Tuesday, 2011-03-15

*** nowen (~nowen@adsl-66-184-38.asm.bellsouth.net) has joined #wikid12:51
*** malcolm (29df2122@gateway/web/freenode/ip.41.223.33.34) has joined #wikid13:11
malcolmHi Neil13:12
nowenHi13:12
nowenbut it is NIck :)13:12
malcolmsorry I meant Nick13:12
nowennp :)13:12
malcolmI was looking at an email alert from someone in my company called Neil13:12
malcolm;)13:12
malcolmI have a quick question regarding the setup we now have13:13
nowenok13:13
malcolmWe have bought the 1 year 0 user license13:13
malcolmhow do we go about setting it up13:13
malcolmthats the first13:13
nowenmalcolm: no need -we track usage via the certificate13:13
malcolmsecondly - where in the radius logs to we find a successful and failed attempts ?13:14
nowenhmm, you're not seeing anything in the WiKIDAdmin logs?13:14
malcolmjust tailing /opt/WiKID/log/radius.log doesn't gie much13:14
nowenIf you want to see the logs in the /opt/WiKID/log directory as well as in the WiKIDAdmin, then you can edit the /etc/WiKID/log4j.properties file to this:13:16
nowenhttp://pastebin.com/MUGwqmud13:16
nowenand restart the server13:16
nowennot sure how much data that will create, so keep an eye on disk usage13:16
malcolmwhere in the WiKIDadmin logs13:17
malcolm?13:17
nowenon the web ui, top right corner there is a link to logs13:17
malcolmah ok let em check that13:18
malcolmwhich "logger" do i choose ?13:18
nowenTo enable debugging for radius, you need to go to Configuration/Enable Protocols/Radius and set debug to True. Restart the server and then go13:19
nowento Logs/Configure Loggers and set com.wikidsystems to debug and add com.wikidsystems.radius.log.DBSvrLogImpl and set it to debug as well.13:19
malcolmok13:19
malcolmdoes the radius support ms-chap ?13:21
nowenyes13:21
malcolmok I am getting this error: 64> Access-Request(1) LEN=216 192.168.10.1:1025 Access-Request by XXXXXXFailed: AccessRejectException: Microsoft MS-CHAP failed authentication13:22
nowenwhat is the network client?13:23
malcolmASA Firewall13:23
malcolmit worked13:23
nowenalso, you should be able to get more info than that.13:24
malcolmuntil we chanegd the domain address13:24
nowendid you restart the server after that?13:24
malcolmjust the WiKID Services13:25
malcolmthis was the domain Live IP13:25
nowenhmm13:25
malcolmswitched it13:25
nowenok, did you make the changes to the loggers?  com.wikidsystems to debug, com.wikidsystems.radius.log.DBSvrLogImpl debug ?13:27
malcolmyes13:28
malcolmboth are debug13:28
nowenis that the only info you're getting?13:28
malcolmwhere do I find the com.wikidsystems on thelist13:28
malcolmto view it13:28
malcolmAh ha13:29
malcolmfound the problem13:29
nowenlog level?13:29
malcolmthe domain code is wrong13:29
malcolmin the wikidaccess4 log13:29
malcolmit still has the old diomain (IP) code13:29
nowenhmm.  maybe you should delete the network client all together and start over13:30
malcolmI have just done that13:30
malcolmShould I delete - stop start then recreate stop start ?13:30
nowenyeah, I think it is worthwhile13:30
malcolmok13:31
malcolmits wierd - only have 1 domain listed in my admin portal13:31
malcolmwe already removed the domain I believe this error is coming up with13:31
malcolmIt seems the domain conf is broken13:32
malcolmfrom what I can tell it still has reference to the old domain "IP)13:33
nowenhmm13:33
nowenwell, I know that the radius server maintains a cache of the data.  perhaps it is not getting cleared?13:34
malcolmI am going to try and remvoe the network client section stop start etc quick13:34
malcolmhow do I clear it13:34
malcolm?13:34
nowenit should clear on a stop.  you can run 'netstat -anp | grep java' to be sure.  and 'killall -9 java' will kill any hanging processes13:35
nowenare you running replication?13:36
malcolmno - seems java was still running after the stop13:37
malcolmjust made the changes13:37
malcolmlets see13:37
malcolmSeems a little better - just waiting to test vpn13:46
malcolmNick - have u received the payment ?13:49
malcolmis it possible to get an invoice ?13:49
malcolmNick - that seems to have worked13:51
nowenmalcolm: good news.  yea, I can email a payment note14:03
nowenmalcolm: have you played with the example.jsp page?14:05
malcolmno - not yet14:17
nowenmalcolm: that is how you can add a second token to the same users, etc14:25
malcolmah - i will have t o have a look14:40
malcolmWe seem to have another issue -14:40
nowensame with the ADRegister.jsp14:41
malcolmthe system is not generating any traffic now14:41
malcolmand I am unable to login14:41
malcolmI logged  in once and now nothing14:41
nowenyou can't login to the vpn?14:41
malcolmno14:41
malcolmno logs being generated either14:41
nowenis there a passcode request?14:42
malcolmyes14:42
malcolmit seems the radius service took ages to start14:43
nowenoh, yeah, that is a known issue14:43
nowensorry.  we can't quite figure out if it is us, or upstream14:43
malcolmany work arounds14:43
malcolmis that it checking the certificate ?14:43
malcolmis our certificate now registered ?14:44
nowenyes14:44
nowenit's not the cert.  something else.  however, once you're in production, you won't be restarting14:44
malcolmthis box is now in production ;)14:45
malcolmThanks14:45
malcolmSeems thats the problem14:45
malcolmWhat services should we be monitoring to conform that the system is up ?14:46
malcolmit took 30 mins for the radius service to start14:47
nowenwell, the tokens are on 80, the admin 443, radius udp 181214:47
nowenreally?  what type of server is this?14:47
malcolmSLES 1114:48
nowenhow much memory?14:48
malcolm2GB14:49
nowenhmm14:49
nowenis there a lot of other stuff running?14:49
malcolmsquid, postfix, zabbix proxy14:50
malcolm+ WiKID14:50
malcolmI have to run15:04
malcolmPlease can you email me your response15:04
malcolmThanks15:04
*** bigbash has quit (Quit: ZNC - http://znc.sourceforge.net)17:24
*** nowen has quit (Quit: Leaving.)21:58

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!