On 01/21/2013 06:47 AM, Tzvika Gelber wrote:
i'm looking to focus a problem i have - i think the main issue is not
freeradius but it's a good place to ask.
I have a server that's do both Radius and accounting for Wifi random
users (web redirected system).
now i just discovered that to
i'm looking to focus a problem i have - i think the main issue is not
freeradius but it's a good place to ask.
I have a server that's do both Radius and accounting for Wifi random users
(web redirected system).
now i just discovered that to authenticate the users i have to use the
server secret
Hi,
I have redundant NAS nodes and they obviously have two different NAS-IP. If
one NAS fails, the entity for which I'm accounting traffic is automatically
switched over to the redundant NAS which can keep sending accounting
records to Radius. However, the records will have different NAS-IP,
adius.org] On Behalf Of Marlon Duksa
Sent: Monday, January 25, 2010 6:12 PM
To: FreeRadius users mailing list
Subject: accounting question
Hi,
I have redundant NAS nodes and they obviously have two different NAS-IP. If
one NAS fails, the entity for which I'm accounting traffic is automatically
switched
-bounces+tim.sylvester=networkradius@lists.freer
adius.org] On Behalf Of Marlon Duksa
Sent: Monday, January 25, 2010 6:12 PM
To: FreeRadius users mailing list
Subject: accounting question
Hi,
I have redundant NAS nodes and they obviously have two different NAS-IP. If
one NAS fails, the entity
Marlon Duksa wrote:
The acct-session-id and framed-ip-addrss will be the same (and this is
what I use to identify the entity for which I collect acct info). Is
there any way that this new records will be written to the same file as
before the failover so that I can correlate the records?
; FreeRadius users mailing list
Subject: Re: Accounting question
David Peterson wrote:
Forgive my newbieness but where would I put that code? I tried adding it to
the sites-available/default file under accounting but I am guessing that's
not right.
That'll stop any potential problems arising
David Peterson wrote:
What I am not understanding at this point is how the authentication works
with the username hashed or using hex stuff but the accounting doesn't.
You can see on this debug that the username looks the same when its
authenticated as it does when it's used for accounting
Peterson-WirelessConnections; FreeRadius users mailing list
Subject: Re: Accounting question
David Peterson wrote:
Forgive my newbieness but where would I put that code? I tried adding it to
the sites-available/default file under accounting but I am guessing that's
not right.
That'll stop
David Peterson wrote:
However the NAS is overrriding the username and replying with:
...
Buy a NAS that works.
Any other thoughts?
Follow the other suggestions that would solve the problem.
Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Radius is storing the accounting information using the EAP hashed username.
Is there a way to change it to store the clear text username with the
accounting info?
David Peterson
Engineer
Wireless Connections
166 Milan Ave., Norwalk, Oh. 44857
ACCessing the Future Today!!
ofc. 419.660.6100 ext
David Peterson wrote:
Radius is storing the accounting information using the EAP hashed
username.
What's an EAP hashed username ?
Is there a way to change it to store the clear text username
with the accounting info?
Sure. Send a User-Name attribute in the Access-Accept, and the NAS
DeKok [mailto:al...@deployingradius.com]
Sent: Tuesday, December 15, 2009 9:13 AM
To: David Peterson-WirelessConnections; FreeRadius users mailing list
Subject: Re: Accounting question
David Peterson wrote:
Radius is storing the accounting information using the EAP hashed
username.
What's
: Tuesday, December 15, 2009 9:13 AM
To: David Peterson-WirelessConnections; FreeRadius users mailing list
Subject: Re: Accounting question
David Peterson wrote:
Radius is storing the accounting information using the EAP hashed
username.
What's an EAP hashed username ?
Is there a way to change
hi,
those look like chargeable user identities - do you have CUI operational
on your config?
alan
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
David Peterson wrote:
From what I can determine, the username is encrypted even though the
authentication is done in clear text during the EAP authentication.
It's not encrypted. My guess is that you are using WiMAX.
As always, run the server in debugging mode to see what's going on.
Subject: Re: Accounting question
David Peterson wrote:
From what I can determine, the username is encrypted even though the
authentication is done in clear text during the EAP authentication.
It's not encrypted. My guess is that you are using WiMAX.
As always, run the server in debugging mode
David Peterson wrote:
WiMax it is... If anyone has any experience with Alvarion WiMax please feel
free to chime in.
Uhh... it would be good for them to follow the specs.
Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
: Accounting question
David Peterson wrote:
From what I can determine, the username is encrypted even though the
authentication is done in clear text during the EAP authentication.
It's not encrypted. My guess is that you are using WiMAX.
As always, run the server in debugging mode to see
list
Subject: Re: Accounting question
David Peterson wrote:
From what I can determine, the username is encrypted even though the
authentication is done in clear text during the EAP authentication.
It's not encrypted. My guess is that you are using WiMAX.
