checkrad not work with cisco VPDN

2007-03-12 Thread satish patel
Dear sir i have useing freeradius + cisco vpdn router but i have this problem when i run checkrad manually [EMAIL PROTECTED] ~]# checkrad cisco 192.168.1.1 800 mlpm034 C555 SNMP Error: Received SNMP response with error code error status: noSuchName index 1 (OID:

Re: IP Address based proxy forward

2007-03-12 Thread Alan DeKok
freeradius wrote: ... -- when I send a request from a NAC with the IP address 192.168.1.129, it does not work as described in the debug output : modcall[authorize]: module files returns notfound for request 34 Does anymone has an idea why it does not work ? Read ALL of the debug

Re: requiring a sample of a mysql radius database

2007-03-12 Thread Alan DeKok
Internet-Wifi Operador wrote: Very well, I´m doing the same, but i can't find information about the way freeradius process the attributes and operator, Does the documentation help? doc/processing_users_file Or man rlm_users? Alan DeKok. -- http://deployingradius.com - The web

Re: rlm_perl/rlm_python adding extra value pairs

2007-03-12 Thread Alan DeKok
Mike O'Connor wrote: I wish to add some extra valid pairs to accounting packets which are being proxied to other radius servers. If in the 'preacct' or the 'accounting' stage I was to add using rlm_python or rlm_perl value pairs would they be sent thought to the other radius servers ?

Re: authenticating multiple modules?

2007-03-12 Thread Alan DeKok
Tim Tyler wrote: Freeradius experts, I want to use one freeradius server to authenticate against a system file for students and against ldap for faculty/staff. I can get the system file to work alone. I can get the ldap module to work alone. But I can't seem to find a way to get

Re: Freeradius and vlan assignment

2007-03-12 Thread A . L . M . Buxey
Hi, I tried to configure my users file like this : - testNasPort-Type == Ethernet Service-Type = Framed-User, Tunnel-Type +=13, Tunnel-Medium-Type =6, Tunnel-Private-Group-ID =2

Re: Help with freeradius 1.1.5

2007-03-12 Thread Alan DeKok
adreas polyxronopoulos wrote: Hi list , I have ubuntu 6.06 LAM and i compile freeradius-1.1.5 . In compilation everthing was ok. But whe i ranning freeradius : radiusd -X i get the following output : can anyone help me ? I don't understand what's happening. It looks like a bug. Can

Re: Freeradius and vlan assignment

2007-03-12 Thread Bruno Mardirossian
Hi, and thanks for your help. What did you mean by return a 'UPDATED' flag ?? Bruno 2007/3/12, [EMAIL PROTECTED] [EMAIL PROTECTED]: Hi, I tried to configure my users file like this : - testNasPort-Type == Ethernet

Re: [Chillispot] Correction of Reply Messages

2007-03-12 Thread Alan DeKok
[EMAIL PROTECTED] wrote: I think that this is a trivial bug: ... It sends reset parameter instead of (?)check name parameter in the reply. You should report it. The reset is often monthly or daily, in which case the message makes sense. Sending the check name wouldn't make sense, as it's

Re: Help with freeradius 1.1.5

2007-03-12 Thread adreas polyxronopoulos
I tryied to run the server under the valgrid but it seems tha i don't have valgrid here is the output: [EMAIL PROTECTED]@dyndns:~# valgrind --tool=memcheck --leak-check=full radiusd -X bash: valgrind: command not found Should i download it? thanks for you help On Mon, 2007-03-12 at 11:28

Re: Help with freeradius 1.1.5

2007-03-12 Thread Alan DeKok
adreas polyxronopoulos wrote: .. bash: valgrind: command not found Should i download it? Uh... yes? It's in apt. Just apt-get install valgrind Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List

Re: Help with freeradius 1.1.5

2007-03-12 Thread adreas polyxronopoulos
Ok i did it. Here is the output of: # valgrind --tool=memcheck --leak-check=full radiusd -X ==16101== Memcheck, a memory error detector. ==16101== Copyright (C) 2002-2005, and GNU GPL'd, by Julian Seward et al. ==16101== Using LibVEX rev 1471, a library for dynamic binary translation.

