proprietarysucks | hi guys, any thoughts on the stuff I posted last night? | 01:14 |
---|---|---|
proprietarysucks | I've installed following the docs, community version twice now and ended up at a 404 page both times. I'm trying to figure out what mistakes I've made or the documentation possibly | 01:15 |
proprietarysucks | also any thoughts about the script I wrote? | 01:15 |
*** nowen (~nowen@adsl-176-210-205.asm.bellsouth.net) has joined #wikid | 13:13 | |
*** cmatthews (d8ed3803@gateway/web/freenode/ip.216.237.56.3) has joined #wikid | 15:59 | |
*** Luiz_ (c8ac968b@gateway/web/freenode/ip.200.172.150.139) has joined #wikid | 16:28 | |
cmatthews | Nick, just send over the PO. | 16:29 |
Luiz_ | Who can help me about wikid with fortigate? | 16:30 |
nowen | ok, cool. we may be able to get started today. it's a bit busy for a Friday. | 16:30 |
*** Luiz_ has quit (Client Quit) | 16:32 | |
nowen | hmm. sorry Luiz | 16:33 |
cmatthews | those firewalls support radius... but he left before we were able to respond.. heh | 16:34 |
nowen | and we have a doc on it ;) | 16:38 |
cmatthews | will you need to login to the wikid server also when doing this? | 16:53 |
nowen | hopefully not | 16:54 |
nowen | you have it working through IAS now, right? I suggest we point freenx to IAS | 16:54 |
cmatthews | yep | 16:55 |
nowen | so, you will need to add the freenx box as a client to IAS | 16:55 |
cmatthews | will do | 16:55 |
cmatthews | Just standard raduis client right>/ | 16:57 |
nowen | yeah, should be | 16:57 |
cmatthews | Nick when possible just plz confirm you can login. | 17:07 |
cmatthews | 22 should be open for you. | 17:07 |
nowen | I'm in | 17:08 |
nowen | I assume that 1812 UDP is open b/t this box and ias? | 17:09 |
cmatthews | yeah should be fine | 17:09 |
cmatthews | hmm I'll double check... | 17:11 |
cmatthews | yeah internal we don't have that stuff locked | 17:13 |
cmatthews | surprised me that nps wouldn't allow telnet but I suppose that is normal. | 17:13 |
cmatthews | After you receive payment, do we need to revise certificates or something on the wikid server? | 17:32 |
nowen | no, you're good to go. | 17:32 |
*** cmatthews has quit (Quit: Page closed) | 18:03 | |
*** cmatthews (d8ed3803@gateway/web/freenode/ip.216.237.56.3) has joined #wikid | 18:05 | |
nowen | cmatthews: have you got the nx client? | 18:20 |
cmatthews | not yet | 18:21 |
cmatthews | I'll go grab it | 18:21 |
nowen | can you try to ssh into the freenx server with a WiKID otp? | 18:21 |
nowen | that's a better 1st test | 18:21 |
cmatthews | use my domain username? | 18:24 |
nowen | if that is how it is registered in WiKID, then yes | 18:25 |
cmatthews | access denied | 18:25 |
cmatthews | I can check the IAS log.. | 18:25 |
cmatthews | see if it got hit sec. | 18:25 |
nowen | don't think it id | 18:26 |
nowen | dud | 18:26 |
nowen | did ! | 18:26 |
cmatthews | yeah doesn't look like it | 18:27 |
nowen | ok - try again | 18:41 |
cmatthews | dtill denied | 19:08 |
cmatthews | still | 19:08 |
nowen | hmm. check IAS again. this got a bit furter | 19:09 |
nowen | boy I cannot type today | 19:09 |
cmatthews | yes eee the attempt | 19:10 |
nowen | does it get all the way to wikid? | 19:10 |
*** cmatthews2 (d8ed3803@gateway/web/freenode/ip.216.237.56.3) has joined #wikid | 19:12 | |
cmatthews2 | I see the username prefixed by my domain in the nps log.. | 19:13 |
cmatthews2 | wondering if that is part of the trouble | 19:13 |
cmatthews2 | checking wikid log now.. and sorry for delays | 19:13 |
cmatthews2 | hmm doesn't look like IAS hit wikid | 19:14 |
nowen | np on the delays. I understand | 19:15 |
cmatthews2 | checking nps conditions ... I think it's set to just time based atm | 19:16 |
