Log partially solved

Sergio Belkin sebelk at gmail.com
Thu Oct 30 15:30:06 CET 2008


2008/10/27 Sergio Belkin <sebelk at gmail.com>:
> 2008/10/27  <tnt at kalik.net>:
>>> detail auth_log {
>>>       detailfile =
>>>${radacctdir}/requests/%{Client-IP-Address}/auth-detail-%Y%m%d_%{EAP-Type}
>>>#      detailfile = ${radacctdir}/%{Client-IP-Address}/auth-detail-%Y%m%d
>>>
>> ..
>>>
>>>But still, it says nothing if supplicant is using TTLS or PAP which is
>>>what I'd like to see as filenames suffixes. Am I missing something?
>>>
>>
>> Try EAP-Type-TTLS and EAP-Type-PEAP instead of EAP-Type.
>>
>> Ivan Kalik
>> Kalik Informatika ISP
>>
>> -
>> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
>>
>
> Sorry, but I don't understand, if I set
> ${radacctdir}/requests/%{Client-IP-Address}/auth-detail-%Y%m%d_EAP-Type-TTLS
> always be appended with "_EAP-Type-TTLS" and if I set
> ${radacctdir}/requests/%{Client-IP-Address}/auth-detail-%Y%m%d_%{EAP-Type-TTLS}
> won't work either.
>
> Am I doing something wrong?
>
> Thanks in advance!
>
> --
> --
> Open Kairos http://www.openkairos.com
> Watch More TV http://sebelk.blogspot.com
> Sergio Belkin -
>

Well I came back to my earlier configuration:

---snip---
 detail auth_log {
      detailfile =
${radacctdir}/requests/%{Client-IP-Address}/auth-detail-%Y%m%d_%{EAP-Type}
#      detailfile = ${radacctdir}/%{Client-IP-Address}/auth-detail-%Y%m%d

     #
     #  This MUST be 0600, otherwise anyone can read
     #  the users passwords!
     # detailperm = 0600

     # You may also strip out passwords completely
     suppress {
         User-Password
     }
   }

---snip---

So far is the best I could do, I guess:


auth-detail-20081029_MS-CHAP-V2  means PEAP try (?)
auth-detail-20081029_NAK means unacceptable type
auth-detail-20081029_Identity means TTLS (??)
auth-detail-20081029_ means Access Accept (??)

I'd like to read more about it...


-- 
--
Open Kairos http://www.openkairos.com
Watch More TV http://sebelk.blogspot.com
Sergio Belkin -



More information about the Freeradius-Users mailing list