Freeradius-Users
Threads by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 27050 discussions
We are migrating from NPS to FreeRADIUS this summer for our eduroam
wireless network. During a transition period I need to proxy clients using
the old configuration to the NPS servers. I am doing this based on outer
identity - the old config lacks outer identity configuration while the new
one specifies anonymous-202106. This is the logic from the outer tunnel
authorize section:
if (&User-Name == "anonymous-202106" || &User-Name == "
anonymous-202106(a)stolaf.edu" || &User-Name == "STOAD\anonymous-202106") {
# Authenticate the request locally
noop
} elsif (&User-Name =~ /stolaf\.edu/ || &User-Name =~ /STOAD/) {
update {
control:Proxy-To-Realm := 'nps_servers'
request:Operator-Name := "1${operator_name}"
}
return
}
The above works well for our old and new client configs. (There is some
additional logic not shown for the case of eduroam guests.)
We have one local realm, stolaf.edu. If I configure this as a realm in
proxy.conf, FR tries to authenticate all requests, from old and new
clients. If I comment it out, I do not get a realm in my log messages for
local authentications (i.e. new clients).
Is my approach above sound? Is there a better way of achieving the above
goal using realm config or something else?
Thanks!
--
*Tony Skalski*
System Administrator | IT
*Office: *507-786-3227 <(507)786-3227>
1510 St. Olaf Avenue Northfield, MN 55057
stolaf.edu
2
1
Hello, need some help.
I have one Ubiquiti using EAP-TTLS MSCHAPV2 auth. I´m using username and password. My radcheck table looks like this:
SCENARIO 1:
mysql> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'mmd13' ORDER BY id;
+-------+----------+--------------------+--------+----+
| id | username | attribute | value | op |
+-------+----------+--------------------+--------+----+
| 64446 | mmd13 | Cleartext-Password | qmk65s | := |
+-------+----------+--------------------+--------+----+
1 row in set (0.01 sec)
I have no problem to find Cleartext-Password in MySQL:
(4) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(4) authorize {
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) } # if (&User-Name) = notfound
(4) } # policy filter_username = notfound
(4) [chap] = noop
(4) mschap: Found MS-CHAP attributes. Setting 'Auth-Type = mschap'
(4) [mschap] = ok
(4) suffix: Checking for suffix after "@"
(4) suffix: No '@' in User-Name = "mmd13", looking up realm NULL
(4) suffix: No such realm "NULL"
(4) [suffix] = noop
(4) update control {
(4) &Proxy-To-Realm := LOCAL
(4) } # update control = noop
(4) eap: No EAP-Message, not doing EAP
(4) [eap] = noop
(4) [files] = noop
(4) sql: EXPAND %{User-Name}
(4) sql: --> mmd13
(4) sql: SQL-User-Name set to 'mmd13'
rlm_sql (sql): Reserved connection (5)
(4) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(4) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'mmd13' ORDER BY id
(4) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'mmd13' ORDER BY id
(4) sql: User found in radcheck table
(4) sql: Conditional check items matched, merging assignment check items
(4) sql: Cleartext-Password := "qmk65s"
(4) sql: EXPAND SELECT id, username, attribute, value, op FROM radreply WHERE username = '%{SQL-User-Name}' ORDER BY id
(4) sql: --> SELECT id, username, attribute, value, op FROM radreply WHERE username = 'mmd13' ORDER BY id
(4) sql: Executing select query: SELECT id, username, attribute, value, op FROM radreply WHERE username = 'mmd13' ORDER BY id
(4) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(4) sql: --> SELECT groupname FROM radusergroup WHERE username = 'mmd13' ORDER BY priority
(4) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'mmd13' ORDER BY priority
(4) sql: User found in the group table
(4) sql: EXPAND SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '%{SQL-Group}' ORDER BY id
(4) sql: --> SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '105' ORDER BY id
(4) sql: Executing select query: SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '105' ORDER BY id
(4) sql: Group "105": Conditional check items matched
(4) sql: Group "105": Merging assignment check items
(4) sql: Simultaneous-Use := 1
(4) sql: EXPAND SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '%{SQL-Group}' ORDER BY id
(4) sql: --> SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '105' ORDER BY id
(4) sql: Executing select query: SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '105' ORDER BY id
(4) sql: Group "105": Merging reply items
(4) sql: Mikrotik-Rate-Limit = "35840k/71680k 0k/0k 0k/0k 0/0 5 35840k/71680k "
(4) sql: WISPr-Bandwidth-Max-Down = 71680000
(4) sql: WISPr-Bandwidth-Max-Up = 35840000
rlm_sql (sql): Released connection (5)
(4) [sql] = ok
(4) [expiration] = noop
(4) [logintime] = noop
(4) pap: WARNING: Auth-Type already set. Not setting to PAP
(4) [pap] = noop
(4) } # authorize = ok
(4) Found Auth-Type = mschap
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(4) authenticate {
(4) mschap: Found Cleartext-Password, hashing to create NT-Password
(4) mschap: Found Cleartext-Password, hashing to create LM-Password
(4) mschap: Creating challenge hash with username: mmd13
(4) mschap: Client is using MS-CHAPv2
Please note these two lines:
(4) sql: Conditional check items matched, merging assignment check items
(4) sql: Cleartext-Password := "qmk65s"
Then MSCHAP found the Cleartext-Password and there is a ACCEPT.
But I need to use Calling-Station-Id into radcheck. The new scenario:
SCENARIO 2:
mysql> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'mmd13' ORDER BY id;
+-------+----------+--------------------+-------------------+----+
| id | username | attribute | value | op |
+-------+----------+--------------------+-------------------+----+
| 63983 | mmd13 | Calling-Station-Id | 00:27:22:A2:07:C5 | == |
| 64446 | mmd13 | Cleartext-Password | qmk65s | := |
+-------+----------+--------------------+-------------------+----+
2 rows in set (0.00 sec)
Now, with two rows in radcheck, SQL returns different:
(4) Received Access-Request Id 28 from 192.168.1.21:51630 to 172.18.0.1:1812 length 361
(4) User-Name = "anonymous(a)myisp.com"
(4) NAS-Identifier = "NanoStation loco M5"
(4) Called-Station-Id = "24-A4-3C-88-F3-94:ubntxxx"
(4) NAS-Port-Type = Wireless-802.11
(4) NAS-Port = 0
(4) Calling-Station-Id = "00-27-22-A2-07-C5"
(4) Connect-Info = "CONNECT 0Mbps 802.11b"
(4) Acct-Session-Id = "5B05AE57-00001E37"
(4) Framed-MTU = 1400
(4) EAP-Message = 0x0259009b15001703010090ad86507970ec1f8873ed46c43aa73a782c9f5eb96775deadb32855fd714ee5ebcc7e5f2e073ea7113072c589b3081fc8070ed2cc480a0d53d55e9553cc0df6703ec7467240604695ee9992e44046a88284dd2624b7b328326414d4055494a2f3c198551b9e4edc7efe29975e
(4) State = 0xfee3d417fdbac1f59e169eb3f2762e68
(4) Message-Authenticator = 0x5acd22b6522a9e9abb4b194da86ecd29
(4) session-state: No cached attributes
(4) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(4) authorize {
(4) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) {
(4) EXPAND %{Cisco-AVPair[*]}
(4) -->
(4) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) -> FALSE
(4) elsif (ERX-Dhcp-Mac-Addr =~ /^([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9])$/) {
(4) ERROR: Failed retrieving values required to evaluate condition
(4) else {
(4) update request {
(4) EXPAND %{toupper:%{Calling-Station-Id}}
(4) --> 00-27-22-A2-07-C5
(4) Calling-Station-Id := 00-27-22-A2-07-C5
(4) } # update request = noop
(4) } # else = noop
(4) if (!control:Cleartext-Password){
(4) if (!control:Cleartext-Password) -> TRUE
(4) (!control:Cleartext-Password) { ... } # empty sub-section is ignored
(4) [preprocess] = ok
(4) [chap] = noop
(4) [mschap] = noop
(4) eap: Peer sent EAP Response (code 2) ID 89 length 155
(4) eap: Continuing tunnel setup
(4) [eap] = ok
(4) sql: EXPAND %{User-Name}
(4) sql: --> anonymous(a)myisp.com
(4) sql: SQL-User-Name set to 'anonymous(a)myisp.com'
rlm_sql (sql): Reserved connection (0)
(4) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(4) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(4) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(4) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(4) sql: --> SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(4) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(4) sql: User not found in any groups
rlm_sql (sql): Released connection (0)
Need 3 more connections to reach 10 spares
rlm_sql (sql): Opening additional connection (7), 1 of 25 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
(4) [sql] = notfound
(4) [pap] = noop
(4) } # authorize = ok
(4) Found Auth-Type = eap
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(4) authenticate {
(4) eap: Expiring EAP session with state 0xfee3d417fdbac1f5
(4) eap: Finished EAP session with state 0xfee3d417fdbac1f5
(4) eap: Previous EAP request found for state 0xfee3d417fdbac1f5, released from the list
(4) eap: Peer sent packet with method EAP TTLS (21)
(4) eap: Calling submodule eap_ttls to process data
(4) eap_ttls: Authenticate
(4) eap_ttls: Continuing EAP-TLS
(4) eap_ttls: [eaptls verify] = ok
(4) eap_ttls: Done initial handshake
(4) eap_ttls: [eaptls process] = ok
(4) eap_ttls: Session established. Proceeding to decode tunneled attributes
(4) eap_ttls: Got tunneled request
(4) eap_ttls: User-Name = "mmd13"
(4) eap_ttls: MS-CHAP-Challenge = 0xa37e37c4f224a5db18cfe440f3fb3e0d
(4) eap_ttls: MS-CHAP2-Response = 0xb300134ddddfb343576a18a0db14877dea13000000000000000079f8618ac9de53a897d7875aefbdcb74c8fcb186761d050c
(4) eap_ttls: FreeRADIUS-Proxied-To = 127.0.0.1
(4) eap_ttls: Sending tunneled request
(4) Virtual server inner-tunnel received request
(4) User-Name = "mmd13"
(4) MS-CHAP-Challenge = 0xa37e37c4f224a5db18cfe440f3fb3e0d
(4) MS-CHAP2-Response = 0xb300134ddddfb343576a18a0db14877dea13000000000000000079f8618ac9de53a897d7875aefbdcb74c8fcb186761d050c
(4) FreeRADIUS-Proxied-To = 127.0.0.1
(4) server inner-tunnel {
(4) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(4) authorize {
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) } # if (&User-Name) = notfound
(4) } # policy filter_username = notfound
(4) [chap] = noop
(4) mschap: Found MS-CHAP attributes. Setting 'Auth-Type = mschap'
(4) [mschap] = ok
(4) suffix: Checking for suffix after "@"
(4) suffix: No '@' in User-Name = "mmd13", looking up realm NULL
(4) suffix: No such realm "NULL"
(4) [suffix] = noop
(4) update control {
(4) &Proxy-To-Realm := LOCAL
(4) } # update control = noop
(4) eap: No EAP-Message, not doing EAP
(4) [eap] = noop
(4) [files] = noop
(4) sql: EXPAND %{User-Name}
(4) sql: --> mmd13
(4) sql: SQL-User-Name set to 'mmd13'
rlm_sql (sql): Reserved connection (5)
(4) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(4) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'mmd13' ORDER BY id
(4) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'mmd13' ORDER BY id
(4) sql: User found in radcheck table
(4) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(4) sql: --> SELECT groupname FROM radusergroup WHERE username = 'mmd13' ORDER BY priority
(4) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'mmd13' ORDER BY priority
(4) sql: User found in the group table
(4) sql: EXPAND SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '%{SQL-Group}' ORDER BY id
(4) sql: --> SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '105' ORDER BY id
(4) sql: Executing select query: SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '105' ORDER BY id
(4) sql: Group "105": Conditional check items matched
(4) sql: Group "105": Merging assignment check items
(4) sql: Simultaneous-Use := 1
(4) sql: EXPAND SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '%{SQL-Group}' ORDER BY id
(4) sql: --> SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '105' ORDER BY id
(4) sql: Executing select query: SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '105' ORDER BY id
(4) sql: Group "105": Merging reply items
(4) sql: Mikrotik-Rate-Limit = "35840k/71680k 0k/0k 0k/0k 0/0 5 35840k/71680k "
(4) sql: WISPr-Bandwidth-Max-Down = 71680000
(4) sql: WISPr-Bandwidth-Max-Up = 35840000
rlm_sql (sql): Released connection (5)
(4) [sql] = ok
(4) [expiration] = noop
(4) [logintime] = noop
(4) [pap] = noop
(4) } # authorize = ok
(4) Found Auth-Type = mschap
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(4) authenticate {
(4) mschap: WARNING: No Cleartext-Password configured. Cannot create NT-Password
(4) mschap: WARNING: No Cleartext-Password configured. Cannot create LM-Password
(4) mschap: Creating challenge hash with username: mmd13
(4) mschap: Client is using MS-CHAPv2
(4) mschap: ERROR: FAILED: No NT/LM-Password. Cannot perform authentication
(4) mschap: ERROR: MS-CHAP2-Response is incorrect
(4) [mschap] = reject
(4) } # authenticate = reject
I got just "(4) sql: User found in radcheck table" but "Conditional check items matched, merging assignment check items" and "Cleartext-password" are missing.
