<p dir="ltr"><br>
Thank you for your reply.</p>
<p dir="ltr">Here is my radius -X</p>
<p dir="ltr">> radiusd: FreeRADIUS Version 3.0.1, for host x86_64-pc-linux-gnu, built on Apr 15 2014 at 14:04:23<br>
><br>
> Copyright (C) 1999-2014 The FreeRADIUS server project and contributors<br>
><br>
> There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A<br>
><br>
> PARTICULAR PURPOSE<br>
><br>
> You may redistribute copies of FreeRADIUS under the terms of the<br>
><br>
> GNU General Public License<br>
><br>
> For more information about these matters, see the file named COPYRIGHT<br>
><br>
> Starting - reading configuration files ...<br>
><br>
> including dictionary file /etc/freeradius/dictionary<br>
><br>
> including configuration file /etc/freeradius/radiusd.conf<br>
><br>
> including configuration file /etc/freeradius/proxy.conf<br>
><br>
> including configuration file /etc/freeradius/clients.conf<br>
><br>
> including files in directory /etc/freeradius/mods-enabled/<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/eap<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/always<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/dynamic_clients<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/detail.log<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/detail<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/sradutmp<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/expiration<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/preprocess<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/logintime<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/soh<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/dhcp<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/radutmp<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/digest<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/exec<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/echo<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/replicate<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/cache_eap<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/linelog<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/utf8<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/attr_filter<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/chap<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/realm<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/passwd<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/ntlm_auth<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/sql<br>
><br>
> including configuration file /etc/freeradius/mods-config/sql/main/mysql/queries.conf<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/sqlcounter<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/pap<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/perl<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/files<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/expr<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/unix<br>
><br>
> including configuration file /etc/freeradius/mods-enabled/mschap<br>
><br>
> including files in directory /etc/freeradius/policy.d/<br>
><br>
> including configuration file /etc/freeradius/policy.d/eap<br>
><br>
> including configuration file /etc/freeradius/policy.d/cui<br>
><br>
> including configuration file /etc/freeradius/policy.d/operator-name<br>
><br>
> including configuration file /etc/freeradius/policy.d/dhcp<br>
><br>
> including configuration file /etc/freeradius/policy.d/control<br>
><br>
> including configuration file /etc/freeradius/policy.d/filter<br>
