I know I have to use the attribute Client-IP-Address, so radckech

Expiration vs WISPr-Session-Terminate-Time

2009-03-24 Thread Santiago Balaguer García
Hi, Today I did some test with radreply.WISPr-Session-Terminate-Time and radcheck.Expiration. It is supposed both attributes do the same, but Expiration is from AAA server side, meanwhile Session-Terminate-Time is from NAS side. However, there is a difference if you want to to set

RE: failover and load balancing

2009-04-22 Thread Santiago Balaguer García
Postgres does supposedly have a version in beta for full master-master replication, but every time we've tried to get it running it's crashed on us as soon as we tried to actually write any data. Postgres in general seemed much slower than MySQL for reading the data we needed as well. I

RE: failover and load balancing POSTGRESQL

2009-04-22 Thread Santiago Balaguer García
Yes, man. We know the PostgreSQL solution does not work. ORACLE is expensive. MySQL is one master and serveral slaves. Do you know another master-master database management system which is cheap? Santiago Ok. That is true. In that case you are talking about loosing money if the

username with sereral passwords. Which op value?

2009-04-22 Thread Santiago Balaguer García
Hi, I want the 'san0001' user has two passwords. There is in my radcheck table: Username | Attribute | op | value san0001 Password ?? santi1 san0001 Password

RE: Dynamic clients and NAS-Identifier

2009-05-20 Thread Santiago Balaguer García
I'm sure that I'm not the only one that have NAS's behind dynamic IPs, and this would make radius traffic from such NAS's much more secure. OK, if you have Dynamic public IP you have two options: 1) use a DNS to identify the dynamic IP of your hotspot. It means that your DSL router or

Stop alive requests in a dead realm

2009-06-03 Thread Santiago Balaguer García
Hi, I am using freeradius 2.1.3 for my AAA servers. I have a little problem when a third-patner RADIUS is dead. My problem is my freeradius send the following status packect every 2-5 seconds. Sending Access-Request of id 77 to 200.160.126.23 port 1812 User-Name :=

RE: How use tagged atrributes?

2009-06-05 Thread Santiago Balaguer García
1) The name os the rewrite name is wrong: try with add_service_volume 2) Do you have in your dictionary the 'ERX-Service-Volume:1' attribute. Unlass try only with 'ERX-Service-Volume' To: freeradius-users@lists.freeradius.org Subject: How use tagged atrributes? From: r.fila...@ttk.ru Date:

Failover fails in proxy.conf

2009-06-15 Thread Santiago Balaguer García
Hi, I am using in my AAA servers the freeradius 2.1.3 version. I am configuring the failover for the myrealm.com in proxy.conf. For myrealm.com realm I have two AAA servers: 1.2.3.4 and 1.2.3.5 home_server primary_server {

RE: Failover fails in proxy.conf

2009-06-16 Thread Santiago Balaguer García
With the primary server everything works fine, but my problem is when I force to switch to fallover server (I switch off IP 1.2.3.4 machine) my freeradius server does not change to request 1.2.3.5 server. How hard have you tried? It does not mark home server as dead on the first packet

RE: Simutaneus Check Query in FR2?

2009-08-04 Thread Santiago Balaguer García
Hi, Currently my Simultaneous-Use attribute is not working and I have few questions regarding this. Following are my setup: OS: CentOS 5.3 freeradius2-2.1.6 MySQL 5.0.45 PERL 5.8.8 === I am consulting the FAQ checklist. Some are not applicable to me

RE: Simutaneus Check Query in FR2?

2009-08-04 Thread Santiago Balaguer García
Date: Tue, 4 Aug 2009 14:42:55 +0800 Subject: Re: Simutaneus Check Query in FR2? From: d88...@gmail.com To: freeradius-users@lists.freeradius.org You are looking for in the wrong directory. In FR2 the SQL queries are in sql/mysql/dialup.conf. In this file you will find the

RE: NAS ? What is the best option

2009-10-13 Thread Santiago Balaguer García
Hi, I am using MikroTik and I am vry satisfied. However, it is not a easy device to configura and understand all its different configurations. I do not understand why you have to ue POD packets. If you do correctly the configurations and you have you want to offer your users, I think you

RE:

