<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-1102</id>
	<title>Nabble - FreeRadius</title>
	<updated>2009-12-21T14:16:55Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/FreeRadius-f1102.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeRadius-f1102.html" />
	<subtitle type="html">FreeRadius home is &lt;a href=&quot;http://www.freeradius.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26880926</id>
	<title>Re: Virtual Server not setting attributes on reply</title>
	<published>2009-12-21T14:16:55Z</published>
	<updated>2009-12-21T14:16:55Z</updated>
	<author>
		<name>Alan Buxey</name>
	</author>
	<content type="html">Hi,
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I think we're getting too far into the detail and losing sight of the
&lt;br&gt;&amp;gt; problem I was trying to report initially.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'd expect the only difference between the proxying to a remote server,
&lt;br&gt;&amp;gt; and proxying to a virtual server to be efficency / ports used, not
&lt;br&gt;&amp;gt; functionality, aka it's more efficnt to use virtual_server= rather
&lt;br&gt;&amp;gt; than define a remote radius server, then have the virtual server
&lt;br&gt;&amp;gt; listen on odd numbered ports on localhost.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; There seems to be a functionality difference when proxied to a virtual server.
&lt;/div&gt;&lt;br&gt;well, looking from the log, your virtual_server doesnt appear to set any attribute
&lt;br&gt;in its post-auth stage. calling the right thing or SQL table? 
&lt;br&gt;&lt;br&gt;my initial thought was your attr_filter wasnt allowing that attribute
&lt;br&gt;through from the virtual_server (much like it would strip it out
&lt;br&gt;if the domain/realm wasnt allowed - check pre-proxy and post-proxy parts)
&lt;br&gt;&lt;br&gt;alan
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Virtual-Server-not-setting-attributes-on-reply-tp26873711p26880926.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26879351</id>
	<title>Re: Virtual Server not setting attributes on reply</title>
	<published>2009-12-21T12:08:59Z</published>
	<updated>2009-12-21T12:08:59Z</updated>
	<author>
		<name>Timothy-45</name>
	</author>
	<content type="html">I think we're getting too far into the detail and losing sight of the
&lt;br&gt;problem I was trying to report initially.
&lt;br&gt;&lt;br&gt;I'd expect the only difference between the proxying to a remote server,
&lt;br&gt;and proxying to a virtual server to be efficency / ports used, not
&lt;br&gt;functionality, aka it's more efficnt to use virtual_server= rather
&lt;br&gt;than define a remote radius server, then have the virtual server
&lt;br&gt;listen on odd numbered ports on localhost.
&lt;br&gt;&lt;br&gt;There seems to be a functionality difference when proxied to a virtual server.
&lt;br&gt;&lt;br&gt;Tim
&lt;br&gt;&lt;br&gt;2009/12/21 Alan Buxey &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26879351&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;A.L.M.Buxey@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Not the default virtual server. The test virtual server
&lt;br&gt;&amp;gt;&amp;gt; The flow is client -&amp;gt; default virtual server acting as a proxy -&amp;gt; test
&lt;br&gt;&amp;gt;&amp;gt; virtual server
&lt;br&gt;&amp;gt;&amp;gt; If the test virtual server is configured as a remote radius server
&lt;br&gt;&amp;gt;&amp;gt; then things work great. If it's configured as a virtual server using
&lt;br&gt;&amp;gt;&amp;gt; the &amp;quot;virtual_server=name&amp;quot; then things break.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; test virtual server not setting the options byt he looks of it...
&lt;br&gt;&amp;gt; post-auth is called in that virtual server - so how should it be getting/setting
&lt;br&gt;&amp;gt; that attribute?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; alan
&lt;br&gt;&amp;gt; -
&lt;br&gt;&amp;gt; List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Virtual-Server-not-setting-attributes-on-reply-tp26873711p26879351.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26879333</id>
	<title>Re: Virtual Server not setting attributes on reply</title>
	<published>2009-12-21T12:08:31Z</published>
	<updated>2009-12-21T12:08:31Z</updated>
	<author>
		<name>Timothy-45</name>
	</author>
	<content type="html">I think we're getting too far into the detail and losing sight of the
&lt;br&gt;problem I was trying to report initially.
&lt;br&gt;&lt;br&gt;I'd expect the only difference between the proxying to a remote server,
&lt;br&gt;and proxying to a virtual server to be efficency / ports used, not
&lt;br&gt;functionality, aka it's more efficnt to use virtual_server= rather
&lt;br&gt;than define a remote radius server, then have the virtual server
&lt;br&gt;listen on odd numbered ports on localhost.
&lt;br&gt;&lt;br&gt;There seems to be a functionality difference when proxied to a virtual server.
&lt;br&gt;&lt;br&gt;Tim
&lt;br&gt;&lt;br&gt;Alan Buxey wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Not the default virtual server. The test virtual server
&lt;br&gt;&amp;gt;&amp;gt; The flow is client -&amp;gt; default virtual server acting as a proxy -&amp;gt; test
&lt;br&gt;&amp;gt;&amp;gt; virtual server
&lt;br&gt;&amp;gt;&amp;gt; If the test virtual server is configured as a remote radius server
&lt;br&gt;&amp;gt;&amp;gt; then things work great. If it's configured as a virtual server using
&lt;br&gt;&amp;gt;&amp;gt; the &amp;quot;virtual_server=name&amp;quot; then things break.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; test virtual server not setting the options byt he looks of it...
&lt;br&gt;&amp;gt; post-auth is called in that virtual server - so how should it be getting/setting
&lt;br&gt;&amp;gt; that attribute?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; alan
&lt;br&gt;&amp;gt; -
&lt;br&gt;&amp;gt; List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;/div&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Virtual-Server-not-setting-attributes-on-reply-tp26873711p26879333.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26879223</id>
	<title>Re: MAC authentication bypass --- How am I supposed	to?edit?theusers?file to include multiple MAC addresses??</title>
	<published>2009-12-21T11:58:44Z</published>
	<updated>2009-12-21T11:58:44Z</updated>
	<author>
		<name>Arran Cudbard-Bell</name>
	</author>
	<content type="html">On 21/12/2009 09:05, Alexander Clouter wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Arran Cudbard-Bell &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26879223&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;a.cudbard-bell@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; the real answer is to get the vendors to sort their cheap shoddy kit out ;-)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; Ahem *Vendor :P - - &amp;nbsp;Sorry I have to do it or they beat me :(
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt; ....dare I ask why you do not use you new 'formal' email address? ;)
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;Because i'm not on site, they've not worked out how to do webmail
&lt;/div&gt;outside of the
&lt;br&gt;intranet, and they've disabled the entourage connector in exchange.
&lt;br&gt;&lt;br&gt;arran.cudbard-bell@popular british manufacturer of tomatoe and brown
&lt;br&gt;sauce.com
&lt;br&gt;&lt;br&gt;Should be back for January *sigh*.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (266 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26879223/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/MAC-authentication-bypass-----How-am-I-supposed-to-edit-the-users-file-to-include-multiple-MAC-addresses---tp26851201p26879223.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26879164</id>
	<title>Re: MAC authentication bypass --- How am I supposed	to?edit?theusers file to include multiple MAC addresses??</title>
	<published>2009-12-21T11:52:57Z</published>
	<updated>2009-12-21T11:52:57Z</updated>
	<author>
		<name>Arran Cudbard-Bell</name>
	</author>
	<content type="html">On 21/12/2009 09:15, Alan Buxey wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; yep - but a user could just as easily log in with the user-name of
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 00:11:22:33:44:55 ;-) 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; Not when you say !EAP-Message too :)
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt; ...and how does that stop, lets just say for example, some user coming
&lt;br&gt;&amp;gt; along with 802.1X configured on their wired interface and logging it
&lt;br&gt;&amp;gt; with 00:11:22:33:44:55 as their user-name with EAP-MD5 ? &amp;nbsp;;-)
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;Last time I checked EAP-MD5-Response was still carried in the
&lt;/div&gt;EAP-Message attribute,
&lt;br&gt;and the documentation in the wiki suggests that the username and
&lt;br&gt;Calling-Station-ID
&lt;br&gt;are canonicalized and compared before attempting Mac-Auth, so you need
&lt;br&gt;to fake
&lt;br&gt;the mac-address in your EAPOL frames too.
&lt;br&gt;&amp;gt;&amp;gt; Although it does nothing about the legacy guff, it stops new guff 
&lt;br&gt;&amp;gt;&amp;gt; connecting.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt; thats true in so much that it controls those things...but lets more evil
&lt;br&gt;&amp;gt; people on due to it being a nice new hole. &amp;nbsp;oh well.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;Well no. You need to know the Mac-Address of a target machine before you
&lt;br&gt;can connect to the network/VLAN.
&lt;br&gt;In order to find out the Mac-Address you need to physically locate
&lt;br&gt;yourself at a terminal, if you can
&lt;br&gt;physically locate yourself at a terminal, you generally have access to
&lt;br&gt;the network connection of the
&lt;br&gt;terminal anyway.
&lt;br&gt;&lt;br&gt;The only thing it lets you do which you could do before, is to do your
&lt;br&gt;cracking in a cafe instead
&lt;br&gt;of in a cluster room :).
&lt;br&gt;&lt;br&gt;The real danger is someone gaining access to the uplink from one your
&lt;br&gt;switches...
&lt;br&gt;which is why 802.1X-REV/Mac-Sec is so frickin awesome!
&lt;br&gt;&lt;br&gt;-Arran
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (266 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26879164/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/MAC-authentication-bypass-----How-am-I-supposed-to-edit-the-users-file-to-include-multiple-MAC-addresses---tp26851201p26879164.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26878601</id>
	<title>Re: STILL Trying to get tunneling to work</title>
	<published>2009-12-21T11:09:19Z</published>
	<updated>2009-12-21T11:09:19Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">Mike Bernhardt wrote:
&lt;br&gt;&amp;gt; ERROR: Failed to create a new socket for proxying requests.
&lt;br&gt;&amp;gt; ERROR: Failed inserting request into proxy hash.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Install 2.1.8 when it comes out. &amp;nbsp;That should be tomorrow, or maybe
&lt;br&gt;Wednesday.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/STILL-Trying-to-get-tunneling-to-work-tp26877255p26878601.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26878585</id>
	<title>Re: ttls+eap-md5</title>
	<published>2009-12-21T11:07:55Z</published>
	<updated>2009-12-21T11:07:55Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">anyi_9 wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;Please help!I've to resolve this problem before tommorrow.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;My task is to cofigure the freeradius using TTLS+EAP-MD5 to
&lt;br&gt;&amp;gt; authenticate users.I've found
&lt;br&gt;&amp;gt; much information about how to configure this type on Internet,but there
&lt;br&gt;&amp;gt; are some differences
&lt;br&gt;&amp;gt; between different vesions.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;My freeradius version is:*2.1.7*
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;Please tell me the specific steps to configure the freeradius.Which
&lt;br&gt;&amp;gt; files do I need to modify and
&lt;br&gt;&amp;gt; how?Thank you very much!
&lt;/div&gt;&lt;br&gt;&amp;nbsp; (a) install the server
&lt;br&gt;&lt;br&gt;&amp;nbsp; (b) run it in debugging mode to get the default certificates
&lt;br&gt;&lt;br&gt;&amp;nbsp; (c) add a &amp;quot;known good&amp;quot; password (e.g. see the FAQ)
&lt;br&gt;&lt;br&gt;&amp;nbsp; (d) TTLS + EAP-MD5 will work.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/ttls%2Beap-md5-tp26877325p26878585.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26878464</id>
	<title>Re: RADIUS 2.x -  modules not loaded correctly</title>
	<published>2009-12-21T10:56:23Z</published>
	<updated>2009-12-21T10:56:23Z</updated>
	<author>
		<name>Josip Rodin-7</name>
	</author>
	<content type="html">On Mon, Dec 21, 2009 at 03:39:24PM +0000, Alan Buxey wrote:
&lt;br&gt;&amp;gt; that makes the modules go into modules-available - but then you need
&lt;br&gt;&amp;gt; to create the modules-enabled directory and put links into there...
&lt;br&gt;&amp;gt; by default the server needs at least a handful of the modules to be present
&lt;br&gt;&amp;gt; for its default config to load/work - i know - i've looked at this in the past.
&lt;br&gt;&amp;gt; you'll also need to patch the radiusd.conf to read in modules-enabled/*
&lt;br&gt;&lt;br&gt;Yes, of course, I just sent the patch as the preliminary intro into the idea
&lt;br&gt;(OP's idea instead had no separate directories and symlinks in mind, it
&lt;br&gt;talked of suffixes).
