Friday, 2011-09-16

*** nowen (~nowen@adsl-74-176-212-133.asm.bellsouth.net) has joined #wikid12:52
*** scranley55 (d839cdfa@gateway/web/freenode/ip.216.57.205.250) has joined #wikid16:29
scranley55hello16:29
nowenhi16:29
scranley55Hey Nick whats the syntax for the radius attritubes on the radius nc? I seem to be getting garbage in my radius log16:30
nowenhmm.16:31
nowenwhat attribute are you using?16:32
nowenbecause you should be able to just drop the text in and get the text out on the other sie16:33
scranley55Auth-Type := Local, User-Password == "test" Service-Type = Login-User, Framed-IP-Address = 10.10.10.1, Framed-IP-Netmask = 255.255.255.0, Juniper-Primary-Dns = 4.2.2.216:33
nowenand the juniper isn't getting that?16:34
scranley55those Framed-IP-Address and such don't seem to be coming back right16:34
scranley55no the juniper isn't getting it, and in the radius debug it shows up and wierd text.16:34
scranley55Let me try again16:34
scranley55Here this is what im getting16:51
scranley55Framed-IP-Netmask = 0x3235352e3235352e3235352e323438 Framed-IP-Address = 0x3137322e32352e302e323336 Service-Type = 0x4c6f67696e2d55736572 Proxy-State = 0x32303816:51
nowenis the auth failing?16:51
scranley55It says access accepted but then yeah I can't login16:54
scranley55if I take the attributes off then it works16:54
scranley55I mean I can login16:55
scranley55but with no ip assign16:55
nowenI think it must be something on the juniper side16:56
nowenI tested this the other day for the same reason16:56
nowencan you test with radlogin or some other tool?16:56
nowen http://www.iea-software.com/products/radlogin4.cfm16:57
*** Lake_Lurker (~Just@h237.205.140.67.dynamic.ip.windstream.net) has joined #wikid16:57
scranley55but thats before it goes to the juniper, that stuff I pasted is coming directly from Wikid16:58
scranley55rad_recv: Access-Accept packet from host 172.55.10.100 port 1812, id=141, length=84         Reply-Message = "Access Granted"         Framed-IP-Netmask = 0x3235352e3235352e3235352e323438         Framed-IP-Address = 0x3137322e32352e302e323336         Service-Type = 0x4c6f67696e2d55736572         Proxy-State = 0x32303816:59
scranley55thats whats coming from wiki16:59
scranley55wikid16:59
scranley55brb16:59
scranley55ok im here17:05
nowen172.55.10.100 == juniper?17:06
scranley55nope thats wikid17:06
scranley55isn't this supposed to be Framed-IP-Address = radiusFramedIPAddress?17:06
scranley55or something like that17:06
scranley55or do I put quotes are something around it?17:07
nowenno quotes neeed17:09
scranley55maybe my freeradius doesn't understand whats coming from wikid?17:10
scranley55Framed-IP-address seems pretty basic though17:10
scranley55you know17:10
nowenhmm, so it freeradius between wikid and the juniper?17:11
scranley55yes17:12
scranley55freeradius proxies the request to wikid17:12
scranley55wikid replies to freeraidus17:12
scranley55freeradius*17:12
nowencan you test by setting up radlogin as another network client with the same attributes?17:12
scranley55ok17:12
scranley55When you rad client, does a suse 11.4 box with ssh count? I tried it on there and it logged me in even with the garbled attributes17:15
nowenactually, I meant using this tool: http://www.iea-software.com/products/radlogin4.cfm17:16
scranley55ah oops ok17:16
nowenit shows you exactly what is returned by the server in html17:16
nowenI have to re-setup my test server17:23
scranley55hm Microsoft security essentials says it's a trojan, Win32/Sefnit.O17:24
nowenhuh. never ran it on windows.  and it's been a while since i downloaded it17:27
scranley55I'll try it on linux17:28
nowenscranley55: you still here?19:07
*** Lake_Lurker has parted #wikid (None)19:43
nowenping scranley5521:51
nowenyou there?21:51
scranley55im here22:48
scranley55I just sent you a mail22:48
scranley55That did the trick22:48
nowenexcellent!22:48
scranley55It's passing the variables now22:48
scranley55Next step I need to make them dynamic22:48
scranley55cause the ldap server is passing per user22:49
scranley55which ip22:49
scranley55it can't be the same IP for every user22:49
scranley55which is what it will do now22:49
nowencan you specify the range?22:49
scranley55that wont do it, because we have to track each user from the VPN by thier IP. at least that is what we were planning22:50
scranley55maybe it will take variables now22:50
scranley55let me try that22:50
nowendunno22:50
nowenthere is a class in the radius server plugin we use that 'guesses' at the format to use.  so, an ip is an integer.22:50
nowenbut maybe if you use a .0...?22:51
scranley55sorry don't get that .0...22:52
scranley55literally?22:52
nowen10.1.1.022:52
nowenwith a /24?22:53
scranley55not sure let me check22:53
nowenlater guys, I've got to get one home23:40
nowenon home23:41
nowenI will be traveling Monday & Tues, so email me if you need me or use the forums.23:41
*** nowen has parted #wikid (None)23:41

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!