Since there are no Cleartext-password, MSCHAP fails: "(4) mschap: ERROR: FAILED: No NT/LM-Password. Cannot perform authentication".
I really need to have Calling-Station-Id and Cleartext-Password into radcheck table.
Requests 0 to 3 are the same into SCENARIO 1 and 2. The difference is in request 4 only.
It seems to me that MySQl does not see the attribute Cleartext-password when it is accompanied by another attribute.
How do I change this behavior?
Below is the output of the freeradius -X command with the first four packages (SCENARIO 2).
Thank you very much
Regards
Fabricio Viana
FreeRADIUS Version 3.0.16
Copyright (C) 1999-2017 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/freeradius/3.0/dictionary
including configuration file /etc/freeradius/3.0/radiusd.conf
including configuration file /etc/freeradius/3.0/proxy.conf
including configuration file /etc/freeradius/3.0/clients.conf
including files in directory /etc/freeradius/3.0/mods-enabled/
including configuration file /etc/freeradius/3.0/mods-enabled/always
including configuration file /etc/freeradius/3.0/mods-enabled/attr_filter
including configuration file /etc/freeradius/3.0/mods-enabled/cache_eap
including configuration file /etc/freeradius/3.0/mods-enabled/chap
including configuration file /etc/freeradius/3.0/mods-enabled/ddns_exec
including configuration file /etc/freeradius/3.0/mods-enabled/detail
including configuration file /etc/freeradius/3.0/mods-enabled/detail.log
including configuration file /etc/freeradius/3.0/mods-enabled/digest
including configuration file /etc/freeradius/3.0/mods-enabled/dynamic_clients
including configuration file /etc/freeradius/3.0/mods-enabled/echo
including configuration file /etc/freeradius/3.0/mods-enabled/exec
including configuration file /etc/freeradius/3.0/mods-enabled/expiration
including configuration file /etc/freeradius/3.0/mods-enabled/expr
including configuration file /etc/freeradius/3.0/mods-enabled/files
including configuration file /etc/freeradius/3.0/mods-enabled/linelog
including configuration file /etc/freeradius/3.0/mods-enabled/logintime
including configuration file /etc/freeradius/3.0/mods-enabled/mschap
including configuration file /etc/freeradius/3.0/mods-enabled/ntlm_auth
including configuration file /etc/freeradius/3.0/mods-enabled/pap
including configuration file /etc/freeradius/3.0/mods-enabled/passwd
including configuration file /etc/freeradius/3.0/mods-enabled/preprocess
including configuration file /etc/freeradius/3.0/mods-enabled/radutmp
including configuration file /etc/freeradius/3.0/mods-enabled/realm
including configuration file /etc/freeradius/3.0/mods-enabled/replicate
including configuration file /etc/freeradius/3.0/mods-enabled/soh
including configuration file /etc/freeradius/3.0/mods-enabled/sql
including configuration file /etc/freeradius/3.0/mods-config/sql/main/mysql/queries.conf
including configuration file /etc/freeradius/3.0/mods-enabled/sqlippool
including configuration file /etc/freeradius/3.0/mods-config/sql/ippool/mysql/queries.conf
including configuration file /etc/freeradius/3.0/mods-enabled/sqlippool_v4
including configuration file /etc/freeradius/3.0/mods-config/sql/ippool/mysql/queries.conf
including configuration file /etc/freeradius/3.0/mods-enabled/sqlippool_v6
including configuration file /etc/freeradius/3.0/mods-config/sql/ippool/mysql/queries_v6.conf
including configuration file /etc/freeradius/3.0/mods-enabled/sradutmp
including configuration file /etc/freeradius/3.0/mods-enabled/unix
including configuration file /etc/freeradius/3.0/mods-enabled/unpack
including configuration file /etc/freeradius/3.0/mods-enabled/utf8
including configuration file /etc/freeradius/3.0/mods-enabled/eap
including files in directory /etc/freeradius/3.0/policy.d/
including configuration file /etc/freeradius/3.0/policy.d/abfab-tr
including configuration file /etc/freeradius/3.0/policy.d/accounting
/etc/freeradius/3.0/policy.d/accounting[42]: Reference "${IDRADIUSSERVER}" not found
/etc/freeradius/3.0/policy.d/accounting[54]: Reference "${IDRADIUSSERVER}" not found
including configuration file /etc/freeradius/3.0/policy.d/canonicalization
including configuration file /etc/freeradius/3.0/policy.d/control
including configuration file /etc/freeradius/3.0/policy.d/cui
including configuration file /etc/freeradius/3.0/policy.d/debug
including configuration file /etc/freeradius/3.0/policy.d/dhcp
including configuration file /etc/freeradius/3.0/policy.d/eap
including configuration file /etc/freeradius/3.0/policy.d/filter
including configuration file /etc/freeradius/3.0/policy.d/moonshot-targeted-ids
including configuration file /etc/freeradius/3.0/policy.d/operator-name
including files in directory /etc/freeradius/3.0/sites-enabled/
including configuration file /etc/freeradius/3.0/sites-enabled/default
including configuration file /etc/freeradius/3.0/sites-enabled/inner-tunnel
including configuration file /etc/freeradius/3.0/freeradius.env
including configuration file /etc/freeradius/3.0/ddns.env
main {
security {
user = "freerad"
group = "freerad"
allow_core_dumps = no
}
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
}
main {
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
libdir = "/usr/lib/freeradius"
radacctdir = "/var/log/freeradius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/var/run/freeradius/freeradius.pid"
checkrad = "/var/scriptsradius/callcheckrad.sh"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
# Creating Auth-Type = mschap
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_always
# Loading module "reject" from file /etc/freeradius/3.0/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file /etc/freeradius/3.0/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /etc/freeradius/3.0/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file /etc/freeradius/3.0/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file /etc/freeradius/3.0/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file /etc/freeradius/3.0/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file /etc/freeradius/3.0/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file /etc/freeradius/3.0/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file /etc/freeradius/3.0/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loaded module rlm_cache
# Loading module "cache_eap" from file /etc/freeradius/3.0/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_chap
# Loading module "chap" from file /etc/freeradius/3.0/mods-enabled/chap
# Loaded module rlm_exec
# Loading module "ddns_del" from file /etc/freeradius/3.0/mods-enabled/ddns_exec
exec ddns_del {
wait = yes
program = "/var/scriptsradius/ddns.php del %{User-Name} %{Framed-IP-Address}"
input_pairs = "request"
shell_escape = no
}
# Loading module "ddns_add" from file /etc/freeradius/3.0/mods-enabled/ddns_exec
exec ddns_add {
wait = yes
program = "/var/scriptsradius/ddns.php add %{User-Name} %{Framed-IP-Address}"
input_pairs = "request"
shell_escape = no
}
# Loaded module rlm_detail
# Loading module "detail" from file /etc/freeradius/3.0/mods-enabled/detail
detail {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "auth_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail auth_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail reply_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail pre_proxy_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail post_proxy_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_digest
# Loading module "digest" from file /etc/freeradius/3.0/mods-enabled/digest
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file /etc/freeradius/3.0/mods-enabled/dynamic_clients
# Loading module "echo" from file /etc/freeradius/3.0/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loading module "exec" from file /etc/freeradius/3.0/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_expiration
# Loading module "expiration" from file /etc/freeradius/3.0/mods-enabled/expiration
# Loaded module rlm_expr
# Loading module "expr" from file /etc/freeradius/3.0/mods-enabled/expr
expr {
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /äéöüàâæçèéêëîïôoeùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔOEÙÛÜY"
}
# Loaded module rlm_files
# Loading module "files" from file /etc/freeradius/3.0/mods-enabled/files
files {
filename = "/etc/freeradius/3.0/mods-config/files/authorize"
acctusersfile = "/etc/freeradius/3.0/mods-config/files/accounting"
preproxy_usersfile = "/etc/freeradius/3.0/mods-config/files/pre-proxy"
}
# Loaded module rlm_linelog
# Loading module "linelog" from file /etc/freeradius/3.0/mods-enabled/linelog
linelog {
filename = "/var/log/freeradius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file /etc/freeradius/3.0/mods-enabled/linelog
linelog log_accounting {
filename = "/var/log/freeradius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_logintime
# Loading module "logintime" from file /etc/freeradius/3.0/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_mschap
# Loading module "mschap" from file /etc/freeradius/3.0/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
winbind_retry_with_normalised_username = no
}
# Loading module "ntlm_auth" from file /etc/freeradius/3.0/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN --username=%{mschap:User-Name} --password=%{User-Password}"
shell_escape = yes
}
# Loaded module rlm_pap
# Loading module "pap" from file /etc/freeradius/3.0/mods-enabled/pap
pap {
normalise = yes
}
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file /etc/freeradius/3.0/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loaded module rlm_preprocess
# Loading module "preprocess" from file /etc/freeradius/3.0/mods-enabled/preprocess
preprocess {
huntgroups = "/etc/freeradius/3.0/mods-config/preprocess/huntgroups"
hints = "/etc/freeradius/3.0/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loaded module rlm_radutmp
# Loading module "radutmp" from file /etc/freeradius/3.0/mods-enabled/radutmp
radutmp {
filename = "/var/log/freeradius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_realm
# Loading module "IPASS" from file /etc/freeradius/3.0/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file /etc/freeradius/3.0/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file /etc/freeradius/3.0/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file /etc/freeradius/3.0/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loaded module rlm_replicate
# Loading module "replicate" from file /etc/freeradius/3.0/mods-enabled/replicate
# Loaded module rlm_soh
# Loading module "soh" from file /etc/freeradius/3.0/mods-enabled/soh
soh {
dhcp = yes
}
# Loaded module rlm_sql
# Loading module "sql" from file /etc/freeradius/3.0/mods-enabled/sql
sql {
driver = "rlm_sql_mysql"
server = "192.0.2.2"
port = 3306
login = "radius_user"
password = <<< secret >>>
radius_db = "radius"
read_groups = yes
read_profiles = yes
