<HTML><HEAD>
<META content="text/html; charset=utf-8" http-equiv=Content-Type>
<META name=GENERATOR content="MSHTML 9.00.8112.16434"></HEAD>
<BODY style="MARGIN: 4px 4px 1px; FONT: 10pt Segoe UI">
<DIV>Greetings all,</DIV>
<DIV> </DIV>
<DIV>I'm trying to get Cisco MAC Authentication bypass working against MS SQL via freeradius (2.1.10 debian iodbc packages) and I have everything working well if I leave groups out of the picture, I.E. the mac address gets put in the correct vlan when it boots up. I would, however, like to clean up the SQL management by establishing a group for each VLAN I want to configure and then using group memberships to assign those attributes rather than having the attributes directly tied to the mac address itself.</DIV>
<DIV> </DIV>
<DIV>I have the read_groups setting set to "yes" in sql.conf and the debug log would make it appear that it's reading it in correctly. The mac is found in radcheck and any attributes in radreply are correctly returned, but rlm_sql never checks for any group memberships at all. I've done a trace on the sql server and it confirms what I see in the debug log from radius - it just never checks.</DIV>
<DIV> </DIV>
<DIV>Thoughts?</DIV>
<DIV> </DIV>
<DIV>Thanks in advance.....</DIV>
<DIV> </DIV>
<DIV> </DIV>
<DIV>FreeRADIUS Version 2.1.10, for host i486-pc-linux-gnu, built on Nov 14 2010 at 20:41:03<BR>Copyright (C) 1999-2009 The FreeRADIUS server project and contributors. <BR>There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A <BR>PARTICULAR PURPOSE. <BR>You may redistribute copies of FreeRADIUS under the terms of the <BR>GNU General Public License v2. <BR>Starting - reading configuration files ...<BR>including configuration file /etc/freeradius/radiusd.conf<BR>including configuration file /etc/freeradius/proxy.conf<BR>including configuration file /etc/freeradius/clients.conf<BR>including files in directory /etc/freeradius/modules/<BR>including configuration file /etc/freeradius/modules/ldap<BR>including configuration file /etc/freeradius/modules/checkval<BR>including configuration file /etc/freeradius/modules/unix<BR>including configuration file /etc/freeradius/modules/mschap<BR>including configuration file /etc/freeradius/modules/files<BR>including configuration file /etc/freeradius/modules/digest<BR>including configuration file /etc/freeradius/modules/ntlm_auth<BR>including configuration file /etc/freeradius/modules/acct_unique<BR>including configuration file /etc/freeradius/modules/perl<BR>including configuration file /etc/freeradius/modules/mac2vlan<BR>including configuration file /etc/freeradius/modules/chap<BR>including configuration file /etc/freeradius/modules/passwd<BR>including configuration file /etc/freeradius/modules/otp<BR>including configuration file /etc/freeradius/modules/exec<BR>including configuration file /etc/freeradius/modules/expr<BR>including configuration file /etc/freeradius/modules/preprocess<BR>including configuration file /etc/freeradius/modules/pam<BR>including configuration file /etc/freeradius/modules/inner-eap<BR>including configuration file /etc/freeradius/modules/opendirectory<BR>including configuration file /etc/freeradius/modules/pap<BR>including configuration file /etc/freeradius/modules/detail.log<BR>including configuration file /etc/freeradius/modules/etc_group<BR>including configuration file /etc/freeradius/modules/cui<BR>including configuration file /etc/freeradius/modules/smbpasswd<BR>including configuration file /etc/freeradius/modules/sradutmp<BR>including configuration file /etc/freeradius/modules/dynamic_clients<BR>including configuration file /etc/freeradius/modules/attr_rewrite<BR>including configuration file /etc/freeradius/modules/counter<BR>including configuration file /etc/freeradius/modules/policy<BR>including configuration file /etc/freeradius/modules/detail<BR>including configuration file /etc/freeradius/modules/ippool<BR>including configuration file /etc/freeradius/modules/mac2ip<BR>including configuration file /etc/freeradius/modules/krb5<BR>including configuration file /etc/freeradius/modules/detail.example.com<BR>including configuration file /etc/freeradius/modules/always<BR>including configuration file /etc/freeradius/modules/wimax<BR>including configuration file /etc/freeradius/modules/smsotp<BR>including configuration file /etc/freeradius/modules/logintime<BR>including configuration file /etc/freeradius/modules/sqlcounter_expire_on_login<BR>including configuration file /etc/freeradius/modules/expiration<BR>including configuration file /etc/freeradius/modules/sql_log<BR>including configuration file /etc/freeradius/modules/linelog<BR>including configuration file /etc/freeradius/modules/realm<BR>including configuration file /etc/freeradius/modules/attr_filter<BR>including configuration file /etc/freeradius/modules/echo<BR>including configuration file /etc/freeradius/modules/radutmp<BR>including configuration file /etc/freeradius/eap.conf<BR>including configuration file /etc/freeradius/sql.conf<BR>including configuration file /etc/freeradius/sql/iodbc/dialup.conf<BR>including configuration file /etc/freeradius/policy.conf<BR>including files in directory /etc/freeradius/sites-enabled/<BR>including configuration file /etc/freeradius/sites-enabled/inner-tunnel<BR>including configuration file /etc/freeradius/sites-enabled/default<BR>main {<BR> user = "freerad"<BR> group = "freerad"<BR> allow_core_dumps = no<BR>}<BR>including dictionary file /etc/freeradius/dictionary<BR>main {<BR> prefix = "/usr"<BR> localstatedir = "/var"<BR> logdir = "/var/log/freeradius"<BR> libdir = "/usr/lib/freeradius"<BR> radacctdir = "/var/log/freeradius/radacct"<BR> hostname_lookups = no<BR> max_request_time = 30<BR> cleanup_delay = 5<BR> max_requests = 1024<BR> pidfile = "/var/run/freeradius/freeradius.pid"<BR> checkrad = "/usr/sbin/checkrad"<BR> debug_level = 0<BR> proxy_requests = yes<BR> log {<BR> stripped_names = no<BR> auth = no<BR> auth_badpass = no<BR> auth_goodpass = no<BR> }<BR> security {<BR> max_attributes = 200<BR> reject_delay = 1<BR> status_server = yes<BR> }<BR>}<BR>radiusd: #### Loading Realms and Home Servers ####<BR> proxy server {<BR> retry_delay = 5<BR> retry_count = 3<BR> default_fallback = no<BR> dead_time = 120<BR> wake_all_if_all_dead = no<BR> }<BR> home_server localhost {<BR> ipaddr = 127.0.0.1<BR> port = 1812<BR> type = "auth"<BR> secret = "testing123"<BR> response_window = 20<BR> max_outstanding = 65536<BR> require_message_authenticator = yes<BR> zombie_period = 40<BR> status_check = "status-server"<BR> ping_interval = 30<BR> check_interval = 30<BR> num_answers_to_alive = 3<BR> num_pings_to_alive = 3<BR> revive_interval = 120<BR> status_check_timeout = 4<BR> irt = 2<BR> mrt = 16<BR> mrc = 5<BR> mrd = 30<BR> }<BR> home_server_pool my_auth_failover {<BR> type = fail-over<BR> home_server = localhost<BR> }<BR> realm example.com {<BR> auth_pool = my_auth_failover<BR> }<BR> realm LOCAL {<BR> }<BR>radiusd: #### Loading Clients ####<BR> client localhost {<BR> ipaddr = 127.0.0.1<BR> require_message_authenticator = no<BR> secret = "testing123"<BR> nastype = "other"<BR> }<BR> client 10.47.249.248/32 {<BR> require_message_authenticator = no<BR> secret = "foobar21"<BR> shortname = "testap"<BR> }<BR> client 10.45.17.117 {<BR> require_message_authenticator = no<BR> secret = "foobar21"<BR> shortname = "test3560"<BR> }<BR>radiusd: #### Instantiating modules ####<BR> instantiate {<BR> Module: Linked to module rlm_exec<BR> Module: Instantiating module "exec" from file /etc/freeradius/modules/exec<BR> exec {<BR> wait = no<BR> input_pairs = "request"<BR> shell_escape = yes<BR> }<BR> Module: Linked to module rlm_expr<BR> Module: Instantiating module "expr" from file /etc/freeradius/modules/expr<BR> Module: Linked to module rlm_expiration<BR> Module: Instantiating module "expiration" from file /etc/freeradius/modules/expiration<BR> expiration {<BR> reply-message = "Password Has Expired "<BR> }<BR> Module: Linked to module rlm_logintime<BR> Module: Instantiating module "logintime" from file /etc/freeradius/modules/logintime<BR> logintime {<BR> reply-message = "You are calling outside your allowed timespan "<BR> minimum-timeout = 60<BR> }<BR> }<BR>radiusd: #### Loading Virtual Servers ####<BR>server inner-tunnel { # from file /etc/freeradius/sites-enabled/inner-tunnel<BR> modules {<BR> Module: Checking authenticate {...} for more modules to load<BR> Module: Linked to module rlm_pap<BR> Module: Instantiating module "pap" from file /etc/freeradius/modules/pap<BR> pap {<BR> encryption_scheme = "auto"<BR> auto_header = no<BR> }<BR> Module: Linked to module rlm_chap<BR> Module: Instantiating module "chap" from file /etc/freeradius/modules/chap<BR> Module: Linked to module rlm_mschap<BR> Module: Instantiating module "mschap" from file /etc/freeradius/modules/mschap<BR> mschap {<BR> use_mppe = yes<BR> require_encryption = no<BR> require_strong = no<BR> with_ntdomain_hack = no<BR> ntlm_auth = "/usr/bin/ntlm_auth --request-nt-key --username=%{%{Stripped-User-Name}:-%{User-Name:-None}} --challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Response:-00}"<BR> }<BR> Module: Linked to module rlm_unix<BR> Module: Instantiating module "unix" from file /etc/freeradius/modules/unix<BR> unix {<BR> radwtmp = "/var/log/freeradius/radwtmp"<BR> }<BR> Module: Linked to module rlm_eap<BR> Module: Instantiating module "eap" from file /etc/freeradius/eap.conf<BR> eap {<BR> default_eap_type = "peap"<BR> timer_expire = 60<BR> ignore_unknown_eap_types = yes<BR> cisco_accounting_username_bug = no<BR> max_sessions = 4096<BR> }<BR> Module: Linked to sub-module rlm_eap_leap<BR> Module: Instantiating eap-leap<BR> Module: Linked to sub-module rlm_eap_gtc<BR> Module: Instantiating eap-gtc<BR> gtc {<BR> challenge = "Password: "<BR> auth_type = "PAP"<BR> }<BR> Module: Linked to sub-module rlm_eap_tls<BR> Module: Instantiating eap-tls<BR> tls {<BR> rsa_key_exchange = no<BR> dh_key_exchange = yes<BR> rsa_key_length = 512<BR> dh_key_length = 512<BR> verify_depth = 0<BR> CA_path = "/etc/freeradius/certs"<BR> pem_file_type = yes<BR> private_key_file = "/etc/freeradius/certs/server.key"<BR> certificate_file = "/etc/freeradius/certs/server.pem"<BR> CA_file = "/etc/freeradius/certs/ca.pem"<BR> private_key_password = "obscured"<BR> dh_file = "/etc/freeradius/certs/dh"<BR> random_file = "/dev/urandom"<BR> fragment_size = 1024<BR> include_length = yes<BR> check_crl = no<BR> cipher_list = "DEFAULT"<BR> make_cert_command = "/etc/freeradius/certs/bootstrap"<BR> cache {<BR> enable = no<BR> lifetime = 24<BR> max_entries = 255<BR> }<BR> verify {<BR> }<BR> }<BR> Module: Linked to sub-module rlm_eap_ttls<BR> Module: Instantiating eap-ttls<BR> ttls {<BR> default_eap_type = "md5"<BR> copy_request_to_tunnel = no<BR> use_tunneled_reply = no<BR> virtual_server = "inner-tunnel"<BR> include_length = yes<BR> }<BR> Module: Linked to sub-module rlm_eap_peap<BR> Module: Instantiating eap-peap<BR> peap {<BR> default_eap_type = "mschapv2"<BR> copy_request_to_tunnel = no<BR> use_tunneled_reply = no<BR> proxy_tunneled_request_as_eap = yes<BR> virtual_server = "inner-tunnel"<BR> }<BR> Module: Linked to sub-module rlm_eap_mschapv2<BR> Module: Instantiating eap-mschapv2<BR> mschapv2 {<BR> with_ntdomain_hack = no<BR> }<BR> Module: Instantiating module "ntlm_auth" from file /etc/freeradius/modules/ntlm_auth<BR> exec ntlm_auth {<BR> wait = yes<BR> program = "/usr/bin/ntlm_auth --request-nt-key --domain=AD --username=%{mschap:User-Name} --password=%{User-Password}"<BR> input_pairs = "request"<BR> shell_escape = yes<BR> }<BR> Module: Checking authorize {...} for more modules to load<BR> Module: Linked to module rlm_realm<BR> Module: Instantiating module "suffix" from file /etc/freeradius/modules/realm<BR> realm suffix {<BR> format = "suffix"<BR> delimiter = "@"<BR> ignore_default = no<BR> ignore_null = no<BR> }<BR> Module: Linked to module rlm_files<BR> Module: Instantiating module "files" from file /etc/freeradius/modules/files<BR> files {<BR> usersfile = "/etc/freeradius/users"<BR> acctusersfile = "/etc/freeradius/acct_users"<BR> preproxy_usersfile = "/etc/freeradius/preproxy_users"<BR> compat = "no"<BR> }<BR> Module: Checking session {...} for more modules to load<BR> Module: Linked to module rlm_radutmp<BR> Module: Instantiating module "radutmp" from file /etc/freeradius/modules/radutmp<BR> radutmp {<BR> filename = "/var/log/freeradius/radutmp"<BR> username = "%{User-Name}"<BR> case_sensitive = yes<BR> check_with_nas = yes<BR> perm = 384<BR> callerid = yes<BR> }<BR> Module: Checking post-proxy {...} for more modules to load<BR> Module: Checking post-auth {...} for more modules to load<BR> Module: Linked to module rlm_attr_filter<BR> Module: Instantiating module "attr_filter.access_reject" from file /etc/freeradius/modules/attr_filter<BR> attr_filter attr_filter.access_reject {<BR> attrsfile = "/etc/freeradius/attrs.access_reject"<BR> key = "%{User-Name}"<BR> }<BR> } # modules<BR>} # server<BR>server { # from file /etc/freeradius/radiusd.conf<BR> modules {<BR> Module: Checking authenticate {...