<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type" />
<title></title>
</head>
<body>
<p style="margin: 0px;">Hi Alan,</p>
<p style="margin: 0px;"><span><br />
</span></p>
<p style="margin: 0px;"><span>I did more tests (now with two winXP clients and one OSX client),</span></p>
<p style="margin: 0px;"><span>the problem is still unsolved:</span></p>
<p style="margin: 0px;"><br />
<span> </span></p>
<p style="margin: 0px;">Wed Aug 18 18:03:21 2010 : Auth: Login OK: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 0 via TLS tunnel)<br />
Wed Aug 18 18:03:21 2010 : Auth: Login OK: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 50043 cli 00-08-74-46-34-F7)<br />
Wed Aug 18 18:03:24 2010 : Auth: Login OK: [jan/<via Auth-Type = mschap>] (from client swba1-00-test port 0 via TLS tunnel)<br />
Wed Aug 18 18:03:24 2010 : Auth: Login OK: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 50039 cli 00-16-CB-AA-0F-CB)<br />
Wed Aug 18 18:03:27 2010 : Auth: Login OK: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 0 via TLS tunnel)<br />
Wed Aug 18 18:03:27 2010 : Auth: Login OK: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 50041 cli 00-1E-37-90-89-D2)<br />
Wed Aug 18 18:03:45 2010 : Error: Child PID 72473 is taking too much time: forcing failure and killing child.<br />
Wed Aug 18 18:03:45 2010 : Auth: Login incorrect: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 0 via TLS tunnel)<br />
Wed Aug 18 18:03:45 2010 : Auth: Login incorrect: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 50043 cli 00-08-74-46-34-F7)<br />
Wed Aug 18 18:03:55 2010 : Error: Child PID 72474 is taking too much time: forcing failure and killing child.<br />
Wed Aug 18 18:03:55 2010 : Auth: Login incorrect: [jan/<via Auth-Type = mschap>] (from client swba1-00-test port 0 via TLS tunnel)<br />
Wed Aug 18 18:03:55 2010 : Auth: Login incorrect: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 50039 cli 00-16-CB-AA-0F-CB)<br />
Wed Aug 18 18:03:55 2010 : Error: rlm_eap: No EAP session matching the State variable.<br />
Wed Aug 18 18:03:55 2010 : Auth: Login incorrect: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 50043 cli 00-08-74-46-34-F7)<br />
Wed Aug 18 18:04:05 2010 : Error: Child PID 72475 is taking too much time: forcing failure and killing child.<br />
Wed Aug 18 18:04:05 2010 : Auth: Login incorrect: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 0 via TLS tunnel)<br />
Wed Aug 18 18:04:05 2010 : Auth: Login incorrect: [jan/<via Auth-Type = EAP>] (from client swba1-00-test port 50041 cli 00-1E-37-90-89-D2)<br />
<br />
</p>
<p style="margin: 0px;"> </p>
<p style="margin: 0px;">The strange thing: freeradius is started with the "no childs" option:</p>
<p style="margin: 0px;"> </p>
<p style="margin: 0px;">freeradius 60384 0.0 0.4 11560 9240 4 S 11:57AM 0:49.13 /usr/local/sbin/radiusd -s</p>
<p style="margin: 0px;"> </p>
<p style="margin: 0px;">So why does it complain about childs that take to long?! Btw: The server has a load of 0.00 and</p>
<p style="margin: 0px;">network IO is only to the ads server. If I block traffic to it, freerad does not complain about</p>
<p style="margin: 0px;">childs that take to long, so the problem hides elsewhere, I guess.</p>
<p style="margin: 0px;"> </p>
<p style="margin: 0px;"> </p>
<p style="margin: 0px;">Thanks for your help!</p>
<p style="margin: 0px;"> </p>
<p style="margin: 0px;">Best, Jan</p>
<p style="margin: 0px;"> </p>
<p> </p>
<div style="margin: 5px 0px 5px 0px; font-family: monospace;">
Alan DeKok <aland@deployingradius.com> hat am 17. August 2010 um 09:47 geschrieben:<br />
<br />
> Jan Zacharias wrote:<br />
> > Sun Aug 15 10:01:39 2010 : Error: Discarding duplicate request from<br />
> > client swba1-00-test port 1645 - ID: 157 due to unfinished request 125603<br />
><br />
> As always, something is blocking the server.<br />
><br />
> > The entry Sun Aug 15 10:01:39 2010 is interesting as no client was<br />
> > connected to port 1645 at that time<br />
><br />
> <shrug> The server doesn't invent packets. *Something* sent it a packet.<br />
><br />
> > My question: can I somehow extend the timeout or do anything else to<br />
> > prevent this from happening?<br />
><br />
> Fix is so that nothing is blocking the server.<br />
><br />
> Alan DeKok.<br />
> -<br />
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
</div>
</body>
</html>