read_clients = yes
delete_stale_sessions = yes
sql_user_name = "%{User-Name}"
default_user_profile = ""
client_query = "SELECT id, nasname, shortname, type, secret, server FROM nas"
authorize_check_query = "SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id"
authorize_reply_query = "SELECT id, username, attribute, value, op FROM radreply WHERE username = '%{SQL-User-Name}' ORDER BY id"
authorize_group_check_query = "SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '%{SQL-Group}' ORDER BY id"
authorize_group_reply_query = "SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '%{SQL-Group}' ORDER BY id"
group_membership_query = "SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority"
simul_count_query = "SELECT COUNT(*) FROM radacct WHERE username = '%{SQL-User-Name}' AND acctstoptime IS NULL"
simul_verify_query = "SELECT radacctid, acctsessionid, username, nasipaddress, nasportid, framedipaddress, callingstationid, framedprotocol FROM radacct WHERE username = '%{SQL-User-Name}' AND acctstoptime IS NULL"
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"
accounting {
reference = "%{tolower:type.%{Acct-Status-Type}.query}"
type {
accounting-on {
query = "UPDATE radacct SET acctstoptime = UTC_TIMESTAMP(), acctsessiontime = UNIX_TIMESTAMP(UTC_TIMESTAMP()) - UNIX_TIMESTAMP(acctstarttime), acctterminatecause = '%{%{Acct-Terminate-Cause}:-NAS-Reboot}' WHERE acctstoptime IS NULL AND nasipaddress = '%{NAS-IP-Address}' AND acctstarttime <= UTC_TIMESTAMP()"
}
accounting-off {
query = "UPDATE radacct SET acctstoptime = UTC_TIMESTAMP(), acctsessiontime = UNIX_TIMESTAMP(UTC_TIMESTAMP()) - UNIX_TIMESTAMP(acctstarttime), acctterminatecause = '%{%{Acct-Terminate-Cause}:-NAS-Reboot}' WHERE acctstoptime IS NULL AND nasipaddress = '%{NAS-IP-Address}' AND acctstarttime <= UTC_TIMESTAMP()"
}
start {
query = "INSERT INTO radacct (acctsessionid, acctuniqueid, username, realm, nasipaddress, nasportid, nasporttype, acctstarttime, acctupdatetime, acctstoptime, acctsessiontime, acctauthentic, connectinfo_start, connectinfo_stop, acctinputoctets, acctoutputoctets, calledstationid, callingstationid, acctterminatecause, servicetype, framedprotocol, framedipaddress, framedipv6prefix, delegatedipv6prefix) VALUES ('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm}', '%{NAS-IP-Address}', '%{%{NAS-Port-ID}:-%{NAS-Port}}', '%{NAS-Port-Type}', UTC_TIMESTAMP(), UTC_TIMESTAMP(), NULL, '0', '%{Acct-Authentic}', '%{Connect-Info}', '', '0', '0', '%{Called-Station-Id}', '%{Calling-Station-Id}', '', '%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}', '%{Framed-IPv6-Prefix}', '%{Delegated-IPv6-Prefix}')"
}
interim-update {
query = "UPDATE radacct SET acctupdatetime = (@acctupdatetime_old:=acctupdatetime), acctupdatetime = UTC_TIMESTAMP(), acctinterval = UNIX_TIMESTAMP(UTC_TIMESTAMP()) - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '%{Framed-IP-Address}', acctsessiontime = %{%{Acct-Session-Time}:-NULL}, acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}', framedipv6prefix = '%{Framed-IPv6-Prefix}', delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', acctstoptime = NULL WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}' OR AcctUniqueId = '%{Segundo-AcctUnique-Id}' OR AcctUniqueId = '%{Terceiro-AcctUnique-Id}'"
}
stop {
query = "UPDATE radacct SET acctstoptime = UTC_TIMESTAMP(), acctsessiontime = %{%{Acct-Session-Time}:-NULL}, acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}', acctterminatecause = '%{Acct-Terminate-Cause}', connectinfo_stop = '%{Connect-Info}' WHERE acctsessionid = '%{Acct-Session-Id}' AND username = '%{SQL-User-Name}' AND nasipaddress = '%{NAS-IP-Address}'"
}
}
}
post-auth {
reference = ".query"
query = "INSERT INTO radpostauth (username, pass, reply, authdate, nasipaddress, callingstationid) VALUES ( '%{SQL-User-Name}', '%{%{User-Password}:-%{Chap-Password}}', '%{reply:Packet-Type}', UTC_TIMESTAMP(), '%{NAS-IP-Address}', '%{Calling-Station-Id}')"
}
}
rlm_sql (sql): Driver rlm_sql_mysql (module rlm_sql_mysql) loaded and linked
Creating attribute SQL-Group
# Loaded module rlm_sqlippool
# Loading module "sqlippool" from file /etc/freeradius/3.0/mods-enabled/sqlippool
sqlippool {
sql_module_instance = "sql"
lease_duration = 3600
pool_name = ""
default_pool = "main_pool"
ipv6 = yes
allocate_begin = "START TRANSACTION"
allocate_clear = "UPDATE radippool SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE expiry_time <= UTC_TIMESTAMP() - INTERVAL 1 SECOND AND nasipaddress = '%{Nas-IP-Address}'"
allocate_find = "SELECT framedipaddress FROM radippool WHERE pool_name = '%{control:Pool-Name}' AND (expiry_time < UTC_TIMESTAMP() OR expiry_time IS NULL) AND banned = 0 ORDER BY (username <> '%{User-Name}'), (callingstationid <> '%{Calling-Station-Id}'), expiry_time LIMIT 1 FOR UPDATE"
allocate_update = "UPDATE radippool SET nasipaddress = '%{NAS-IP-Address}', pool_key = '%{NAS-Port}', callingstationid = '%{Calling-Station-Id}', username = '%{User-Name}', expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE framedipaddress = '%I' AND expiry_time IS NULL"
allocate_commit = "COMMIT"
pool_check = "SELECT id FROM radippool WHERE pool_name='%{control:Pool-Name}' LIMIT 1"
start_begin = "START TRANSACTION"
start_update = "UPDATE radippool SET expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE nasipaddress = '%{NAS-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IP-Address}'"
start_commit = "COMMIT"
alive_begin = "START TRANSACTION"
alive_update = "UPDATE radippool SET expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE nasipaddress = '%{Nas-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IP-Address}'"
alive_commit = "COMMIT"
stop_begin = "START TRANSACTION"
stop_clear = "UPDATE radippool SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IP-Address}'"
stop_commit = "COMMIT"
on_begin = "START TRANSACTION"
on_clear = "UPDATE radippool SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}'"
on_commit = "COMMIT"
off_begin = "START TRANSACTION"
off_clear = "UPDATE radippool SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}'"
off_commit = "COMMIT"
messages {
exists = "Existing IP: %{reply:Framed-IP-Address} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
success = "Allocated IP: %{reply:Framed-IP-Address} from %{control:Pool-Name} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
clear = "Released IP %{Framed-IP-Address} (did %{Called-Station-Id} cli %{Calling-Station-Id} user %{User-Name})"
failed = "IP Allocation FAILED from %{control:Pool-Name} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
nopool = "No Pool-Name defined (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
}
}
# Loading module "sqlippool_v4" from file /etc/freeradius/3.0/mods-enabled/sqlippool_v4
sqlippool sqlippool_v4 {
sql_module_instance = "sql"
lease_duration = 3600
pool_name = ""
default_pool = "main_pool"
allocate_begin = "START TRANSACTION"
allocate_clear = "UPDATE radippool SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE expiry_time <= UTC_TIMESTAMP() - INTERVAL 1 SECOND AND nasipaddress = '%{Nas-IP-Address}'"
allocate_find = "SELECT framedipaddress FROM radippool WHERE pool_name = '%{control:Pool-Name}' AND (expiry_time < UTC_TIMESTAMP() OR expiry_time IS NULL) AND banned = 0 ORDER BY (username <> '%{User-Name}'), (callingstationid <> '%{Calling-Station-Id}'), expiry_time LIMIT 1 FOR UPDATE"
allocate_update = "UPDATE radippool SET nasipaddress = '%{NAS-IP-Address}', pool_key = '%{NAS-Port}', callingstationid = '%{Calling-Station-Id}', username = '%{User-Name}', expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE framedipaddress = '%I' AND expiry_time IS NULL"
allocate_commit = "COMMIT"
pool_check = "SELECT id FROM radippool WHERE pool_name='%{control:Pool-Name}' LIMIT 1"
start_begin = "START TRANSACTION"
start_update = "UPDATE radippool SET expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE nasipaddress = '%{NAS-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IP-Address}'"
start_commit = "COMMIT"
alive_begin = "START TRANSACTION"
alive_update = "UPDATE radippool SET expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE nasipaddress = '%{Nas-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IP-Address}'"
alive_commit = "COMMIT"
stop_begin = "START TRANSACTION"
stop_clear = "UPDATE radippool SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IP-Address}'"
stop_commit = "COMMIT"
on_begin = "START TRANSACTION"
on_clear = "UPDATE radippool SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}'"
on_commit = "COMMIT"
off_begin = "START TRANSACTION"
off_clear = "UPDATE radippool SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}'"
off_commit = "COMMIT"
messages {
exists = "Existing IP: %{reply:Framed-IP-Address} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
success = "Allocated IP: %{reply:Framed-IP-Address} from %{control:Pool-Name} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
clear = "Released IP %{Framed-IP-Address} (did %{Called-Station-Id} cli %{Calling-Station-Id} user %{User-Name})"
failed = "IP Allocation FAILED from %{control:Pool-Name} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
nopool = "No Pool-Name defined (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
}
}
# Loading module "sqlippool_v6" from file /etc/freeradius/3.0/mods-enabled/sqlippool_v6
sqlippool sqlippool_v6 {
sql_module_instance = "sql"
lease_duration = 3600
pool_name = ""
default_pool = "main_pool"
ipv6 = yes
allocate_begin = "START TRANSACTION"
allocate_clear = "UPDATE radippoolv6 SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE expiry_time <= UTC_TIMESTAMP() - INTERVAL 1 SECOND AND nasipaddress = '%{Nas-IP-Address}'"
allocate_find = "SELECT framedipaddress FROM radippoolv6 WHERE pool_name = '%{control:Pool-Name}' AND (expiry_time < UTC_TIMESTAMP() OR expiry_time IS NULL) ORDER BY (username <> '%{User-Name}'), (callingstationid <> '%{Calling-Station-Id}'), expiry_time LIMIT 1 FOR UPDATE"
allocate_update = "UPDATE radippoolv6 SET nasipaddress = '%{NAS-IP-Address}', pool_key = '%{NAS-Port}', callingstationid = '%{Calling-Station-Id}', username = '%{User-Name}', expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE framedipaddress = '%I' AND expiry_time IS NULL"
allocate_commit = "COMMIT"
pool_check = "SELECT id FROM radippoolv6 WHERE pool_name='%{control:Pool-Name}' LIMIT 1"
start_begin = "START TRANSACTION"
start_update = "UPDATE radippoolv6 SET expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE nasipaddress = '%{NAS-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IPv6-Prefix}'"
start_commit = "COMMIT"
alive_begin = "START TRANSACTION"
alive_update = "UPDATE radippoolv6 SET expiry_time = UTC_TIMESTAMP() + INTERVAL 3600 SECOND WHERE nasipaddress = '%{Nas-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IPv6-Prefix}'"
alive_commit = "COMMIT"
stop_begin = "START TRANSACTION"