><br>
> including configuration file /etc/freeradius/policy.d/canonicalization<br>
><br>
> including configuration file /etc/freeradius/policy.d/accounting<br>
><br>
> including files in directory /etc/freeradius/sites-enabled/<br>
><br>
> including configuration file /etc/freeradius/sites-enabled/inner-tunnel<br>
><br>
> including configuration file /etc/freeradius/sites-enabled/default<br>
><br>
> main {<br>
><br>
> security {<br>
><br>
> user = "freerad"<br>
><br>
> group = "freerad"<br>
><br>
> allow_core_dumps = no<br>
><br>
> }<br>
><br>
> }<br>
><br>
> main {<br>
><br>
> name = "freeradius"<br>
><br>
> prefix = "/usr"<br>
><br>
> localstatedir = "/var"<br>
><br>
> sbindir = "/usr/sbin"<br>
><br>
> logdir = "/var/log/freeradius"<br>
><br>
> run_dir = "/var/run/freeradius"<br>
><br>
> libdir = "/usr/lib/freeradius"<br>
><br>
> radacctdir = "/var/log/freeradius/radacct"<br>
><br>
> hostname_lookups = no<br>
><br>
> max_request_time = 30<br>
><br>
> cleanup_delay = 5<br>
><br>
> max_requests = 1024<br>
><br>
> pidfile = "/var/run/freeradius/freeradius.pid"<br>
><br>
> checkrad = "/usr/sbin/checkrad"<br>
><br>
> debug_level = 0<br>
><br>
> proxy_requests = no<br>
><br>
> log {<br>
><br>
> stripped_names = no<br>
><br>
> auth = no<br>
><br>
> auth_badpass = no<br>
><br>
> auth_goodpass = no<br>
><br>
> colourise = yes<br>
><br>
> }<br>
><br>
> security {<br>
><br>
> max_attributes = 200<br>
><br>
> reject_delay = 1<br>
><br>
> status_server = yes<br>
><br>
> }<br>
><br>
> }<br>
><br>
> radiusd: #### Loading Realms and Home Servers ####<br>
><br>
> proxy server {<br>
><br>
> retry_delay = 5<br>
><br>
> retry_count = 3<br>
><br>
> default_fallback = no<br>
><br>
> dead_time = 120<br>
><br>
> wake_all_if_all_dead = no<br>
><br>
> }<br>
><br>
> home_server localhost {<br>
><br>
> ipaddr = 127.0.0.1<br>
><br>
> port = 1812<br>
><br>
> type = "auth"<br>
><br>
> secret = "testing123"<br>
><br>
> response_window = 20<br>
><br>
> max_outstanding = 65536<br>
><br>
> zombie_period = 40<br>
><br>
> status_check = "status-server"<br>
><br>
> ping_interval = 30<br>
><br>
> check_interval = 30<br>
><br>
> num_answers_to_alive = 3<br>
><br>
> revive_interval = 120<br>
><br>
> status_check_timeout = 4<br>
><br>
> coa {<br>
><br>
> irt = 2<br>
><br>
> mrt = 16<br>
><br>
> mrc = 5<br>
><br>
> mrd = 30<br>
><br>
> }<br>
><br>
> limit {<br>
><br>
> max_connections = 16<br>
><br>
> max_requests = 0<br>
><br>
> lifetime = 0<br>
><br>
> idle_timeout = 0<br>
><br>
> }<br>
><br>
> }<br>
><br>
> home_server_pool my_auth_failover {<br>
><br>
> type = fail-over<br>
><br>
> home_server = localhost<br>
><br>
> }<br>
><br>
> realm <a href="http://example.com">example.com</a> {<br>
><br>
> auth_pool = my_auth_failover<br>
><br>
> }<br>
><br>
> realm LOCAL {<br>
><br>
> }<br>
><br>
> radiusd: #### Loading Clients ####<br>
><br>
> client localhost {<br>
><br>
> ipaddr = 127.0.0.1<br>
><br>
> require_message_authenticator = no<br>
><br>
> secret = "radius"<br>
><br>
> shortname = "localhost"<br>
><br>
> nas_type = "other"<br>
><br>
> proto = "*"<br>
><br>
> limit {<br>
><br>
> max_connections = 16<br>
><br>
> lifetime = 0<br>
><br>
> idle_timeout = 30<br>
><br>
> }<br>
><br>
> }<br>
><br>
> client 27.33.228.125 {<br>
><br>
> require_message_authenticator = no<br>
><br>
> secret = "radius"<br>
><br>
> shortname = "14kimberleyst"<br>
><br>
> nas_type = "mikrotik"<br>
><br>
> limit {<br>
><br>
> max_connections = 16<br>
><br>
> lifetime = 0<br>
><br>
> idle_timeout = 30<br>
><br>
> }<br>
><br>
> }<br>
><br>