&lt;br&gt;&lt;br&gt;As it stands, all entries in current modules/ are harmless when enabled
&lt;br&gt;(by default), so that part could stay as is, functionally.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;2. That which causes joy or happiness.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/RADIUS-2.x----modules-not-loaded-correctly-tp26782251p26878464.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26877325</id>
	<title>ttls+eap-md5</title>
	<published>2009-12-21T09:36:01Z</published>
	<updated>2009-12-21T09:36:01Z</updated>
	<author>
		<name>anyi_9</name>
	</author>
	<content type="html">&lt;div&gt;Hello,all!&lt;br&gt;&amp;nbsp;&amp;nbsp; Please help!I've to resolve this problem before tommorrow.&lt;br&gt;&amp;nbsp;&amp;nbsp; My task is to cofigure the freeradius using TTLS+EAP-MD5 to authenticate users.I've found&lt;br&gt;much information about how to configure this type on Internet,but there are some differences&lt;br&gt;between different vesions.&lt;br&gt;&amp;nbsp;&amp;nbsp; My freeradius version is:&lt;b&gt;2.1.7&lt;/b&gt;&lt;br&gt;&amp;nbsp;&amp;nbsp; Please tell me the specific steps to configure the freeradius.Which files do I need to modify and&lt;br&gt;how?Thank you very much!&lt;br&gt;&lt;br&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;span title=&quot;neteasefooter&quot; /&gt;&lt;/span&gt;&lt;br /&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/ttls%2Beap-md5-tp26877325p26877325.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26877255</id>
	<title>STILL Trying to get tunneling to work</title>
	<published>2009-12-21T09:30:44Z</published>
	<updated>2009-12-21T09:30:44Z</updated>
	<author>
		<name>Mike Bernhardt</name>
	</author>
	<content type="html">&lt;div class='shrinkable-quote'&gt;&amp;gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26877255&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tnt@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26877255&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tnt@...&lt;/a&gt;] 
&lt;br&gt;&amp;gt;Sent: Thursday, December 10, 2009 5:05 PM
&lt;br&gt;&amp;gt;To: FreeRadius users mailing list
&lt;br&gt;&amp;gt;Subject: Re: Trying to get tunneling to work
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I am trying to set up freeradius to proxy requests 802.11 MSCHAPv2 to an
&lt;br&gt;&amp;gt;&amp;gt; IAS
&lt;br&gt;&amp;gt;&amp;gt; server. The IAS requests are authenticated by a Safeword server, which
&lt;br&gt;&amp;gt;&amp;gt; doesn't support 802.11. So the idea is that freeradius takes the request,
&lt;br&gt;&amp;gt;&amp;gt; proxies it to IAS as if it was a non-802.11 client, IAS passes it to the
&lt;br&gt;&amp;gt;&amp;gt; integrated Safeword server, and everything is happy.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; My configuration works from a 802.11 supplicant if the user exist locally
&lt;br&gt;&amp;gt;&amp;gt; in
&lt;br&gt;&amp;gt;&amp;gt; freeradius, but no proxying happens when the user doesn't exist locally.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Read comments in peap section of eap.conf. Replace LOCAL in Proxy-To-Realm
&lt;br&gt;&amp;gt;statement in inner-tunnel virtual server with the name of the realm
&lt;br&gt;&amp;gt;pointing to IAS server.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Ivan Kalik
&lt;/div&gt;&lt;br&gt;As far as I know, this is the case. It is replaced in the users file. I did
&lt;br&gt;a little cleanup on the other config files too. Here is the new output,
&lt;br&gt;though the result is the same. The request is never forwarded out from
&lt;br&gt;freeeradius. Help, anyone?
&lt;br&gt;&lt;br&gt;&lt;br&gt;radiusd: #### Loading Realms and Home Servers ####
&lt;br&gt;&amp;nbsp;proxy server {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; retry_delay = 5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; retry_count = 3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; default_fallback = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dead_time = 120
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; wake_all_if_all_dead = no
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;realm safeword.eng {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; authhost = 192.168.30.29:1812
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; accthost = 192.168.30.29:1813
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; secret = Testing_Testing
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;home_server localhost {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipaddr = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; port = 1812
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = &amp;quot;auth&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; secret = &amp;quot;testing123&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; response_window = 20
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_outstanding = 65536
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_message_authenticator = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; zombie_period = 40
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; status_check = &amp;quot;status-server&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ping_interval = 30
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; check_interval = 30
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; num_answers_to_alive = 3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; num_pings_to_alive = 3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; revive_interval = 120
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; status_check_timeout = 4
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; irt = 2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mrt = 16
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mrc = 5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mrd = 30
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;home_server_pool my_auth_failover {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = fail-over
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; home_server = localhost
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;radiusd: #### Loading Clients ####
&lt;br&gt;&amp;nbsp;client 192.168.7.139/32 {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_message_authenticator = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; secret = &amp;quot;Testing_Testing&amp;quot;
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;client 127.0.0.1/32 {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_message_authenticator = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; secret = &amp;quot;testing123&amp;quot;
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&lt;br&gt;radiusd: #### Loading Virtual Servers ####
&lt;br&gt;server inner-tunnel {
&lt;br&gt;&amp;nbsp;modules {
&lt;br&gt;&amp;nbsp;Module: Checking authenticate {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_pap
&lt;br&gt;&amp;nbsp;Module: Instantiating pap
&lt;br&gt;&amp;nbsp; pap {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; encryption_scheme = &amp;quot;auto&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auto_header = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_chap
&lt;br&gt;&amp;nbsp;Module: Instantiating chap
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_mschap
&lt;br&gt;&amp;nbsp;Module: Instantiating mschap
&lt;br&gt;&amp;nbsp; mschap {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use_mppe = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_encryption = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_strong = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_ntdomain_hack = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_unix
&lt;br&gt;&amp;nbsp;Module: Instantiating unix
&lt;br&gt;&amp;nbsp; unix {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; radwtmp = &amp;quot;/usr/local/var/log/radius/radwtmp&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_eap
&lt;br&gt;&amp;nbsp;Module: Instantiating eap
&lt;br&gt;&amp;nbsp; eap {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; default_eap_type = &amp;quot;peap&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; timer_expire = 60
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ignore_unknown_eap_types = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cisco_accounting_username_bug = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_sessions = 2048
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_md5
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-md5
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_leap
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-leap
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_gtc
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-gtc
&lt;br&gt;&amp;nbsp; &amp;nbsp;gtc {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; challenge = &amp;quot;Password: &amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auth_type = &amp;quot;PAP&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_tls
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-tls
&lt;br&gt;&amp;nbsp; &amp;nbsp;tls {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; rsa_key_exchange = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dh_key_exchange = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; rsa_key_length = 512
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dh_key_length = 512
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; verify_depth = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pem_file_type = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; private_key_file = &amp;quot;/usr/local/etc/raddb/certs/server.pem&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; certificate_file = &amp;quot;/usr/local/etc/raddb/certs/server.pem&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CA_file = &amp;quot;/usr/local/etc/raddb/certs/ca.pem&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; private_key_password = &amp;quot;whatever&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dh_file = &amp;quot;/usr/local/etc/raddb/certs/dh&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; random_file = &amp;quot;/usr/local/etc/raddb/certs/random&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; fragment_size = 1024
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; include_length = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; check_crl = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cipher_list = &amp;quot;DEFAULT&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; make_cert_command = &amp;quot;/usr/local/etc/raddb/certs/bootstrap&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; cache {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; enable = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lifetime = 24
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_entries = 255
&lt;br&gt;&amp;nbsp; &amp;nbsp; }
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_ttls
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-ttls
&lt;br&gt;&amp;nbsp; &amp;nbsp;ttls {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; default_eap_type = &amp;quot;md5&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; copy_request_to_tunnel = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use_tunneled_reply = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; virtual_server = &amp;quot;inner-tunnel&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; include_length = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_peap
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-peap
&lt;br&gt;&amp;nbsp; &amp;nbsp;peap {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; default_eap_type = &amp;quot;mschapv2&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; copy_request_to_tunnel = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use_tunneled_reply = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; proxy_tunneled_request_as_eap = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; virtual_server = &amp;quot;inner-tunnel&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_mschapv2
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-mschapv2
&lt;br&gt;&amp;nbsp; &amp;nbsp;mschapv2 {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_ntdomain_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Checking authorize {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_realm
&lt;br&gt;&amp;nbsp;Module: Instantiating suffix
&lt;br&gt;&amp;nbsp; realm suffix {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; format = &amp;quot;suffix&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; delimiter = &amp;quot;@&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ignore_default = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ignore_null = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_files
&lt;br&gt;&amp;nbsp;Module: Instantiating files
&lt;br&gt;&amp;nbsp; files {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; usersfile = &amp;quot;/usr/local/etc/raddb/users&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; acctusersfile = &amp;quot;/usr/local/etc/raddb/acct_users&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; preproxy_usersfile = &amp;quot;/usr/local/etc/raddb/preproxy_users&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; compat = &amp;quot;no&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking session {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_radutmp
&lt;br&gt;&amp;nbsp;Module: Instantiating radutmp
&lt;br&gt;&amp;nbsp; radutmp {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; filename = &amp;quot;/usr/local/var/log/radius/radutmp&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; username = &amp;quot;%{User-Name}&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; case_sensitive = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; check_with_nas = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; perm = 384
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; callerid = yes
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking post-proxy {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Checking post-auth {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_attr_filter
&lt;br&gt;&amp;nbsp;Module: Instantiating attr_filter.access_reject
&lt;br&gt;&amp;nbsp; attr_filter attr_filter.access_reject {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; attrsfile = &amp;quot;/usr/local/etc/raddb/attrs.access_reject&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; key = &amp;quot;%{User-Name}&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;} # modules
&lt;br&gt;} # server
&lt;br&gt;server {
&lt;br&gt;&amp;nbsp;modules {
&lt;br&gt;&amp;nbsp;Module: Checking authenticate {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Checking authorize {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_preprocess
&lt;br&gt;&amp;nbsp;Module: Instantiating preprocess
&lt;br&gt;&amp;nbsp; preprocess {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; huntgroups = &amp;quot;/usr/local/etc/raddb/huntgroups&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hints = &amp;quot;/usr/local/etc/raddb/hints&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_ascend_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ascend_channels_per_line = 23
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_ntdomain_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_specialix_jetstream_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_cisco_vsa_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_alvarion_vsa_hack = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking preacct {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_acct_unique
&lt;br&gt;&amp;nbsp;Module: Instantiating acct_unique
&lt;br&gt;&amp;nbsp; acct_unique {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; key = &amp;quot;User-Name, Acct-Session-Id, NAS-IP-Address,
&lt;br&gt;Client-IP-Address, NAS-Port&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking accounting {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_detail
&lt;br&gt;&amp;nbsp;Module: Instantiating detail
&lt;br&gt;&amp;nbsp; detail {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; detailfile =
&lt;br&gt;&amp;quot;/usr/local/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; header = &amp;quot;%t&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; detailperm = 384
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dirperm = 493
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; locking = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; log_packet_header = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Instantiating attr_filter.accounting_response
&lt;br&gt;&amp;nbsp; attr_filter attr_filter.accounting_response {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; attrsfile = &amp;quot;/usr/local/etc/raddb/attrs.accounting_response&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; key = &amp;quot;%{User-Name}&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking session {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Checking post-proxy {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Checking post-auth {...} for more modules to load
&lt;br&gt;&amp;nbsp;} # modules
&lt;br&gt;} # server
&lt;br&gt;radiusd: #### Opening IP addresses and Ports ####
&lt;br&gt;listen {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = &amp;quot;auth&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipaddr = *
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; port = 0
&lt;br&gt;}
&lt;br&gt;listen {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = &amp;quot;acct&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipaddr = *
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; port = 0
&lt;br&gt;}
&lt;br&gt;listen {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = &amp;quot;control&amp;quot;
&lt;br&gt;&amp;nbsp;listen {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; socket = &amp;quot;/usr/local/var/run/radiusd/radiusd.sock&amp;quot;
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;}
&lt;br&gt;Listening on authentication address * port 1812
&lt;br&gt;Listening on accounting address * port 1813
&lt;br&gt;Listening on command file /usr/local/var/run/radiusd/radiusd.sock
&lt;br&gt;Listening on proxy address * port 1814
&lt;br&gt;Listening on proxy address 127.0.0.1 port 35452
&lt;br&gt;Ready to process requests.
