mgmitch mgmitch at
Tue Dec 14 20:25:51 CET 2010


I've been trying to configure a new freeradius server (ver. 2.1.7)  to proxy
a OTP passcode to an existing (production) freeradius server (ver. 1.0.1)
that is already setup to accept and authenticate the OTP passcodes for our
remote access NAS devices (VPN, etc).  I would like to use PEAP/EAP-GTC for
wired 802.1x on our Cisco edge switches and terminate the PEAP tunnel on the
new radius server, sending the passcode on to the existing radius server for
authentication by proxy.  I've been able to accomplish this using Cisco ACS
but would like to use freeradius instead so that some other things can be
done easier which ACS is not well suited for.   From what I've read, "proxy
auth" is possible and done quite a bit but mainly using mschapv2 as the
inner auth method instead of gtc.  I've been beating on this for days now
and starting to feel I may never get this accomplished w/o help.  I get to
the point where either the PEAP tunnel is terminated on the new server and
the gtc passcode is not proxied to the other server or the authentication is
proxied to the other server but as EAP instead of just the cleartext OTP

Following is the output of starting freeradius in debug mode, followed by
the dubug results during anauthentication attempt.  I assume all the needed
info will be in this output.  Sorry in advance if I have not provided enough
info or too much. ANy help or suggestions would be appreciated.  I have read
a lot of the documentation and forum info but I havent found any obvious
solution to my problem yet.



Debug output:

[root at mackeral-dev raddb]# /usr/sbin/radiusd -X
FreeRADIUS Version 2.1.7, for host x86_64-redhat-linux-gnu, built on Dec 30
2009 at 13:46:28
Copyright (C) 1999-2009 The FreeRADIUS server project and contributors. 
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A 
You may redistribute copies of FreeRADIUS under the terms of the 
GNU General Public License v2. 
Starting - reading configuration files ...
including configuration file /etc/raddb/radiusd.conf
including configuration file /etc/raddb/proxy.conf
including configuration file /etc/raddb/clients.conf
including files in directory /etc/raddb/modules/
including configuration file /etc/raddb/modules/digest
including configuration file /etc/raddb/modules/ippool
including configuration file /etc/raddb/modules/echo
including configuration file /etc/raddb/modules/
including configuration file /etc/raddb/modules/passwd
including configuration file /etc/raddb/modules/pap
including configuration file /etc/raddb/modules/exec
including configuration file /etc/raddb/modules/logintime
including configuration file /etc/raddb/modules/mac2ip
including configuration file /etc/raddb/modules/counter
including configuration file /etc/raddb/modules/always
including configuration file /etc/raddb/modules/mac2vlan
including configuration file /etc/raddb/modules/attr_filter
including configuration file /etc/raddb/modules/pam
including configuration file /etc/raddb/modules/attr_rewrite
including configuration file /etc/raddb/modules/sqlcounter_expire_on_login
including configuration file /etc/raddb/modules/cui
including configuration file /etc/raddb/modules/sql_log
including configuration file /etc/raddb/modules/inner-eap
including configuration file /etc/raddb/modules/sradutmp
including configuration file /etc/raddb/modules/mschap
including configuration file /etc/raddb/modules/perl
including configuration file /etc/raddb/modules/expr
including configuration file /etc/raddb/modules/files
including configuration file /etc/raddb/modules/chap
including configuration file /etc/raddb/modules/radutmp
including configuration file /etc/raddb/modules/etc_group
including configuration file /etc/raddb/modules/realm
including configuration file /etc/raddb/modules/smsotp
including configuration file /etc/raddb/modules/preprocess
including configuration file /etc/raddb/modules/expiration
including configuration file /etc/raddb/modules/checkval
including configuration file /etc/raddb/modules/detail.log
including configuration file /etc/raddb/modules/linelog
including configuration file /etc/raddb/modules/smbpasswd
including configuration file /etc/raddb/modules/unix
including configuration file /etc/raddb/modules/detail
including configuration file /etc/raddb/modules/wimax
including configuration file /etc/raddb/modules/otp
including configuration file /etc/raddb/modules/acct_unique