As always, run the server
:56 AM
To: David Peterson-WirelessConnections; FreeRadius users mailing list
Subject: Re: Accounting question
David Peterson wrote:
Here is the accounting packet information I am getting:
rad_recv: Accounting-Request packet from host 172.16.4.2 port 1813, id=5,
length=239
Acct-Status
-Original Message-
From: Arran Cudbard-Bell [mailto:a.cudbard-b...@sussex.ac.uk]
Sent: Tuesday, December 15, 2009 10:56 AM
To: David Peterson-WirelessConnections; FreeRadius users mailing list
Subject: Re: Accounting question
David Peterson wrote:
Here is the accounting packet
On Tue, Dec 15, 2009 at 01:10:20PM -0500, David Peterson wrote:
What I am not understanding at this point is how the authentication works
with the username hashed or using hex stuff but the accounting
doesn't. You can see on this debug that the username looks the same when
its authenticated
-Original Message-
From: Arran Cudbard-Bell [mailto:a.cudbard-b...@sussex.ac.uk]
Sent: Tuesday, December 15, 2009 10:56 AM
To: David Peterson-WirelessConnections; FreeRadius users mailing list
Subject: Re: Accounting question
David Peterson wrote:
Here is the accounting packet information I am
When I connect to my AP, authenticated by freeradius using EAP-TLS, I
get an entry into radpostauth, entries
in /var/log/radius/radacct/192.168.3.115/detail-auth and detail-reply
files, but I am not getting any entries into radacct. I don't know
whether this is because the NAS is not sending any
Ian Truelsen wrote:
When I connect to my AP, authenticated by freeradius using EAP-TLS, I
get an entry into radpostauth, entries
in /var/log/radius/radacct/192.168.3.115/detail-auth and detail-reply
files, but I am not getting any entries into radacct. I don't know
whether this is because the
On 4/9/07, Alan DeKok [EMAIL PROTECTED] wrote:
Ian Truelsen wrote:
When I connect to my AP, authenticated by freeradius using EAP-TLS, I
get an entry into radpostauth, entries
in /var/log/radius/radacct/192.168.3.115/detail-auth and detail-reply
files, but I am not getting any entries
Chuck [EMAIL PROTECTED] wrote:
would it also do the same thing if I removed the simultaneous-use=1 check
statement from the user group?
No. That's enforcement, not accounting.
Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
we keep getting a lot of missed stop packets that we never had problems with
when we ran icradius. I don't know what the problem could be but I am getting
ready to turn accounting off for us. However I have a major concern with
this.
We are using the mysql option with freeradius including the
Chuck [EMAIL PROTECTED] wrote:
If I turn accounting off, is there a way we can still pass
accounting through to our remote realms, or is it a global on/off
switch that affects everyone?
Yes. You can delete the detail and sql entries from accounting,
and it won't log accounting to the local
On Thursday 10 November 2005 05:44 pm, Alan DeKok wrote:
would it also do the same thing if I removed the simultaneous-use=1 check
statement from the user group? until i can figure this out that would be my
easiest thing still allowing writing to accounting for other purposes.
Chuck [EMAIL
Hello,
I have a question regarding the way accounting is done. I configured
freeradius 1.0.1 with openssl and mysql support on a Fedora Core 3
system. I'm using it with PEAP and TLS for wireless authentication.
The authentication works fine, but the accounting packets are always
missing the
Hello,
I think my question ist quite related to yours although we do
EAP-TTLS, i.e. PAP inside the tunnel.
I have a question regarding the way accounting is done. I configured
freeradius 1.0.1 with openssl and mysql support on a Fedora Core 3
system. I'm using it with PEAP and TLS for
Joseph Abadi [EMAIL PROTECTED] wrote:
The authentication works fine, but the accounting packets are always
missing the username and the IPs of client and NAS seem to be
interchanged.
See the FAQ. The server logs what the NAS sends it. If the NAS
sends the wrong thing, the server logs it.
Hello,
I have compiled and installed freeradius and it is working fine. My
question now is:
At this point a user logs in with a password, is authenticated and enters
the system but if I want to set user x to only have 2 hours connection time
only and user y to only have 1 hour of connection,
[EMAIL PROTECTED] wrote:
Hello,
I have compiled and installed freeradius and it is working fine. My
question now is:
At this point a user logs in with a password, is authenticated and
enters
the system but if I want to set user x to only have 2 hours
connection time only and user y to
. Mai 2005 19:45
To: freeradius-users@lists.freeradius.org
Subject: RE: Freeradius accounting question
[EMAIL PROTECTED] wrote:
Hello,
I have compiled and installed freeradius and it is working fine. My
question now is:
At this point a user logs in with a password, is authenticated
My guess would be that you need to set the Session-Timeout variable. 2 hours
would be 7200 and 1 hour would be 3600.
hope this helps.
Andrey
Quoting Software Development Group [EMAIL PROTECTED]:
Hello,
I have compiled and installed freeradius and it is working fine. My
question now is:
At this
[EMAIL PROTECTED] wrote:
My guess would be that you need to set the Session-Timeout
variable.
hope this helps.
Andrey
Yes, it will help, im using it on production, the counter module sets the
Session-Timeout automatically
i.e.
keciel# cat radiusd.conf
[... blablabla ...]
sqlcounter
Hi.
I just resubscribed to the mailinglist and found that topic unanswered.
You can accomplish that in two ways. One is with counter module and one with
SQL which uses sqlcounter module.
