Configurable timeout in rlm_exec

Alan DeKok aland at deployingradius.com
Tue Sep 25 15:25:15 CEST 2012


Philipp Hug wrote:
> We don't have control over which NAS are used. It should work with
> different NAS implementations.

  Then a 2 minute timeout WILL NOT WORK.

  Pretty much every single NAS in existence will give up after about 30
seconds.  So sending an Access-Accept after that time is uselss.

> We use for example a VPN gateway which uses Radius, but it should also
> work with different NAS.

  The only real solution is to let the user in, but block them at a
captive portal.  Once they authenticate, change the permissions in the
captive portal to let them access the network.

  Alan DeKok.


More information about the Freeradius-Devel mailing list