iprs and pri and phone numbers ...

Karen R McArthur kmcarthu at bates.edu
Wed Jun 27 15:57:19 CEST 2007


How do I restrict access to a phone number via radius?  I currently have 
the following.  Radiusd restarts with no errors, however I can login 
using both numbers even when I am not in the ldap-group "admin".  I have 
verified that the correct called-station-id is being passed into 
"rad_recv".  Output from "radiusd -X"  is attached.

huntgroups:
admin           NAS-IP-Address == 192.168.1.1
                 Called-Station-Id == "xxxyyyy"

public          NAS-IP-Address == 192.168.1.1
                 Called-Station-Id == "xxxzzzz",
                 Idle-Timeout = 3600

users:
DEFAULT Huntgroup-Name == public
         Fall-Through = no

DEFAULT Huntgroup-Name == admin, Ldap-Group == admin
         Fall-Through = no

DEFAULT Auth-Type := Reject
-- 
Karen R. McArthur <kmcarthu at bates.edu>
Systems Administrator
Information and Library Services, Bates College
Lewiston, Maine 04240 USA
ph:(207)786-8236   fax:(207)786-6057

If you find that everybody else is right and you're wrong,
it might just be that you're thinking outside the box. The
world is yet to catch up.
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: radiusd.log.txt
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20070627/84304f96/attachment.txt>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 4394 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20070627/84304f96/attachment.bin>


More information about the Freeradius-Users mailing list