log_badlogins include SRC IP Address

Gary Gatten Ggatten at waddell.com
Sat Mar 20 00:23:18 CET 2010


First, you need to make sure the "client" (switch, not host) is providing that info.

________________________________
From: freeradius-users-bounces+ggatten=waddell.com at lists.freeradius.org <freeradius-users-bounces+ggatten=waddell.com at lists.freeradius.org>
To: freeradius-users at lists.freeradius.org <freeradius-users at lists.freeradius.org>
Sent: Fri Mar 19 18:05:35 2010
Subject: log_badlogins include SRC IP Address


Hi,
I am trying to configure the log_badlogins to include the src IP address of the client host.
I am noticing that in the radius.log does not include the src IP.

Example.
Fri Mar 19 15:11:39 2010 : Auth: Login incorrect: [jack] (from client testswitch port 0)

Does anyone know how to change either radius or syslog-ng to include the src ip of the host that is attempting to break in?


-Eric






<font size="1">
<div style='border:none;border-bottom:double windowtext 2.25pt;padding:0in 0in 1.0pt 0in'>
</div>
"This email is intended to be reviewed by only the intended recipient
 and may contain information that is privileged and/or confidential.
 If you are not the intended recipient, you are hereby notified that
 any review, use, dissemination, disclosure or copying of this email
 and its attachments, if any, is strictly prohibited.  If you have
 received this email in error, please immediately notify the sender by
 return email and delete this email from your system."
</font>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20100319/9501008c/attachment.html>


More information about the Freeradius-Users mailing list