Friday, 2011-01-21

*** nowen (~nowen@adsl-176-210-205.asm.bellsouth.net) has joined #wikid13:15
*** JP_ (cf683602@gateway/web/freenode/ip.207.104.54.2) has joined #wikid18:06
JP_Hello... I am having a slight issue with the Network Clients. I have added my Cisco ASA as a network client using radius. I have setup two domains, one for remote mobile clients and another for internal PCs. My mobile client domain code is an external facing IP, my internal domain code is a private IP. I am using the same network client (Cisco ASA) IP address in both domains. The problem I am having is that when I go to authenticate to my 18:13
JP_wikid is mapping it to my internal domain code.18:13
JP_and rejecting my mobile token18:13
nowenyeah, each network client must be limited to one domain in radius.  I guess you are using the same IP address for both network clients?18:14
nowenis it possible to use a different network client?18:14
JP_yes. it seems that having the same network client in two domains may be the issue?18:14
nowenyes - it's a problem only for radius18:15
JP_no, our users would only be connecting to the Cisco ASA for remote access18:15
JP_ah ok18:15
nowensome people create a firewall rule to allow internal requests hit the outside ip, but that might be an issue for you18:16
JP_i was thinking the same thing18:16
JP_in practice we wouldn't be doing much internal authentication anyways18:16
JP_I am just using it for testing purposes18:17
nowenyeah, I think that's the other part - we see this in testin,g but not productino18:17
JP_ok, good to know, thanks again.18:17
nowennp18:17
*** JP_ has quit (Quit: Page closed)18:17
*** sean (43a40ced@gateway/web/freenode/ip.67.164.12.237) has joined #wikid21:11
seanNick?21:11
nowenyes21:11
*** sean is now known as Guest4367021:11
Guest43670Hi - I just emailed you back21:11
Guest43670Anyways21:12
nowenahh21:12
Guest43670How long does it take to get the CERT back?21:12
nowennone - it comes in a popup now ;)21:12
nowenbut I can mail it to you also ;)21:12
Guest43670I just submitted it and it told me to wait for an email...21:13
Guest43670the submission was in a popup21:13
nowenbe sure to cut and paste as plain text21:13
Guest43670for the CSR21:13
nowenyeah, it should come back in the same pop up21:13
Guest43670i closed that popup heh21:13
nowenhehe.   what version of openvpn?21:13
Guest436701.6.121:14
nowenthe opensource version?21:14
Guest43670i don't think so21:14
Guest43670i downloaded the centos package from their website21:14
nowenwell, Access Server has built-in support for Radius21:15
Guest43670yea I downloaded openvpn-as21:16
Guest43670that's the right one correct?21:16
nowenthey both work, AS is a bit easier21:16
Guest43670cool21:17
Guest43670so I guess I just need the signed cert21:17
Guest43670ah got it21:17
nowenI don't have a doc on it, but just create a network client on the WiKID server that uses radius and on AS, tell it to use radius and point it to wikid21:17
nowenuse port 1812 UDP21:17
Guest43670im following the howto here: http://www.howtoforge.com/how-to-add-two-factor-authentication-to-openvpn-as-with-the-wikid-strong-authentication-server-p221:18
nowenhaha. I forgot about that one!21:18
Guest43670hopefully that works21:18
nowenyeah it should21:18
Guest43670sweet.21:18
Guest43670OK thanks for the info. I'm gonna get back to it. I'll come back if I run into trouble :)21:19
nowenok21:19
nowenI'm east coast time, btw21:19
Guest43670ok thx21:19
*** Guest43670 has quit (Ping timeout: 265 seconds)21:24
*** sean (43a40ced@gateway/web/freenode/ip.67.164.12.237) has joined #wikid22:52
*** sean is now known as Guest5229822:52
Guest52298are you still around, Nick?22:53
nowenyep22:53
Guest52298Maybe you can help me out here...22:53
nowensure22:53
Guest52298I have everything setup with the token etc22:53
Guest52298it connects to the wikid server and i enter my pin and it gives me a temp pass22:53
nowenok22:53
Guest52298then i go to the openvpn server22:54
Guest52298download & install the software22:54
Guest52298and nothing happnes22:54
Guest52298I login with my user and pass and it takes me to the "download the installer and then you will be connected automatically" page22:54
nowenhmm. I don't remember much about installing openvpn22:55
Guest52298any ideas?22:55
Guest52298it's in your HOWTO22:55
nowenhehe. let me look at it again22:55
Guest52298http://www.howtoforge.com/how-to-add-two-factor-authentication-to-openvpn-as-with-the-wikid-strong-authentication-server-p222:55
Guest52298at the bottom22:55
nowenahh22:56
Guest52298yea heh22:56
nowenok, so you want to install the Windows client and use the client.opvn file22:56
nowenI mean the other one22:56
nowendid you install the client?22:56
Guest52298where is this client file?22:56
Guest52298yea22:56
Guest52298openvpn client is installed22:57
nowenand did  you pu the config where it is suppose to go?22:57
Guest52298i didn't see anything about config in your howto22:57
Guest52298did i miss it?22:58
nowenwell, I really focused on the integration side. I guess I assumed that openvpn was already setup22:58
Guest52298when you get the "download" link, it looks nothing like how you have it22:59
Guest52298there is no link to opvn file22:59
nowenthey may have updated it22:59
Guest52298so there is some extra setup in openvpn i need to do?22:59
nowenthe user is getting validated?23:00
Guest52298yes23:00
nowendoes it look like this: http://openvpn.net/index.php/access-server/docs/admin-guides/457-connect-to-openvpn-access-server-using-the-connect-client.html23:00
Guest52298but then it re-directs me do the download page again23:00
Guest52298yup23:01
Guest52298i get past that23:01
nowenmaybe you need to restart the client?23:01
Guest52298i did that multiple times23:01
nowenwhat is it supposed to look like?23:01
nowenI guess that last screen ship23:01
nowenshot23:01
Guest52298i have no idea - but i know for a fact I don't get assigned an IP23:01
Guest52298see the 2nd screenshot?23:02
Guest52298in that link you sent me23:02
nowenyes23:02
Guest52298that's where I get stuck23:02
Guest52298I never get "connected"23:02
nowencan you install the client?23:02
Guest52298even though i already have the client installed23:02
Guest52298yea23:02
nowendo you have the little icon on the task bar?23:03
Guest52298yup23:03
Guest52298orange/white icon23:03
Guest52298"disconnect" is greyed out23:03
nowenis there an option to connect?23:04
Guest52298i even have my antivirus off, and I disabled iptables on the server23:04
Guest52298yes23:04
Guest52298when I "Go to x.x.x.x:1194"23:04
nowenand you connect and get that screen again23:04
Guest52298it goes to the install screen23:04
Guest52298yup23:04
nowenand you've rebooted?23:04
nowenand you've installed it in a location where you have permissions?23:05
Guest52298yea23:05
Guest52298i'll try uninstalling and re-installing23:05
nowenyou might try #openvpn23:05
nowenI really only test it enough to get the docs done23:05
Guest52298ok np23:06
Guest52298thank you23:06
nowenyeah, let me know what you find out23:07
nowenmight be time to update the docs23:07
Guest52298will do23:07
Guest52298bleh. they re-directed me to their support web page.23:12
nowenhmm23:12
Guest52298i'll try and figure this out and let you know if i fix it.23:12
nowenok23:12
nowensorry23:12
*** Guest52298 has quit (Quit: Page closed)23:12
*** nowen has parted #wikid (None)23:12

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!