Re: How to enable Freeradius to support a smart card with AES encryption algorithm?

2007-03-12 Thread yao guoxian
Thanks,Alan. But I have a few questions. First, if I create a new attribute My-Aes-Password and include it in the Access-Requet packet, I should not include the attributes such as User-Password or Chap-Password.Is it right? For I have read RFC 2865, and gotten the message from page 64th

Re: Freeradius and vlan assignment

2007-03-12 Thread A . L . M . Buxey
Hi, Hi, and thanks for your help. What did you mean by return a 'UPDATED' flag ?? eg with rlm_perl you set the return code to be RLM_MODULE_UPDATED which notifies the server that everything is OK and that attribute pairs have been modified. alan - List info/subscribe/unsubscribe? See

Support for EAP-AKA

2007-03-12 Thread awaneesh kumar
HI, Does Freeradius 1.1.5 supports EAP-AKA? Thanks - Sucker-punch spam with award-winning protection. Try the free Yahoo! Mail Beta.- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FR supported attributes

2007-03-12 Thread tnt
Wired chilli? The makers say: ChilliSpot is an open source captive portal or wireless LAN access point controller. It is used for authenticating users of a wireless LAN. Do you know something they don't? Expiration is an internal FreeRadius attribute - it doesn't go out in radius packets. It is

Default attributes

2007-03-12 Thread Norbert Wegener
On different equipment the following profiles give me connections, that behave identically. [EMAIL PROTECTED] Auth-Type := Local, User-Password == 12345 Service-Type = Framed-User, Framed-Protocol = PPP [EMAIL PROTECTED] Auth-Type := Local, User-Password == 12345 Service-Type =

Re: Default attributes

2007-03-12 Thread Alan DeKok
Norbert Wegener wrote: ... Are Service-Type = Framed-User and Framed-Protocol = PPP defaults these days or do those connections work only accidentally? It's up to the NAS. My guess is that the NAS vendors saw that too many people were forgetting to set Service-Type = PPP, and decided to

Re: checkrad not work with cisco VPDN

2007-03-12 Thread tnt
This is how it should work: setting Simultaneous-Use will produce a check in the database if the user is online; if the user is online according to database (end of story if nastype is set to other) checkrad is called to see if the NAS agrees if user is not online according to NAS connection will

Re: [Chillispot] Correction of Reply Messages

2007-03-12 Thread tnt
Oh, I see. So the script works as it should but the people complain that the message doesn't sound right when never is there. You could put an if there to send the message without the parameter for never and as it is for others, but if configurable message is in the pipeline it probably isn't

Re: Oracle 10g

2007-03-12 Thread Andrea Gabellini
Yasser, are you using instantclient or the full installation? Which OS? With solaris and instant client I used: CFLAGS=-I/usr/local/oracle/sdk/include ./configure --with-oracle-home-dir=/usr/local/oracle /usr/local/oracle is my ORACLE_HOME, /usr/local/oracle is in my environment with

checkrad or sql base simultaneous-use

2007-03-12 Thread satish patel
anyone help me please I have many problem for simultaneous login user problem i have freeradius-1.1.0 with MSSQL with cisco VPDN configuration i dont know why simultaneous not working with checkrad script can u explain me i have confusen in radwho and checkrad command so checkrad command

checkrad snmp + cisco VPDN problem

2007-03-12 Thread satish patel
Dear alll I have problem last 2 month nobady give me solution of this error when i run checkrad manually i got this error [EMAIL PROTECTED] satishp]# checkrad cisco 192.168.1.1 1034 mlpm542 999 SNMP Error: Received SNMP response with error code error status: noSuchName index 1

checkrad replace by other script

2007-03-12 Thread satish patel
can i replace checkrad with another script $ cat ~/satish/url.txt System administrator ( Data Center ) please visit this site http://linux.tulipit.com - Here’s a new way to find what you're looking for - Yahoo! Answers -

