Friday, 2011-01-07

*** nowen (~nowen@adsl-176-210-205.asm.bellsouth.net) has joined #wikid13:19
*** gvidals_ (18f9cf04@gateway/web/freenode/ip.24.249.207.4) has joined #wikid17:27
gvidals_owen is it possible to have  linux server that is ONLY on a private IP use two factor auth?17:28
nowengvidals_: not sure I follow.  is the server the wikid server or the target server?17:29
gvidals_the problem is that the domain for the wikid server is a public IP 20715801001117:29
nowenok - you can nat the WiKID server17:29
nowenthat's fine17:30
nowenas long as the traffic gets to the WiKID server17:30
gvidals_so the wikid server has both a public and private IP and has a domain of 207158010011 and the ubuntu server is only on a private IP.17:30
nowenthe ubuntu server is your ssh target?17:31
gvidals_so in pam_radius_auth.conf i chanted the server from 207.158.158.11 to 10.84.168.1117:31
gvidals_i thought this should work without having to do nat?17:31
nowenthe wikid server doesn't need to have the external ip - if you have a firewall doing nat.17:32
gvidals_yes ubuntu server is ssh target17:32
nowenor it can have the external ip17:32
gvidals_:q17:32
nowenI was thinking you wanted to nat it.. but you don't have to17:34
nowenis this for *another* customer?? ;)17:34
gvidals_this is for the first customer.17:37
nowenok ;)17:37
gvidals_does the wikid domain 207158010011 have any bearing on the ssh target being on a private IP?17:38
nowenno - it is just about the tokens17:39
gvidals_ok.17:39
nowenonly the WiKID server needs to talk to the ssh target box17:39
gvidals_may be i have to restart pam services or something for the changes in pam_radius_auth to take effect? i don't how to to restart it...17:39
nowenno need to restart17:40
nowenwhat is the error your getting?17:40
nowenyou might look in /var/log/secure on the target17:40
gvidals_The NAS IP supplied does not match the NAS table17:42
gvidals_that is the entry in the wikid log.17:42
nowenis the network client IP correct?17:42
gvidals_so the ubuntu ssh target had two IPs - a public and private one - i disabled the public IP and changed pam_radius_auth.conf to include the private IP for the wikid server.17:44
nowenok - is the private ip what is used on the WiKID server Network clients tab?17:44
gvidals_so it seems that the wikid server is expecting the IP from the ubuntu target to be a public IP.17:45
nowenjust delete the old network client and create a new one with the private ip and restart17:45
nowenradius will not accept packets from unknown ips17:45
gvidals_ok i see what you mean. instead of deleting, i modified the network client and now it works :-)17:51
gvidals_thanks again.17:51
nowenok cool!17:51
gvidals_i have two more opportunities for wikid servers. hopefully one will come through soon.17:51
gvidals_and i plan on downloading the NFR one you said you would give me soon.17:51
nowenplease do!17:52
gvidals_we'll be able to get more business once the rankings for "hipaa compliant hosting" go up.17:52
gvidals_currently we made it to position #10 in google and so we are on the home page.17:53
nowenexcellent17:53
gvidals_we're targeting being in the top #1-3 spot so we have more work to do.17:53
nowenanything I can do?17:53
gvidals_yes, if you can put a link on your website to www.vmracks.com (instead of esx-hosting.vm-racks.com)17:54
gvidals_we recently go rid of the esx-hosting.vm-racks.com for the shorter www.vmracks.com17:54
nowenok17:55
gvidals_i would like to do another press release like we did last time. if you are up for it, let me know and i can write one.17:55
nowenwebsite updated17:56
nowensure17:56
gvidals_that was fast. thanks18:01
nowennp18:02
*** gvidals_ has quit (Ping timeout: 265 seconds)18:35
*** jhill_ (ada1a201@gateway/web/freenode/ip.173.161.162.1) has joined #wikid19:22
jhill_Hello, I'm testing out WiKID integrating with NPS and am having trouble NPS to look at AD user accounts before passing the request off to WiKID19:24
nowenhold on one minute - on the phone19:24
jhill_will do19:24
nowenok - thanks19:31
nowenall the sudden real busy ;)19:31
jhill_I understand :)19:31
nowenare you following the how to?19:32
jhill_I did19:32
nowendamn phone again19:33
jhill_:)19:33
jhill_I have to step out for a minute, but here's my issue in a nutshell...20:04
jhill_Trying to connect a firewall / VPN to NPS+WiKID. The firewall is set up as a RADIUS client on NPS, with a shared secret. The firewall has a RADIUS server configured pointing to NPS, with that same shared secret.  The WiKID server is configured in NPS as a RADIUS server, with a separate shared secret. I've configured a Connection Request Policy to forward authentication to WiKID.    At this point, I can test the auth and am successful, 20:04
nowenok20:04
jhill_mbers of the AD domain.20:04
nowensorry :(20:05
nowenok - bio-break and I'll be right back20:08
nowenjhill_: let me know when you're back20:11
jhill_OK, I'm back20:27
nowenok20:27
nowenso, tell me where it is failing?  the user doesn't have to be in the right group?20:28
jhill_Right, I created a WiKID-only user and can auth successfully20:29
nowenok, so the settings in nps aren't quite right somehow. the permissions aren't getting checked20:29
jhill_Yep, that seems right20:30
nowenon your network policy, what is set for the conditions?20:31
jhill_I think that's where the problem is... I can't seem to figure out the connection between the Connection Request Policy (where WiKID's configured) and the Network Policy.20:32
nowenyeah, there's not much on the doc.20:33
noweni have notes for IAS, the nps predecessor20:34
nowenConnection Request Policies > Edit Profile > 'Advanced' Tab > Add 'Remote-RADIUS-to-Windows-User-Mapping' = true20:34
jhill_I read that too, but couldn't the equivalent in 200820:34
nowenis there something for settings?20:37
nowenyou should be able to add Remote-RADIUS-to-Windows-User-Mapping20:37
nowenall I have is a screen grab20:38
nowenbut it looks like policy >> condition >> settings?20:38
jhill_Let me take a look20:38
jhill_Here http://technet.microsoft.com/en-us/library/cc771347.aspx it says that it should be in the Connection Request Policy20:43
nowenhmm. yes.20:50
nowenI'll try to start up our nps vm20:50
jhill_OK, I've got to head out for a bit again. I'll leave the window open, if you see it, let me know. Otherwise, I'll circle back around when I figure it out. :)20:51
nowenok, please do. I would like to add it to the docs20:52
nowenjhill_: check out http://aaronwalrath.wordpress.com/2010/06/22/install-windows-2008-r2-nps-for-radius-authentication-for-cisco-router-logins/20:53
jhill_I get that option in the Network Policies, but not the connection request policy20:55
nowendo you have conditions set for the connection request policy?21:01
jhill_Yeah, just the IP of the firewall21:02
nowenlike that the client ipv4 address be you firewall?21:02
jhill_yep21:02
nowenhttp://technet.microsoft.com/en-us/library/cc753603.aspx21:03
nowenit's not clear how the settings are entered tho21:06
*** nowen has parted #wikid (None)23:25

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!