} for more modules to load<BR> Module: Linked to module rlm_always<BR> Module: Instantiating module "ok" from file /etc/freeradius/modules/always<BR> always ok {<BR> rcode = "ok"<BR> simulcount = 0<BR> mpp = no<BR> }<BR> Module: Linked to module rlm_digest<BR> Module: Instantiating module "digest" from file /etc/freeradius/modules/digest<BR> Module: Checking authorize {...} for more modules to load<BR> Module: Linked to module rlm_preprocess<BR> Module: Instantiating module "preprocess" from file /etc/freeradius/modules/preprocess<BR> preprocess {<BR> huntgroups = "/etc/freeradius/huntgroups"<BR> hints = "/etc/freeradius/hints"<BR> with_ascend_hack = no<BR> ascend_channels_per_line = 23<BR> with_ntdomain_hack = no<BR> with_specialix_jetstream_hack = no<BR> with_cisco_vsa_hack = no<BR> with_alvarion_vsa_hack = no<BR> }<BR> Module: Loading virtual module rewrite_calling_station_id<BR> Module: Instantiating module "noop" from file /etc/freeradius/modules/always<BR> always noop {<BR> rcode = "noop"<BR> simulcount = 0<BR> mpp = no<BR> }<BR> Module: Loading virtual module rewrite_called_station_id<BR> Module: Linked to module rlm_sql<BR> Module: Instantiating module "sql" from file /etc/freeradius/sql.conf<BR> sql {<BR> driver = "rlm_sql_iodbc"<BR> server = "DSN=WSC_freeRadius;UID=freeradius;PWD=kradadius"<BR> port = ""<BR> login = "freeradius"<BR> password = "kradadius"<BR> radius_db = "WSC_freeRadius"<BR> read_groups = yes<BR> sqltrace = no<BR> sqltracefile = "/var/log/freeradius/sqltrace.sql"<BR> readclients = no<BR> deletestalesessions = yes<BR> num_sql_socks = 5<BR> lifetime = 0<BR> max_queries = 0<BR> sql_user_name = "%{User-Name}"<BR> default_user_profile = ""<BR> nas_query = "SELECT id,nasname,shortname,type,secret FROM nas"<BR> authorize_check_query = "SELECT id,UserName,Attribute,Value,op FROM radcheck WHERE Username = '%{SQL-User-Name}' ORDER BY id"<BR> authorize_reply_query = "SELECT id,UserName,Attribute,Value,op FROM radreply WHERE Username = '%{SQL-User-Name}' ORDER BY id"<BR> authorize_group_check_query = "SELECT radgroupcheck.id,radgroupcheck.GroupName,radgroupcheck.Attribute,radgroupcheck.Value,radgroupcheck.op FROM radgroupcheck,radusergroup WHERE radusergroup.Username = '%{SQL-User-Name}' AND radusergroup.GroupName = radgroupcheck.GroupName ORDER BY radgroupcheck.id"<BR> authorize_group_reply_query = "SELECT radgroupreply.id,radgroupreply.GroupName,radgroupreply.Attribute,radgroupreply.Value,radgroupreply.op FROM radgroupreply,radusergroup WHERE radusergroup.Username = '%{SQL-User-Name}' AND radusergroup.GroupName = radgroupreply.GroupName ORDER BY radgroupreply.id"<BR> accounting_onoff_query = "UPDATE radacct SET AcctStopTime='%S', AcctSessionTime=unix_timestamp('%S') - unix_timestamp(AcctStartTime), AcctTerminateCause='%{Acct-Terminate-Cause}', AcctStopDelay = %{Acct-Delay-Time:-0} WHERE AcctStopTime=0 AND NASIPAddress= '%{NAS-IP-Address}' AND AcctStartTime <= '%S'"<BR> accounting_update_query = "UPDATE radacct SET FramedIPAddress = '%{Framed-IP-Address}' WHERE AcctSessionId = '%{Acct-Session-Id}' AND UserName = '%{SQL-User-Name}' AND NASIPAddress= '%{NAS-IP-Address}' AND AcctStopTime = 0"<BR> accounting_update_query_alt = "INSERT into radacct (AcctSessionId, AcctUniqueId, UserName, Realm, NASIPAddress, NASPort, NASPortType, AcctSessionTime, AcctAuthentic, ConnectInfo_start, AcctInputOctets, AcctOutputOctets, CalledStationId, CallingStationId, ServiceType, FramedProtocol, FramedIPAddress, AcctStartDelay, XAscendSessionSvrKey) VALUES('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port-Id}', '%{NAS-Port-Type}', '%{Acct-Session-Time}', '%{Acct-Authentic}', '', '%{Acct-Input-Octets}', '%{Acct-Output-Octets}', '%{Called-Station-Id}', '%{Calling-Station-Id}', '%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}', '0', '%{X-Ascend-Session-Svr-Key}')"<BR> accounting_start_query = "INSERT into radacct (AcctSessionId, AcctUniqueId, UserName, Realm, NASIPAddress, NASPort, NASPortType, AcctStartTime, AcctSessionTime, AcctAuthentic, ConnectInfo_start, ConnectInfo_stop, AcctInputOctets, AcctOutputOctets, CalledStationId, CallingStationId, AcctTerminateCause, ServiceType, FramedProtocol, FramedIPAddress, AcctStartDelay, AcctStopDelay, XAscendSessionSvrKey) VALUES('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port-Id}', '%{NAS-Port-Type}', '%S', '0', '%{Acct-Authentic}', '%{Connect-Info}', '', '0', '0', '%{Called-Station-Id}', '%{Calling-Station-Id}', '', '%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}', '%{Acct-Delay-Time}', '0', '%{X-Ascend-Session-Svr-Key}')"<BR> accounting_start_query_alt = "UPDATE radacct SET AcctStartTime = '%S', AcctStartDelay = '%{Acct-Delay-Time:-0}', ConnectInfo_start = '%{Connect-Info}' WHERE AcctSessionId = '%{Acct-Session-Id}' AND UserName = '%{SQL-User-Name}' AND NASIPAddress = '%{NAS-IP-Address}' AND AcctStopTime = 0"<BR> accounting_stop_query = "UPDATE radacct SET AcctStopTime = '%S', AcctSessionTime = '%{Acct-Session-Time}', AcctInputOctets = '%{Acct-Input-Octets}', AcctOutputOctets = '%{Acct-Output-Octets}', AcctTerminateCause = '%{Acct-Terminate-Cause}', AcctStopDelay = '%{Acct-Delay-Time:-0}', ConnectInfo_stop = '%{Connect-Info}' WHERE AcctSessionId = '%{Acct-Session-Id}' AND UserName = '%{SQL-User-Name}' AND NASIPAddress = '%{NAS-IP-Address}' AND AcctStopTime = 0"<BR> accounting_stop_query_alt = "INSERT into radacct (AcctSessionId, AcctUniqueId, UserName, Realm, NASIPAddress, NASPort, NASPortType, AcctStopTime, AcctSessionTime, AcctAuthentic, ConnectInfo_start, ConnectInfo_stop, AcctInputOctets, AcctOutputOctets, CalledStationId, CallingStationId, AcctTerminateCause, ServiceType, FramedProtocol, FramedIPAddress, AcctStartDelay, AcctStopDelay) values('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port-Id}', '%{NAS-Port-Type}', '%S', '%{Acct-Session-Time}', '%{Acct-Authentic}', '', '%{Connect-Info}', '%{Acct-Input-Octets}', '%{Acct-Output-Octets}', '%{Called-Station-Id}', '%{Calling-Station-Id}', '%{Acct-Terminate-Cause}', '%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}', '0', '%{Acct-Delay-Time:-0}')"<BR> connect_failure_retry_delay = 60<BR> simul_count_query = ""<BR> simul_verify_query = ""<BR> postauth_query = ""<BR> safe-characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"<BR> }<BR>rlm_sql (sql): Driver rlm_sql_iodbc (module rlm_sql_iodbc) loaded and linked<BR>rlm_sql (sql): Attempting to connect to <A href="mailto:freeradius@DSN=WSC_freeRadius;UID=freeradius;PWD=kradadius:/WSC_freeRadius">freeradius@DSN=WSC_freeRadius;UID=freeradius;PWD=kradadius:/WSC_freeRadius</A><BR>rlm_sql (sql): starting 0<BR>rlm_sql (sql): Attempting to connect rlm_sql_iodbc #0<BR>rlm_sql (sql): Connected new DB handle, #0<BR>rlm_sql (sql): starting 1<BR>rlm_sql (sql): Attempting to connect rlm_sql_iodbc #1<BR>rlm_sql (sql): Connected new DB handle, #1<BR>rlm_sql (sql): starting 2<BR>rlm_sql (sql): Attempting to connect rlm_sql_iodbc #2<BR>rlm_sql (sql): Connected new DB handle, #2<BR>rlm_sql (sql): starting 3<BR>rlm_sql (sql): Attempting to connect rlm_sql_iodbc #3<BR>rlm_sql (sql): Connected new DB handle, #3<BR>rlm_sql (sql): starting 4<BR>rlm_sql (sql): Attempting to connect rlm_sql_iodbc #4<BR>rlm_sql (sql): Connected new DB handle, #4<BR> Module: Checking preacct {...} for more modules to load<BR> Module: Linked to module rlm_acct_unique<BR> Module: Instantiating module "acct_unique" from file /etc/freeradius/modules/acct_unique<BR> acct_unique {<BR> key = "User-Name, Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port"<BR> }<BR> Module: Checking accounting {...} for more modules to load<BR> Module: Linked to module rlm_detail<BR> Module: Instantiating module "detail" from file /etc/freeradius/modules/detail<BR> detail {<BR> detailfile = "/var/log/freeradius/radacct/%{Client-IP-Address}/detail-%Y%m%d"<BR> header = "%t"<BR> detailperm = 384<BR> dirperm = 493<BR> locking = no<BR> log_packet_header = no<BR> }<BR> Module: Instantiating module "attr_filter.accounting_response" from file /etc/freeradius/modules/attr_filter<BR> attr_filter attr_filter.accounting_response {<BR> attrsfile = "/etc/freeradius/attrs.accounting_response"<BR> key = "%{User-Name}"<BR> }<BR> Module: Checking session {...} for more modules to load<BR> Module: Checking post-proxy {...} for more modules to load<BR> Module: Checking post-auth {...} for more modules to load<BR> } # modules<BR>} # server<BR>radiusd: #### Opening IP addresses and Ports ####<BR>listen {<BR> type = "auth"<BR> ipaddr = *<BR> port = 0<BR>}<BR>listen {<BR> type = "acct"<BR> ipaddr = *<BR> port = 0<BR>}<BR>listen {<BR> type = "auth"<BR> ipaddr = 127.0.0.1<BR> port = 18120<BR>}<BR>Listening on authentication address * port 1812<BR>Listening on accounting address * port 1813<BR>Listening on authentication address 127.0.0.1 port 18120 as server inner-tunnel<BR>Listening on proxy address * port 1814<BR>Ready to process requests.<BR>rad_recv: Access-Request packet from host 10.45.17.117 port 1645, id=10, length=138<BR> User-Name = "0022645ae01f"<BR> User-Password = "0022645ae01f"<BR> Service-Type = Call-Check<BR> Framed-MTU = 1500<BR> Called-Station-Id = "00-18-B9-99-B6-B3"<BR> Calling-Station-Id = "00-22-64-5A-E0-1F"<BR> Message-Authenticator = 0x415829b9c54cb3c639abc6971e7714fd<BR> NAS-Port-Type = Ethernet<BR> NAS-Port = 50047<BR> NAS-IP-Address = 10.45.17.117<BR># Executing section authorize from file /etc/freeradius/sites-enabled/default<BR>+- entering group authorize {...}<BR>++[preprocess] returns ok<BR>++- entering policy rewrite_calling_station_id {...}<BR>+++? if (calling-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i)<BR>? Evaluating (calling-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i) -> TRUE<BR>+++? if (calling-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i) -> TRUE<BR>+++- entering if (calling-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i) {...