2009-10-20 Thread Santiago Balaguer García
You need additional attributes if you use vendor attributes. Special attributes are related to the NAS you use. The migration from MySQL to PostgreSQL is easy since there is th postgresql DB schema in the instalacion sources (find some file with sql extension). The use of a DHCP server

RE: radacct and db handles

2009-10-27 Thread Santiago Balaguer García
The problem is 'Reply-Msg' attribute is not recognized by the radius server becasuse it is a specific vendor attribute. Try to find the specific dictionary. From: adem...@netwizard.com.br To: t...@kalik.net; freeradius-users@lists.freeradius.org Subject: RE: radacct and db handles Date:

Duplicate SQL queries

2009-12-14 Thread Santiago Balaguer García
Hi, It is a long time since I work with FR and hotspots. I am using a Postgres database, but I want to move to a ORACLE database. To keep the consistency and the service I want to run simultaneously both databases, so the INSERTs and UPDATEs have to be done in Postgres and ORACLE

RE: accounting

2009-12-16 Thread Santiago Balaguer García
1. Can freeradius log accounting info in a local file, meaning not to use a sql database? If yes, how to enable that and where the log files will be (configurable?) You needn't use a database if you do ot want. Depend on the level of the detail you want there is the var/log/freeradius

RE: Is it possible to authenticate RADIUS users just on Username with no password?

2005-02-22 Thread Santiago Balaguer García
Yes, It is possible and I use it for authenticating routers and IP phones. These devices don't respond a login request with login/passwd. a solution is, if your NAT supports it, put as login = device MAC address and as PASSWORD = nothing. Obviusly, your have to declare this user=MAC in

Security in the network traffic

2005-04-08 Thread Santiago Balaguer García
Hi people, I am still using freeradius 0.9.3 in a server with devian distribution for more than one year. However I have a doubt: Can I use acctSessionId AcctUniqueId attributes in order to crypt the traffic to achieve a safer communications ? If it is so, How do you implement in the system?

RE: EAP-SIM HOWTO

2005-04-22 Thread Santiago Balaguer García
I have the same problem although my RADIUS server is running for two years. I don't know how authenticate the SIM cards?? From: "Giorgos Kostopoulos" [EMAIL PROTECTED] Reply-To: freeradius-users@lists.freeradius.org To: freeradius-users@lists.freeradius.org Subject: EAP-SIM HOWTO Date: Wed, 13

Database Replication

2005-07-05 Thread Santiago Balaguer García
Hi people, I am using freeradius 1.0.3 for lot od months and in the previous version it had been working so well. Nowadays I am changes my systems: servers. And I using instead of MySQL, Postgres. Everythings work OK. My both Postgres servers have database replicacion working well. My question

Proble with an Accounting query

2005-07-19 Thread Santiago Balaguer García
Hi people, I am using freeradius with mysql support for two years. I installed the last version of freeradius 1.0.4 and a Postgres DB. My Radius server authorize well, however it can not account. When I debug with radius -X in the inictial mesages appear this query: INSERT into radacct

Postgres problem

2005-07-20 Thread Santiago Balaguer García
I am migrating mu MySQL DB to Postgres. My authentication ios OK, but the accounting query insertion fails with the following error: rlm_sql_postgresql: Status: PGRES_FATAL_ERRORrlm_sql_postgresql: affected rows =rlm_sql_postgresql: Postgresql check_error: PGRES_FATAL_ERROR, returning

RE: Ading NAS to MySQL DB

2005-11-16 Thread Santiago Balaguer García
I am very keen on knowing how I can replace my clients.conf file by a SQL query. From: "Alex M" [EMAIL PROTECTED]Reply-To: FreeRadius users mailing list freeradius-users@lists.freeradius.orgTo: "'FreeRadius users mailing list'" freeradius-users@lists.freeradius.orgSubject: Ading NAS to MySQL

DNS non reachable

2006-01-04 Thread Santiago Balaguer García
Hi people, I noticed a possible error in freeradius 1.0.5 running in a Debian Server. Iuse clients.conf file to list my NAS clients.What happens if one DNS entry in clients.conf is not reachable by the RADIUS server? My experience is when you re-launch the radiusd process, this process can not