stop_clear = "UPDATE radippoolv6 SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}' AND pool_key = '%{NAS-Port}' AND username = '%{User-Name}' AND callingstationid = '%{Calling-Station-Id}' AND framedipaddress = '%{Framed-IPv6-Prefix}'"
stop_commit = "COMMIT"
on_begin = "START TRANSACTION"
on_clear = "UPDATE radippoolv6 SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}'"
on_commit = "COMMIT"
off_begin = "START TRANSACTION"
off_clear = "UPDATE radippoolv6 SET nasipaddress = '', pool_key = 0, callingstationid = '', username = '', expiry_time = NULL WHERE nasipaddress = '%{Nas-IP-Address}'"
off_commit = "COMMIT"
messages {
exists = "Existing IP: %{reply:Framed-IP-Address} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
success = "Allocated IP: %{reply:Framed-IP-Address} from %{control:Pool-Name} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
clear = "Released IP %{Framed-IP-Address} (did %{Called-Station-Id} cli %{Calling-Station-Id} user %{User-Name})"
failed = "IP Allocation FAILED from %{control:Pool-Name} (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
nopool = "No Pool-Name defined (did %{Called-Station-Id} cli %{Calling-Station-Id} port %{NAS-Port} user %{User-Name})"
}
}
# Loading module "sradutmp" from file /etc/freeradius/3.0/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/freeradius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_unix
# Loading module "unix" from file /etc/freeradius/3.0/mods-enabled/unix
unix {
radwtmp = "/var/log/freeradius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_unpack
# Loading module "unpack" from file /etc/freeradius/3.0/mods-enabled/unpack
# Loaded module rlm_utf8
# Loading module "utf8" from file /etc/freeradius/3.0/mods-enabled/utf8
# Loaded module rlm_eap
# Loading module "eap" from file /etc/freeradius/3.0/mods-enabled/eap
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
instantiate {
}
# Instantiating module "reject" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "fail" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "ok" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "handled" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "invalid" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "userlock" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "notfound" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "noop" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "updated" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "attr_filter.post-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/access_reject
[/etc/freeradius/3.0/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay" found in filter list for realm "DEFAULT".
[/etc/freeradius/3.0/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay-USec" found in filter list for realm "DEFAULT".
# Instantiating module "attr_filter.access_challenge" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/accounting_response
# Instantiating module "cache_eap" from file /etc/freeradius/3.0/mods-enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module rlm_cache_rbtree) loaded and linked
# Instantiating module "detail" from file /etc/freeradius/3.0/mods-enabled/detail
# Instantiating module "auth_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output
# Instantiating module "reply_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "pre_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "expiration" from file /etc/freeradius/3.0/mods-enabled/expiration
# Instantiating module "files" from file /etc/freeradius/3.0/mods-enabled/files
reading pairlist file /etc/freeradius/3.0/mods-config/files/authorize
reading pairlist file /etc/freeradius/3.0/mods-config/files/accounting
reading pairlist file /etc/freeradius/3.0/mods-config/files/pre-proxy
# Instantiating module "linelog" from file /etc/freeradius/3.0/mods-enabled/linelog
# Instantiating module "log_accounting" from file /etc/freeradius/3.0/mods-enabled/linelog
# Instantiating module "logintime" from file /etc/freeradius/3.0/mods-enabled/logintime
# Instantiating module "mschap" from file /etc/freeradius/3.0/mods-enabled/mschap
rlm_mschap (mschap): using internal authentication
# Instantiating module "pap" from file /etc/freeradius/3.0/mods-enabled/pap
# Instantiating module "etc_passwd" from file /etc/freeradius/3.0/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "preprocess" from file /etc/freeradius/3.0/mods-enabled/preprocess
reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/huntgroups
reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/hints
# Instantiating module "IPASS" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "suffix" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "realmpercent" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "ntdomain" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "sql" from file /etc/freeradius/3.0/mods-enabled/sql
rlm_sql_mysql: libmysql version: 5.7.25
mysql {
tls {
}
warnings = "auto"
}
rlm_sql (sql): Attempting to connect to database "radius"
rlm_sql (sql): Initialising connection pool
pool {
start = 5
min = 3
max = 32
spare = 10
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 30
spread = no
}
rlm_sql (sql): Opening additional connection (0), 1 of 32 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
rlm_sql (sql): Opening additional connection (1), 1 of 31 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
rlm_sql (sql): Opening additional connection (2), 1 of 30 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
rlm_sql (sql): Opening additional connection (3), 1 of 29 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
rlm_sql (sql): Opening additional connection (4), 1 of 28 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
rlm_sql (sql): Processing generate_sql_clients
rlm_sql (sql) in generate_sql_clients: query is SELECT id, nasname, shortname, type, secret, server FROM nas
rlm_sql (sql): Reserved connection (0)
rlm_sql (sql): Executing select query: SELECT id, nasname, shortname, type, secret, server FROM nas
rlm_sql (sql): Adding client 172.18.0.2 (teste) to global clients list
rlm_sql (172.18.0.2): Client "teste" (sql) added
rlm_sql (sql): Adding client 192.168.1.21 (radio) to global clients list
rlm_sql (192.168.1.21): Client "radio" (sql) added
rlm_sql (sql): Released connection (0)
Need 5 more connections to reach 10 spares
rlm_sql (sql): Opening additional connection (5), 1 of 27 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
# Instantiating module "sqlippool" from file /etc/freeradius/3.0/mods-enabled/sqlippool
# Instantiating module "sqlippool_v4" from file /etc/freeradius/3.0/mods-enabled/sqlippool_v4
# Instantiating module "sqlippool_v6" from file /etc/freeradius/3.0/mods-enabled/sqlippool_v6
# Instantiating module "eap" from file /etc/freeradius/3.0/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/freeradius/3.0/certs"
pem_file_type = yes
private_key_file = "/etc/ssl/private/ssl-cert-snakeoil.key"
certificate_file = "/etc/ssl/certs/ssl-cert-snakeoil.pem"
ca_file = "/etc/ssl/certs/ca-certificates.crt"
private_key_password = <<< secret >>>
dh_file = "/etc/freeradius/3.0/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
ecdh_curve = "prime256v1"
tls_max_version = ""
tls_min_version = "1.0"
cache {
enable = yes
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/freeradius/3.0/radiusd.conf
} # server
server default { # from file /etc/freeradius/3.0/sites-enabled/default
# Loading authenticate {...}
# Loading authorize {...}
# Loading preacct {...}
# Loading accounting {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server default
server inner-tunnel { # from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
Ignoring "ldap" (see raddb/mods-available/README.rst)
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server inner-tunnel
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Listening on proxy address * port 51633
Listening on proxy address :: port 34439
Ready to process requests
(0) Received Access-Request Id 24 from 192.168.1.21:51630 to 172.18.0.1:1812 length 212
(0) User-Name = "anonymous(a)myisp.com"
(0) NAS-Identifier = "NanoStation loco M5"
(0) Called-Station-Id = "24-A4-3C-88-F3-94:ubntxxx"
(0) NAS-Port-Type = Wireless-802.11
(0) NAS-Port = 0
(0) Calling-Station-Id = "00-27-22-A2-07-C5"
(0) Connect-Info = "CONNECT 0Mbps 802.11b"
(0) Acct-Session-Id = "5B05AE57-00001E37"
(0) Framed-MTU = 1400
(0) EAP-Message = 0x0255001801616e6f6e796d6f7573406d796973702e636f6d
(0) Message-Authenticator = 0xd882609ef53a3a6c32afb21915dfc072
(0) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(0) authorize {
(0) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) {
(0) EXPAND %{Cisco-AVPair[*]}
(0) -->
(0) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) -> FALSE
(0) elsif (ERX-Dhcp-Mac-Addr =~ /^([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9])$/) {
(0) ERROR: Failed retrieving values required to evaluate condition
(0) else {
(0) update request {
(0) EXPAND %{toupper:%{Calling-Station-Id}}
(0) --> 00-27-22-A2-07-C5
(0) Calling-Station-Id := 00-27-22-A2-07-C5
(0) } # update request = noop
(0) } # else = noop
(0) if (!control:Cleartext-Password){
(0) if (!control:Cleartext-Password) -> TRUE
(0) (!control:Cleartext-Password) { ... } # empty sub-section is ignored
(0) [preprocess] = ok
(0) [chap] = noop
(0) [mschap] = noop
(0) eap: Peer sent EAP Response (code 2) ID 85 length 24
(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(0) [eap] = ok
(0) sql: EXPAND %{User-Name}
(0) sql: --> anonymous(a)myisp.com
(0) sql: SQL-User-Name set to 'anonymous(a)myisp.com'
rlm_sql (sql): Reserved connection (1)
(0) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(0) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(0) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(0) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(0) sql: --> SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(0) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(0) sql: User not found in any groups
rlm_sql (sql): Released connection (1)
Need 4 more connections to reach 10 spares
rlm_sql (sql): Opening additional connection (6), 1 of 26 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
(0) [sql] = notfound
(0) pap: WARNING: No "known good" password found for the user. Not setting Auth-Type
(0) pap: WARNING: Authentication will fail unless a "known good" password is available
(0) [pap] = noop
(0) } # authorize = ok
(0) Found Auth-Type = eap
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(0) authenticate {
(0) eap: Peer sent packet with method EAP Identity (1)
(0) eap: Calling submodule eap_md5 to process data
(0) eap_md5: Issuing MD5 Challenge
(0) eap: Sending EAP Request (code 1) ID 86 length 22
(0) eap: EAP session adding &reply:State = 0xfee3d417feb5d0f5
(0) [eap] = handled
(0) } # authenticate = handled
(0) Using Post-Auth-Type Challenge
(0) Post-Auth-Type sub-section not found. Ignoring.