&lt;br&gt;&lt;br&gt;rad_recv: Access-Request packet from host 192.168.7.139 port 1645, id=148,
&lt;br&gt;length=152
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;mbernhardt&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1400
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;000a.f4e2.2a00&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;0021.6a46.b0cc&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Login-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x26cd48e5b9fc61664cee336cc1792ccc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020700061900
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 3292
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xc871db2ccc76c2f4ed36eeb8b11d50cb
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 192.168.7.139
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;lks15w-ap350&amp;quot;
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;mbernhardt&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 7 length 6
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] Received TLS ACK
&lt;br&gt;[peap] ACK handshake is finished
&lt;br&gt;[peap] eaptls_verify returned 3 
&lt;br&gt;[peap] eaptls_process returned 3 
&lt;br&gt;[peap] EAPTLS_SUCCESS
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 148 to 192.168.7.139 port 1645
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message =
&lt;br&gt;0x0108002019001703010015ec4896e2cabf793395eed36c929b08a15179a89940
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xc871db2ccd79c2f4ed36eeb8b11d50cb
&lt;br&gt;Finished request 21.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 2.2 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host 192.168.7.139 port 1645, id=149,
&lt;br&gt;length=184
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;mbernhardt&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1400
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;000a.f4e2.2a00&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;0021.6a46.b0cc&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Login-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x6a4dbd84e5ab9893eeba02d1c466b5f2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message =
&lt;br&gt;0x020800261900170301001be14c477ed7b3337d1f7a595cbfe47a98ceb6bbac01a2b8d714fb
&lt;br&gt;21
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 3292
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xc871db2ccd79c2f4ed36eeb8b11d50cb
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 192.168.7.139
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;lks15w-ap350&amp;quot;
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;mbernhardt&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 8 length 38
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] eaptls_verify returned 7 
&lt;br&gt;[peap] Done initial handshake
&lt;br&gt;[peap] eaptls_process returned 7 
&lt;br&gt;[peap] EAPTLS_OK
&lt;br&gt;[peap] Session established. &amp;nbsp;Decoding tunneled attributes.
&lt;br&gt;[peap] Identity - mbernhardt
&lt;br&gt;[peap] Got tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0208000f016d6265726e6861726474
&lt;br&gt;server &amp;nbsp;{
&lt;br&gt;&amp;nbsp; PEAP: Got tunneled identity of mbernhardt
&lt;br&gt;&amp;nbsp; PEAP: Setting default EAP type for tunneled EAP session.
&lt;br&gt;&amp;nbsp; PEAP: Setting User-Name to mbernhardt
&lt;br&gt;Sending tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0208000f016d6265726e6861726474
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS-Proxied-To = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;mbernhardt&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1400
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;000a.f4e2.2a00&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;0021.6a46.b0cc&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Login-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 3292
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 192.168.7.139
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;lks15w-ap350&amp;quot;
&lt;br&gt;server inner-tunnel {
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;++[unix] returns updated
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;mbernhardt&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[control] returns noop
&lt;br&gt;[eap] Request is supposed to be proxied to Realm LOCAL. &amp;nbsp;Not doing EAP.
&lt;br&gt;++[eap] returns noop
&lt;br&gt;[files] users: Matched entry DEFAULT at line 3
&lt;br&gt;++[files] returns ok
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;} # server inner-tunnel
&lt;br&gt;[peap] Got tunneled reply code 0
&lt;br&gt;&amp;nbsp; PEAP: Calling authenticate in order to initiate tunneled EAP session.
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] EAP Identity
&lt;br&gt;[eap] processing type mschapv2
&lt;br&gt;rlm_eap_mschapv2: Issuing Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;&amp;nbsp; &amp;nbsp; PEAP: Cancelling proxy to realm safeword.eng until the tunneled EAP
&lt;br&gt;session has been established
&lt;br&gt;[peap] Got tunneled reply RADIUS code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message =
&lt;br&gt;0x010900241a0109001f10421fda5c741f99bbbd660650209f40a16d6265726e6861726474
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x3dd5fbf33ddce1440d05495c582e500e
&lt;br&gt;[peap] Got tunneled Access-Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 149 to 192.168.7.139 port 1645
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 
&lt;br&gt;&lt;br&gt;0x0109003b190017030100307e4b0e6a672924f75bbb213a62d8e08842877ff9e84d690b7bf5
&lt;br&gt;5531e4eced9572a2c0f4f230db301d3
&lt;br&gt;&lt;br&gt;ac0e43d4ec15e
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xc871db2cce78c2f4ed36eeb8b11d50cb
&lt;br&gt;Finished request 22.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 2.2 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host 192.168.7.139 port 1645, id=150,
&lt;br&gt;length=238
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;mbernhardt&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1400
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;000a.f4e2.2a00&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;0021.6a46.b0cc&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Login-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x29cb8c7c5e0ea13931129b5404267fbd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 
&lt;br&gt;&lt;br&gt;0x0209005c19001703010051da572ed9a75ebdddd39a40408f8c6eb4f537f65470fba05b8b82
&lt;br&gt;c174224dcd6de968b259232794f361d
&lt;br&gt;&lt;br&gt;51ab246ab8b41b50bd8dac1777fc412c4f78b4015250d700441464b71f7c27aa6c3901adfff3
&lt;br&gt;1a7
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 3292
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xc871db2cce78c2f4ed36eeb8b11d50cb
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 192.168.7.139
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;lks15w-ap350&amp;quot;
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;mbernhardt&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 9 length 92
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] eaptls_verify returned 7 
&lt;br&gt;[peap] Done initial handshake
&lt;br&gt;[peap] eaptls_process returned 7 
&lt;br&gt;[peap] EAPTLS_OK
&lt;br&gt;[peap] Session established. &amp;nbsp;Decoding tunneled attributes.
&lt;br&gt;[peap] EAP type mschapv2
&lt;br&gt;[peap] Got tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 
&lt;br&gt;&lt;br&gt;0x020900451a0209004031b326572c085e1b042802b27f632ddc860000000000000000914fa3
&lt;br&gt;c6b927312212cb1ae7675131d7f1a75
&lt;br&gt;&lt;br&gt;7e2a0deaeab006d6265726e6861726474
&lt;br&gt;server &amp;nbsp;{
&lt;br&gt;&amp;nbsp; PEAP: Setting User-Name to mbernhardt
&lt;br&gt;Sending tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 
&lt;br&gt;&lt;br&gt;0x020900451a0209004031b326572c085e1b042802b27f632ddc860000000000000000914fa3
&lt;br&gt;c6b927312212cb1ae7675131d7f1a75
&lt;br&gt;&lt;br&gt;7e2a0deaeab006d6265726e6861726474
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS-Proxied-To = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;mbernhardt&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x3dd5fbf33ddce1440d05495c582e500e
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1400
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;000a.f4e2.2a00&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;0021.6a46.b0cc&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Login-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 3292
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 192.168.7.139
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;lks15w-ap350&amp;quot;
&lt;br&gt;server inner-tunnel {
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;++[unix] returns updated
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;mbernhardt&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[control] returns noop
&lt;br&gt;[eap] Request is supposed to be proxied to Realm LOCAL. &amp;nbsp;Not doing EAP.
&lt;br&gt;++[eap] returns noop
&lt;br&gt;[files] users: Matched entry DEFAULT at line 3
&lt;br&gt;++[files] returns ok
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;} # server inner-tunnel
&lt;br&gt;[peap] Got tunneled reply code 0
&lt;br&gt;&amp;nbsp; PEAP: Calling authenticate in order to initiate tunneled EAP session.
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/mschapv2
&lt;br&gt;[eap] processing type mschapv2
&lt;br&gt;[eap] &amp;nbsp; Not-EAP proxy set. &amp;nbsp;Not composing EAP
&lt;br&gt;++[eap] returns handled
&lt;br&gt;&amp;nbsp; PEAP: Tunneled authentication will be proxied to safeword.eng
&lt;br&gt;&amp;nbsp; PEAP: Remembering to do EAP-MS-CHAP-V2 post-proxy.
&lt;br&gt;[eap] &amp;nbsp; Tunneled session will be proxied. &amp;nbsp;Not doing EAP.
&lt;br&gt;++[eap] returns handled
&lt;br&gt;&amp;nbsp; WARNING: Empty section. &amp;nbsp;Using default return values.
&lt;br&gt;ERROR: Failed to create a new socket for proxying requests.
&lt;br&gt;ERROR: Failed inserting request into proxy hash.
&lt;br&gt;ERROR: Failed to proxy request 23
&lt;br&gt;There was no response configured: rejecting request 23
&lt;br&gt;Using Post-Auth-Type Reject
&lt;br&gt;+- entering group REJECT {...}
&lt;br&gt;[attr_filter.access_reject] &amp;nbsp; &amp;nbsp; expand: %{User-Name} -&amp;gt; mbernhardt
&lt;br&gt;&amp;nbsp;attr_filter: Matched entry DEFAULT at line 11
&lt;br&gt;++[attr_filter.access_reject] returns updated
&lt;br&gt;Delaying reject of request 23 for 1 seconds
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 0.9 seconds.
&lt;br&gt;&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/STILL-Trying-to-get-tunneling-to-work-tp26877255p26877255.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26877236</id>
	<title>Re: RADIUS 2.x -  modules not loaded correctly</title>
	<published>2009-12-21T09:30:38Z</published>
	<updated>2009-12-21T09:30:38Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">Josip Rodin wrote:
&lt;br&gt;&amp;gt; I was thinking we should use the mods-{available,enabled}, also mimicking
&lt;br&gt;&amp;gt; apache2 and sites-*. That way we can worry less about the admin editing and
&lt;br&gt;&amp;gt; leaving junk in one directory, when only the other one is supposed to be
&lt;br&gt;&amp;gt; clean. Something like this?
&lt;br&gt;&lt;br&gt;&amp;nbsp; For 2.2.0, yes.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/RADIUS-2.x----modules-not-loaded-correctly-tp26782251p26877236.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26876941</id>
	<title>Re: Multiple clients on same IP address</title>
	<published>2009-12-21T08:37:32Z</published>
	<updated>2009-12-21T08:37:32Z</updated>
	<author>
		<name>Alexander Clouter</name>
	</author>
	<content type="html">Fahd Kasri &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26876941&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fahd.kasri@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; That's what I thought. I tried the first solution (wanting to avoid the two
&lt;br&gt;&amp;gt; others), and apparently the configuration works. Just wanted to know if
&lt;br&gt;&amp;gt; there could be any problems with two or more clients using the exact some
&lt;br&gt;&amp;gt; configuration. Thanks for the info.
&lt;br&gt;&amp;gt; 
&lt;br&gt;Depends on what you want to do with the accounting data. &amp;nbsp;You might find 
&lt;br&gt;that tracking your users when NAS-IP-Address is the same becomes really 
&lt;br&gt;awkward[1]. &amp;nbsp;Anything that keys off that attribute (such as 
&lt;br&gt;Acct-Unique-Session-Id, as Acct-Session-Id is rarely unique) might cause 
&lt;br&gt;your grief.
&lt;br&gt;&lt;br&gt;So, authentication should work...you might have some problems with 
&lt;br&gt;simulateous logins *possibly* and your accounting records might be a 
&lt;br&gt;pain to work with.
&lt;br&gt;&lt;br&gt;You need to define what 'work' means for yourself and decide from there.
&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;&lt;br&gt;[1] then you hope your venduh lets you amend the NAS-Identifier 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; attribute
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Alexander Clouter
&lt;br&gt;.sigmonster says: TAILFINS!! ... click ...
&lt;br&gt;&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Multiple-clients-on-same-IP-address-tp26874156p26876941.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26875665</id>
	<title>Re: RADIUS 2.x -  modules not loaded correctly</title>
	<published>2009-12-21T07:39:24Z</published>
	<updated>2009-12-21T07:39:24Z</updated>
	<author>
		<name>Alan Buxey</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;&amp;gt; I was thinking we should use the mods-{available,enabled}, also mimicking
&lt;br&gt;&amp;gt; apache2 and sites-*. That way we can worry less about the admin editing and
&lt;br&gt;&amp;gt; leaving junk in one directory, when only the other one is supposed to be
&lt;br&gt;&amp;gt; clean. Something like this?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; git mv raddb/modules raddb/mods-available
&lt;br&gt;&amp;gt; patch -p1 &amp;lt; mods.diff # attached
&lt;br&gt;&lt;br&gt;that makes the modules go into modules-available - but then you need
&lt;br&gt;to create the modules-enabled directory and put links into there...
&lt;br&gt;by default the server needs at least a handful of the modules to be present
&lt;br&gt;for its default config to load/work - i know - i've looked at this in the past.
&lt;br&gt;you'll also need to patch the radiusd.conf to read in modules-enabled/*
&lt;br&gt;&lt;br&gt;alan
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/RADIUS-2.x----modules-not-loaded-correctly-tp26782251p26875665.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26875550</id>
	<title>Re: RADIUS 2.x -  modules not loaded correctly</title>
	<published>2009-12-21T07:29:09Z</published>
	<updated>2009-12-21T07:29:09Z</updated>
	<author>
		<name>Josip Rodin-7</name>
	</author>
	<content type="html">On Tue, Dec 15, 2009 at 09:03:33AM +0100, Alan DeKok wrote:
&lt;br&gt;&amp;gt; Axel Vogel wrote:
&lt;br&gt;&amp;gt; &amp;gt; Please look at the configuration of virtual hosts in apache2.
