RADIUS Auth-Type

Phil Mayers p.mayers at imperial.ac.uk
Sat Dec 3 16:07:34 CET 2005


Bohannan, Chad W wrote:
> OK, here is the situation. I have successfully configured RADIUS to 
> authenticate/authorize NAS requests from my Cisco gear so long as the 
> user “Auth-Type= System”. I have also managed to get Samba working and 
> have joined the radius server to the AD realm in question. This is 
> confirmed through the following:


The radius server doesn't specify MSCHAP. The NAS *tells* the radius 
server that this request *is* using MSCHAP by virtue of sending the 
appropriate MSCHAP attributes.

Configure your NAS (dialup server, VPN, IPSec+xauth, whatever) to do 
MSCHAP, and as long as the mschap module is in the authorize and 
authenticate sections, it will work.



More information about the Freeradius-Users mailing list