post-auth | ldap-group | huntgroup

Alan DeKok aland at deployingradius.com
Fri Feb 5 16:46:30 CET 2021



> On Feb 5, 2021, at 10:37 AM, Markus Demmert (BESITEC-DEHAM) <MDemmert at besitec.com> wrote:
> 
> Sorry I overread 
>> So... where is the the Huntrgoup-Name coming from?
> 
> I edited the file huntgroup with the following:
> cisco-group	NAS-IP-Address == 10.3.10.10

  And the debug output shows that the "preprocess" module doesn't match anything.  Why?  Reading the debug output again shows that the packet contains:

> (0) Received Access-Request Id 19 from 10.3.10.10:49205 to 10.3.3.10:1812 length 94
> (0)   User-Name = "user.name"
> (0)   User-Password = "pass.word"
> (0)   Cisco-AVPair = "shell:priv-lvl=1"
> (0)   NAS-IP-Address = 0.0.0.0
> (0)   Acct-Session-Id = "0500015B"

  Why doesn't this packet match

	NAS-IP-Address == 10.3.10.10

  ?

  Alan DeKok.




More information about the Freeradius-Users mailing list