&lt;br&gt;&amp;gt; &amp;gt; The httpd.conf incudes only files with a well defined suffix
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp;vhosts.d/*.conf
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; Sure. &amp;nbsp;Send a patch.
&lt;br&gt;&lt;br&gt;I was thinking we should use the mods-{available,enabled}, also mimicking
&lt;br&gt;apache2 and sites-*. That way we can worry less about the admin editing and
&lt;br&gt;leaving junk in one directory, when only the other one is supposed to be
&lt;br&gt;clean. Something like this?
&lt;br&gt;&lt;br&gt;git mv raddb/modules raddb/mods-available
&lt;br&gt;patch -p1 &amp;lt; mods.diff # attached
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;2. That which causes joy or happiness.
&lt;br&gt;&lt;br /&gt;&lt;hr align=&quot;left&quot; width=&quot;300&quot; /&gt;&lt;tt&gt;diff --git a/raddb/Makefile b/raddb/Makefile
&lt;br&gt;index 01d3f03..9a3e5b5 100644
&lt;br&gt;--- a/raddb/Makefile
&lt;br&gt;+++ b/raddb/Makefile
&lt;br&gt;@@ -33,9 +33,9 @@ install:
&lt;br&gt;&amp;nbsp;	$(INSTALL) -d -m 750	$(R)$(raddbdir)
&lt;br&gt;&amp;nbsp;	$(INSTALL) -d -m 750	$(R)$(raddbdir)/sites-available
&lt;br&gt;&amp;nbsp;	$(INSTALL) -d -m 750	$(R)$(raddbdir)/sites-enabled
&lt;br&gt;-	$(INSTALL) -d -m 750	$(R)$(raddbdir)/modules
&lt;br&gt;+	$(INSTALL) -d -m 750	$(R)$(raddbdir)/mods-available
&lt;br&gt;&amp;nbsp;	@echo &amp;quot;Creating/updating files in $(R)$(raddbdir)&amp;quot;; \
&lt;br&gt;-	for i in $(FILES) `find sites-available/ modules/ -type f -print | sed 's/.*CVS.*//;s/.*~//;s/.*#.*//' `; do \
&lt;br&gt;+	for i in $(FILES) `find sites-available/ mods-available/ -type f -print | sed 's/.*CVS.*//;s/.*~//;s/.*#.*//' `; do \
&lt;br&gt;&amp;nbsp;		[ ! -f $(R)$(raddbdir)/$$i ] &amp;&amp; $(INSTALL) -m 640 $$i $(R)$(raddbdir)/$$i; \
&lt;br&gt;&amp;nbsp;		if [ &amp;quot;`find $$i -newer $(R)$(raddbdir)/$$i`&amp;quot; ]; then \
&lt;br&gt;&amp;nbsp;			echo &amp;quot;** $(R)$(raddbdir)/$$i&amp;quot;; \
&lt;br&gt;@@ -85,6 +85,12 @@ install:
&lt;br&gt;&amp;nbsp;		cd $(R)$(raddbdir)/sites-enabled/; \
&lt;br&gt;&amp;nbsp;		ln -s ../sites-available/control-socket; \
&lt;br&gt;&amp;nbsp;	fi
&lt;br&gt;+	@for m in `cd mods-available/ &amp;&amp; ls -1 | sed 's/.*CVS.*//;s/.*~//;s/.*#.*//' `; do \
&lt;br&gt;+		if [ ! -L $(R)$(raddbdir)/$$m ]; then \
&lt;br&gt;+			echo &amp;quot;** Enabling default module $(R)$(raddbdir)/$$m&amp;quot;; \
&lt;br&gt;+			ln -s ../mods-available/$$m $(R)$(raddbdir)/$$m; \
&lt;br&gt;+		fi; \
&lt;br&gt;+	done
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;clean:
&lt;br&gt;&amp;nbsp;	rm -rf sites-enabled/inner-tunnel sites-enabled/default
&lt;br&gt;&lt;/tt&gt;&lt;hr align=&quot;left&quot; width=&quot;300&quot; /&gt;&lt;br /&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/RADIUS-2.x----modules-not-loaded-correctly-tp26782251p26875550.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26875394</id>
	<title>Re: Multiple clients on same IP address</title>
	<published>2009-12-21T07:18:24Z</published>
	<updated>2009-12-21T07:18:24Z</updated>
	<author>
		<name>Fahd Kasri</name>
	</author>
	<content type="html">That&amp;#39;s what I thought. I tried the first solution (wanting to avoid the two others), and apparently the configuration works. Just wanted to know if there could be any problems with two or more clients using the exact some configuration. Thanks for the info.&lt;br&gt;
&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;2009/12/21 Alexander Clouter &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26875394&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;alex@...&lt;/a&gt;&amp;gt;&lt;/span&gt;&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;
&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;h5&quot;&gt;Fahd Kasri &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26875394&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fahd.kasri@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Is it possible to have multiple Radius clients behind a router connect to a&lt;br&gt;
&amp;gt; distant Freeradius server (these clients would therefore have the same IP&lt;br&gt;
&amp;gt; address and be the same client in clients.conf)?&lt;br&gt;
&amp;gt; I&amp;#39;ve this and apparently it works, but could there be any problems in the&lt;br&gt;
&amp;gt; long run?&lt;br&gt;
&amp;gt;&lt;br&gt;
&lt;/div&gt;&lt;/div&gt;They would either:&lt;br&gt;
 * need to use the same shared secret&lt;br&gt;
 * connect to different IP&amp;#39;s provisioned by FreeRADIUS (the server is&lt;br&gt;
        bind()&amp;#39;ed to more than one address)&lt;br&gt;
 * send traffic to different port numbers being listened to by&lt;br&gt;
        FreeRADIUS (listens on ports other than the &amp;#39;official&amp;#39; ones)&lt;br&gt;
&lt;br&gt;
You can use a combination of the above (if you are crazy), but you will&lt;br&gt;
need to use at lease *one*.  The alternative is to kill NAT...for it is&lt;br&gt;
evil[1].&lt;br&gt;
&lt;br&gt;
Cheers&lt;br&gt;
&lt;br&gt;
[1] if the network is &amp;#39;trusted&amp;#39; then use an IPIP/GRE tunnel to get the&lt;br&gt;
        traffic to the RADIUS server&lt;br&gt;
&lt;font color=&quot;#888888&quot;&gt;&lt;br&gt;
--&lt;br&gt;
Alexander Clouter&lt;br&gt;
.sigmonster says: A dead man cannot bite.&lt;br&gt;
                                -- Gnaeus Pompeius (Pompey)&lt;br&gt;
&lt;/font&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;h5&quot;&gt;&lt;br&gt;
-&lt;br&gt;
List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Fahd Kasri&lt;br&gt;Directeur Technique&lt;br&gt;Weblib&lt;br&gt;&lt;a href=&quot;http://www.weblib.eu&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.weblib.eu&lt;/a&gt;&lt;br&gt;
&lt;br /&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Multiple-clients-on-same-IP-address-tp26874156p26875394.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26875248</id>
	<title>Re: Multiple clients on same IP address</title>
	<published>2009-12-21T06:48:55Z</published>
	<updated>2009-12-21T06:48:55Z</updated>
	<author>
		<name>Alexander Clouter</name>
	</author>
	<content type="html">Fahd Kasri &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26875248&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fahd.kasri@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Is it possible to have multiple Radius clients behind a router connect to a
&lt;br&gt;&amp;gt; distant Freeradius server (these clients would therefore have the same IP
&lt;br&gt;&amp;gt; address and be the same client in clients.conf)?
&lt;br&gt;&amp;gt; I've this and apparently it works, but could there be any problems in the
&lt;br&gt;&amp;gt; long run?
&lt;br&gt;&amp;gt; 
&lt;br&gt;They would either:
&lt;br&gt;&amp;nbsp;* need to use the same shared secret
&lt;br&gt;&amp;nbsp;* connect to different IP's provisioned by FreeRADIUS (the server is 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bind()'ed to more than one address)
&lt;br&gt;&amp;nbsp;* send traffic to different port numbers being listened to by 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS (listens on ports other than the 'official' ones)
&lt;br&gt;&lt;br&gt;You can use a combination of the above (if you are crazy), but you will 
&lt;br&gt;need to use at lease *one*. &amp;nbsp;The alternative is to kill NAT...for it is 
&lt;br&gt;evil[1].
&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;&lt;br&gt;[1] if the network is 'trusted' then use an IPIP/GRE tunnel to get the 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; traffic to the RADIUS server
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Alexander Clouter
&lt;br&gt;.sigmonster says: A dead man cannot bite.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 		-- Gnaeus Pompeius (Pompey)
&lt;br&gt;&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Multiple-clients-on-same-IP-address-tp26874156p26875248.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26874970</id>
	<title>Re: Virtual Server not setting attributes on reply</title>
	<published>2009-12-21T06:48:00Z</published>
	<updated>2009-12-21T06:48:00Z</updated>
	<author>
		<name>Alan Buxey</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;&amp;gt; Not the default virtual server. The test virtual server
&lt;br&gt;&amp;gt; The flow is client -&amp;gt; default virtual server acting as a proxy -&amp;gt; test
&lt;br&gt;&amp;gt; virtual server
&lt;br&gt;&amp;gt; If the test virtual server is configured as a remote radius server
&lt;br&gt;&amp;gt; then things work great. If it's configured as a virtual server using
&lt;br&gt;&amp;gt; the &amp;quot;virtual_server=name&amp;quot; then things break.
&lt;br&gt;&lt;br&gt;test virtual server not setting the options byt he looks of it...
&lt;br&gt;post-auth is called in that virtual server - so how should it be getting/setting
&lt;br&gt;that attribute?
&lt;br&gt;&lt;br&gt;alan
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Virtual-Server-not-setting-attributes-on-reply-tp26873711p26874970.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26874690</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T06:27:02Z</published>
	<updated>2009-12-21T06:27:02Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">Alexander Clouter wrote:
&lt;br&gt;&amp;gt; Want to put it down to a neutrino burst? :)
&lt;br&gt;&lt;br&gt;&amp;nbsp; Been there. &amp;nbsp;Done that.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://www.sno.phy.queensu.ca/sno/papers/nim_paper_99.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.sno.phy.queensu.ca/sno/papers/nim_paper_99.pdf&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; 9th author, on the first page.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26874690.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26874272</id>
	<title>Re: Virtual Server not setting attributes on reply</title>
	<published>2009-12-21T05:55:11Z</published>
	<updated>2009-12-21T05:55:11Z</updated>
	<author>
		<name>Timothy-45</name>
	</author>
	<content type="html">2009/12/21 Alan Buxey &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26874272&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;A.L.M.Buxey@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; If I authenticate to TEST1/user
&lt;br&gt;&amp;gt;&amp;gt; My response is &amp;quot;only&amp;quot; a successful auth.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; If I authenticate to TEST2/user
&lt;br&gt;&amp;gt;&amp;gt; My response is a successful auth WITH Attributes (in this case the
&lt;br&gt;&amp;gt;&amp;gt; attribute I'm setting is
&lt;br&gt;&amp;gt;&amp;gt; Cisco-AVPair = &amp;quot;shell:priv-lvl=15&amp;quot;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; where are you setting that attribute? in the default virtual_server
&lt;br&gt;&amp;gt; in the post-auth?
&lt;/div&gt;&lt;br&gt;Not the default virtual server. The test virtual server
&lt;br&gt;The flow is client -&amp;gt; default virtual server acting as a proxy -&amp;gt; test
&lt;br&gt;virtual server
&lt;br&gt;If the test virtual server is configured as a remote radius server
&lt;br&gt;then things work great. If it's configured as a virtual server using
&lt;br&gt;the &amp;quot;virtual_server=name&amp;quot; then things break.
&lt;br&gt;&lt;br&gt;I'm setting the attribues in the test virtual server via post-auth.
&lt;br&gt;&lt;br&gt;The idea would be to have the different virtual servers using tables /
&lt;br&gt;databases for their own user list.
&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt; It appears to me that using the virtual server is stripping the
&lt;br&gt;&amp;gt;&amp;gt; attributes from the reply.
