Config for proxying based on auth-protocol
Nitin Bhardwaj
nbhardwaj at merunetworks.com
Tue May 10 12:18:01 CEST 2011
On 10/05/2011 12:54 PM, Alan DeKok wrote:
> Nitin Bhardwaj wrote:
>> I want to configure FreeRADIUS to do the following two things:
>>
>> (1) Handle tunnel for PEAP authentication requested by any supplicant(s),
>> and do mschapv2 auth with another RADIUS server. (Irrespective of
>> the realm in the user-name)
>>
>> (2) Transparently proxy all other non-PEAP requests to another RADIUS
>> server (like LEAP, EAP-FAST etc etc).
>> ( Again, Irrespective of the realm in the user-name).
> That's impossible.
>
> By the time the server discovers that the client is using a particular
> EAP method, the EAP session has started, and it's impossible to proxy it
> to another RADIUS server.
>
> Alan DeKok.
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Thanks a lot Alan for the insight.
--
Nitin Bhardwaj
More information about the Freeradius-Users
mailing list