including configuration file /etc/raddb/modules/policy
including configuration file /etc/raddb/eap.conf
including configuration file /etc/raddb/policy.conf
including files in directory /etc/raddb/sites-enabled/
including configuration file /etc/raddb/sites-enabled/control-socket
including configuration file /etc/raddb/sites-enabled/default
including configuration file /etc/raddb/sites-enabled/inner-tunnel
including configuration file /etc/raddb/sites-enabled/proxy-inner-tunnel
group = radiusd
user = radiusd
including dictionary file /etc/raddb/dictionary
main {
        prefix = "/usr"
        localstatedir = "/var"
        logdir = "/var/log/radius"
        libdir = "/usr/lib64/freeradius"
        radacctdir = "/var/log/radius/radacct"
        hostname_lookups = no
        max_request_time = 30
        cleanup_delay = 5
        max_requests = 1024
        allow_core_dumps = no
        pidfile = "/var/run/radiusd/"
        checkrad = "/usr/sbin/checkrad"
        debug_level = 0
        proxy_requests = yes
 log {
        stripped_names = no
        auth = no
        auth_badpass = no
        auth_goodpass = no
 security {
        max_attributes = 200
        reject_delay = 1
        status_server = yes
radiusd: #### Loading Realms and Home Servers ####
 proxy server {
        retry_delay = 5
        retry_count = 3
        default_fallback = no
        dead_time = 120
        wake_all_if_all_dead = no
 realm test {
        authhost =
        accthost =
        secret = testing
 home_server localhost {
        ipaddr =
        port = 1812
        type = "auth"
        secret = "testing123"
        response_window = 20
        max_outstanding = 65536
        require_message_authenticator = no
        zombie_period = 40
        status_check = "status-server"
        ping_interval = 30
        check_interval = 30
        num_answers_to_alive = 3
        num_pings_to_alive = 3
        revive_interval = 120
        status_check_timeout = 4
        irt = 2
        mrt = 16
        mrc = 5
        mrd = 30
 home_server_pool my_auth_failover {
        type = fail-over
        home_server = localhost
 realm {
        auth_pool = my_auth_failover
 realm LOCAL {
radiusd: #### Loading Clients ####
 client localhost {
        ipaddr =
        require_message_authenticator = no
        secret = "testing123"
        nastype = "other"
 client {
        require_message_authenticator = no
        secret = "testing"
        shortname = "test-switch"
radiusd: #### Instantiating modules ####
 instantiate {
 Module: Linked to module rlm_exec
 Module: Instantiating exec
  exec {
        wait = no
        input_pairs = "request"
        shell_escape = yes
 Module: Linked to module rlm_expr
 Module: Instantiating expr
 Module: Linked to module rlm_expiration
 Module: Instantiating expiration
  expiration {
        reply-message = "Password Has Expired  "
 Module: Linked to module rlm_logintime
 Module: Instantiating logintime
  logintime {
        reply-message = "You are calling outside your allowed timespan  "
        minimum-timeout = 60
radiusd: #### Loading Virtual Servers ####
server inner-tunnel {
 modules {
 Module: Checking authenticate {...} for more modules to load
 Module: Linked to module rlm_pap
 Module: Instantiating pap
  pap {
        encryption_scheme = "auto"
        auto_header = no
 Module: Linked to module rlm_chap
 Module: Instantiating chap
 Module: Linked to module rlm_mschap
 Module: Instantiating mschap
  mschap {
        use_mppe = yes
        require_encryption = no
        require_strong = no
        with_ntdomain_hack = no
 Module: Linked to module rlm_unix
 Module: Instantiating unix
  unix {
        radwtmp = "/var/log/radius/radwtmp"
 Module: Linked to module rlm_eap
 Module: Instantiating eap
  eap {
        default_eap_type = "peap"
        timer_expire = 60
        ignore_unknown_eap_types = no
        cisco_accounting_username_bug = no
        max_sessions = 2048
 Module: Linked to sub-module rlm_eap_md5
 Module: Instantiating eap-md5
 Module: Linked to sub-module rlm_eap_leap
 Module: Instantiating eap-leap
 Module: Linked to sub-module rlm_eap_gtc
 Module: Instantiating eap-gtc
   gtc {
        challenge = "Password: "
        auth_type = "PAP"
 Module: Linked to sub-module rlm_eap_tls
 Module: Instantiating eap-tls
   tls {
        rsa_key_exchange = no
        dh_key_exchange = yes
        rsa_key_length = 512
        dh_key_length = 512
        verify_depth = 0
        pem_file_type = yes
