RADIUS Auth-Type
Phil Mayers
p.mayers at imperial.ac.uk
Sat Dec 3 16:07:34 CET 2005
Bohannan, Chad W wrote:
> OK, here is the situation. I have successfully configured RADIUS to
> authenticate/authorize NAS requests from my Cisco gear so long as the
> user “Auth-Type= System”. I have also managed to get Samba working and
> have joined the radius server to the AD realm in question. This is
> confirmed through the following:
The radius server doesn't specify MSCHAP. The NAS *tells* the radius
server that this request *is* using MSCHAP by virtue of sending the
appropriate MSCHAP attributes.
Configure your NAS (dialup server, VPN, IPSec+xauth, whatever) to do
MSCHAP, and as long as the mschap module is in the authorize and
authenticate sections, it will work.
More information about the Freeradius-Users
mailing list