Re: [lms] Radius+LMS+ MAC Authentication
Tak wygląda podłączenie mikrotik do radiusa
Ready to process requests. rad_recv: Accounting-Request packet from host 10.0.0.2 port 48102, id=3, length=48 Acct-Status-Type = Accounting-On NAS-Identifier = "MikroTik" NAS-IP-Address = 10.0.0.2 Acct-Delay-Time = 0 +- entering group preacct ++[preprocess] returns ok rlm_acct_unique: WARNING: Attribute NAS-Port was not found in request, unique ID MAY be inconsistent rlm_acct_unique: WARNING: Attribute Acct-Session-Id was not found in request, unique ID MAY be inconsistent rlm_acct_unique: WARNING: Attribute User-Name was not found in request, unique ID MAY be inconsistent rlm_acct_unique: Hashing ',Client-IP-Address = 10.0.0.2,NAS-IP-Address = 10.0.0.2,,' rlm_acct_unique: Acct-Unique-Session-ID = "f86ac4289cbec3af". ++[acct_unique] returns ok ++[files] returns noop +- entering group accounting expand: /var/log/freeradius/radacct/%{Client-IP-Address}/detail-%Y%m%d -> /var/log/freeradius/radacct/10.0.0.2/detail-20111106 rlm_detail: /var/log/freeradius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands to /var/log/freeradius/radacct/10.0.0.2/detail-20111106 expand: %t -> Sun Nov 6 19:10:01 2011 ++[detail] returns ok ++[unix] returns noop expand: /var/log/freeradius/radutmp -> /var/log/freeradius/radutmp rlm_radutmp: NAS MikroTik restarted (Accounting-On packet seen) ++[radutmp] returns ok Sending Accounting-Response of id 3 to 10.0.0.2 port 48102 Finished request 1. Cleaning up request 1 ID 3 with timestamp +228 Going to the next request Ready to process requests. --------------------------------------------------------------------------------------
A tak wygląda podłączenie klienta pod wifi
Ready to process requests. rad_recv: Access-Request packet from host 10.0.0.2 port 51605, id=4, length=133 Service-Type = Framed-User NAS-Port-Id = "wlan1" User-Name = "00:12:F0:E9:74:B7" Calling-Station-Id = "00-12-F0-E9-74-B7" Called-Station-Id = "00-02-6F-46-F9-DD:MikroTik" User-Password = "" NAS-Identifier = "MikroTik" NAS-IP-Address = 10.0.0.2 +- entering group authorize ++[preprocess] returns ok ++[chap] returns noop ++[mschap] returns noop expand: %{User-Name} -> 00:12:F0:E9:74:B7 rlm_sql (sql): sql_set_user escaped user --> '00:12:F0:E9:74:B7' rlm_sql (sql): Reserving sql socket id: 13 expand: SELECT id, upper(mac) as UserName , 'User-Password' as Attribute, '' as Value, '==' as op FROM nodes WHERE upper(mac) = '%{SQL-User-Name}' and access=1 ORDER by id -> SELECT id, upper(mac) as UserName , 'User-Password' as Attribute, '' as Value, '==' as op FROM nodes WHERE upper(mac) = '00:12:F0:E9:74:B7' and access=1 ORDER by id rlm_sql_mysql: MYSQL check_error: 1054 received rlm_sql_getvpdata: database query error rlm_sql (sql): SQL query error; rejecting user rlm_sql (sql): Released sql socket id: 13 ++[sql] returns fail Invalid user: [00:12:F0:E9:74:B7/] (from client MikroTik port 0 cli 00-12-F0-E9-74-B7) Delaying reject of request 2 for 1 seconds Going to the next request
uczestnicy (1)
-
Jakub