Tuesday, 2013-09-03

*** coolacid has quit (Read error: Connection reset by peer)01:00
*** coolacid (~CoolAcid@2001:470:c025:f00d:8e89:a5ff:fe30:c728) has joined #wikid01:01
*** coolacid has quit (Changing host)01:01
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid01:01
*** Prasad (50a80b3e@gateway/web/freenode/ip.80.168.11.62) has joined #wikid08:46
PrasadHi, Prasad from Subex UK Ltd..08:47
Prasadis there any contact number for wikid sales please?08:47
*** Prasad has quit (Client Quit)08:51
*** nowen (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid12:52
*** JRorie (0c6ee002@gateway/web/freenode/ip.12.110.224.2) has joined #wikid14:10
nowenhey Jason!14:10
JRorieHey Nick.14:10
JRorieI am getting a page cannot be displayed after the install.14:10
nowenok - hmm14:10
nowenrun 'netstat -anp | grep 443'14:11
JRorieIt didn't return anything14:12
nowenok - so WiKID isn't starting.14:12
JRorie80 did14:12
nowenwhat did it return?14:12
JRorie2781/ntpd14:13
JRorierg/kernel/udev/udevd14:13
nowenoh, ok.  that's probably not on http port 8014:13
nowenrun 'more /opt/WiKID/tomcat/logs/catalina.out' and look for an error14:13
JRoriehow do I start the service then?14:13
nowen' wikidctl start' should do it14:14
nowendid you install the latest utilities rpm?14:14
JRoriemorYes, I did.14:14
JRorieI started it and it wants a new password for WikID14:15
JRorieOr new Unix Password that is.14:15
nowenok - you can enter whatever you like for that14:16
nowenare you doing this as root?14:16
JRorieyes14:16
JRorieIt is wanting to go through creating a self signed cert now. Is this all part of the initial install?14:19
JRorieMaybe I just hadn't completed it.14:19
JRorieFrom within the Linux window.14:19
nowenyes - that is for the WiKIDAdmin UI14:20
JRorieGot it.14:20
JRorieOkay. The webpage came up!14:21
nowenawesome14:24
JRorieAfter installing my certificates and restarting the service it says Stopping Tomcat server...usr/bin/sudo: error while loading shared libraries libldap-2.3.so.0: cannot open shared object file: No such file or directory. Then when I try to enter the passphrase I created it comes back and says invalid passphrase.14:40
nowenhmm14:41
nowenrun 'updatedb' and then 'locate libldap'14:42
JRorieneither one of those commands came back with anything.14:43
nowenI'm not sure why you would get that error, but we can probably fix it by running 'yum install openldap'.  Also, go ahead and run 'yum -y update'14:44
JRorieOkay, it is running. Should I try starting after it completes?14:47
nowenyes14:47
nowenalso, you can rerun updatedb and locate libldap.  you should see them now14:47
nowenIs this a virtual machine?14:48
JRorieYes14:49
nowenIf you want to start fresh, I can send you the link for the appliance ISO.  Some of these errors may be from removing WiKID.  If this doesn't work, it might be easiest14:50
JRorieIt took my password and had no errors this time.15:00
nowennice - can you get to the ui?15:08
JRorieI have everything configured, but still cannot get a VPN to connect.15:16
nowenok - what are you seeing?15:17
JRorieI see it hit the firewall, but nothing in the WiKID logs. What should the radius server address be on the firewall? The WiKID server?15:20
nowenyes - port 1812 udp15:20
nowenon the WiKID server you can run 'tcpdump -v port radius' and it will tell you if the packets are getting there15:20
JRorieI don't see anything hitting it.I am pretty sure my Watchguard is setup okay.15:27
nowenhmm15:27
nowendid you restart wikid after add the watchguard as a network client?15:28
JRorieDoes the Watchguad have to be the network client or a Internal radius server? The guy before had a NPS server setup and that listed as the network client.15:30
nowenahh - yes, it can be that way.  In that case, the Watchguard points to NPS and NPS points to WiKID15:31
JRorieThat is probably what is wrong15:31
nowenyou would want NPS to be the network client15:31