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(0) Sent Access-Challenge Id 24 from 172.18.0.1:1812 to 192.168.1.21:51630 length 0
(0) EAP-Message = 0x0156001604103959bae31c3ad8c88e8161aca2f9895a
(0) Message-Authenticator = 0x00000000000000000000000000000000
(0) State = 0xfee3d417feb5d0f59e169eb3f2762e68
(0) Finished request
Waking up in 4.9 seconds.
(1) Received Access-Request Id 25 from 192.168.1.21:51630 to 172.18.0.1:1812 length 212
(1) User-Name = "anonymous(a)myisp.com"
(1) NAS-Identifier = "NanoStation loco M5"
(1) Called-Station-Id = "24-A4-3C-88-F3-94:ubntxxx"
(1) NAS-Port-Type = Wireless-802.11
(1) NAS-Port = 0
(1) Calling-Station-Id = "00-27-22-A2-07-C5"
(1) Connect-Info = "CONNECT 0Mbps 802.11b"
(1) Acct-Session-Id = "5B05AE57-00001E37"
(1) Framed-MTU = 1400
(1) EAP-Message = 0x025600060315
(1) State = 0xfee3d417feb5d0f59e169eb3f2762e68
(1) Message-Authenticator = 0xebeac517405cf78a9d8e9e78deaf7759
(1) session-state: No cached attributes
(1) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(1) authorize {
(1) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) {
(1) EXPAND %{Cisco-AVPair[*]}
(1) -->
(1) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) -> FALSE
(1) elsif (ERX-Dhcp-Mac-Addr =~ /^([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9])$/) {
(1) ERROR: Failed retrieving values required to evaluate condition
(1) else {
(1) update request {
(1) EXPAND %{toupper:%{Calling-Station-Id}}
(1) --> 00-27-22-A2-07-C5
(1) Calling-Station-Id := 00-27-22-A2-07-C5
(1) } # update request = noop
(1) } # else = noop
(1) if (!control:Cleartext-Password){
(1) if (!control:Cleartext-Password) -> TRUE
(1) (!control:Cleartext-Password) { ... } # empty sub-section is ignored
(1) [preprocess] = ok
(1) [chap] = noop
(1) [mschap] = noop
(1) eap: Peer sent EAP Response (code 2) ID 86 length 6
(1) eap: No EAP Start, assuming it's an on-going EAP conversation
(1) [eap] = updated
(1) sql: EXPAND %{User-Name}
(1) sql: --> anonymous(a)myisp.com
(1) sql: SQL-User-Name set to 'anonymous(a)myisp.com'
rlm_sql (sql): Reserved connection (2)
(1) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(1) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(1) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(1) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(1) sql: --> SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(1) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(1) sql: User not found in any groups
rlm_sql (sql): Released connection (2)
(1) [sql] = notfound
(1) pap: WARNING: No "known good" password found for the user. Not setting Auth-Type
(1) pap: WARNING: Authentication will fail unless a "known good" password is available
(1) [pap] = noop
(1) } # authorize = updated
(1) Found Auth-Type = eap
(1) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(1) authenticate {
(1) eap: Expiring EAP session with state 0xfee3d417feb5d0f5
(1) eap: Finished EAP session with state 0xfee3d417feb5d0f5
(1) eap: Previous EAP request found for state 0xfee3d417feb5d0f5, released from the list
(1) eap: Peer sent packet with method EAP NAK (3)
(1) eap: Found mutually acceptable type TTLS (21)
(1) eap: Calling submodule eap_ttls to process data
(1) eap_ttls: Initiating new EAP-TLS session
(1) eap_ttls: [eaptls start] = request
(1) eap: Sending EAP Request (code 1) ID 87 length 6
(1) eap: EAP session adding &reply:State = 0xfee3d417ffb4c1f5
(1) [eap] = handled
(1) } # authenticate = handled
(1) Using Post-Auth-Type Challenge
(1) Post-Auth-Type sub-section not found. Ignoring.
(1) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(1) Sent Access-Challenge Id 25 from 172.18.0.1:1812 to 192.168.1.21:51630 length 0
(1) EAP-Message = 0x015700061520
(1) Message-Authenticator = 0x00000000000000000000000000000000
(1) State = 0xfee3d417ffb4c1f59e169eb3f2762e68
(1) Finished request
Waking up in 4.8 seconds.
(2) Received Access-Request Id 26 from 192.168.1.21:51630 to 172.18.0.1:1812 length 274
(2) User-Name = "anonymous(a)myisp.com"
(2) NAS-Identifier = "NanoStation loco M5"
(2) Called-Station-Id = "24-A4-3C-88-F3-94:ubntxxx"
(2) NAS-Port-Type = Wireless-802.11
(2) NAS-Port = 0
(2) Calling-Station-Id = "00-27-22-A2-07-C5"
(2) Connect-Info = "CONNECT 0Mbps 802.11b"
(2) Acct-Session-Id = "5B05AE57-00001E37"
(2) Framed-MTU = 1400
(2) EAP-Message = 0x02570044150016030100390100003503015b06a5552d61e921482136f319e46b1b0c351aacfda8ba971a4c94c17466a0ba00000e003d0035003c002f000a000500040100
(2) State = 0xfee3d417ffb4c1f59e169eb3f2762e68
(2) Message-Authenticator = 0xec2de8307b1a35a8a71d04903e4b656a
(2) session-state: No cached attributes
(2) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(2) authorize {
(2) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) {
(2) EXPAND %{Cisco-AVPair[*]}
(2) -->
(2) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) -> FALSE
(2) elsif (ERX-Dhcp-Mac-Addr =~ /^([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9])$/) {
(2) ERROR: Failed retrieving values required to evaluate condition
(2) else {
(2) update request {
(2) EXPAND %{toupper:%{Calling-Station-Id}}
(2) --> 00-27-22-A2-07-C5
(2) Calling-Station-Id := 00-27-22-A2-07-C5
(2) } # update request = noop
(2) } # else = noop
(2) if (!control:Cleartext-Password){
(2) if (!control:Cleartext-Password) -> TRUE
(2) (!control:Cleartext-Password) { ... } # empty sub-section is ignored
(2) [preprocess] = ok
(2) [chap] = noop
(2) [mschap] = noop
(2) eap: Peer sent EAP Response (code 2) ID 87 length 68
(2) eap: Continuing tunnel setup
(2) [eap] = ok
(2) sql: EXPAND %{User-Name}
(2) sql: --> anonymous(a)myisp.com
(2) sql: SQL-User-Name set to 'anonymous(a)myisp.com'
rlm_sql (sql): Reserved connection (3)
(2) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(2) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(2) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(2) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(2) sql: --> SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(2) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(2) sql: User not found in any groups
rlm_sql (sql): Released connection (3)
(2) [sql] = notfound
(2) [pap] = noop
(2) } # authorize = ok
(2) Found Auth-Type = eap
(2) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(2) authenticate {
(2) eap: Expiring EAP session with state 0xfee3d417ffb4c1f5
(2) eap: Finished EAP session with state 0xfee3d417ffb4c1f5
(2) eap: Previous EAP request found for state 0xfee3d417ffb4c1f5, released from the list
(2) eap: Peer sent packet with method EAP TTLS (21)
(2) eap: Calling submodule eap_ttls to process data
(2) eap_ttls: Authenticate
(2) eap_ttls: Continuing EAP-TLS
(2) eap_ttls: [eaptls verify] = ok
(2) eap_ttls: Done initial handshake
(2) eap_ttls: (other): before SSL initialization
(2) eap_ttls: TLS_accept: before SSL initialization
(2) eap_ttls: TLS_accept: before SSL initialization
(2) eap_ttls: <<< recv TLS 1.2 [length 0039]
(2) eap_ttls: TLS_accept: SSLv3/TLS read client hello
(2) eap_ttls: >>> send TLS 1.0 Handshake [length 002a], ServerHello
(2) eap_ttls: TLS_accept: SSLv3/TLS write server hello
(2) eap_ttls: >>> send TLS 1.0 Handshake [length 02e5], Certificate
(2) eap_ttls: TLS_accept: SSLv3/TLS write certificate
(2) eap_ttls: >>> send TLS 1.0 Handshake [length 0004], ServerHelloDone
(2) eap_ttls: TLS_accept: SSLv3/TLS write server done
(2) eap_ttls: TLS_accept: Need to read more data: SSLv3/TLS write server done
(2) eap_ttls: In SSL Handshake Phase
(2) eap_ttls: In SSL Accept mode
(2) eap_ttls: [eaptls process] = handled
(2) eap: Sending EAP Request (code 1) ID 88 length 812
(2) eap: EAP session adding &reply:State = 0xfee3d417fcbbc1f5
(2) [eap] = handled
(2) } # authenticate = handled
(2) Using Post-Auth-Type Challenge
(2) Post-Auth-Type sub-section not found. Ignoring.
(2) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(2) Sent Access-Challenge Id 26 from 172.18.0.1:1812 to 192.168.1.21:51630 length 0
(2) EAP-Message = 0x0158032c158000000322160301002a0200002603012795f32c0527049fd37b3a15556d59374531a84298ffeb5b3318d7ec4d4997630000350016030102e50b0002e10002de0002db308202d7308201bfa003020102020900bcde151bf742f509300d06092a864886f70d01010b05003017311530130603
(2) Message-Authenticator = 0x00000000000000000000000000000000
(2) State = 0xfee3d417fcbbc1f59e169eb3f2762e68
(2) Finished request
Waking up in 4.6 seconds.