> client 220.244.108.10 {<br>
><br>
> require_message_authenticator = no<br>
><br>
> secret = "radius"<br>
><br>
> shortname = "30cookst"<br>
><br>
> nas_type = "mikrotik_snmp"<br>
><br>
> limit {<br>
><br>
> max_connections = 16<br>
><br>
> lifetime = 0<br>
><br>
> idle_timeout = 30<br>
><br>
> }<br>
><br>
> }<br>
><br>
> client <a href="http://10.1.1.22/24">10.1.1.22/24</a> {<br>
><br>
> require_message_authenticator = no<br>
><br>
> secret = "radius"<br>
><br>
> shortname = "MikroTik"<br>
><br>
> limit {<br>
><br>
> max_connections = 16<br>
><br>
> lifetime = 0<br>
><br>
> idle_timeout = 30<br>
><br>
> }<br>
><br>
> }<br>
><br>
> client <a href="http://99hamilton.no-ip.biz">99hamilton.no-ip.biz</a> {<br>
><br>
> require_message_authenticator = no<br>
><br>
> secret = "radius"<br>
><br>
> shortname = "99hamilton"<br>
><br>
> nas_type = "mikrotik"<br>
><br>
> limit {<br>
><br>
> max_connections = 16<br>
><br>
> lifetime = 0<br>
><br>
> idle_timeout = 30<br>
><br>
> }<br>
><br>
> }<br>
><br>
> radiusd: #### Instantiating modules ####<br>
><br>
> instantiate {<br>
><br>
> }<br>
><br>
> modules {<br>
><br>
> # Loaded module rlm_eap<br>
><br>
> # Instantiating module "eap" from file /etc/freeradius/mods-enabled/eap<br>
><br>
> eap {<br>
><br>
> default_eap_type = "md5"<br>
><br>
> timer_expire = 60<br>
><br>
> ignore_unknown_eap_types = no<br>
><br>
> mod_accounting_username_bug = no<br>
><br>
> max_sessions = 4096<br>
><br>
> }<br>
><br>
> # Linked to sub-module rlm_eap_md5<br>
><br>
> # Linked to sub-module rlm_eap_leap<br>
><br>
> # Linked to sub-module rlm_eap_gtc<br>
><br>
> gtc {<br>
><br>
> challenge = "Password: "<br>
><br>
> auth_type = "PAP"<br>
><br>
> }<br>
><br>
> # Linked to sub-module rlm_eap_tls<br>
><br>
> tls {<br>
><br>
> tls = "tls-common"<br>
><br>
> }<br>
><br>
> tls-config tls-common {<br>
><br>
> rsa_key_exchange = no<br>
><br>
> dh_key_exchange = yes<br>
><br>
> rsa_key_length = 512<br>
><br>
> dh_key_length = 512<br>
><br>
> verify_depth = 0<br>
><br>
> ca_path = "/etc/freeradius/certs"<br>
><br>
> pem_file_type = yes<br>
><br>
> private_key_file = "/etc/freeradius/certs/server.pem"<br>
><br>
> certificate_file = "/etc/freeradius/certs/server.pem"<br>
><br>
> ca_file = "/etc/freeradius/certs/ca.pem"<br>
><br>
> private_key_password = "whatever"<br>
><br>
> dh_file = "/etc/freeradius/certs/dh"<br>
><br>
> fragment_size = 1024<br>
><br>
> include_length = yes<br>
><br>
> check_crl = no<br>
><br>
> cipher_list = "DEFAULT"<br>
><br>
> ecdh_curve = "prime256v1"<br>
><br>
> cache {<br>
><br>
> enable = yes<br>
><br>
> lifetime = 24<br>
><br>
> max_entries = 255<br>
><br>
> }<br>
><br>
> verify {<br>
><br>
> }<br>
><br>
> ocsp {<br>
><br>
> enable = no<br>
><br>
> override_cert_url = yes<br>
><br>
> url = "<a href="http://127.0.0.1/ocsp/">http://127.0.0.1/ocsp/</a>"<br>
><br>
> use_nonce = yes<br>
><br>
> timeout = 0<br>
><br>
> softfail = yes<br>
><br>
> }<br>
><br>
> }<br>
><br>
> # Linked to sub-module rlm_eap_ttls<br>
><br>
> ttls {<br>
><br>
> tls = "tls-common"<br>
><br>
> default_eap_type = "md5"<br>
><br>
> copy_request_to_tunnel = no<br>
><br>
> use_tunneled_reply = no<br>
><br>
> virtual_server = "inner-tunnel"<br>
><br>
> include_length = yes<br>
><br>
> require_client_cert = no<br>
><br>
> }<br>
><br>
> Using cached TLS configuration from previous invocation<br>
><br>
> # Linked to sub-module rlm_eap_peap<br>
><br>
> peap {<br>
><br>
> tls = "tls-common"<br>
><br>
> default_method = "mschapv2"<br>
><br>
> copy_request_to_tunnel = no<br>
><br>
> use_tunneled_reply = no<br>
><br>
