solution---Re: Re: help--- IPsec VPN on radius

Bjørn Mork bjorn at mork.no
Wed Nov 18 14:07:29 CET 2009


Alan DeKok <aland at deployingradius.com> writes:
> Yagnesh Dave wrote:
>> Found the solution from one of the previous posts.
>> 
>> http://lists.cistron.nl/pipermail/freeradius-users/2005-July/msg00273.html
>> 
>> I just the did the same, added the below line in the dictionary file at
>> /usr/local/share/freeradius/dictionary
>> 
>> VALUE Service-Type outbound 5
>
>   Or, you could use the RFC name, and the name which is in
> dictionary.rfc2865: "Outbound-User"

BTW, I am wondering if this redefinition should have been moved to
dictionary.ascend.illegal?:

 bjorn at canardo:/usr/local/src/git/freeradius$ grep '     Service-Type' share/dictionary.ascend
 VALUE   Service-Type                    Dialout-Framed-User     5


Such duplicate definitions confuse me whenever I look at the output from
radclient...

Another one I've been hit by recently is this one (which seems to be
very deliberate):

 VALUE   Acct-Status-Type                Alive                   3   # dup
 VALUE   Acct-Status-Type                Interim-Update          3


Deliberate or not, this broke a FR 1.0 based perl module doing  
 "if ($RAD_REQUEST{'Acct-Status-Type'} eq 'Alive') {}) {...}"




Bjørn




More information about the Freeradius-Users mailing list