(3) Received Access-Request Id 27 from 192.168.1.21:51630 to 172.18.0.1:1812 length 540
(3) User-Name = "anonymous(a)myisp.com"
(3) NAS-Identifier = "NanoStation loco M5"
(3) Called-Station-Id = "24-A4-3C-88-F3-94:ubntxxx"
(3) NAS-Port-Type = Wireless-802.11
(3) NAS-Port = 0
(3) Calling-Station-Id = "00-27-22-A2-07-C5"
(3) Connect-Info = "CONNECT 0Mbps 802.11b"
(3) Acct-Session-Id = "5B05AE57-00001E37"
(3) Framed-MTU = 1400
(3) EAP-Message = 0x0258014c1500160301010610000102010068ca25a16af516561f95f2b966452099afdd99e736a185c4991a9e1a5412e3b2d234d1fda8ceec7d4bbb688eda83c5ec048360f234ec7ea0522548fafe71b7b648f45b30ea887f4004ab623115251df3cea9ee3bb81eeb5a9f870046ae74410df5fa6778b763
(3) State = 0xfee3d417fcbbc1f59e169eb3f2762e68
(3) Message-Authenticator = 0x2ea9059ed724879594a39da4565a8a8d
(3) session-state: No cached attributes
(3) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(3) authorize {
(3) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) {
(3) EXPAND %{Cisco-AVPair[*]}
(3) -->
(3) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) -> FALSE
(3) elsif (ERX-Dhcp-Mac-Addr =~ /^([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9])$/) {
(3) ERROR: Failed retrieving values required to evaluate condition
(3) else {
(3) update request {
(3) EXPAND %{toupper:%{Calling-Station-Id}}
(3) --> 00-27-22-A2-07-C5
(3) Calling-Station-Id := 00-27-22-A2-07-C5
(3) } # update request = noop
(3) } # else = noop
(3) if (!control:Cleartext-Password){
(3) if (!control:Cleartext-Password) -> TRUE
(3) (!control:Cleartext-Password) { ... } # empty sub-section is ignored
(3) [preprocess] = ok
(3) [chap] = noop
(3) [mschap] = noop
(3) eap: Peer sent EAP Response (code 2) ID 88 length 332
(3) eap: Continuing tunnel setup
(3) [eap] = ok
(3) sql: EXPAND %{User-Name}
(3) sql: --> anonymous(a)myisp.com
(3) sql: SQL-User-Name set to 'anonymous(a)myisp.com'
rlm_sql (sql): Reserved connection (4)
(3) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(3) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(3) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(3) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(3) sql: --> SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(3) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(3) sql: User not found in any groups
rlm_sql (sql): Released connection (4)
(3) [sql] = notfound
(3) [pap] = noop
(3) } # authorize = ok
(3) Found Auth-Type = eap
(3) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(3) authenticate {
(3) eap: Expiring EAP session with state 0xfee3d417fcbbc1f5
(3) eap: Finished EAP session with state 0xfee3d417fcbbc1f5
(3) eap: Previous EAP request found for state 0xfee3d417fcbbc1f5, released from the list
(3) eap: Peer sent packet with method EAP TTLS (21)
(3) eap: Calling submodule eap_ttls to process data
(3) eap_ttls: Authenticate
(3) eap_ttls: Continuing EAP-TLS
(3) eap_ttls: [eaptls verify] = ok
(3) eap_ttls: Done initial handshake
(3) eap_ttls: TLS_accept: SSLv3/TLS write server done
(3) eap_ttls: <<< recv TLS 1.0 Handshake [length 0106], ClientKeyExchange
(3) eap_ttls: TLS_accept: SSLv3/TLS read client key exchange
(3) eap_ttls: TLS_accept: SSLv3/TLS read change cipher spec
(3) eap_ttls: <<< recv TLS 1.0 Handshake [length 0010], Finished
(3) eap_ttls: TLS_accept: SSLv3/TLS read finished
(3) eap_ttls: >>> send TLS 1.0 ChangeCipherSpec [length 0001]
(3) eap_ttls: TLS_accept: SSLv3/TLS write change cipher spec
(3) eap_ttls: >>> send TLS 1.0 Handshake [length 0010], Finished
(3) eap_ttls: TLS_accept: SSLv3/TLS write finished
(3) eap_ttls: (other): SSL negotiation finished successfully
(3) eap_ttls: SSL Connection Established
(3) eap_ttls: [eaptls process] = handled
(3) eap: Sending EAP Request (code 1) ID 89 length 69
(3) eap: EAP session adding &reply:State = 0xfee3d417fdbac1f5
(3) [eap] = handled
(3) } # authenticate = handled
(3) Using Post-Auth-Type Challenge
(3) Post-Auth-Type sub-section not found. Ignoring.
(3) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(3) Sent Access-Challenge Id 27 from 172.18.0.1:1812 to 192.168.1.21:51630 length 0
(3) EAP-Message = 0x0159004515800000003b1403010001011603010030cd896000d31f05321d53db841d2ce9c057def717303b55ec79a61972cee9ef9b5a47c6abdbdcab2242e055fc913c88d2
(3) Message-Authenticator = 0x00000000000000000000000000000000
(3) State = 0xfee3d417fdbac1f59e169eb3f2762e68
(3) Finished request
Waking up in 4.3 seconds.
(4) Received Access-Request Id 28 from 192.168.1.21:51630 to 172.18.0.1:1812 length 361
(4) User-Name = "anonymous(a)myisp.com"
(4) NAS-Identifier = "NanoStation loco M5"
(4) Called-Station-Id = "24-A4-3C-88-F3-94:ubntxxx"
(4) NAS-Port-Type = Wireless-802.11
(4) NAS-Port = 0
(4) Calling-Station-Id = "00-27-22-A2-07-C5"
(4) Connect-Info = "CONNECT 0Mbps 802.11b"
(4) Acct-Session-Id = "5B05AE57-00001E37"
(4) Framed-MTU = 1400
(4) EAP-Message = 0x0259009b15001703010090ad86507970ec1f8873ed46c43aa73a782c9f5eb96775deadb32855fd714ee5ebcc7e5f2e073ea7113072c589b3081fc8070ed2cc480a0d53d55e9553cc0df6703ec7467240604695ee9992e44046a88284dd2624b7b328326414d4055494a2f3c198551b9e4edc7efe29975e
(4) State = 0xfee3d417fdbac1f59e169eb3f2762e68
(4) Message-Authenticator = 0x5acd22b6522a9e9abb4b194da86ecd29
(4) session-state: No cached attributes
(4) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(4) authorize {
(4) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) {
(4) EXPAND %{Cisco-AVPair[*]}
(4) -->
(4) if ("%{Cisco-AVPair[*]}" =~ /client-mac-address=(.*)/) -> FALSE
(4) elsif (ERX-Dhcp-Mac-Addr =~ /^([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9]).([a-f0-9][a-f0-9])([a-f0-9][a-f0-9])$/) {
(4) ERROR: Failed retrieving values required to evaluate condition
(4) else {
(4) update request {
(4) EXPAND %{toupper:%{Calling-Station-Id}}
(4) --> 00-27-22-A2-07-C5
(4) Calling-Station-Id := 00-27-22-A2-07-C5
(4) } # update request = noop
(4) } # else = noop
(4) if (!control:Cleartext-Password){
(4) if (!control:Cleartext-Password) -> TRUE
(4) (!control:Cleartext-Password) { ... } # empty sub-section is ignored
(4) [preprocess] = ok
(4) [chap] = noop
(4) [mschap] = noop
(4) eap: Peer sent EAP Response (code 2) ID 89 length 155
(4) eap: Continuing tunnel setup
(4) [eap] = ok
(4) sql: EXPAND %{User-Name}
(4) sql: --> anonymous(a)myisp.com
(4) sql: SQL-User-Name set to 'anonymous(a)myisp.com'
rlm_sql (sql): Reserved connection (0)
(4) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(4) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(4) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'anonymous(a)myisp.com' ORDER BY id
(4) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(4) sql: --> SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(4) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'anonymous(a)myisp.com' ORDER BY priority
(4) sql: User not found in any groups
rlm_sql (sql): Released connection (0)
Need 3 more connections to reach 10 spares
rlm_sql (sql): Opening additional connection (7), 1 of 25 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on 192.0.2.2 via TCP/IP, server version 5.7.18-log, protocol version 10
(4) [sql] = notfound
(4) [pap] = noop
(4) } # authorize = ok
(4) Found Auth-Type = eap
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(4) authenticate {
(4) eap: Expiring EAP session with state 0xfee3d417fdbac1f5
(4) eap: Finished EAP session with state 0xfee3d417fdbac1f5
(4) eap: Previous EAP request found for state 0xfee3d417fdbac1f5, released from the list
(4) eap: Peer sent packet with method EAP TTLS (21)
(4) eap: Calling submodule eap_ttls to process data
(4) eap_ttls: Authenticate
(4) eap_ttls: Continuing EAP-TLS
(4) eap_ttls: [eaptls verify] = ok
(4) eap_ttls: Done initial handshake
(4) eap_ttls: [eaptls process] = ok
(4) eap_ttls: Session established. Proceeding to decode tunneled attributes
(4) eap_ttls: Got tunneled request
(4) eap_ttls: User-Name = "mmd13"
(4) eap_ttls: MS-CHAP-Challenge = 0xa37e37c4f224a5db18cfe440f3fb3e0d
(4) eap_ttls: MS-CHAP2-Response = 0xb300134ddddfb343576a18a0db14877dea13000000000000000079f8618ac9de53a897d7875aefbdcb74c8fcb186761d050c
(4) eap_ttls: FreeRADIUS-Proxied-To = 127.0.0.1
(4) eap_ttls: Sending tunneled request
(4) Virtual server inner-tunnel received request
(4) User-Name = "mmd13"
(4) MS-CHAP-Challenge = 0xa37e37c4f224a5db18cfe440f3fb3e0d
(4) MS-CHAP2-Response = 0xb300134ddddfb343576a18a0db14877dea13000000000000000079f8618ac9de53a897d7875aefbdcb74c8fcb186761d050c
(4) FreeRADIUS-Proxied-To = 127.0.0.1
(4) server inner-tunnel {
(4) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(4) authorize {
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) } # if (&User-Name) = notfound
(4) } # policy filter_username = notfound
(4) [chap] = noop
(4) mschap: Found MS-CHAP attributes. Setting 'Auth-Type = mschap'
(4) [mschap] = ok
(4) suffix: Checking for suffix after "@"
(4) suffix: No '@' in User-Name = "mmd13", looking up realm NULL
(4) suffix: No such realm "NULL"
(4) [suffix] = noop
(4) update control {
(4) &Proxy-To-Realm := LOCAL
(4) } # update control = noop
(4) eap: No EAP-Message, not doing EAP
(4) [eap] = noop
(4) [files] = noop
(4) sql: EXPAND %{User-Name}
(4) sql: --> mmd13
(4) sql: SQL-User-Name set to 'mmd13'
rlm_sql (sql): Reserved connection (5)
(4) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(4) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'mmd13' ORDER BY id
(4) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'mmd13' ORDER BY id
(4) sql: User found in radcheck table
(4) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(4) sql: --> SELECT groupname FROM radusergroup WHERE username = 'mmd13' ORDER BY priority
(4) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'mmd13' ORDER BY priority
(4) sql: User found in the group table
(4) sql: EXPAND SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '%{SQL-Group}' ORDER BY id