> proxy_tunneled_request_as_eap = yes<br>
><br>
> virtual_server = "inner-tunnel"<br>
><br>
> soh = no<br>
><br>
> require_client_cert = no<br>
><br>
> }<br>
><br>
> Using cached TLS configuration from previous invocation<br>
><br>
> # Linked to sub-module rlm_eap_mschapv2<br>
><br>
> mschapv2 {<br>
><br>
> with_ntdomain_hack = no<br>
><br>
> send_error = no<br>
><br>
> }<br>
><br>
> # Loaded module rlm_always<br>
><br>
> # Instantiating module "fail" from file /etc/freeradius/mods-enabled/always<br>
><br>
> always fail {<br>
><br>
> rcode = "fail"<br>
><br>
> simulcount = 0<br>
><br>
> mpp = no<br>
><br>
> }<br>
><br>
> # Instantiating module "reject" from file /etc/freeradius/mods-enabled/always<br>
><br>
> always reject {<br>
><br>
> rcode = "reject"<br>
><br>
> simulcount = 0<br>
><br>
> mpp = no<br>
><br>
> }<br>
><br>
> # Instantiating module "noop" from file /etc/freeradius/mods-enabled/always<br>
><br>
> always noop {<br>
><br>
> rcode = "noop"<br>
><br>
> simulcount = 0<br>
><br>
> mpp = no<br>
><br>
> }<br>
><br>
> # Instantiating module "handled" from file /etc/freeradius/mods-enabled/always<br>
><br>
> always handled {<br>
><br>
> rcode = "handled"<br>
><br>
> simulcount = 0<br>
><br>
> mpp = no<br>
><br>
> }<br>
><br>
> # Instantiating module "updated" from file /etc/freeradius/mods-enabled/always<br>
><br>
> always updated {<br>
><br>
> rcode = "updated"<br>
><br>
> simulcount = 0<br>
><br>
> mpp = no<br>
><br>
> }<br>
><br>
> # Instantiating module "notfound" from file /etc/freeradius/mods-enabled/always<br>
><br>
> always notfound {<br>
><br>
> rcode = "notfound"<br>
><br>
> simulcount = 0<br>
><br>
> mpp = no<br>
><br>
> }<br>
><br>
> # Instantiating module "ok" from file /etc/freeradius/mods-enabled/always<br>
><br>
> always ok {<br>
><br>
> rcode = "ok"<br>
><br>
> simulcount = 0<br>
><br>
> mpp = no<br>
><br>
> }<br>
><br>
> # Loaded module rlm_dynamic_clients<br>
><br>
> # Instantiating module "dynamic_clients" from file /etc/freeradius/mods-enabled/dynamic_clients<br>
><br>
> # Loaded module rlm_detail<br>
><br>
> # Instantiating module "auth_log" from file /etc/freeradius/mods-enabled/detail.log<br>
><br>
> detail auth_log {<br>
><br>
> filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"<br>
><br>
> header = "%t"<br>
><br>
> permissions = 384<br>
><br>
> dir_permissions = 493<br>
><br>
> locking = no<br>
><br>
> log_packet_header = no<br>
><br>
> }<br>
><br>
> rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output<br>
><br>
> # Instantiating module "reply_log" from file /etc/freeradius/mods-enabled/detail.log<br>
><br>
> detail reply_log {<br>
><br>
> filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"<br>
><br>
> header = "%t"<br>
><br>
> permissions = 384<br>
><br>
> dir_permissions = 493<br>
><br>
> locking = no<br>
><br>
> log_packet_header = no<br>
><br>
> }<br>
><br>
> # Instantiating module "pre_proxy_log" from file /etc/freeradius/mods-enabled/detail.log<br>
><br>
> detail pre_proxy_log {<br>
><br>
> filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"<br>
><br>
> header = "%t"<br>
><br>
> permissions = 384<br>
><br>
> dir_permissions = 493<br>
><br>
> locking = no<br>
><br>
> log_packet_header = no<br>
><br>
> }<br>
><br>
> # Instantiating module "post_proxy_log" from file /etc/freeradius/mods-enabled/detail.log<br>
><br>
> detail post_proxy_log {<br>
><br>
> filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"<br>
><br>
> header = "%t"<br>
><br>
> permissions = 384<br>
><br>
> dir_permissions = 493<br>
><br>
> locking = no<br>
><br>