&lt;br&gt;&lt;br&gt;&amp;gt; check your attr filter - check that those attributes arent cleared - if
&lt;br&gt;&amp;gt; you run in full debug mode you should see everything that is happening
&lt;br&gt;&amp;gt; and exactly where it gets set and where it gets wiped
&lt;br&gt;&lt;br&gt;The attributes just don't look to be getting set. I'm guessing that
&lt;br&gt;the post-auth section isn't being used with you proxy to a &amp;quot;virtual
&lt;br&gt;server&amp;quot; rather than to a &amp;quot;real&amp;quot; server
&lt;br&gt;&lt;br&gt;realm TEST1 using &amp;quot;virtual server&amp;quot;
&lt;br&gt;&lt;br&gt;rad_recv: Access-Request packet from host 192.168.183.20 port 2530,
&lt;br&gt;id=16, length=106
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;TEST1/default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Acct-Session-Id = &amp;quot;1261403370P17nsl&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;Localhost&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;1115551212&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Password = &amp;quot;password&amp;quot;
&lt;br&gt;+- entering group authorize
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Looking up realm &amp;quot;TEST1&amp;quot; for User-Name = &amp;quot;TEST1/default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Found realm &amp;quot;TEST1&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Adding Stripped-User-Name = &amp;quot;default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Adding Realm = &amp;quot;TEST1&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Proxying request from user default to realm TEST1
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Preparing to proxy authentication request to realm &amp;quot;TEST1&amp;quot;
&lt;br&gt;++[slash] returns updated
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Request already proxied. &amp;nbsp;Ignoring.
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;&amp;nbsp; rlm_eap: No EAP-Message, not doing EAP
&lt;br&gt;++[eap] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Sending proxied request internally to virtual server.
&lt;br&gt;server test {
&lt;br&gt;+- entering group authorize
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{Stripped-User-Name} -&amp;gt; default
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{%{Stripped-User-Name}:-%{%{User-Name}:-DEFAULT}} -&amp;gt; default
&lt;br&gt;rlm_sql (sql): sql_set_user escaped user --&amp;gt; 'default'
&lt;br&gt;rlm_sql (sql): Reserving sql socket id: 3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT id, username, attribute, value, op
&lt;br&gt;FROM radcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = '%{SQL-User-Name}'
&lt;br&gt;ORDER BY id -&amp;gt; SELECT id, username, attribute, value, op
&lt;br&gt;FROM radcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY
&lt;br&gt;id
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT id, username, attribute, value, op
&lt;br&gt;&amp;nbsp; &amp;nbsp; FROM radcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER
&lt;br&gt;BY id
&lt;br&gt;rlm_sql (sql): User found in radcheck table
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT id, username, attribute, value, op
&lt;br&gt;FROM radreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = '%{SQL-User-Name}'
&lt;br&gt;ORDER BY id -&amp;gt; SELECT id, username, attribute, value, op
&lt;br&gt;FROM radreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY
&lt;br&gt;id
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT id, username, attribute, value, op
&lt;br&gt;&amp;nbsp; &amp;nbsp; FROM radreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER
&lt;br&gt;BY id
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT groupname &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radusergroup
&lt;br&gt;WHERE username = '%{SQL-User-Name}' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY priority -&amp;gt;
&lt;br&gt;SELECT groupname &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radusergroup &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username
&lt;br&gt;= 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY priority
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT groupname &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radusergroup
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY priority
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT id, groupname, attribute, &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Value, op
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname = '%{Sql-Group}'
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ORDER BY id -&amp;gt; SELECT id, groupname, attribute,
&lt;br&gt;Value, op &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname =
&lt;br&gt;'shells' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY id
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT id, groupname, attribute,
&lt;br&gt;Value, op &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname =
&lt;br&gt;'shells' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY id
&lt;br&gt;rlm_sql (sql): User found in group shells
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT id, groupname, attribute, &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; value, op
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname = '%{Sql-Group}'
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ORDER BY id -&amp;gt; SELECT id, groupname, attribute,
&lt;br&gt;value, op &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname =
&lt;br&gt;'shells' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY id
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT id, groupname, attribute,
&lt;br&gt;value, op &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname =
&lt;br&gt;'shells' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY id
&lt;br&gt;rlm_sql (sql): Released sql socket id: 3
&lt;br&gt;++[sql] returns ok
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;rlm_pap: Normalizing MD5-Password from hex encoding
&lt;br&gt;++[pap] returns updated
&lt;br&gt;&amp;nbsp; rad_check_password: &amp;nbsp;Found Auth-Type
&lt;br&gt;auth: type &amp;quot;PAP&amp;quot;
&lt;br&gt;+- entering group PAP
&lt;br&gt;rlm_pap: login attempt with password &amp;quot;password&amp;quot;
&lt;br&gt;rlm_pap: Using MD5 encryption.
&lt;br&gt;rlm_pap: User authenticated successfully
&lt;br&gt;++[pap] returns ok
&lt;br&gt;Login OK: [default/password] (from client desktop port 0 cli
&lt;br&gt;1115551212 via TLS tunnel)
&lt;br&gt;+- entering group post-auth
&lt;br&gt;rlm_sql (sql): Processing sql_postauth
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{Stripped-User-Name} -&amp;gt; default
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{%{Stripped-User-Name}:-%{%{User-Name}:-DEFAULT}} -&amp;gt; default
&lt;br&gt;rlm_sql (sql): sql_set_user escaped user --&amp;gt; 'default'
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{User-Password} -&amp;gt; password
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: INSERT INTO radpostauth
&lt;br&gt;(username, pass, reply, authdate) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VALUES (
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; '%{User-Name}',
&lt;br&gt;'%{%{User-Password}:-%{Chap-Password}}',
&lt;br&gt;'%{reply:Packet-Type}', '%S') -&amp;gt; INSERT INTO radpostauth
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (username, pass, reply, authdate)
&lt;br&gt;&amp;nbsp;VALUES ( &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'default',
&lt;br&gt;&amp;nbsp; 'password', &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'Access-Accept', '2009-12-21
&lt;br&gt;13:49:30')
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: /var/log/freeradius/sqltrace.sql -&amp;gt;
&lt;br&gt;/var/log/freeradius/sqltrace.sql
&lt;br&gt;rlm_sql (sql) in sql_postauth: query is INSERT INTO radpostauth
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(username, pass, reply, authdate)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VALUES ( &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'default',
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;'password', &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'Access-Accept',
&lt;br&gt;'2009-12-21 13:49:30')
&lt;br&gt;rlm_sql (sql): Reserving sql socket id: 2
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;INSERT INTO radpostauth
&lt;br&gt;&amp;nbsp; (username, pass, reply, authdate) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VALUES (
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'default',
&lt;br&gt;'password', &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'Access-Accept', '2009-12-21
&lt;br&gt;13:49:30')
&lt;br&gt;rlm_sql (sql): Released sql socket id: 2
&lt;br&gt;++[sql] returns ok
&lt;br&gt;} # server test
&lt;br&gt;Going to the next request
&lt;br&gt;&amp;lt;&amp;lt;&amp;lt; Received proxied response from internal virtual server.
&lt;br&gt;+- entering group authorize
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Proxy reply, or no User-Name. &amp;nbsp;Ignoring.
&lt;br&gt;++[slash] returns noop
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Proxy reply, or no User-Name. &amp;nbsp;Ignoring.
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[eap] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;&amp;nbsp; rad_check_password: &amp;nbsp;Found Auth-Type
&lt;br&gt;&amp;nbsp; rad_check_password: Auth-Type = Accept, accepting the user
&lt;br&gt;Login OK: [TEST1/default/password] (from client desktop port 0 cli 1115551212)
&lt;br&gt;+- entering group post-auth
&lt;br&gt;++[exec] returns noop
&lt;br&gt;Sending Access-Accept of id 16 to 192.168.183.20 port 2530
&lt;br&gt;Finished request 0.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;Cleaning up request 0 ID 16 with timestamp +11
&lt;br&gt;Ready to process requests.
&lt;br&gt;&lt;br&gt;&lt;br&gt;realm TEST2 using &amp;quot;real&amp;quot; server
&lt;br&gt;&lt;br&gt;&lt;br&gt;rad_recv: Access-Request packet from host 192.168.183.20 port 2535,
&lt;br&gt;id=17, length=106
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;TEST2/default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Acct-Session-Id = &amp;quot;1261403531L18dgh&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;Localhost&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;1115551212&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Password = &amp;quot;password&amp;quot;
&lt;br&gt;+- entering group authorize
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Looking up realm &amp;quot;TEST2&amp;quot; for User-Name = &amp;quot;TEST2/default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Found realm &amp;quot;TEST2&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Adding Stripped-User-Name = &amp;quot;default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Adding Realm = &amp;quot;TEST2&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Proxying request from user default to realm TEST2
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Preparing to proxy authentication request to realm &amp;quot;TEST2&amp;quot;
&lt;br&gt;++[slash] returns updated
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Request already proxied. &amp;nbsp;Ignoring.
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;&amp;nbsp; rlm_eap: No EAP-Message, not doing EAP
&lt;br&gt;++[eap] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Sending Access-Request of id 34 to 127.0.0.1 port 11812
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Acct-Session-Id = &amp;quot;1261403531L18dgh&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;Localhost&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;1115551212&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Password = &amp;quot;password&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Proxy-State = 0x3137
&lt;br&gt;Proxying request 1 to home server 127.0.0.1 port 11812
&lt;br&gt;Sending Access-Request of id 34 to 127.0.0.1 port 11812
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Acct-Session-Id = &amp;quot;1261403531L18dgh&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;Localhost&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;1115551212&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Password = &amp;quot;password&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Proxy-State = 0x3137
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 0.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host 127.0.0.1 port 1814, id=34, length=104
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;default&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Acct-Session-Id = &amp;quot;1261403531L18dgh&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;Localhost&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;1115551212&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Password = &amp;quot;password&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Proxy-State = 0x3137
&lt;br&gt;server test {
&lt;br&gt;+- entering group authorize
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{Stripped-User-Name} -&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{User-Name} -&amp;gt; default
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{%{User-Name}:-DEFAULT} -&amp;gt; default
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{%{Stripped-User-Name}:-%{%{User-Name}:-DEFAULT}} -&amp;gt; default
&lt;br&gt;rlm_sql (sql): sql_set_user escaped user --&amp;gt; 'default'
&lt;br&gt;rlm_sql (sql): Reserving sql socket id: 1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT id, username, attribute, value, op
&lt;br&gt;FROM radcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = '%{SQL-User-Name}'
&lt;br&gt;ORDER BY id -&amp;gt; SELECT id, username, attribute, value, op
&lt;br&gt;FROM radcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY
&lt;br&gt;id
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT id, username, attribute, value, op
&lt;br&gt;&amp;nbsp; &amp;nbsp; FROM radcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER
&lt;br&gt;BY id
&lt;br&gt;rlm_sql (sql): User found in radcheck table
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT id, username, attribute, value, op
&lt;br&gt;FROM radreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = '%{SQL-User-Name}'
&lt;br&gt;ORDER BY id -&amp;gt; SELECT id, username, attribute, value, op
&lt;br&gt;FROM radreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY
&lt;br&gt;id
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT id, username, attribute, value, op
&lt;br&gt;&amp;nbsp; &amp;nbsp; FROM radreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER
&lt;br&gt;BY id
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT groupname &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radusergroup
&lt;br&gt;WHERE username = '%{SQL-User-Name}' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY priority -&amp;gt;
&lt;br&gt;SELECT groupname &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radusergroup &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE username
&lt;br&gt;= 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY priority
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT groupname &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radusergroup
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;WHERE username = 'default' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY priority
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT id, groupname, attribute, &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Value, op
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname = '%{Sql-Group}'
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ORDER BY id -&amp;gt; SELECT id, groupname, attribute,
&lt;br&gt;Value, op &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname =
&lt;br&gt;'shells' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY id
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT id, groupname, attribute,
&lt;br&gt;Value, op &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupcheck &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname =
&lt;br&gt;'shells' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY id
&lt;br&gt;rlm_sql (sql): User found in group shells
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: SELECT id, groupname, attribute, &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; value, op
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname = '%{Sql-Group}'
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ORDER BY id -&amp;gt; SELECT id, groupname, attribute,
&lt;br&gt;value, op &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname =
&lt;br&gt;'shells' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY id
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;SELECT id, groupname, attribute,
&lt;br&gt;value, op &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FROM radgroupreply &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; WHERE groupname =
&lt;br&gt;'shells' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ORDER BY id
&lt;br&gt;rlm_sql (sql): Released sql socket id: 1
&lt;br&gt;++[sql] returns ok
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;rlm_pap: Normalizing MD5-Password from hex encoding
&lt;br&gt;++[pap] returns updated
&lt;br&gt;&amp;nbsp; rad_check_password: &amp;nbsp;Found Auth-Type
&lt;br&gt;auth: type &amp;quot;PAP&amp;quot;
&lt;br&gt;+- entering group PAP
&lt;br&gt;rlm_pap: login attempt with password &amp;quot;password&amp;quot;
&lt;br&gt;rlm_pap: Using MD5 encryption.