(4) sql: --> SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '105' ORDER BY id
(4) sql: Executing select query: SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '105' ORDER BY id
(4) sql: Group "105": Conditional check items matched
(4) sql: Group "105": Merging assignment check items
(4) sql: Simultaneous-Use := 1
(4) sql: EXPAND SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '%{SQL-Group}' ORDER BY id
(4) sql: --> SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '105' ORDER BY id
(4) sql: Executing select query: SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '105' ORDER BY id
(4) sql: Group "105": Merging reply items
(4) sql: Mikrotik-Rate-Limit = "35840k/71680k 0k/0k 0k/0k 0/0 5 35840k/71680k "
(4) sql: WISPr-Bandwidth-Max-Down = 71680000
(4) sql: WISPr-Bandwidth-Max-Up = 35840000
rlm_sql (sql): Released connection (5)
(4) [sql] = ok
(4) [expiration] = noop
(4) [logintime] = noop
(4) [pap] = noop
(4) } # authorize = ok
(4) Found Auth-Type = mschap
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(4) authenticate {
(4) mschap: WARNING: No Cleartext-Password configured. Cannot create NT-Password
(4) mschap: WARNING: No Cleartext-Password configured. Cannot create LM-Password
(4) mschap: Creating challenge hash with username: mmd13
(4) mschap: Client is using MS-CHAPv2
(4) mschap: ERROR: FAILED: No NT/LM-Password. Cannot perform authentication
(4) mschap: ERROR: MS-CHAP2-Response is incorrect
(4) [mschap] = reject
(4) } # authenticate = reject
(4) Failed to authenticate the user
(4) Using Post-Auth-Type Reject
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(4) Post-Auth-Type REJECT {
(4) sql: EXPAND .query
(4) sql: --> .query
(4) sql: Using query template 'query'
rlm_sql (sql): Reserved connection (1)
(4) sql: EXPAND %{User-Name}
(4) sql: --> mmd13
(4) sql: SQL-User-Name set to 'mmd13'
(4) sql: EXPAND INSERT INTO radpostauth (username, pass, reply, authdate, nasipaddress, callingstationid) VALUES ( '%{SQL-User-Name}', '%{%{User-Password}:-%{Chap-Password}}', '%{reply:Packet-Type}', UTC_TIMESTAMP(), '%{NAS-IP-Address}', '%{Calling-Station-Id}')
(4) sql: --> INSERT INTO radpostauth (username, pass, reply, authdate, nasipaddress, callingstationid) VALUES ( 'mmd13', '', 'Access-Reject', UTC_TIMESTAMP(), '', '')
(4) sql: Executing query: INSERT INTO radpostauth (username, pass, reply, authdate, nasipaddress, callingstationid) VALUES ( 'mmd13', '', 'Access-Reject', UTC_TIMESTAMP(), '', '')
(4) sql: SQL query returned: success
(4) sql: 1 record(s) updated
rlm_sql (sql): Released connection (1)
(4) [sql] = ok
(4) attr_filter.access_reject: EXPAND %{User-Name}
(4) attr_filter.access_reject: --> mmd13
(4) attr_filter.access_reject: Matched entry DEFAULT at line 11
(4) [attr_filter.access_reject] = updated
(4) update outer.session-state {
(4) &Module-Failure-Message := &request:Module-Failure-Message -> 'mschap: FAILED: No NT/LM-Password. Cannot perform authentication'
(4) } # update outer.session-state = noop
(4) } # Post-Auth-Type REJECT = updated
(4) } # server inner-tunnel
(4) Virtual server sending reply
(4) MS-CHAP-Error = "\263E=691 R=1 C=3e0e75d6ae9bd3607f8fa1bb71a1ef9e V=3 M=Authentication rejected"
(4) eap_ttls: Got tunneled Access-Reject
(4) eap: ERROR: Failed continuing EAP TTLS (21) session. EAP sub-module failed
(4) eap: Sending EAP Failure (code 4) ID 89 length 4
(4) eap: Failed in EAP select
(4) [eap] = invalid
(4) } # authenticate = invalid
(4) Failed to authenticate the user
(4) Using Post-Auth-Type Reject
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(4) Post-Auth-Type REJECT {
(4) sql: EXPAND .query
(4) sql: --> .query
(4) sql: Using query template 'query'
rlm_sql (sql): Reserved connection (6)
(4) sql: EXPAND %{User-Name}
(4) sql: --> anonymous(a)myisp.com
(4) sql: SQL-User-Name set to 'anonymous(a)myisp.com'
(4) sql: EXPAND INSERT INTO radpostauth (username, pass, reply, authdate, nasipaddress, callingstationid) VALUES ( '%{SQL-User-Name}', '%{%{User-Password}:-%{Chap-Password}}', '%{reply:Packet-Type}', UTC_TIMESTAMP(), '%{NAS-IP-Address}', '%{Calling-Station-Id}')
(4) sql: --> INSERT INTO radpostauth (username, pass, reply, authdate, nasipaddress, callingstationid) VALUES ( 'anonymous(a)myisp.com', '', 'Access-Reject', UTC_TIMESTAMP(), '192.168.1.21', '00-27-22-A2-07-C5')
(4) sql: Executing query: INSERT INTO radpostauth (username, pass, reply, authdate, nasipaddress, callingstationid) VALUES ( 'anonymous(a)myisp.com', '', 'Access-Reject', UTC_TIMESTAMP(), '192.168.1.21', '00-27-22-A2-07-C5')
(4) sql: SQL query returned: success
(4) sql: 1 record(s) updated
rlm_sql (sql): Released connection (6)
(4) [sql] = ok
(4) attr_filter.access_reject: EXPAND %{User-Name}
(4) attr_filter.access_reject: --> anonymous(a)myisp.com
(4) attr_filter.access_reject: Matched entry DEFAULT at line 11
(4) [attr_filter.access_reject] = updated
(4) [eap] = noop
(4) policy remove_reply_message_if_eap {
(4) if (&reply:EAP-Message && &reply:Reply-Message) {
(4) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(4) else {
(4) [noop] = noop
(4) } # else = noop
(4) } # policy remove_reply_message_if_eap = noop
(4) } # Post-Auth-Type REJECT = updated
(4) Delaying response for 1.000000 seconds
Waking up in 0.2 seconds.
Waking up in 0.7 seconds.
(4) Sending delayed response
(4) Sent Access-Reject Id 28 from 172.18.0.1:1812 to 192.168.1.21:51630 length 44
(4) EAP-Message = 0x04590004
(4) Message-Authenticator = 0x00000000000000000000000000000000
2
1
Hi,
since the update from 3.0.19 to 3.0.22 we have problems with our clients
configured using sql. They get ignored by the virtual servers.
Adding to the global list seems to work fine:
rlm_sql (sql): Adding client 127.0.0.2 (testclient) to global clients list
rlm_sql (127.0.0.2): Client "testclient" (sql) added
rlm_sql (sql): Adding client 127.0.0.3 (testclient) to global clients list
rlm_sql (127.0.0.3): Client "testclient" (sql) added
rlm_sql (sql): Adding client 127.0.0.4 (testclient) to global clients list
rlm_sql (127.0.0.4): Client "testclient" (sql) added
But the request of these clients are ignored:
Ignoring request to auth address * port 1812 bound to server default
from unknown client 127.0.0.4 port 35289 proto udp
Ready to process requests
Ignoring request to auth address * port 1812 bound to server default
from unknown client 127.0.0.3 port 43190 proto udp
Ready to process requests
Shouldn't global clients be used in every virtual server?
I double checked, that we don't configure clients anywhere else (only
using sql module). So there should be no override.
Any ideas?
Kind regards,
Enno
--
Enno Gröper
Charité – Universitätsmedizin Berlin
Geschäftsbereich IT | Netz
2
3
We use LDAP-groups (from AD, if that matters) to map
radius-reply-items for general network access on switches, routers,
optical gear, etc. Each vendor is their own special flower so needs
its own thing.
The way we're handling this currently is in post-auth where we specify
reply-items per group using if/elseif/else per
https://networkradius.com/doc/3.0.10/unlang/keywords.html.
This works great if things are simple - you're a member of one group
or another. However, we've not yet gotten it to work if one is a
member of multiple groups, and to have each group match and get
reply-items from each.
Example of now:
if (LDAP-Group == "network-administrators") {
update reply {
cisco-avpair = "shell:priv-lvl=15",
Service-Type = "6",
Juniper-Local-User-Name = "superuser",
PaloAlto-Admin-Role = "superuser",
}
}
elsif (LDAP-Group == "network-users") {
update reply {
cisco-avpair = "shell:priv-lvl=1",
Juniper-Local-User-Name = "op",
PaloAlto-Admin-Role = "devicereader",
}
}
else {
reject
}
Note that this will do a single match and bail out of the if
statement. What we'd like to do is to keep matching accumulatively.
The use case is per above it's layer2/3 devices, we'd like to add some
other types of gear to the list where someone in the above groups
shouldnt have access to, but someone in network-administrators AND
$othergroup should have access to.
Per Unlang, it looks like there is a case/switch statement but I
believe we'd be hitting the same limitation there.
tldr; how can we match multiple LDAP-groups and get reply-items from
all that match?
Cheers,
Chris
4
14
Hi,
I`m looking how to ignore\blacklist request based on certain condition,
e.g. ip address, something like:
if "%{request:Calling-Station-Id}" == <ip_address> {
(ignore request)
}
or any module which would enable blacklisting?
I would need to drop a packet rather than reject it.
Appreciate this software and your help, thanks
Bart
2
1
Version 3.0.22 has now been released. It's been rather a long delay due
to a number of reasons, but hopefully worth the wait.
There have been a lot of updates in this "TLS and DHCP" release, and a
number of new features. Some highlights:
- TLS1.3 support, thanks to Alexander Clouter
- Major DHCP improvements from Terry Burton and Nick Porter
- Significant improvements to readability of TLS debug messages
- rlm_sql_map, to handle multiple columns in SQL queries
- rlm_totp, for calculating Google Authenticator type OTP codes
As well as many other improvements and bug fixes. Full release notes are
available on the web site:
https://freeradius.org/release_notes/?br=3.0.x&re=3.0.22
Download from the usual places:
https://freeradius.org/releases/
ftp://ftp.freeradius.org/pub/freeradius/
https://github.com/FreeRADIUS/freeradius-server/releases/tag/release_3_0_22
Packages are available on the Network RADIUS web site:
https://packages.networkradius.com/
Docker images will also be available on Dockerhub shortly:
https://hub.docker.com/u/freeradius
--
Matthew
2
1
I would like to run an sql update statement, every time the user disconnects a session.