cmatthews2 | yeah all hits should forward | 19:18 |
cmatthews2 | i'm goign to just try again | 19:18 |
nowen | hmm | 19:20 |
nowen | "Received disconnect from 172.17.12.106: 13: Unable to authenticate" | 19:21 |
nowen | that's not the ias ip | 19:21 |
cmatthews2 | nope | 19:22 |
cmatthews2 | thats my local machine | 19:22 |
nowen | try again | 19:23 |
cmatthews2 | nope | 19:26 |
nowen | did you try with the domain + user or just user? | 19:27 |
cmatthews2 | both | 19:27 |
cmatthews2 | wierd thing is not seeing NPS hit wikid in wikid logs | 19:28 |
nowen | pam_radius_auth: DEBUG: getservbyname(radius, udp) returned 9411552 | 19:28 |
cmatthews2 | sec | 19:28 |
cmatthews2 | HAH | 19:29 |
cmatthews2 | sec I think my acct is locked | 19:29 |
nowen | heh | 19:29 |
cmatthews2 | why it's not being forwarded | 19:29 |
cmatthews2 | unlocked and tried again | 19:36 |
cmatthews2 | still ntohign in wikid logs | 19:36 |
nowen | and this is the same ias that works with the VPN? the only difference is that the radius client is different? Is the network policy the same? | 19:37 |
cmatthews2 | yeah let me see about testing once with firewall to ensure we are still up.. | 19:38 |
cmatthews2 | my firewall IT guy is telling me may be his fault that nps isn't talking to wikid and he's checking. | 19:44 |
nowen | ok | 19:44 |
cmatthews2 | it isn't hitting from the firewall at all right now. | 19:45 |
cmatthews2 | were restarting IAS server | 19:54 |
nowen | ok | 19:54 |
nowen | hmm | 19:58 |
nowen | still no go | 19:58 |
nowen | anything on WiKID? | 19:58 |
cmatthews2 | that seems to be the problem... nothing is going to wikid from nps. | 19:59 |
nowen | is the last thing you see in the WiKID logs the request for the OTP? | 20:05 |
nowen | is the vpn not working either? | 20:05 |
cmatthews2 | yes last wikid entry is OTP request | 20:14 |
cmatthews2 | and | 20:14 |
cmatthews2 | no matter source of NPS request NPS is not passing to wikid. | 20:14 |
cmatthews2 | one thing different | 20:15 |
cmatthews2 | sec | 20:15 |
*** cmatthews2 has quit (Quit: Page closed) | 20:15 | |
cmatthews | yesterday when our firewall was hitting nps the nps log entries looked like this | 20:15 |
cmatthews | 0x3C4576656E743E3C54696D657374616D7020646174615F747970653D2234223E31312F31372F323031302030383A35363A32382E3133333C2F54696D657374616D703E3C436F6D70757465722D4E616D6520646174615F747970653D2231223E45504C2D4E50532D30313C2F436F6D70757465722D4E616D653E3C4576656E742D536F7572636520646174615F747970653D2231223E4941533C2F4576656E742D536F757263653E3C4E41532D506F727420646174615F747970653D2230223E313134313139323333393C2F4E41532D506F72743E3C4672616 | 20:15 |
cmatthews | today they look like this | 20:16 |
cmatthews | <Event><Timestamp data_type="4">11/19/2010 12:14:03.515</Timestamp><Computer-Name data_type="1">EPL-NPS-01</Computer-Name><Event-Source data_type="1">IAS</Event-Source><User-Name data_type="1">matthc01</User-Name><NAS-IP-Address data_type="3">127.0.0.1</NAS-IP-Address><NAS-Identifier data_type="1">sshd</NAS-Identifier><NAS-Port data_type="0">8243</NAS-Port><NAS-Port-Type data_type="0">5</NAS-Port-Type><Service-Type data_type="0">8</S | 20:16 |
cmatthews | one thing I'm not quite getting | 20:16 |
cmatthews | is why or how the nps server is knowing that the request is related at all to epl-dev-07 | 20:17 |
cmatthews | my local machine name | 20:17 |
cmatthews | when I'm originating the request through putty on the freenx system | 20:17 |
nowen | hmm | 20:18 |
cmatthews | I emailed you the full handshake that nps is performing | 20:18 |
cmatthews | I see two rows in the nps log everytime I hit it from the freenx system | 20:19 |