&lt;br&gt;rlm_pap: User authenticated successfully
&lt;br&gt;++[pap] returns ok
&lt;br&gt;Login OK: [default/password] (from client LocalHost port 0 cli 1115551212)
&lt;br&gt;+- entering group post-auth
&lt;br&gt;rlm_sql (sql): Processing sql_postauth
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{Stripped-User-Name} -&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{User-Name} -&amp;gt; default
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{%{User-Name}:-DEFAULT} -&amp;gt; default
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{%{Stripped-User-Name}:-%{%{User-Name}:-DEFAULT}} -&amp;gt; default
&lt;br&gt;rlm_sql (sql): sql_set_user escaped user --&amp;gt; 'default'
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: %{User-Password} -&amp;gt; password
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: INSERT INTO radpostauth
&lt;br&gt;(username, pass, reply, authdate) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VALUES (
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; '%{User-Name}',
&lt;br&gt;'%{%{User-Password}:-%{Chap-Password}}',
&lt;br&gt;'%{reply:Packet-Type}', '%S') -&amp;gt; INSERT INTO radpostauth
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (username, pass, reply, authdate)
&lt;br&gt;&amp;nbsp;VALUES ( &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'default',
&lt;br&gt;&amp;nbsp; 'password', &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'Access-Accept', '2009-12-21
&lt;br&gt;13:52:11')
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; expand: /var/log/freeradius/sqltrace.sql -&amp;gt;
&lt;br&gt;/var/log/freeradius/sqltrace.sql
&lt;br&gt;rlm_sql (sql) in sql_postauth: query is INSERT INTO radpostauth
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(username, pass, reply, authdate)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VALUES ( &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'default',
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;'password', &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'Access-Accept',
&lt;br&gt;'2009-12-21 13:52:11')
&lt;br&gt;rlm_sql (sql): Reserving sql socket id: 0
&lt;br&gt;rlm_sql_mysql: query: &amp;nbsp;INSERT INTO radpostauth
&lt;br&gt;&amp;nbsp; (username, pass, reply, authdate) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VALUES (
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'default',
&lt;br&gt;'password', &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 'Access-Accept', '2009-12-21
&lt;br&gt;13:52:11')
&lt;br&gt;rlm_sql (sql): Released sql socket id: 0
&lt;br&gt;++[sql] returns ok
&lt;br&gt;} # server test
&lt;br&gt;Sending Access-Accept of id 34 to 127.0.0.1 port 1814
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = NAS-Prompt-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cisco-AVPair = &amp;quot;shell:priv-lvl=15&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; APC-Service-Type = Admin
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Proxy-State = 0x3137
&lt;br&gt;Finished request 2.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 0.9 seconds.
&lt;br&gt;rad_recv: Access-Accept packet from host 127.0.0.1 port 11812, id=34, length=67
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = NAS-Prompt-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cisco-AVPair = &amp;quot;shell:priv-lvl=15&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; APC-Service-Type = Admin
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Proxy-State = 0x3137
&lt;br&gt;+- entering group post-proxy
&lt;br&gt;&amp;nbsp; rlm_eap: No pre-existing handler found
&lt;br&gt;++[eap] returns noop
&lt;br&gt;+- entering group authorize
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Proxy reply, or no User-Name. &amp;nbsp;Ignoring.
&lt;br&gt;++[slash] returns noop
&lt;br&gt;&amp;nbsp; &amp;nbsp; rlm_realm: Proxy reply, or no User-Name. &amp;nbsp;Ignoring.
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[eap] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;&amp;nbsp; rad_check_password: &amp;nbsp;Found Auth-Type
&lt;br&gt;&amp;nbsp; rad_check_password: Auth-Type = Accept, accepting the user
&lt;br&gt;Login OK: [TEST2/default/password] (from client desktop port 0 cli 1115551212)
&lt;br&gt;+- entering group post-auth
&lt;br&gt;++[exec] returns noop
&lt;br&gt;Sending Access-Accept of id 17 to 192.168.183.20 port 2535
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = NAS-Prompt-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cisco-AVPair = &amp;quot;shell:priv-lvl=15&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; APC-Service-Type = Admin
&lt;br&gt;Finished request 1.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;Cleaning up request 2 ID 34 with timestamp +172
&lt;br&gt;Cleaning up request 1 ID 17 with timestamp +172
&lt;br&gt;Ready to process requests.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Virtual-Server-not-setting-attributes-on-reply-tp26873711p26874272.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26874156</id>
	<title>Multiple clients on same IP address</title>
	<published>2009-12-21T05:45:51Z</published>
	<updated>2009-12-21T05:45:51Z</updated>
	<author>
		<name>Fahd Kasri</name>
	</author>
	<content type="html">Hi,&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Is it possible to have multiple Radius clients behind a router connect to a distant Freeradius server (these clients would therefore have the same IP address and be the same client in clients.conf)?&lt;/div&gt;
&lt;div&gt;I&amp;#39;ve this and apparently it works, but could there be any problems in the long run?&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Thanks.&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Fahd &lt;br&gt;
&lt;/div&gt;
&lt;br /&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Multiple-clients-on-same-IP-address-tp26874156p26874156.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26873979</id>
	<title>Re: Virtual Server not setting attributes on reply</title>
	<published>2009-12-21T05:29:29Z</published>
	<updated>2009-12-21T05:29:29Z</updated>
	<author>
		<name>Alan Buxey</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;&amp;gt; If I authenticate to TEST1/user
&lt;br&gt;&amp;gt; My response is &amp;quot;only&amp;quot; a successful auth.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; If I authenticate to TEST2/user
&lt;br&gt;&amp;gt; My response is a successful auth WITH Attributes (in this case the
&lt;br&gt;&amp;gt; attribute I'm setting is
&lt;br&gt;&amp;gt; Cisco-AVPair = &amp;quot;shell:priv-lvl=15&amp;quot;
&lt;br&gt;&lt;br&gt;where are you setting that attribute? in the default virtual_server 
&lt;br&gt;in the post-auth?
&lt;br&gt;&lt;br&gt;&amp;gt; It appears to me that using the virtual server is stripping the
&lt;br&gt;&amp;gt; attributes from the reply.
&lt;br&gt;&lt;br&gt;check your attr filter - check that those attributes arent cleared - if
&lt;br&gt;you run in full debug mode you should see everything that is happening
&lt;br&gt;and exactly where it gets set and where it gets wiped
&lt;br&gt;&lt;br&gt;alan
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Virtual-Server-not-setting-attributes-on-reply-tp26873711p26873979.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26874432</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T05:21:55Z</published>
	<updated>2009-12-21T05:21:55Z</updated>
	<author>
		<name>Alexander Clouter</name>
	</author>
	<content type="html">Alan DeKok &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26874432&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aland@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; Then shortly after restarting it:
&lt;br&gt;&amp;gt;&amp;gt; ----
&lt;br&gt;&amp;gt;&amp;gt; Program received signal SIGABRT, Aborted.
&lt;br&gt;&amp;gt;&amp;gt; [Switching to Thread 0x4f492950 (LWP 23808)]
&lt;br&gt;&amp;gt;&amp;gt; 0x00007f0060554ed5 in raise () from /lib/libc.so.6
&lt;br&gt;&amp;gt;&amp;gt; (gdb) wher
&lt;br&gt;&amp;gt;&amp;gt; #0 &amp;nbsp;0x00007f0060554ed5 in raise () from /lib/libc.so.6
&lt;br&gt;&amp;gt;&amp;gt; #1 &amp;nbsp;0x00007f00605563f3 in abort () from /lib/libc.so.6
&lt;br&gt;&amp;gt;&amp;gt; #2 &amp;nbsp;0x00000000004281f2 in rad_assert_fail (file=0x4455ef &amp;quot;threads.c&amp;quot;, line=406, 
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; expr=0x445628 &amp;quot;(*request)-&amp;gt;magic == REQUEST_MAGIC&amp;quot;) at util.c:363
&lt;br&gt;&amp;gt;&amp;gt; #3 &amp;nbsp;0x0000000000426adf in request_dequeue (request=0x7f004c006f30, fun=0x4f491d30) at threads.c:406
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp;That shouldn't happen... ever!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp;In fact, I've never seen it happen. &amp;nbsp;It can occur only when memory is
&lt;br&gt;&amp;gt; free'd, and still used.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; [snipped]
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; As for the latter one, that's new to me. &amp;nbsp;Alas it is going to be 
&lt;br&gt;&amp;gt;&amp;gt; difficult to repeat this 'experiment' as I would have to turn power off 
&lt;br&gt;&amp;gt;&amp;gt; to one of our server rooms...tends to annoy the yokels.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp;It should either happen a lot, or not at all.
&lt;br&gt;&amp;gt; 
&lt;/div&gt;Well as I said it is the first time I have seen it and I have been 
&lt;br&gt;running this code straight since that commit came out on the 5th. &amp;nbsp;So we 
&lt;br&gt;cannot say 'not at all'.
&lt;br&gt;&lt;br&gt;Want to put it down to a neutrino burst? :)
&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Alexander Clouter
&lt;br&gt;.sigmonster says: Shut off engine before fueling.
&lt;br&gt;&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26874432.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26873731</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T04:59:08Z</published>
	<updated>2009-12-21T04:59:08Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">Alexander Clouter wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Not quite on the pre-release but running 
&lt;br&gt;&amp;gt; f691b0ec7d4c92919bdd4dc81e8a86b211c00832 from the stable branch I got 
&lt;br&gt;&amp;gt; these after a 'hiccup' this morning on the network:
&lt;br&gt;&amp;gt; ----
&lt;br&gt;&amp;gt; Program received signal SIGPIPE, Broken pipe.
&lt;br&gt;&amp;gt; [Switching to Thread 0x411b9950 (LWP 18045)]
&lt;br&gt;&amp;gt; 0x00007fa8a156b75b in write () from /lib/libpthread.so.0
&lt;br&gt;&amp;gt; (gdb) bt
&lt;br&gt;&amp;gt; #0 &amp;nbsp;0x00007fa8a156b75b in write () from /lib/libpthread.so.0
&lt;br&gt;&amp;gt; #1 &amp;nbsp;0x00007fa89e51c1a9 in ?? () from /usr/lib/liblber-2.4.so.2
&lt;br&gt;&amp;gt; #2 &amp;nbsp;0x00007fa89e06f4b9 in _gnutls_io_write_buffered () from /usr/lib/libgnutls.so.26
&lt;/div&gt;&lt;br&gt;&amp;nbsp; Ugh.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Then shortly after restarting it:
&lt;br&gt;&amp;gt; ----
&lt;br&gt;&amp;gt; Program received signal SIGABRT, Aborted.
&lt;br&gt;&amp;gt; [Switching to Thread 0x4f492950 (LWP 23808)]
&lt;br&gt;&amp;gt; 0x00007f0060554ed5 in raise () from /lib/libc.so.6
&lt;br&gt;&amp;gt; (gdb) wher
&lt;br&gt;&amp;gt; #0 &amp;nbsp;0x00007f0060554ed5 in raise () from /lib/libc.so.6
&lt;br&gt;&amp;gt; #1 &amp;nbsp;0x00007f00605563f3 in abort () from /lib/libc.so.6
&lt;br&gt;&amp;gt; #2 &amp;nbsp;0x00000000004281f2 in rad_assert_fail (file=0x4455ef &amp;quot;threads.c&amp;quot;, line=406, 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; expr=0x445628 &amp;quot;(*request)-&amp;gt;magic == REQUEST_MAGIC&amp;quot;) at util.c:363
&lt;br&gt;&amp;gt; #3 &amp;nbsp;0x0000000000426adf in request_dequeue (request=0x7f004c006f30, fun=0x4f491d30) at threads.c:406
&lt;/div&gt;&lt;br&gt;&amp;nbsp; That shouldn't happen... ever!
&lt;br&gt;&lt;br&gt;&amp;nbsp; In fact, I've never seen it happen. &amp;nbsp;It can occur only when memory is
&lt;br&gt;free'd, and still used.
&lt;br&gt;&lt;br&gt;&amp;gt; The former one I have seen before and assuemd it was a bug in libldap, 
&lt;br&gt;&amp;gt; however I guess maybe freeradius should be catching the SIGPIPE there?
&lt;br&gt;&lt;br&gt;&amp;nbsp; Nope. &amp;nbsp;The libraries usually re-set the signal handlers.
&lt;br&gt;&lt;br&gt;&amp;gt; As for the latter one, that's new to me. &amp;nbsp;Alas it is going to be 
&lt;br&gt;&amp;gt; difficult to repeat this 'experiment' as I would have to turn power off 
&lt;br&gt;&amp;gt; to one of our server rooms...tends to annoy the yokels.
&lt;br&gt;&lt;br&gt;&amp;nbsp; It should either happen a lot, or not at all.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26873731.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26873711</id>
	<title>Virtual Server not setting attributes on reply</title>
	<published>2009-12-21T04:58:53Z</published>
	<updated>2009-12-21T04:58:53Z</updated>
	<author>
		<name>Timothy-45</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I'm having problems when using a virtual server.