Re: checkrad or sql base simultaneous-use

2007-03-12 Thread tnt
radwho lists online users according to radutmp checkrad doesn't use radwho. It asks NAS if user so and so is on port so and so with session ID so and so. In session you choose if looking for online users will be done in database or radutmp. checkrad will be called when online user is detecded if

Re: Help with freeradius 1.1.5

2007-03-12 Thread Alan DeKok
adreas polyxronopoulos wrote: Ok i did it. Here is the output of: ... ==16038== Invalid read of size 4 ==16038==at 0x4822448: dict_attr_value_cmp (dict.c:146) OK, that's a bug that I fixed recently in the CVS head, and I guess I didn't back-port the patch to 1.1.5. I've committed a fix

Re: [Chillispot] Correction of Reply Messages

2007-03-12 Thread Internet-Wifi Operador
I give to you a fast solution to show the message that you want, otherwise edit the module, rewrite and compile it. Fabián From: [EMAIL PROTECTED] Reply-To: FreeRadius users mailing list freeradius-users@lists.freeradius.org To: FreeRadius users mailing list

Kreberos module config

2007-03-12 Thread John T. Guthrie
Hello all, I was just looking through the Kerberos code in rlm_krb5.c, and I found this little code snippet: static CONF_PARSER module_config[] = { { keytab, PW_TYPE_STRING_PTR, offsetof(rlm_krb5_t,keytab), NULL, NULL }, { service_principal, PW_TYPE_STRING_PTR,

Re: FR supported attributes

2007-03-12 Thread Internet-Wifi Operador
Chillispot is a captive portal that's it You can use it with wired and wireless LAN. Check It!!! Other point. You right, Expiration is an Internal Freeradius Attribute, but by default only check if the expiration date NOW(), so if user make a connection 1 milisecond beford that expiration

Can compile FR 1.1.5 Mysql 5.0.33 on FC4

2007-03-12 Thread Jose Guevarra
Hi, I'm trying to install Freeradius 1.1.5 with MySQL 5.0.33 on fedora core 4. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Compile Freeradius 1.1.5 with MySQL 5.0.33 on fedora core 4

2007-03-12 Thread Jose Guevarra
Hi, I'm trying to install Freeradius 1.1.5 with MySQL 5.0.33 on fedora core 4. I'm upgrading from FR1.1.1 with a standard mysql install. My MySQL installation is in a non-standard place /srv/mysql5033 So I configure FR with these options ./configure --prefix=/srv/freeradius115

Re: authenticating multiple modules?

2007-03-12 Thread Tim Tyler
Ivan, or others, Ok, I can't seem to find documentation on this. If I don't use the users file, I presume I should create the groups in the radiusd.conf file. How does one create a group for Students and Staff (syntax)? Can I assign Auth-Type = System for Staff and Auth-Type = LDAP for

Ssl help

2007-03-12 Thread Hillary Marek
I am trying to set up a Fedora Core 6 computer as a FreeRadius Server. It is currently running, and authenticating via mac address. I also want to set the same computer up as a CA using openssl. When I run the CA script, I get the following output: CA certificate filename (or enter to create)

EAP-TTLS outer identity accounting

2007-03-12 Thread Sam Schultz
I'm currently using EAP-TTLS PAP (via SecureW2) to authorize authenticate wireless clients against specific realms. Users are able to authorize authenticate properly, but the username in incoming accounting replies come in as 'anonymous@realmname'. I had this spitting out proper accounting