nowenmost likely.15:31
nowencheck that the NPS has the new WiKID IP too15:32
JRorieIt Does. It still doesn't seem to be working though.15:37
nowenwell, NPS connection policies are a bit of a mystery15:37
nowendoes it have the watchguard IP correct?15:37
JRorieIt does. I has the IP of the NPS server15:40
nowenwhat is in the Event Viewer?15:40
JRorieThe NPS event log has nothing new in it. Is there a way to do it without NPS?15:43
nowenyes, the Watchguard can talk directly to WiKID.  The benefit of having NPS in the middle is that if you remove/disable a user in AD, they can no longer get remote access. If they talk directly, you have to disable the person in both NPS and WiKID15:45
nowenthis doc might help: http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-nps15:45
nowenof course, if you only have a few users, direct might be simplest16:15
JRorieWe only have a few. I cannot get NPS to work for the life of me.16:57
nowenit's a pain16:57
JRorieSo, how does the direct work then?17:02
nowenoh - just put the WiKID server in the watchguard as the server and put the watchguard in WiKID as a network client17:09
JRorieI tried that, and it isn't communicating from what I can see.17:15
nowendid you try that tcpdump command?17:15
nowenalso, did you restart WiKID after putting the Watchguard in as  a network client?17:17
JRorieI did restart the WiKID. How can you tell if anything came in after running the tcpdump?17:25
nowenwell, you would see it there.  run 'tcpdump port 443' and you'll see17:26
nowenrun 'iptables -L -n' , do you see the Watchguard IP listed?17:26
JRorieI don't.17:27
nowenhmm17:27
nowenok - run 'wikidctl stop'17:27
nowenand then 'killall -9 java17:27
nowen'17:27
nowenand then 'wikidctl start'17:28
JRorieDid that and nada. Does this make a difference per Watchguards site?17:34
JRorieTo establish the PPTP connection the user must be a member of a group named PPTP-Users.Once the user is authenticated, the Firebox keeps a list of all groups that a user is a member of. Use any of the groups in a policy to control traffic from the user.17:34
nowengot me, not very familiar with the watchguard17:34
nowendo you see the old NPS address listed in iptables?17:35
JRorieNo, only 127.0.0.1 and 0.0.0.017:36
nowenrun 'service iptables stop' and then the tcpdump command and try to login again17:37
JRorieNo luck with that either.17:41
JRorie0 packets captured.17:41
nowenso, I'm pretty sure it must be the watchguard.17:42
nowenyou are using port 1812, right?17:56
JRorieYes, I am. It's weird. I can see it allowing the traffic through18:00
JRorieIs it PPTP?18:02
nowenno - the radius traffic is 1812 for the watchguard to wikid auth traffic18:05
nowenthe old port is 1645, so sometimes firewalls offer up both18:05
JRorieUsing windows built in VPN client should work though, right?18:06
nowenyes18:07
nowenjust wanted to check what your settings are the the radius server on the watchguard18:07
nowenwhat are the options under the authentication servers for the watchguard?18:08
nowenthe watchguard may be one of the ones still using port 164518:17
JRorieIt is 1812. I am going to try a firmware upgrade.18:18
nowenhmm18:19
nowenwhat errors do you get in the Watchguard logs?18:19
JRorieI get no errors at all.18:20
nowenbut does the authentication fail?18:20
JRorieIt never says whether it does or not. It never even says it is trying to authenticate.18:29
nowenwe are way out of my area18:32
JRorieI opened a case with Watchguard too. I would think I would see something in the logs. It is almost like it is not sending the radius trafic20:05
nowenhmm20:05
nowenwhich watchguard model is it?20:06
JRorieXTM 505 I use it in other offices with Radius.20:07
nowenok - so you know way more than I do.20:12
nowentime for me to check out21:42
*** nowen has quit (Quit: Leaving.)21:46

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!