&lt;br&gt;When using the &amp;quot;virtual_server&amp;quot; I'm not getting the reply attributes set.
&lt;br&gt;&lt;br&gt;It may be a config thing, but I haven't been able to find where the
&lt;br&gt;problem is from the documentation. And I can't understand why there
&lt;br&gt;would be the difference.
&lt;br&gt;&lt;br&gt;I have 2 realms set using the same virtual server. The only difference is
&lt;br&gt;realm TEST1 {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;virtual_server = test
&lt;br&gt;}
&lt;br&gt;realm TEST2 {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;= radius
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; format &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; = prefix
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; delimiter &amp;nbsp; &amp;nbsp; &amp;nbsp;= &amp;quot;/&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; authhost &amp;nbsp; &amp;nbsp; &amp;nbsp;= 127.0.0.1:11812
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; accthost &amp;nbsp; &amp;nbsp; &amp;nbsp;= 127.0.0.1:11813
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; secret &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;= secret
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;If I authenticate to TEST1/user
&lt;br&gt;My response is &amp;quot;only&amp;quot; a successful auth.
&lt;br&gt;&lt;br&gt;If I authenticate to TEST2/user
&lt;br&gt;My response is a successful auth WITH Attributes (in this case the
&lt;br&gt;attribute I'm setting is
&lt;br&gt;Cisco-AVPair = &amp;quot;shell:priv-lvl=15&amp;quot;
&lt;br&gt;&lt;br&gt;It appears to me that using the virtual server is stripping the
&lt;br&gt;attributes from the reply.
&lt;br&gt;&lt;br&gt;Can anyone tell me
&lt;br&gt;a) The approprate documentation covering this is so I know.
&lt;br&gt;b) What I have done wrong (and where to find the answers)
&lt;br&gt;or
&lt;br&gt;c) This is an actual bug and someone will look at it
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;Timothy
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Virtual-Server-not-setting-attributes-on-reply-tp26873711p26873711.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26873653</id>
	<title>Re: Debian, EAP, and the OpenSSL and GPL incompatibility</title>
	<published>2009-12-21T04:57:38Z</published>
	<updated>2009-12-21T04:57:38Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">Bjørn Mork wrote:
&lt;br&gt;&amp;gt; Just noticed:
&lt;br&gt;...
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Add OpenSSL license exception
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; commit 5ed6809aad46a999db022d9a0be417178b93dff6
&lt;br&gt;&amp;gt; Author: Alan T. DeKok &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26873653&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aland@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Date: &amp;nbsp; Mon Dec 21 10:49:50 2009 +0100
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Synced with upstream debian
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks!
&lt;/div&gt;&lt;br&gt;&amp;nbsp; More to come. :)
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/freeradius-%2B-ldap--eap-ttls-pap-tp26466404p26873653.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26872877</id>
	<title>Re: Debian, EAP, and the OpenSSL and GPL incompatibility</title>
	<published>2009-12-21T03:41:15Z</published>
	<updated>2009-12-21T03:41:15Z</updated>
	<author>
		<name>Bjørn Mork</name>
	</author>
	<content type="html">Just noticed:
&lt;br&gt;&lt;br&gt;commit 48674ba26a39620448723f5852aa30a899d515ac
&lt;br&gt;Author: Alan T. DeKok &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26872877&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aland@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Date: &amp;nbsp; Mon Dec 21 12:07:08 2009 +0100
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Add OpenSSL license exception
&lt;br&gt;&lt;br&gt;commit 5ed6809aad46a999db022d9a0be417178b93dff6
&lt;br&gt;Author: Alan T. DeKok &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26872877&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aland@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Date: &amp;nbsp; Mon Dec 21 10:49:50 2009 +0100
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Synced with upstream debian
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks!
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Bjørn
&lt;br&gt;&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/freeradius-%2B-ldap--eap-ttls-pap-tp26466404p26872877.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26872534</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T02:31:36Z</published>
	<updated>2009-12-21T02:31:36Z</updated>
	<author>
		<name>Alexander Clouter</name>
	</author>
	<content type="html">Alan DeKok &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26872534&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aland@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;I've put a pre-release of version 2.1.8 on the web site:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://git.freeradius.org/pre/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://git.freeradius.org/pre/&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp;Please do some sanity checks, and see if it works for you.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp;This version is from the new &amp;quot;v2.1.x&amp;quot; branch, which is Version 2.1.7,
&lt;br&gt;&amp;gt; plus *only* bug fixes. &amp;nbsp;The &amp;quot;stable&amp;quot; branch is now planned to become
&lt;br&gt;&amp;gt; version 2.2.0 in January. &amp;nbsp;It will include TCP transport, among other
&lt;br&gt;&amp;gt; new features.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp;If there are no major issues, we can release 2.1.8 next week.
&lt;br&gt;&amp;gt; 
&lt;/div&gt;Not quite on the pre-release but running 
&lt;br&gt;f691b0ec7d4c92919bdd4dc81e8a86b211c00832 from the stable branch I got 
&lt;br&gt;these after a 'hiccup' this morning on the network:
&lt;br&gt;----
&lt;br&gt;Program received signal SIGPIPE, Broken pipe.
&lt;br&gt;[Switching to Thread 0x411b9950 (LWP 18045)]
&lt;br&gt;0x00007fa8a156b75b in write () from /lib/libpthread.so.0
&lt;br&gt;(gdb) bt
&lt;br&gt;#0 &amp;nbsp;0x00007fa8a156b75b in write () from /lib/libpthread.so.0
&lt;br&gt;#1 &amp;nbsp;0x00007fa89e51c1a9 in ?? () from /usr/lib/liblber-2.4.so.2
&lt;br&gt;#2 &amp;nbsp;0x00007fa89e06f4b9 in _gnutls_io_write_buffered () from /usr/lib/libgnutls.so.26
&lt;br&gt;#3 &amp;nbsp;0x00007fa89e06c601 in _gnutls_send_int () from /usr/lib/libgnutls.so.26
&lt;br&gt;#4 &amp;nbsp;0x00007fa89e08a6e0 in gnutls_alert_send () from /usr/lib/libgnutls.so.26
&lt;br&gt;#5 &amp;nbsp;0x00007fa89e06c90f in gnutls_bye () from /usr/lib/libgnutls.so.26
&lt;br&gt;#6 &amp;nbsp;0x00007fa89e754c30 in ?? () from /usr/lib/libldap_r-2.4.so.2
&lt;br&gt;#7 &amp;nbsp;0x00007fa89e51c6ec in ber_int_sb_close () from /usr/lib/liblber-2.4.so.2
&lt;br&gt;#8 &amp;nbsp;0x00007fa89e745f5d in ldap_free_connection () from /usr/lib/libldap_r-2.4.so.2
&lt;br&gt;#9 &amp;nbsp;0x00007fa89e73c8cf in ldap_ld_free () from /usr/lib/libldap_r-2.4.so.2
&lt;br&gt;#10 0x00007fa89e96e1c1 in perform_search (instance=0x1f2a0e0, conn=0x1f2a5b0, 
&lt;br&gt;&amp;nbsp; &amp;nbsp; search_basedn=0x260b3e0 &amp;quot;ou=Networks,ou=LanWarden,o=soas&amp;quot;, scope=1, 
&lt;br&gt;&amp;nbsp; &amp;nbsp; filter=0x27f6fc0 &amp;quot;(&amp;(objectClass=lanwardenNetwork)(member=cn=001e4fe171de,ou=users-staff,ou=imported,ou=Hosts,ou=LanWarden,o=soas))&amp;quot;, attrs=0x2676c70, result=0x411b7050) at rlm_ldap.c:811
&lt;br&gt;#11 0x00007fa89e96f6ab in ldap_xlat (instance=0x1f2a0e0, request=0x7fa894002530, 
&lt;br&gt;&amp;nbsp; &amp;nbsp; fmt=0x2de8ae0 &amp;quot;ldap:///ou=Networks,ou=LanWarden,o=soas?cn?one?(&amp;(objectClass=lanwardenNetwork)(member=%{control:MAC-Address-LdapDn}))&amp;quot;, out=0x411b7840 &amp;quot;&amp;quot;, freespace=254, func=0x42ba4c &amp;lt;xlat_copy&amp;gt;) at rlm_ldap.c:1199
&lt;br&gt;#12 0x000000000042b89b in decode_attribute (from=0x411b76d0, to=0x411b76c8, freespace=254, open_p=0x411b765c, 
&lt;br&gt;&amp;nbsp; &amp;nbsp; request=0x7fa894002530, func=0x42ba4c &amp;lt;xlat_copy&amp;gt;) at xlat.c:911
&lt;br&gt;#13 0x000000000042bd4f in radius_xlat (out=0x411b7840 &amp;quot;&amp;quot;, outlen=254, 
&lt;br&gt;&amp;nbsp; &amp;nbsp; fmt=0x2288d30 &amp;quot;%{ldap_autz_soasauth-nd1:ldap:///ou=Networks,ou=LanWarden,o=soas?cn?one?(&amp;(objectClass=lanwardenNetwork)(member=%{control:MAC-Address-LdapDn}))}&amp;quot;, request=0x7fa894002530, func=0x42ba4c &amp;lt;xlat_copy&amp;gt;) at xlat.c:1086
&lt;br&gt;#14 0x00007fa89be8b4bb in do_attr_rewrite (instance=0x2288680, request=0x7fa894002530) at rlm_attr_rewrite.c:179
&lt;br&gt;#15 0x00007fa89be8c0c8 in attr_rewrite_postauth (instance=0x2288680, request=0x7fa894002530)
&lt;br&gt;&amp;nbsp; &amp;nbsp; at rlm_attr_rewrite.c:453
&lt;br&gt;#16 0x0000000000420655 in call_modsingle (component=7, sp=0x2288540, request=0x7fa894002530) at modcall.c:297
&lt;br&gt;#17 0x00000000004214ac in modcall (component=7, c=0x2287f50, request=0x7fa894002530) at modcall.c:669
&lt;br&gt;#18 0x000000000041ec68 in indexed_modcall (comp=7, idx=0, request=0x7fa894002530) at modules.c:691
&lt;br&gt;#19 0x00000000004200ff in module_post_auth (postauth_type=0, request=0x7fa894002530) at modules.c:1533
&lt;br&gt;#20 0x000000000040a148 in rad_postauth (request=0x7fa894002530) at auth.c:421
&lt;br&gt;#21 0x000000000040ac45 in rad_authenticate (request=0x7fa894002530) at auth.c:811
&lt;br&gt;#22 0x0000000000434ef7 in radius_handle_request (request=0x7fa894002530, fun=0x40a194 &amp;lt;rad_authenticate&amp;gt;)
&lt;br&gt;&amp;nbsp; &amp;nbsp; at event.c:4097
&lt;br&gt;#23 0x0000000000426cb3 in request_handler_thread (arg=0x7fa8940023d0) at threads.c:492
&lt;br&gt;#24 0x00007fa8a1564fc7 in start_thread () from /lib/libpthread.so.0
&lt;br&gt;#25 0x00007fa8a08af5ad in clone () from /lib/libc.so.6
&lt;br&gt;#26 0x0000000000000000 in ?? ()
&lt;br&gt;(gdb) 
&lt;br&gt;----
&lt;br&gt;&lt;br&gt;Then shortly after restarting it:
&lt;br&gt;----
&lt;br&gt;Program received signal SIGABRT, Aborted.
&lt;br&gt;[Switching to Thread 0x4f492950 (LWP 23808)]
&lt;br&gt;0x00007f0060554ed5 in raise () from /lib/libc.so.6
&lt;br&gt;(gdb) wher
&lt;br&gt;#0 &amp;nbsp;0x00007f0060554ed5 in raise () from /lib/libc.so.6
&lt;br&gt;#1 &amp;nbsp;0x00007f00605563f3 in abort () from /lib/libc.so.6
&lt;br&gt;#2 &amp;nbsp;0x00000000004281f2 in rad_assert_fail (file=0x4455ef &amp;quot;threads.c&amp;quot;, line=406, 
&lt;br&gt;&amp;nbsp; &amp;nbsp; expr=0x445628 &amp;quot;(*request)-&amp;gt;magic == REQUEST_MAGIC&amp;quot;) at util.c:363
&lt;br&gt;#3 &amp;nbsp;0x0000000000426adf in request_dequeue (request=0x7f004c006f30, fun=0x4f491d30) at threads.c:406
&lt;br&gt;#4 &amp;nbsp;0x0000000000426c3d in request_handler_thread (arg=0x7f004c006f00) at threads.c:483
&lt;br&gt;#5 &amp;nbsp;0x00007f00612a7fc7 in start_thread () from /lib/libpthread.so.0
&lt;br&gt;#6 &amp;nbsp;0x00007f00605f25ad in clone () from /lib/libc.so.6
&lt;br&gt;#7 &amp;nbsp;0x0000000000000000 in ?? ()
&lt;br&gt;(gdb) 
&lt;br&gt;----
&lt;br&gt;&lt;br&gt;The former one I have seen before and assuemd it was a bug in libldap, 
&lt;br&gt;however I guess maybe freeradius should be catching the SIGPIPE there?