> log_packet_header = no<br>
><br>
> }<br>
><br>
> # Instantiating module "detail" from file /etc/freeradius/mods-enabled/detail<br>
><br>
> detail {<br>
><br>
> filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"<br>
><br>
> header = "%t"<br>
><br>
> permissions = 384<br>
><br>
> dir_permissions = 493<br>
><br>
> locking = no<br>
><br>
> log_packet_header = no<br>
><br>
> }<br>
><br>
> # Loaded module rlm_radutmp<br>
><br>
> # Instantiating module "sradutmp" from file /etc/freeradius/mods-enabled/sradutmp<br>
><br>
> radutmp sradutmp {<br>
><br>
> filename = "/var/log/freeradius/sradutmp"<br>
><br>
> username = "%{User-Name}"<br>
><br>
> case_sensitive = yes<br>
><br>
> check_with_nas = yes<br>
><br>
> permissions = 420<br>
><br>
> caller_id = no<br>
><br>
> }<br>
><br>
> # Loaded module rlm_expiration<br>
><br>
> # Instantiating module "expiration" from file /etc/freeradius/mods-enabled/expiration<br>
><br>
> # Loaded module rlm_preprocess<br>
><br>
> # Instantiating module "preprocess" from file /etc/freeradius/mods-enabled/preprocess<br>
><br>
> preprocess {<br>
><br>
> huntgroups = "/etc/freeradius/mods-config/preprocess/huntgroups"<br>
><br>
> hints = "/etc/freeradius/mods-config/preprocess/hints"<br>
><br>
> with_ascend_hack = no<br>
><br>
> ascend_channels_per_line = 23<br>
><br>
> with_ntdomain_hack = no<br>
><br>
> with_specialix_jetstream_hack = no<br>
><br>
> with_cisco_vsa_hack = no<br>
><br>
> with_alvarion_vsa_hack = no<br>
><br>
> }<br>
><br>
> reading pairlist file /etc/freeradius/mods-config/preprocess/huntgroups<br>
><br>
> reading pairlist file /etc/freeradius/mods-config/preprocess/hints<br>
><br>
> # Loaded module rlm_logintime<br>
><br>
> # Instantiating module "logintime" from file /etc/freeradius/mods-enabled/logintime<br>
><br>
> logintime {<br>
><br>
> minimum_timeout = 60<br>
><br>
> }<br>
><br>
> # Loaded module rlm_soh<br>
><br>
> # Instantiating module "soh" from file /etc/freeradius/mods-enabled/soh<br>
><br>
> soh {<br>
><br>
> dhcp = yes<br>
><br>
> }<br>
><br>
> # Loaded module rlm_dhcp<br>
><br>
> # Instantiating module "dhcp" from file /etc/freeradius/mods-enabled/dhcp<br>
><br>
> # Instantiating module "radutmp" from file /etc/freeradius/mods-enabled/radutmp<br>
><br>
> radutmp {<br>
><br>
> filename = "/var/log/freeradius/radutmp"<br>
><br>
> username = "%{User-Name}"<br>
><br>
> case_sensitive = yes<br>
><br>
> check_with_nas = yes<br>
><br>
> permissions = 384<br>
><br>
> caller_id = yes<br>
><br>
> }<br>
><br>
> # Loaded module rlm_digest<br>
><br>
> # Instantiating module "digest" from file /etc/freeradius/mods-enabled/digest<br>
><br>
> # Loaded module rlm_exec<br>
><br>
> # Instantiating module "exec" from file /etc/freeradius/mods-enabled/exec<br>
><br>
> exec {<br>
><br>
> wait = no<br>
><br>
> input_pairs = "request"<br>
><br>
> shell_escape = yes<br>
><br>
> timeout = 10<br>
><br>
> }<br>
><br>
> # Instantiating module "echo" from file /etc/freeradius/mods-enabled/echo<br>
><br>
> exec echo {<br>
><br>
> wait = yes<br>
><br>
> program = "/bin/echo %{User-Name}"<br>
><br>
> input_pairs = "request"<br>
><br>
> output_pairs = "reply"<br>
><br>
> shell_escape = yes<br>
><br>
> }<br>
><br>
> # Loaded module rlm_replicate<br>
><br>
> # Instantiating module "replicate" from file /etc/freeradius/mods-enabled/replicate<br>
><br>
> # Loaded module rlm_cache<br>
><br>
> # Instantiating module "cache_eap" from file /etc/freeradius/mods-enabled/cache_eap<br>
><br>
> cache cache_eap {<br>
><br>
> key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"<br>
><br>