        private_key_file = "/etc/raddb/certs/server.pem"
        certificate_file = "/etc/raddb/certs/server.pem"
        CA_file = "/etc/raddb/certs/ca.pem"
        private_key_password = "whatever"
        dh_file = "/etc/raddb/certs/dh"
        random_file = "/etc/raddb/certs/random"
        fragment_size = 1024
        include_length = yes
        check_crl = no
        cipher_list = "DEFAULT"
        make_cert_command = "/etc/raddb/certs/bootstrap"
    cache {
        enable = no
        lifetime = 24
        max_entries = 255
 Module: Linked to sub-module rlm_eap_ttls
 Module: Instantiating eap-ttls
   ttls {
        default_eap_type = "md5"
        copy_request_to_tunnel = no
        use_tunneled_reply = no
        virtual_server = "inner-tunnel"
        include_length = yes
 Module: Linked to sub-module rlm_eap_peap
 Module: Instantiating eap-peap
   peap {
        default_eap_type = "gtc"
        copy_request_to_tunnel = no
        use_tunneled_reply = no
        proxy_tunneled_request_as_eap = no
 Module: Linked to sub-module rlm_eap_mschapv2
 Module: Instantiating eap-mschapv2
   mschapv2 {
        with_ntdomain_hack = no
 Module: Checking authorize {...} for more modules to load
 Module: Linked to module rlm_realm
 Module: Instantiating suffix
  realm suffix {
        format = "suffix"
        delimiter = "@"
        ignore_default = no
        ignore_null = no
 Module: Linked to module rlm_files
 Module: Instantiating files
  files {
        usersfile = "/etc/raddb/users"
        acctusersfile = "/etc/raddb/acct_users"
        preproxy_usersfile = "/etc/raddb/preproxy_users"
        compat = "no"
 Module: Checking session {...} for more modules to load
 Module: Linked to module rlm_radutmp
 Module: Instantiating radutmp
  radutmp {
        filename = "/var/log/radius/radutmp"
        username = "%{User-Name}"
        case_sensitive = yes
        check_with_nas = yes
        perm = 384
        callerid = yes
 Module: Checking post-proxy {...} for more modules to load
 Module: Checking post-auth {...} for more modules to load
 Module: Linked to module rlm_attr_filter
 Module: Instantiating attr_filter.access_reject
  attr_filter attr_filter.access_reject {
        attrsfile = "/etc/raddb/attrs.access_reject"
        key = "%{User-Name}"
 } # modules
} # server
server proxy-inner-tunnel {
 modules {
 Module: Checking authenticate {...} for more modules to load
 Module: Checking authorize {...} for more modules to load
 Module: Checking post-proxy {...} for more modules to load
 } # modules
} # server
server {
 modules {
 Module: Checking authenticate {...} for more modules to load
 Module: Checking authorize {...} for more modules to load
 Module: Linked to module rlm_preprocess
 Module: Instantiating preprocess
  preprocess {
        huntgroups = "/etc/raddb/huntgroups"
        hints = "/etc/raddb/hints"
        with_ascend_hack = no
        ascend_channels_per_line = 23
        with_ntdomain_hack = no
        with_specialix_jetstream_hack = no
        with_cisco_vsa_hack = no
        with_alvarion_vsa_hack = no
 Module: Checking preacct {...} for more modules to load
 Module: Linked to module rlm_acct_unique
 Module: Instantiating acct_unique
  acct_unique {
        key = "User-Name, Acct-Session-Id, NAS-IP-Address,
Client-IP-Address, NAS-Port"
 Module: Checking accounting {...} for more modules to load
 Module: Linked to module rlm_detail
 Module: Instantiating detail
  detail {
        detailfile =
        header = "%t"
        detailperm = 384
        dirperm = 493
        locking = no
        log_packet_header = no
 Module: Instantiating attr_filter.accounting_response
  attr_filter attr_filter.accounting_response {
        attrsfile = "/etc/raddb/attrs.accounting_response"
        key = "%{User-Name}"
 Module: Checking session {...} for more modules to load
 Module: Checking post-proxy {...} for more modules to load
 Module: Checking post-auth {...} for more modules to load
 } # modules
} # server
radiusd: #### Opening IP addresses and Ports ####
listen {
        type = "auth"
        ipaddr = *
        port = 0
listen {
        type = "acct"
        ipaddr = *
        port = 0
listen {
        type = "control"
 listen {
        socket = "/var/run/radiusd/radiusd.sock"
Listening on authentication address * port 1812
Listening on accounting address * port 1813
Listening on command file /var/run/radiusd/radiusd.sock
Listening on proxy address * port 1814
Ready to process requests.