cmatthews | but nothing on the wikid server | 20:19 |
cmatthews | even when I try to login to the freenx ssh with root it isn't letting me now | 20:21 |
cmatthews | is that related | 20:21 |
nowen | no - I have made a change to the /etc/pam.d/sshd file | 20:21 |
nowen | I changed it back though. | 20:22 |
nowen | try logging in one more time, I upped the logging to debug for ssh | 20:23 |
cmatthews | yeah I did........ | 20:25 |
cmatthews | so wierd | 20:25 |
cmatthews | that nps isn't hitting wikid | 20:25 |
nowen | run 'iptables -L -n' on wikid and look for the NPS ip address | 20:27 |
cmatthews | nope | 20:28 |
cmatthews | not their | 20:28 |
nowen | hmm | 20:28 |
cmatthews | wait | 20:28 |
cmatthews | it is | 20:28 |
nowen | ok | 20:28 |
cmatthews | ACCEPT tcp -- 172.17.15.132 0.0.0.0/0 state NEW tcp dpt:49 | 20:29 |
nowen | just wanted to make sure the wikid firewall wasn't blocking | 20:29 |
cmatthews | sorry about this I'm pretty sure someone has done something on my end that changed something and they just don't know it. | 20:30 |
nowen | np | 20:30 |
cmatthews | my staff is all out for food atm. | 20:30 |
cmatthews | I think what we should do since you believe the config should be working is.. | 20:30 |
cmatthews | let me get our firewall testing that had success yesterday back to operations | 20:31 |
cmatthews | operational | 20:31 |
nowen | ok | 20:31 |
cmatthews | then try this on my own | 20:31 |
cmatthews | and then let you know if it is still not working. | 20:31 |
nowen | that works. | 20:31 |
cmatthews | in theory though | 20:31 |
cmatthews | I should be able to just ssh to the centos server and connect with a otp and my acct | 20:31 |
nowen | hold on - I want to test one more thing | 20:32 |
nowen | ok - try one more time | 20:34 |
cmatthews | k | 20:34 |
nowen | ok, yeah. I think you'll need to figure out the NPS > WiKID bit | 20:36 |
nowen | the other thing to test is nps without wikid - can you login to ssh with your AD creds | 20:36 |
nowen | If you can login with your AD creds and the VPN is still working, I would look at the policy | 20:37 |
cmatthews | trying that | 20:37 |
nowen | you can't login to the VPN, look at the network | 20:37 |
cmatthews | yeah I can login to our main FW fine without wikid related. | 20:40 |
cmatthews | can't login to the SSH system with or without domain creds. | 20:41 |
cmatthews | and with or without domain prefix | 20:41 |
nowen | did you remove the NPS policy? | 20:41 |
cmatthews | No I'll try that | 20:41 |
nowen | try that, I;m assuming that will then just auth with AD creds, but I'm not 100% on that | 20:42 |
cmatthews | No either way the system doesn't take the credentials... | 20:46 |
cmatthews | with or without the policy... | 20:46 |
nowen | is that shared secret we shared correct? | 20:46 |
cmatthews | I'll retype in the client config just in case | 20:47 |
cmatthews | just did wikidctl restart to see if / when the radius listener restarts | 20:52 |
nowen | you can also run 'netstat -anp | grep 1812' | 20:52 |
cmatthews | so far returning nothing | 20:53 |
nowen | it might take awhile | 20:53 |
cmatthews | the joy of daemons as I understand it.. | 20:53 |
cmatthews | not yet... | 20:56 |
nowen | hmm. do you also have ldap on? | 20:58 |
nowen | still nothing? | 21:01 |
cmatthews | yeah it eventually started | 21:01 |
cmatthews | and I tried again | 21:02 |
cmatthews | and nps never asked wikid anything | 21:02 |
cmatthews | I'll let you know when I think I'm ready to go again with something functional. | 21:02 |
nowen | ok | 21:02 |
cmatthews | thanks | 21:02 |
*** nowen has quit (Quit: Leaving.) | 23:15 |
Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!