> ttl = 15<br>
><br>
> max_entries = 16384<br>
><br>
> epoch = 0<br>
><br>
> add_stats = no<br>
><br>
> }<br>
><br>
> # Loaded module rlm_linelog<br>
><br>
> # Instantiating module "linelog" from file /etc/freeradius/mods-enabled/linelog<br>
><br>
> linelog {<br>
><br>
> filename = "/var/log/freeradius/linelog"<br>
><br>
> permissions = 384<br>
><br>
> format = "This is a log message for %{User-Name}"<br>
><br>
> reference = "%{%{Packet-Type}:-format}"<br>
><br>
> }<br>
><br>
> # Loaded module rlm_utf8<br>
><br>
> # Instantiating module "utf8" from file /etc/freeradius/mods-enabled/utf8<br>
><br>
> # Loaded module rlm_attr_filter<br>
><br>
> # Instantiating module "attr_filter.post-proxy" from file /etc/freeradius/mods-enabled/attr_filter<br>
><br>
> attr_filter attr_filter.post-proxy {<br>
><br>
> filename = "/etc/freeradius/mods-config/attr_filter/post-proxy"<br>
><br>
> key = "%{Realm}"<br>
><br>
> relaxed = no<br>
><br>
> }<br>
><br>
> reading pairlist file /etc/freeradius/mods-config/attr_filter/post-proxy<br>
><br>
> # Instantiating module "attr_filter.pre-proxy" from file /etc/freeradius/mods-enabled/attr_filter<br>
><br>
> attr_filter attr_filter.pre-proxy {<br>
><br>
> filename = "/etc/freeradius/mods-config/attr_filter/pre-proxy"<br>
><br>
> key = "%{Realm}"<br>
><br>
> relaxed = no<br>
><br>
> }<br>
><br>
> reading pairlist file /etc/freeradius/mods-config/attr_filter/pre-proxy<br>
><br>
> # Instantiating module "attr_filter.access_reject" from file /etc/freeradius/mods-enabled/attr_filter<br>
><br>
> attr_filter attr_filter.access_reject {<br>
><br>
> filename = "/etc/freeradius/mods-config/attr_filter/access_reject"<br>
><br>
> key = "%{User-Name}"<br>
><br>
> relaxed = no<br>
><br>
> }<br>
><br>
> reading pairlist file /etc/freeradius/mods-config/attr_filter/access_reject<br>
><br>
> # Instantiating module "attr_filter.access_challenge" from file /etc/freeradius/mods-enabled/attr_filter<br>
><br>
> attr_filter attr_filter.access_challenge {<br>
><br>
> filename = "/etc/freeradius/mods-config/attr_filter/access_challenge"<br>
><br>
> key = "%{User-Name}"<br>
><br>
> relaxed = no<br>
><br>
> }<br>
><br>
> reading pairlist file /etc/freeradius/mods-config/attr_filter/access_challenge<br>
><br>
> # Instantiating module "attr_filter.accounting_response" from file /etc/freeradius/mods-enabled/attr_filter<br>
><br>
> attr_filter attr_filter.accounting_response {<br>
><br>
> filename = "/etc/freeradius/mods-config/attr_filter/accounting_response"<br>
><br>
> key = "%{User-Name}"<br>
><br>
> relaxed = no<br>
><br>
> }<br>
><br>
> reading pairlist file /etc/freeradius/mods-config/attr_filter/accounting_response<br>
><br>
> # Loaded module rlm_chap<br>
><br>
> # Instantiating module "chap" from file /etc/freeradius/mods-enabled/chap<br>
><br>
> # Loaded module rlm_realm<br>
><br>
> # Instantiating module "IPASS" from file /etc/freeradius/mods-enabled/realm<br>
><br>
> realm IPASS {<br>
><br>
> format = "prefix"<br>
><br>
> delimiter = "/"<br>
><br>
> ignore_default = no<br>
><br>
> ignore_null = no<br>
><br>
> }<br>
><br>
> # Instantiating module "suffix" from file /etc/freeradius/mods-enabled/realm<br>
><br>
> realm suffix {<br>
><br>
> format = "suffix"<br>
><br>
> delimiter = "@"<br>
><br>
> ignore_default = no<br>
><br>
> ignore_null = no<br>
><br>
> }<br>
><br>
> # Instantiating module "realmpercent" from file /etc/freeradius/mods-enabled/realm<br>
><br>
> realm realmpercent {<br>
><br>
> format = "suffix"<br>
><br>
> delimiter = "%"<br>
><br>
> ignore_default = no<br>
><br>