And here's the dubug output during an authentication attempt:

rad_recv: Access-Request packet from host port 1645, id=224,
        User-Name = "mgmitch"
        Service-Type = Framed-User
        Framed-MTU = 1500
        Called-Station-Id = "00-1C-B0-AB-3D-81"
        Calling-Station-Id = "00-16-D3-22-CD-24"
        EAP-Message = 0x0201000c016d676d69746368
        Message-Authenticator = 0x876a775afd4fabbf05cbbc0553b468b5
        NAS-Port-Type = Ethernet
        NAS-Port = 50101
        NAS-Port-Id = "GigabitEthernet1/0/1"
        NAS-IP-Address =
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "mgmitch", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 1 length 12
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[unix] returns notfound
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user.  Authentication
may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 224 to port 1645
        EAP-Message = 0x010200061920
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf6df016cf6dd18ad384e3bf6a1b809e8
Finished request 0.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1645, id=225,
        User-Name = "mgmitch"
        Service-Type = Framed-User
        Framed-MTU = 1500
        Called-Station-Id = "00-1C-B0-AB-3D-81"
        Calling-Station-Id = "00-16-D3-22-CD-24"
        EAP-Message =
        Message-Authenticator = 0xdd018506f3d2e96d9c604742f45250ba
        NAS-Port-Type = Ethernet
        NAS-Port = 50101
        NAS-Port-Id = "GigabitEthernet1/0/1"
        State = 0xf6df016cf6dd18ad384e3bf6a1b809e8
        NAS-IP-Address =
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "mgmitch", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 2 length 92
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap]     (other): before/accept initialization 
[peap]     TLS_accept: before/accept initialization 
[peap] <<< TLS 1.0 Handshake [length 0051], ClientHello  
[peap]     TLS_accept: SSLv3 read client hello A 
[peap] >>> TLS 1.0 Handshake [length 002a], ServerHello  
[peap]     TLS_accept: SSLv3 write server hello A 
[peap] >>> TLS 1.0 Handshake [length 085e], Certificate  
[peap]     TLS_accept: SSLv3 write certificate A 
[peap] >>> TLS 1.0 Handshake [length 020d], ServerKeyExchange  
[peap]     TLS_accept: SSLv3 write key exchange A 
[peap] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone  
[peap]     TLS_accept: SSLv3 write server done A 
[peap]     TLS_accept: SSLv3 flush data 
[peap]     TLS_accept: Need to read more data: SSLv3 read client certificate
In SSL Handshake Phase 
In SSL Accept mode  
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 225 to port 1645
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message = 0xa73082038fa0030201020209
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf6df016cf7dc18ad384e3bf6a1b809e8
Finished request 1.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1645, id=226,
        User-Name = "mgmitch"
        Service-Type = Framed-User
        Framed-MTU = 1500
        Called-Station-Id = "00-1C-B0-AB-3D-81"
        Calling-Station-Id = "00-16-D3-22-CD-24"
        EAP-Message = 0x020300061900
        Message-Authenticator = 0xe97484975a808e5c4c0e9c12b8eef547
        NAS-Port-Type = Ethernet
        NAS-Port = 50101
        NAS-Port-Id = "GigabitEthernet1/0/1"
        State = 0xf6df016cf7dc18ad384e3bf6a1b809e8
        NAS-IP-Address =
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "mgmitch", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 3 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 226 to port 1645
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message = 0x2c59aed1eab2c2f1
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf6df016cf4db18ad384e3bf6a1b809e8
Finished request 2.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1645, id=227,
        User-Name = "mgmitch"
        Service-Type = Framed-User
        Framed-MTU = 1500
        Called-Station-Id = "00-1C-B0-AB-3D-81"
        Calling-Station-Id = "00-16-D3-22-CD-24"
        EAP-Message = 0x020400061900
        Message-Authenticator = 0xc748c58f114831f9e0c9efc212a54c00
        NAS-Port-Type = Ethernet
        NAS-Port = 50101
        NAS-Port-Id = "GigabitEthernet1/0/1"
        State = 0xf6df016cf4db18ad384e3bf6a1b809e8
        NAS-IP-Address =
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "mgmitch", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 4 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 227 to port 1645
        EAP-Message =
        EAP-Message =
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf6df016cf5da18ad384e3bf6a1b809e8
Finished request 3.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1645, id=228,
        User-Name = "mgmitch"
        Service-Type = Framed-User
        Framed-MTU = 1500
        Called-Station-Id = "00-1C-B0-AB-3D-81"
        Calling-Station-Id = "00-16-D3-22-CD-24"
        EAP-Message =
        Message-Authenticator = 0x5e9a5e77e0b55fc6414a51a2c65cd60e
        NAS-Port-Type = Ethernet
        NAS-Port = 50101
