pix auth and spawn_flag

Curtis Doty Curtis at GreenKey.net
Mon Mar 6 04:43:41 CET 2006


Curtis Doty wrote:
> Alan DeKok wrote:
>> Curtis Doty <Curtis at GreenKey.net> wrote:
>>  
>>> To which freeradius does not respond until *after* the pix sends the 
>>> first retry packet.     
>>
>>   Set reject_delay = 0
>>   
>
> Yes, disabling this feature works around. But what about the 
> aforementioned request confuses radiusd? Auth failures respond 
> immediately from other nas devices. And the reject_delay feature is 
> desirable.
>
> Also, I tried compiling --without-threads but the source ignored this 
> and still built with.

Nevermind on that last comment only. I was installing in the wrong 
location. Compiling on Fedora Core --without-threads does also work 
around the buggy handling of these auth requests.

I'm still curious as to why radiusd can't handle these requests but 
handles others fine. Does this bug belong on http://bugs.freeradius.org 
or on the http://bugzilla.redhat.com site?

../C




More information about the Freeradius-Users mailing list