}<BR> expand: %{1}%{2}%{3}%{4}%{5}%{6} -> 0022645AE01F<BR>++++[request] returns ok<BR>+++- if (calling-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i) returns ok<BR>+++ ... skipping else for request 0: Preceding "if" was taken<BR>++- policy rewrite_calling_station_id returns ok<BR>++- entering policy rewrite_called_station_id {...}<BR>+++? if (Called-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i)<BR>? Evaluating (Called-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i) -> TRUE<BR>+++? if (Called-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i) -> TRUE<BR>+++- entering if (Called-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i) {...}<BR> expand: %{1}%{2}%{3}%{4}%{5}%{6} -> 0018B999B6B3<BR>++++[request] returns ok<BR>+++- if (Called-Station-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([-a-z0-9_.]*)?/i) returns ok<BR>+++ ... skipping else for request 0: Preceding "if" was taken<BR>++- policy rewrite_called_station_id returns ok<BR>++? if (( Service-Type == 'Call-Check') || (User-Name =~ /^%{Calling-Station-ID}$/i))<BR>?? Evaluating (Service-Type == 'Call-Check') -> TRUE<BR>?? Skipping (User-Name =~ /^%{Calling-Station-ID}$/i)<BR>++? if (( Service-Type == 'Call-Check') || (User-Name =~ /^%{Calling-Station-ID}$/i)) -> TRUE<BR>++- entering if (( Service-Type == 'Call-Check') || (User-Name =~ /^%{Calling-Station-ID}$/i)) {...}<BR>+++- if (( Service-Type == 'Call-Check') || (User-Name =~ /^%{Calling-Station-ID}$/i)) returns notfound<BR>++- group authorize returns notfound<BR>[sql] expand: %{User-Name} -> 0022645ae01f<BR>[sql] sql_set_user escaped user --> '0022645ae01f'<BR>rlm_sql (sql): Reserving sql socket id: 4<BR>[sql] expand: SELECT id,UserName,Attribute,Value,op FROM radcheck WHERE Username = '%{SQL-User-Name}' ORDER BY id -> SELECT id,UserName,Attribute,Value,op FROM radcheck WHERE Username = '0022645ae01f' ORDER BY id<BR>[sql] User found in radcheck table<BR>[sql] expand: SELECT id,UserName,Attribute,Value,op FROM radreply WHERE Username = '%{SQL-User-Name}' ORDER BY id -> SELECT id,UserName,Attribute,Value,op FROM radreply WHERE Username = '0022645ae01f' ORDER BY id<BR>rlm_sql (sql): Released sql socket id: 4<BR>++[sql] returns ok<BR>++[chap] returns noop<BR>++[mschap] returns noop<BR>++[digest] returns noop<BR>[suffix] No <A href="mailto:'@'">'@'</A> in User-Name = "0022645ae01f", looking up realm NULL<BR>[suffix] No such realm "NULL"<BR>++[suffix] returns noop<BR>[eap] No EAP-Message, not doing EAP<BR>++[eap] returns noop<BR>++[files] returns noop<BR>++[expiration] returns noop<BR>++[logintime] returns noop<BR>++[pap] returns updated<BR>Found Auth-Type = PAP<BR># Executing group from file /etc/freeradius/sites-enabled/default<BR>+- entering group PAP {...}<BR>[pap] login attempt with password "0022645ae01f"<BR>[pap] Using clear text password "0022645ae01f"<BR>[pap] User authenticated successfully<BR>++[pap] returns ok<BR># Executing section post-auth from file /etc/freeradius/sites-enabled/default<BR>+- entering group post-auth {...}<BR>[sql] expand: %{User-Name} -> 0022645ae01f<BR>[sql] sql_set_user escaped user --> '0022645ae01f'<BR>++[sql] returns noop<BR>++[exec] returns noop<BR>Sending Access-Accept of id 10 to 10.45.17.117 port 1645<BR>Finished request 0.<BR>Going to the next request<BR>Waking up in 4.9 seconds.<BR>Cleaning up request 0 ID 10 with timestamp +39<BR>Ready to process requests.</DIV>
<DIV> </DIV></BODY></HTML>