NAS table

2006-01-23 Thread Santiago Balaguer García
Hi people, I am using freeradius as authentication service for two years. I use freeradius 1.0.4 in a Debian servers. My quiestion is I use clients.conf file for mu nas clients, however I read in the freeradius doc that this file can be supported in an database ( it is very useful for me because

realms in DB

2006-03-03 Thread Santiago Balaguer García
Hi people, I am using freeradius-1.0.4 for more than two years in a Debian machine. I have all my user configurations in a Postgres DB. Now I migrate the clients.conf to DB successfully. For that porpouse I write at the end of my clients.conf: # Set to 'yes' to read radius clients from the

Realms in DB

2006-03-06 Thread Santiago Balaguer García
Hi people, I am using freeradius-1.0.4 for more than two years in a Debian machine. I have all my user configurations in a Postgres DB. Now I migrate the clients.conf to DB successfully. For that porpouse I write at the end of my sql.conf: # Set to 'yes' to read radius clients from the

EAP-TTLS

2006-03-06 Thread Santiago Balaguer García
Hi people, When I configure eap.conf file and re-launch ./radiusd -X appears: * rlm_eap: Loaded and initialized type gtc tls: rsa_key_exchange = no tls: dh_key_exchange = yes tls: rsa_key_length = 512 tls: dh_key_length = 512 tls: verify_depth = 0 tls: CA_path =

Re: Realms in DB

2006-03-06 Thread Santiago Balaguer García
I do roaming with third companies, so instead of add all the realms in the file proxy.conf file, I would prefer to have them in realm table in my postgres DB. It is easier to handle. Otherwise, what is the use of realms and realmgroup tables?? I can also see a dictionary table commented

Accounting

2006-03-09 Thread Santiago Balaguer García
Hi, I do proxy RADIUS correctly. so a radius account can be connected by different NAS'es. Each NAS is owned by a Hotspot Operator. I have different costs of roaming service depending on the Hotspot Operator. How can I controll the NAS of a hotspot Operator (not is valid the nasipaddress) ?

Proxy RADIUS problem

2006-04-24 Thread Santiago Balaguer García
Hi people, I have a LINUX machine with freeradius 1.1.10. I do proxy RADIUS correctly with one remote server, but if I add in my proxy.conf file a redundant one because the primary RADIUS fails, it doesn't work correctly. I want to do roaming with two remote RADIUS servers to the

RE: Proxy RADIUS problem

2006-04-25 Thread Santiago Balaguer García
My problem with the configuration above described is my RADIUS proxy doesn't active fallover. It means the first entry falis, freeradius doesn't verify the following entry of domain1. I test putting the label: ldflag = fail_over in the description os a realm entry. Whay can I

Allowed and forbitten users in a NAS.

2006-04-25 Thread Santiago Balaguer García
I have a freeradius 1.1.0 and a DB with all my users. I have two kinds of users: * users who can connect to all hotspots * user who can only connect to one or some hotspots. Actually I can use a script in Exec-Program-Wait property to differenciate, but I don't seem a very clean method.

Several passwords for a user

2006-05-11 Thread Santiago Balaguer García
Hi, I use freeradius-1.1.0. Where is any problem an account has two or more entries in radcheck table??? I use : 11:22:33:44:55:66 :='' 11:22:33:44:55:66 :=mypassword I change the op := instead of ==. Is there any problem???

RE: Several passwords for a user

2006-05-12 Thread Santiago Balaguer García
The answer why I have several password for a same radius account is easy. I have two or more hotspot models (Nomadix, Mikrotik, Gemtek...) and I want to active successfully MAC authentication method of these kind od devices. While one hotspot accept blank password (see some previous entries

Re: Several passwords for a user

2006-05-12 Thread Santiago Balaguer García
I made a mistake!! the correct 'op' attribute is '+=' instead of '==' or ':=' * [EMAIL PROTECTED] wrote: I use freeradius-1.1.0. Where is any problem an account has two or more entries in radcheck table??? I use : 11:22:33:44:55:66

Forbidden allowed NASes

2006-05-23 Thread Santiago Balaguer García
Hi people, I use freeradius-1.1.0 for several months. I have several types of prepaid accounts, these accounts are limited in time, but I want some accounts are only allow in some hotspots, and they are forbiden in the rest. I read it is possoble from huntgroup file. But is it possible to

nas table

2006-05-25 Thread Santiago Balaguer García
Hi people, I use freeradius 1.0.5 and am getting my nas information from nas table since several months ago. How ever, I realize I have to put DNS in this table because I have DDNS entries. Where must I put the DDNS in this table?? In ipddr I can not because is inet type and a primary key.