        NAS-Port-Id = "GigabitEthernet1/0/1"
        State = 0xf6df016cf5da18ad384e3bf6a1b809e8
        NAS-IP-Address =
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "mgmitch", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 5 length 204
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap] <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange  
[peap]     TLS_accept: SSLv3 read client key exchange A 
[peap] <<< TLS 1.0 ChangeCipherSpec [length 0001]  
[peap] <<< TLS 1.0 Handshake [length 0010], Finished  
[peap]     TLS_accept: SSLv3 read finished A 
[peap] >>> TLS 1.0 ChangeCipherSpec [length 0001]  
[peap]     TLS_accept: SSLv3 write change cipher spec A 
[peap] >>> TLS 1.0 Handshake [length 0010], Finished  
[peap]     TLS_accept: SSLv3 write finished A 
[peap]     TLS_accept: SSLv3 flush data 
[peap]     (other): SSL negotiation finished successfully 
SSL Connection Established 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 228 to port 1645
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf6df016cf2d918ad384e3bf6a1b809e8
Finished request 4.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1645, id=229,
        User-Name = "mgmitch"
        Service-Type = Framed-User
        Framed-MTU = 1500
        Called-Station-Id = "00-1C-B0-AB-3D-81"
        Calling-Station-Id = "00-16-D3-22-CD-24"
        EAP-Message = 0x020600061900
        Message-Authenticator = 0xbdec9b5d34c954ced59ac3ea5d6e650e
        NAS-Port-Type = Ethernet
        NAS-Port = 50101
        NAS-Port-Id = "GigabitEthernet1/0/1"
        State = 0xf6df016cf2d918ad384e3bf6a1b809e8
        NAS-IP-Address =
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "mgmitch", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 6 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake is finished
[peap] eaptls_verify returned 3 
[peap] eaptls_process returned 3 
++[eap] returns handled
Sending Access-Challenge of id 229 to port 1645
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf6df016cf3d818ad384e3bf6a1b809e8
Finished request 5.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1645, id=230,
        User-Name = "mgmitch"
        Service-Type = Framed-User
        Framed-MTU = 1500
        Called-Station-Id = "00-1C-B0-AB-3D-81"
        Calling-Station-Id = "00-16-D3-22-CD-24"
        EAP-Message =
        Message-Authenticator = 0x499bb31965aa74f94d70460b29e04cb1
        NAS-Port-Type = Ethernet
        NAS-Port = 50101
        NAS-Port-Id = "GigabitEthernet1/0/1"
        State = 0xf6df016cf3d818ad384e3bf6a1b809e8
        NAS-IP-Address =
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "mgmitch", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 80
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap] eaptls_process returned 7 
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Identity - mgmitch
[peap] Got tunneled request
        EAP-Message = 0x0207000c016d676d69746368
server  {
  PEAP: Got tunneled identity of mgmitch
  PEAP: Setting default EAP type for tunneled EAP session.
  PEAP: Setting User-Name to mgmitch
Sending tunneled request
        EAP-Message = 0x0207000c016d676d69746368
        FreeRADIUS-Proxied-To =
        User-Name = "mgmitch"
server  {
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "mgmitch", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 12
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[unix] returns notfound
[files] users: Matched entry DEFAULT at line 1
++[files] returns ok
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
} # server 
[peap] Got tunneled reply code 0
  PEAP: Calling authenticate in order to initiate tunneled EAP session.
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type gtc
[eap]   Not-EAP proxy set.  Not composing EAP
++[eap] returns handled
  PEAP: Tunneled authentication will be proxied to test
  PEAP: Remembering to do EAP-MS-CHAP-V2 post-proxy.
[eap]   Tunneled session will be proxied.  Not doing EAP.
++[eap] returns handled
  WARNING: Empty section.  Using default return values.
ERROR: Failed to create a new socket for proxying requests.
ERROR: Failed inserting request into proxy hash.
ERROR: Failed to proxy request 6
There was no response configured: rejecting request 6
Using Post-Auth-Type Reject
+- entering group REJECT {...}
[attr_filter.access_reject]     expand: %{User-Name} -> mgmitch
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 6 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 6
Sending Access-Reject of id 230 to port 1645
Waking up in 3.8 seconds.
Cleaning up request 0 ID 224 with timestamp +14
Cleaning up request 1 ID 225 with timestamp +14
Cleaning up request 2 ID 226 with timestamp +14
Cleaning up request 3 ID 227 with timestamp +14
Cleaning up request 4 ID 228 with timestamp +14
Cleaning up request 5 ID 229 with timestamp +14
Waking up in 1.0 seconds.
Cleaning up request 6 ID 230 with timestamp +14
Ready to process requests.

View this message in context:
Sent from the FreeRadius - User mailing list archive at

More information about the Freeradius-Users mailing list