> ignore_null = no<br>
><br>
> }<br>
><br>
> # Instantiating module "ntdomain" from file /etc/freeradius/mods-enabled/realm<br>
><br>
> realm ntdomain {<br>
><br>
> format = "prefix"<br>
><br>
> delimiter = "\"<br>
><br>
> ignore_default = no<br>
><br>
> ignore_null = no<br>
><br>
> }<br>
><br>
> # Loaded module rlm_passwd<br>
><br>
> # Instantiating module "etc_passwd" from file /etc/freeradius/mods-enabled/passwd<br>
><br>
> passwd etc_passwd {<br>
><br>
> filename = "/etc/passwd"<br>
><br>
> format = "*User-Name:Crypt-Password:"<br>
><br>
> delimiter = ":"<br>
><br>
> ignore_nislike = no<br>
><br>
> ignore_empty = yes<br>
><br>
> allow_multiple_keys = no<br>
><br>
> hash_size = 100<br>
><br>
> }<br>
><br>
> rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no<br>
><br>
> # Instantiating module "ntlm_auth" from file /etc/freeradius/mods-enabled/ntlm_auth<br>
><br>
> exec ntlm_auth {<br>
><br>
> wait = yes<br>
><br>
> program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN --username=%{mschap:User-Name} --password=%{User-Password}"<br>
><br>
> shell_escape = yes<br>
><br>
> }<br>
><br>
> # Loaded module rlm_sql<br>
><br>
> # Instantiating module "sql" from file /etc/freeradius/mods-enabled/sql<br>
><br>
> sql {<br>
><br>
> driver = "rlm_sql_mysql"<br>
><br>
> server = "localhost"<br>
><br>
> port = "3306"<br>
><br>
> login = "radius"<br>
><br>
> password = "fheman"<br>
><br>
> radius_db = "radius"<br>
><br>
> read_groups = yes<br>
><br>
> read_clients = yes<br>
><br>
> delete_stale_sessions = yes<br>
><br>
> sql_user_name = "%{User-Name}"<br>
><br>
> default_user_profile = ""<br>
><br>
> client_query = "SELECT id, nasname, shortname, type, secret, server FROM nas"<br>
><br>
> authorize_check_query = "SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id"<br>
><br>
> authorize_reply_query = "SELECT id, username, attribute, value, op FROM radreply WHERE username = '%{SQL-User-Name}' ORDER BY id"<br>
><br>
> authorize_group_check_query = "SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '%{Sql-Group}' ORDER BY id"<br>
><br>
> authorize_group_reply_query = "SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '%{Sql-Group}' ORDER BY id"<br>
><br>
> group_membership_query = "SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority"<br>
><br>
> simul_count_query = "SELECT COUNT(*) FROM radacct WHERE username = '%{SQL-User-Name}' AND acctstoptime IS NULL"<br>
><br>
> simul_verify_query = "SELECT radacctid, acctsessionid, username, nasipaddress, nasportid, framedipaddress, callingstationid, framedprotocol FROM radacct WHERE username = '%{SQL-User-Name}' AND acctstoptime IS NULL"<br>
><br>
> safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"<br>
><br>
> }<br>
><br>
> accounting {<br>
><br>
> reference = "%{tolower:type.%{Acct-Status-Type}.query}"<br>
><br>
> }<br>
><br>
> post-auth {<br>
><br>
> reference = ".query"<br>
><br>
> }<br>
><br>
> mysql {<br>
><br>
> tls {<br>
><br>
> }<br>
><br>
> }<br>
><br>
> rlm_sql (sql): Driver rlm_sql_mysql (module rlm_sql_mysql) loaded and linked<br>
><br>
> rlm_sql (sql): Attempting to connect to database "radius"<br>
><br>
> rlm_sql (sql): Initialising connection pool<br>
><br>
> pool {<br>
><br>
> start = 5<br>
><br>
> min = 4<br>
><br>
> max = 10<br>
><br>
> spare = 3<br>
><br>
> uses = 0<br>
><br>
> lifetime = 0<br>
><br>
> cleanup_delay = 5<br>
><br>
> idle_timeout = 60<br>
><br>
> spread = no<br>
><br>
> }<br>
><br>
> rlm_sql (sql): Opening additional connection (0)<br>
><br>
> rlm_sql_mysql: Starting connect to MySQL server<br>
><br>
> ...</p>