Re: Can compile FR 1.1.5 Mysql 5.0.33 on FC4

2007-03-12 Thread A . L . M . Buxey
Hi, Hi, I'm trying to install Freeradius 1.1.5 with MySQL 5.0.33 on fedora core 4. a little more info wouldnt go amiss! such as - wheres your output log from the failed compile? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

ldap groups + freeradius

2007-03-12 Thread Karen R McArthur
I know this question has been asked many times before. I have searched the archives and I have tried what I've found there, but I can't seem to get this working. RedHat EL 4 (managed through RHN, so latest available versions) freeradius-1.0.1-3 openldap-2.2.13-6 I have 4 NAS-IP-Addresses. My

Re: Compile Freeradius 1.1.5 with MySQL 5.0.33 on fedora core 4

2007-03-12 Thread Jose Guevarra
I tried without the terminating slash and the same errors occur. The user i'm compiling with has access to all those directories. ./configure --help doesnt have all the mysql switches listed. where can I find all the configure options for mysql support in FR? Thanks. On 3/12/07, [EMAIL

Re: Can compile FR 1.1.5 Mysql 5.0.33 on FC4

2007-03-12 Thread Jose Guevarra
Here's the most relevant parts of the log... = checking for string.h... yes checking for memory.h... yes checking for strings.h... yes checking for inttypes.h... yes checking for stdint.h... yes checking for unistd.h... yes checking sys/mman.h usability... yes checking

Re: Ssl help

2007-03-12 Thread John T. Guthrie
On Mon, 2007-03-12 at 13:52 -0400, Hillary Marek wrote: I am trying to set up a Fedora Core 6 computer as a FreeRadius Server. It is currently running, and authenticating via mac address. I also want to set the same computer up as a CA using openssl. When I run the CA script, I get the

Re: authenticating multiple modules?

2007-03-12 Thread tnt
Hi Tim, No others so I'll try. I assume that it should work like this: DEFAULT Auth-Type := System Fall-Through = Yes DEFAULT Auth-Type := LDAP I think that users will be checked against the system first and if not found against LDAP. Take this with a pinch of salt - I

Debian

2007-03-12 Thread Tas Dionisakos
Hello All, I just compiled radius and tried to create the deb packages using the method mentioned on the freeradius wiki. When the process finishes the deb packages are version 1.1.3, is there a way of correcting this as apt gets confused? Tas. -- * Tas

Re: Kerberos module config

2007-03-12 Thread John T. Guthrie
On Mon, 2007-03-12 at 12:45 -0400, John T. Guthrie wrote: Hello all, I was just looking through the Kerberos code in rlm_krb5.c, and I found this little code snippet: static CONF_PARSER module_config[] = { { keytab, PW_TYPE_STRING_PTR, offsetof(rlm_krb5_t,keytab), NULL,

Re: checkrad or sql base simultaneous-use

2007-03-12 Thread satish patel
Tanks dear But dear my problem is i am useing simultaneous-use with sql and it is working fine but my problem is users connect with NAS ( cisco vpdn ) but some user stuck in mssql database radacct tables means user connection error or any other error users got disconnect and then

Syntax error converting datetime from character string

2007-03-12 Thread satish patel
Dear all I have setup freeradius-1.1.0 with Cisco VPDN with MSSQL2000 but i got this error and my radius goes down Tue Mar 13 10:57:44 2007 : Error: rlm_sql_unixodbc: '22007 [unixODBC][FreeTDS][SQL Server]Syntax error converting datetime from character string.' Tue Mar 13

RE: Syntax error converting datetime from character string

2007-03-12 Thread Cory Robson
You will need to configure your sql server to store dates in unix format, not having worked with mssql2000 for a while I couldn't tell you how to do it but I'm betting that's where your problem is. _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of satish patel Sent:

Re: Debian

2007-03-12 Thread Markus Krause
Zitat von Tas Dionisakos [EMAIL PROTECTED]: Hello All, I just compiled radius and tried to create the deb packages using the method mentioned on the freeradius wiki. When the process finishes the deb packages are version 1.1.3, is there a way of correcting this as apt gets confused? just