Re: How to specify multiple values for Called-Station-Id (checkval)

2006-05-26 Thread Santiago Balaguer García
This is a very interesting question because I am looking for a solution for enable/forbitten NAS. From: Mike Jakubik [EMAIL PROTECTED] Reply-To: FreeRadius users mailing list freeradius-users@lists.freeradius.org To: FreeRadius users mailing list freeradius-users@lists.freeradius.org

huntgroup file

2004-01-07 Thread Santiago Balaguer García
Can someone send me an example of huntgroup file and it ísn`t the huntgroup one that appears in the examples or faqs? Thanks _ Charla con tus amigos en línea mediante MSN Messenger. http://messenger.microsoft.com/es - List

Re: how can i limit traffic use?

2004-03-01 Thread Santiago Balaguer García
Hi people, I am working about traffic limitations and all the answers are not complete. As a person said, RADIUS can control the traffic off-line when a user connects and, in the case this user spent all his quota, RADIUS reject him. However, this kind of control has to be done on-line, that

Duplicate conections to mysql

2004-04-07 Thread Santiago Balaguer García
Hi people, I have installed freeradius-0.93 with Debian Distribution. The system functions, however I don't know why there are 4 conncection to mysql: * rlm_sql (sql): Driver rlm_sql_mysql (module rlm_sql_mysql) loaded and linked

Simultaneous Use Verification

2004-04-07 Thread Santiago Balaguer García
Hi People, I have freeradius-0.9.3 with Debian Distribution. I read all the documentation about Simultaneous-Use in the manual and some web pages, but i'm not sure how to install it. Ii is supposed that if I install `mrtg' package and set DEFAULT Simultaneous-Use:=1 in users file ?

Re: Duplicate conections to mysql

2004-04-07 Thread Santiago Balaguer García
The system functions, however I don't know why there are 4 conncection to mysql: [ snip ] I only want an answer of this behaivour. Thanks Well, there are actually 5 connections listed there. This would be why: sql: num_sql_socks = 5 If you want to increase/decrease the number

mysql libraries

2004-04-08 Thread Santiago Balaguer García
Hi People, I have freeradius.9.3 running in a Mandrake Distribution. Can someone send me a precompiled drivers to mysql? I need the files of /usr/local/lib/rlm_sql_mysql.* . Thanks _ Déjanos tu CV y

Re: expiration attribute

2004-04-21 Thread Santiago Balaguer García
It is easy for with my method. I suposse that you have RADIUS counts with a specific login, if you want that a count expires in 30 days after its activation, you only have to get the activation date (you know with NOW() in mysql) and add to this date 30 in MySQL sentences. This calculated date

VoIP Implementation

2004-05-27 Thread Santiago Balaguer García
Hi people, First of all I want to thank Allan to assist ourselves in any kind of question. I proposed to myself and to my company if the VoIP service can be served with RADIUS. If so, I want to know how it will be possible and the steps to follow. Thanks,

RE: public secret and public radius server. Is it secure?

2006-06-05 Thread Santiago Balaguer García
If you don't want Dynamic address use VPN between your RADIUS server an your hotspots. My question is : - What can a malicious user can do with the secret? Can it alter accounting and other things? (chillispot uses chap auth-type) one is spell it out and try rumble it so he forms a new word

RE: Malfunctioning Nomadix

2006-06-26 Thread Santiago Balaguer García
True. Nomadix developers told me ir is a problem of my RADIUS server. I think it is almost impossible because Radius server it is a 'silly' machine. If a NSE tells radius thatinsert a registes in radacct, radius server does and it is supposed NAS controls its ID's. It is true I can add a DB

Diferent Session-Timeout depending on NAS

2006-06-30 Thread Santiago Balaguer García
Hi people, I have been working with RADIUS for sereral years and now we want to implement a different accounting for prepaid cards. I will explain my quesion shortly. Two types of hotspots zones: Spain and Mexico. Everyone know prizces in Mexico are cheaper than in Spain. Well, my

  1   2   >