The sqlcounter needs the experimental modules to be compiled in.
I use MySQL to store my users's info so for
Hi,
I have a question about radius,
Is there anyone on this list that can help?
I'm sure this is a very common request.
I have a situation where radius accounting is logged to a mysql database.
I'd like to find a way to show the accurate number of users that are currently
online.
Up till now
I think radwho can accomplish this request
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of
[EMAIL PROTECTED]
Sent: Tuesday, May 03, 2005 9:38 AM
To: freeradius-users@lists.freeradius.org
Subject: accounting question
Hi,
I have a question about radius
Hello,
I have successfully installed radius.
It is working very nice. Great job.
I have following question.
I would like to do accounting. So every dial-up user will be able to go on
line only for 60 minutes.
Then when he uses his limit he should not be able to go on line any more?
Is it
Bartosz Jozwiak [EMAIL PROTECTED] wrote:
I have successfully installed radius.
It is working very nice. Great job.
Thank you.
I have following question.
I would like to do accounting. So every dial-up user will be able to go on
line only for 60 minutes.
Then when he uses his limit he
Do I need to recompile freeradius with:
./configure --with-experimental-modules
To make use of rlm_sqlcounter ?
I have the 1.0.0-pre3 version.
Bartosz
Bartosz Jozwiak [EMAIL PROTECTED] wrote:
I have successfully installed radius.
It is working very nice. Great job.
Thank you.
I have
Hi all,
I have been play with FreeRadius for a few weeks in the following
enviroment:
Funk Software Odyssey Client + Belken wireless router + FreeRadius 1.0.0
Pre2. Finally, I get the system working last night, but I found out a
problem with accounting file. I turn on detail, auth_detail and
Michael Ding [EMAIL PROTECTED] wrote:
I have been play with FreeRadius for a few weeks in the following
enviroment:
Funk Software Odyssey Client + Belken wireless router + FreeRadius 1.0.0
Pre2. Finally, I get the system working last night, but I found out a
problem with accounting file. I
A followup for all...
I have been looking for an inexpensive WAP (Wireless Access Point) or WRT (Wireless
Router) that sends the Radius Accounting information to the Radius Server - to date I
have NOT found any of the inexpensive WAP or WRT devices which send the accounting
information to the
How much is inexpensive?
At home, I use a D-Link DWL 7000AP (an a/b/g access point with 802.1x
and WPA) that generated RADIUS accounting information.
Gary McKinney wrote:
A followup for all...
I have been looking for an inexpensive WAP (Wireless Access Point) or WRT (Wireless
Router) that sends
an idea:
turn log_auth_badpass = on and write a shellscript which read out the logfile
and delete the user who tried to login with a bad pazzword.
i wrote a similar script to delete users by expiring date, using sed.
ciao marc werner
Am Dienstag, 23. März 2004 08:47 schrieb Tim Bots:
As I am
-
Van: Marc Werner [mailto:[EMAIL PROTECTED]
Verzonden: Tuesday, March 23, 2004 9:22
Aan: [EMAIL PROTECTED]
Onderwerp: Re: accounting question
an idea:
turn log_auth_badpass = on and write a shellscript which read out the logfile
and delete the user who tried to login with a bad pazzword.
i wrote
Please Note: Radius does NOT disconnect users, only the NAS can
disconnect the
user.
You will need to figure out how to send a command to your NAS to
disconnect the
user, and run that program in order to trigger a user disconnect.
Graeme Hinchliffe wrote:
On Tue, 16 Mar 2004 16:17:03 +0100
Tim Bots [EMAIL PROTECTED] wrote:
The thing is that my hotspot can kill/logoff users when they have
reached a certain amount of time/data transfer. The standard time that
users get when they logon when I use freeradius is 5 hours. Is there a
way to change this time?
Yes. See the
Hi everyone,
I have freeradius working correct at this moment and now is my question how can I
enable accounting? I mean: how can I give users more or less time / more or less
session bytes with freeradius?
I use freeradius version 0.9.3 running on a p1 with 64 mb memory (I guess) with linux
-Oorspronkelijk bericht-
Van: Graeme Hinchliffe [mailto:[EMAIL PROTECTED]
Verzonden: Tuesday, March 16, 2004 17:43
Aan: [EMAIL PROTECTED]
Onderwerp: Re: accounting question
On Tue, 16 Mar 2004 16:17:03 +0100
Tim Bots [EMAIL PROTECTED] wrote:
Hi everyone,
I have freeradius working correct
Hi!
I see messages like this in radius.log:
Sun Jan 11 13:00:06 2004 : Info: rlm_sql (sql): There are no DB handles
to use! skipped 0, tried to connect 0
When it happens, the accounting will be continous or this message
indicates lost data?
Thanks,
Andras
--
-
List
-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of
Fogarasi Andras
Sent: Sunday, January 11, 2004 2:08 PM
To: [EMAIL PROTECTED]
Subject: mysql accounting question
Hi!
I see messages like this in radius.log:
Sun Jan 11 13:00:06 2004 : Info: rlm_sql (sql): There are no DB handles
to use
57 matches
Mail list logo