Correct me if I'm wrong, but I believe I should capture that inside accounting { ... } where the final acctstoptime etc get stored into radacct table.
But I don't know how exactly to achieve this.
I suppose something like this below, but how do I know if the user actually disconnected?
accounting {
update request {
...
}
}
Thanks,
Mark
Sent with [ProtonMail](https://protonmail.com) Secure Email.
3
15
Hello,
I have setup freeradius to disconnect the NAS when certain conditions are met.
However the COA server can't be reached or doesn't react, so the requests get duplicated and sent over and over again, until it times out.
(3) Received Accounting-Request Id 220 from 127.0.0.1:36559 to 127.0.0.1:1813 length 158
(3) User-Name = "mark"
(3) NAS-IP-Address = 127.0.0.1
(3) NAS-Port = 1
(3) Service-Type = Outbound-User
(3) Framed-Protocol = PPP
(3) Framed-IP-Address = 10.8.0.2
(3) Calling-Station-Id = "89.32.xxx.xxx"
(3) NAS-Identifier = "OpenVpn"
(3) Acct-Status-Type = Interim-Update
(3) Acct-Input-Octets = 103730
(3) Acct-Output-Octets = 356871
(3) Acct-Session-Id = "A7E4B3803D0E4A87C8CC76B5C0E1910B"
(3) Acct-Session-Time = 20
(3) Acct-Input-Gigawords = 0
(3) Acct-Output-Gigawords = 0
(3) NAS-Port-Type = Virtual
(3) # Executing section preacct from file /etc/freeradius/3.0/sites-enabled/default
(3) preacct {
(3) update control {
(3) EXPAND %l
(3)--> 1620718410
(3) &Current-Timestamp := 1620718410
(3) } # update control = noop
(3) update request {
rlm_sql (sql): Reserved connection (0)
rlm_sql (sql): Released connection (0)
Need 2 more connections to reach 10 spares
rlm_sql (sql): Opening additional connection (8), 1 of 24 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius_db' on 3.64.143.170 via TCP/IP, server version 8.0.24, protocol version 10
(3) EXPAND %{User-Name}
(3)--> mark
(3) SQL-User-Name set to 'mark'
rlm_sql (sql): Reserved connection (5)
(3) Executing select query: SELECT COALESCE((SELECT UNIX_TIMESTAMP(expires_at) FROM master_db.device d WHERE d.id='mark'), 0)
rlm_sql (sql): Released connection (5)
(3) EXPAND %{sql:SELECT COALESCE((SELECT UNIX_TIMESTAMP(expires_at) FROM master_db.device d WHERE d.id='%{User-Name}'), 0)}
(3)--> 1589143717
(3) &Expires-Timestamp := 1589143717
rlm_sql (sql): Reserved connection (1)
rlm_sql (sql): Released connection (1)
(3) EXPAND %{User-Name}
(3)--> mark
(3) SQL-User-Name set to 'mark'
rlm_sql (sql): Reserved connection (7)
(3) Executing select query: SELECT COALESCE(MAX(is_banned), 0) as banned FROM master_db.device d WHERE d.id = 'mark'
rlm_sql (sql): Released connection (7)
(3) EXPAND %{sql:SELECT COALESCE(MAX(is_banned), 0) as banned FROM master_db.device d WHERE d.id = '%{User-Name}'}
(3)--> 0
(3) &Banned := 0
(3) } # update request = noop
(3) if (&request:Banned == 1) {
(3) if (&request:Banned == 1)-> FALSE
(3) if (&control:Current-Timestamp > &request:Expires-Timestamp) {
(3) if (&control:Current-Timestamp > &request:Expires-Timestamp)-> TRUE
(3) if (&control:Current-Timestamp > &request:Expires-Timestamp){
(3) update disconnect {
(3) EXPAND %{User-Name}
(3)--> mark
(3) &User-Name = mark
(3) } # update disconnect = noop
(3) } # if (&control:Current-Timestamp > &request:Expires-Timestamp)= noop
(3) [preprocess] = ok
(3) policy acct_unique {
(3) update request {
(3) &Tmp-String-9 := "ai:"
(3) } # update request = noop
(3) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:&Class}" =~ /^ai:([0-9a-f]{32})/i)) {
(3) EXPAND %{hex:&Class}
(3)-->
(3) EXPAND ^%{hex:&Tmp-String-9}
(3)--> ^61693a
(3) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:&Class}" =~ /^ai:([0-9a-f]{32})/i))-> FALSE
(3) else {
(3) update request {
(3) EXPAND %{md5:%{User-Name},%{Acct-Session-ID},%{%{NAS-IPv6-Address}:-%{NAS-IP-Address}},%{NAS-Identifier},%{NAS-Port-ID},%{NAS-Port}}
(3)--> 47a7883f04b4faeba08349f153a68b6b
(3) &Acct-Unique-Session-Id := 47a7883f04b4faeba08349f153a68b6b
(3) } # update request = noop
(3) } # else = noop
(3) } # policy acct_unique = noop
(3) suffix: Checking for suffix after "@"
(3) suffix: No '@' in User-Name = "mark", looking up realm NULL
(3) suffix: No such realm "NULL"
(3) [suffix] = noop
(3) } # preacct = ok
(3) # Executing section accounting from file /etc/freeradius/3.0/sites-enabled/default
(3) accounting {
(3) detail: EXPAND /var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d
(3) detail:--> /var/log/freeradius/radacct/127.0.0.1/detail-20210511
(3) detail: /var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d expands to /var/log/freeradius/radacct/127.0.0.1/detail-20210511
(3) detail: EXPAND %t
(3) detail:--> Tue May 11 07:33:30 2021
(3) [detail] = ok
(3) [unix] = noop
(3) sql: EXPAND %{tolower:type.%{%{Acct-Status-Type}:-%{Request-Processing-Stage}}.query}
(3) sql:--> type.interim-update.query
(3) sql: Using query template 'query'
rlm_sql (sql): Reserved connection (6)
(3) sql: EXPAND %{User-Name}
(3) sql:--> mark
(3) sql: SQL-User-Name set to 'mark'
(3) sql: EXPAND UPDATE radacct SET acctupdatetime= (@acctupdatetime_old:=acctupdatetime), acctupdatetime= FROM_UNIXTIME(%{%{integer:Event-Timestamp}:-%l}), acctinterval= %{%{integer:Event-Timestamp}:-%l} - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '%{Framed-IP-Address}', framedipv6address = '%{Framed-IPv6-Address}', framedipv6prefix = '%{Framed-IPv6-Prefix}', framedinterfaceid = '%{Framed-Interface-Id}', delegatedipv6prefix = '%{Delegated-IPv6-Prefix}', acctsessiontime = %{%{Acct-Session-Time}:-NULL}, acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}' WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'
(3) sql:--> UPDATE radacct SET acctupdatetime= (@acctupdatetime_old:=acctupdatetime), acctupdatetime= FROM_UNIXTIME(1620718410), acctinterval= 1620718410 - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '10.8.0.2', framedipv6address = '', framedipv6prefix = '', framedinterfaceid = '', delegatedipv6prefix = '', acctsessiontime = 20, acctinputoctets = '0' << 32 | '103730', acctoutputoctets = '0' << 32 | '356871' WHERE AcctUniqueId = '47a7883f04b4faeba08349f153a68b6b'
(3) sql: Executing query: UPDATE radacct SET acctupdatetime= (@acctupdatetime_old:=acctupdatetime), acctupdatetime= FROM_UNIXTIME(1620718410), acctinterval= 1620718410 - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '10.8.0.2', framedipv6address = '', framedipv6prefix = '', framedinterfaceid = '', delegatedipv6prefix = '', acctsessiontime = 20, acctinputoctets = '0' << 32 | '103730', acctoutputoctets = '0' << 32 | '356871' WHERE AcctUniqueId = '47a7883f04b4faeba08349f153a68b6b'
rlm_sql_mysql: Rows matched: 1Changed: 1Warnings: 1
(3) sql: SQL query returned: success
(3) sql: 1 record(s) updated
rlm_sql (sql): Released connection (6)
(3) [sql] = ok
(3) [exec] = noop
(3) attr_filter.accounting_response: EXPAND %{User-Name}
(3) attr_filter.accounting_response:--> mark
(3) attr_filter.accounting_response: Matched entry DEFAULT at line 12
(3) [attr_filter.accounting_response] = updated
(3) } # accounting = updated
(3) Sent Disconnect-Request Id 155 from 0.0.0.0:57659 to 127.0.0.1:3799 length 28
(3) User-Name = "mark"
(3) Sent Accounting-Response Id 220 from 127.0.0.1:1813 to 127.0.0.1:36559 length 0
(3) Finished request
(3) Cleaning up request packet ID 220 with timestamp +44
Waking up in 2.3 seconds.
(3) Sending duplicate CoA request to home server 127.0.0.1 port 3799 - ID: 155
Waking up in 4.5 seconds.
(5) Sending duplicate CoA request to home server 127.0.0.1 port 3799 - ID: 211
Waking up in 0.3 seconds.
(6) Sending duplicate CoA request to home server 127.0.0.1 port 3799 - ID: 79
Waking up in 3.5 seconds.
...
(4) ERROR: Failing request - originate-coa ID 83, due to lack of any response from coa server 127.0.0.1 port 3799 within 30 seconds
This is the coa section defined in the /etc/freeradius/3.0/proxy.conf
home_server my-coa {
type = coa
ipaddr = 127.0.0.1
port = 3799
secret = coa123
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
Do I also have to set it in /etc/freeradius/3.0/clients.conf:
client localhost {
...
coa_server = my-coa
}
Is there anything else I need to do to setup the COA server?
My NAS is OpenVPN and I'm using openvpn-auth-radius plugin from Debian:
https://packages.debian.org/buster/openvpn-auth-radius
/etc/openvpn/radiusplugin.cnf
NAS-Identifier=OpenVpn
Service-Type=5
Framed-Protocol=1
NAS-Port-Type=5
NAS-IP-Address=127.0.0.1
OpenVPNConfig=/etc/openvpn/server.conf
subnet=255.255.255.0
overwriteccfiles=true
server
{
authport=1812
name=127.0.0.1
retry=1
wait=1
sharedsecret=${CLIENT_SECRET}
}
Thanks
2
4
Hello List,
Someone can explain how Acct-Interim-Interval works?
This function checks if the IP on radippool is active in NAS?
Many thanks
Aurélio
2
1
Hello,
I would like to set up VPN on a Samba DC (Debian Bullseye). I could set it
up with ntlm_auth, but I read that ntlm_auth may serve about 30 request per
second maximum, and uses smbv1.
I would like to filter users by group or msNPAllowDialin AD property.
I can use:
winbind_username = "%{mschap:User-Name}"
winbind_domain = "%{mschap:NT-Domain}"
in mschap, but how I can filter users?
Regards,
Tamas.
4
33