&lt;br&gt;&lt;br&gt;As for the latter one, that's new to me. &amp;nbsp;Alas it is going to be 
&lt;br&gt;difficult to repeat this 'experiment' as I would have to turn power off 
&lt;br&gt;to one of our server rooms...tends to annoy the yokels.
&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Alexander Clouter
&lt;br&gt;.sigmonster says: BOFH excuse #276:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; U.S. Postal Service
&lt;br&gt;&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26872534.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26872077</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T02:19:19Z</published>
	<updated>2009-12-21T02:19:19Z</updated>
	<author>
		<name>Alan Buxey</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&amp;gt; Alan Buxey wrote:
&lt;br&gt;&amp;gt; &amp;gt; aye - there were some questions relating to getting some of the older
&lt;br&gt;&amp;gt; &amp;gt; requested patches put into 2.1.8 too - has that been addressed?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; Which patches?
&lt;br&gt;&lt;br&gt;there were a couple cant remember exactly - i know one was '17' - the CHAP one. 
&lt;br&gt;I applied it locally to my pre 2.1.8 - it didnt go in 100% clean because
&lt;br&gt;it was written some time back....things appear to be okay after it went in.
&lt;br&gt;&lt;br&gt;wasnt there also an SQL one and a proxy one?
&lt;br&gt;&lt;br&gt;alan
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26872077.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26872052</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T02:15:00Z</published>
	<updated>2009-12-21T02:15:00Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">Bjørn Mork wrote:
&lt;br&gt;&amp;gt; The v2.1.x branch from github up to and including commit
&lt;br&gt;&amp;gt; 1d80707880c1bf94ad1e87be74221a6c7b4cb4c7 has now been running stable for
&lt;br&gt;&amp;gt; more than 5 days for me. &amp;nbsp;All the previously reported problems seem to
&lt;br&gt;&amp;gt; be gone. &amp;nbsp;So I'd say it makes a good 2.1.8 release for Christmas.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Thanks. &amp;nbsp;I've added a bunch more minor changes (docs, checks from
&lt;br&gt;static analysis tools, etc.) &amp;nbsp;But no more code changes.
&lt;br&gt;&lt;br&gt;&amp;nbsp; It should be good to go...
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26872052.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26872031</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T02:14:02Z</published>
	<updated>2009-12-21T02:14:02Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">Alan Buxey wrote:
&lt;br&gt;&amp;gt; aye - there were some questions relating to getting some of the older
&lt;br&gt;&amp;gt; requested patches put into 2.1.8 too - has that been addressed?
&lt;br&gt;&lt;br&gt;&amp;nbsp; Which patches?
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26872031.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26871993</id>
	<title>Re: Certificate not valid in PEAP</title>
	<published>2009-12-21T02:10:31Z</published>
	<updated>2009-12-21T02:10:31Z</updated>
	<author>
		<name>Alan DeKok-2</name>
	</author>
	<content type="html">Fernando Calvelo Vazquez wrote:
&lt;br&gt;&amp;gt; Hi folks:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm still trying to configure any authentication method that includes a
&lt;br&gt;&amp;gt; client certificate validation (PEAP, EAP-TTLS... ) behind my
&lt;br&gt;&amp;gt; window-vista supplicant software client, but unfortunately no successfully.
&lt;br&gt;&amp;gt; Attached to this mail is the output of one PEAP try.
&lt;br&gt;&amp;gt; The authentication starts once and again forever, in a loop, but never
&lt;br&gt;&amp;gt; ends successfully.
&lt;br&gt;&lt;br&gt;&amp;nbsp; There are two ways to figure out what's going on.
&lt;br&gt;&lt;br&gt;1) test it with a real client to be sure it works.
&lt;br&gt;&lt;br&gt;&amp;nbsp; See &lt;a href=&quot;http://deployingradius.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://deployingradius.com/&lt;/a&gt;&amp;nbsp;for instructions on using eapol_test.
&lt;br&gt;&amp;nbsp;You can also use client certificates. &amp;nbsp;See the wpa_supplicant docs for
&lt;br&gt;more information.
&lt;br&gt;&lt;br&gt;2) debug Windows
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://technet.microsoft.com/en-us/library/cc766215(WS.10).aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://technet.microsoft.com/en-us/library/cc766215(WS.10).aspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; If (1) works with client certs, then the issue is only (2).
&lt;br&gt;&lt;br&gt;&amp;gt; I'm a bit frustrated with this &amp;quot;certificates&amp;quot; locking point.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Blame Microsoft. &amp;nbsp;They put great effort into breaking
&lt;br&gt;inter-operability, and in ensuring that it's nearly impossible for
&lt;br&gt;administrators to quickly discover the cause of the problem.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Alan DeKok.
&lt;br&gt;&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Certificate-not-valid-in-PEAP-tp26871830p26871993.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26871949</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T02:03:40Z</published>
	<updated>2009-12-21T02:03:40Z</updated>
	<author>
		<name>Alan Buxey</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;&amp;gt; The v2.1.x branch from github up to and including commit
&lt;br&gt;&amp;gt; 1d80707880c1bf94ad1e87be74221a6c7b4cb4c7 has now been running stable for
&lt;br&gt;&amp;gt; more than 5 days for me. &amp;nbsp;All the previously reported problems seem to
&lt;br&gt;&amp;gt; be gone. &amp;nbsp;So I'd say it makes a good 2.1.8 release for Christmas.
&lt;br&gt;&lt;br&gt;aye - there were some questions relating to getting some of the older
&lt;br&gt;requested patches put into 2.1.8 too - has that been addressed?
&lt;br&gt;&lt;br&gt;alan
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26871949.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26871925</id>
	<title>Re: Certificate not valid in PEAP</title>
	<published>2009-12-21T02:02:24Z</published>
	<updated>2009-12-21T02:02:24Z</updated>
	<author>
		<name>Alan Buxey</name>
	</author>
	<content type="html">hi,
&lt;br&gt;&lt;br&gt;not sure about your mix of PEAP or EAP-TTLS iwht client certificate - 
&lt;br&gt;usually these systems use another form of user auth - such
&lt;br&gt;as password, generic token card etc ....
&lt;br&gt;&lt;br&gt;what you need is the server certificate and you also need to ensure that the
&lt;br&gt;CA that signed the servr cert is installed on the windows system - plenty
&lt;br&gt;of sites that say how to do this - or you can simply google for
&lt;br&gt;eg wireless setup instructions (most universities are starting to have
&lt;br&gt;very good pages ;-) )
&lt;br&gt;&lt;br&gt;EAP-TLS uses client certificates - and if you eg put the matching
&lt;br&gt;entry for the CN into the users file then it'd know that user/cert is valid
&lt;br&gt;(to reject you need to revoke the cert)
&lt;br&gt;&lt;br&gt;alan
&lt;br&gt;&amp;nbsp;
&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Certificate-not-valid-in-PEAP-tp26871830p26871925.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26871830</id>
	<title>Certificate not valid in PEAP</title>
	<published>2009-12-21T01:50:56Z</published>
	<updated>2009-12-21T01:50:56Z</updated>
	<author>
		<name>swatzy</name>
	</author>
	<content type="html">Hi folks:
&lt;br&gt;&lt;br&gt;I'm still trying to configure any authentication method that includes a 
&lt;br&gt;client certificate validation (PEAP, EAP-TTLS... ) behind my 
&lt;br&gt;window-vista supplicant software client, but unfortunately no successfully.
&lt;br&gt;Attached to this mail is the output of one PEAP try.
&lt;br&gt;The authentication starts once and again forever, in a loop, but never 
&lt;br&gt;ends successfully.
&lt;br&gt;I have verify that the client certificate include the Microsoft extensions
&lt;br&gt;# openssl x509 -text -in client.pem
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; X509v3 extensions:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; X509v3 Extended Key Usage:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; TLS Web Client Authentication
&lt;br&gt;and also... I have signed certificates by using the Makefile from 
&lt;br&gt;version 2.1.8 (latest one)
&lt;br&gt;&lt;br&gt;I'm a bit frustrated with this &amp;quot;certificates&amp;quot; locking point.
&lt;br&gt;Thanks a lot in advance for your help.
&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Fernando.
&lt;br&gt;&lt;br /&gt;FreeRADIUS Version 2.1.7, for host x86_64-unknown-linux-gnu, built on Nov 16 2009 at 14:08:53
&lt;br&gt;Copyright (C) 1999-2009 The FreeRADIUS server project and contributors. 
&lt;br&gt;There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A 
&lt;br&gt;PARTICULAR PURPOSE. 
&lt;br&gt;You may redistribute copies of FreeRADIUS under the terms of the 
&lt;br&gt;GNU General Public License v2. 
&lt;br&gt;Starting - reading configuration files ...
&lt;br&gt;including configuration file /usr/local/etc/raddb/radiusd.conf
&lt;br&gt;including configuration file /usr/local/etc/raddb/proxy.conf
&lt;br&gt;including configuration file /usr/local/etc/raddb/clients.conf
&lt;br&gt;including files in directory /usr/local/etc/raddb/modules/
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/pam
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/counter
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/cui
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/wimax
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/sradutmp
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/sqlcounter_expire_on_login
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/etc_group
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/logintime
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/policy
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/digest
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/pap
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/acct_unique
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/unix
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/smbpasswd
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/detail.log
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/files
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/ippool
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/realm
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/ldap
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/linelog
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/sql_log
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/chap
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/mac2ip
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/attr_rewrite
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/preprocess
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/detail.example.com
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/detail
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/expiration
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/otp
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/exec
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/inner-eap
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/mac2vlan
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/passwd
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/attr_filter
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/expr
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/smsotp
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/krb5
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/radutmp
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/checkval
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/echo
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/perl
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/always
&lt;br&gt;including configuration file /usr/local/etc/raddb/modules/mschap
&lt;br&gt;including configuration file /usr/local/etc/raddb/eap.conf
&lt;br&gt;including configuration file /usr/local/etc/raddb/policy.conf
&lt;br&gt;including files in directory /usr/local/etc/raddb/sites-enabled/
&lt;br&gt;including configuration file /usr/local/etc/raddb/sites-enabled/default
&lt;br&gt;including configuration file /usr/local/etc/raddb/sites-enabled/inner-tunnel
&lt;br&gt;including configuration file /usr/local/etc/raddb/sites-enabled/control-socket
&lt;br&gt;including dictionary file /usr/local/etc/raddb/dictionary
&lt;br&gt;main {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; prefix = &amp;quot;/usr/local&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; localstatedir = &amp;quot;/usr/local/var&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; logdir = &amp;quot;/usr/local/var/log/radius&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; libdir = &amp;quot;/usr/local/lib&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; radacctdir = &amp;quot;/usr/local/var/log/radius/radacct&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hostname_lookups = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_request_time = 30
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cleanup_delay = 5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_requests = 1024
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; allow_core_dumps = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pidfile = &amp;quot;/usr/local/var/run/radiusd/radiusd.pid&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; checkrad = &amp;quot;/usr/local/sbin/checkrad&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; debug_level = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; proxy_requests = yes
&lt;br&gt;&amp;nbsp;log {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; stripped_names = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auth = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auth_badpass = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auth_goodpass = no
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;security {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_attributes = 200
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; reject_delay = 1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; status_server = yes
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;}
&lt;br&gt;radiusd: #### Loading Realms and Home Servers ####
&lt;br&gt;&amp;nbsp;proxy server {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; retry_delay = 5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; retry_count = 3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; default_fallback = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dead_time = 120
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; wake_all_if_all_dead = no
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;home_server localhost {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipaddr = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; port = 1812
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = &amp;quot;auth&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; response_window = 20
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_outstanding = 65536
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_message_authenticator = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; zombie_period = 40
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; status_check = &amp;quot;status-server&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ping_interval = 30
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; check_interval = 30
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; num_answers_to_alive = 3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; num_pings_to_alive = 3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; revive_interval = 120
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; status_check_timeout = 4
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; irt = 2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mrt = 16
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mrc = 5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mrd = 30
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;home_server_pool my_auth_failover {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = fail-over
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; home_server = localhost
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;realm example.com {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auth_pool = my_auth_failover
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;realm LOCAL {
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;radiusd: #### Loading Clients ####
&lt;br&gt;&amp;nbsp;client localhost {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipaddr = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_message_authenticator = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; nastype = &amp;quot;other&amp;quot;
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;client X.X.X.X {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_message_authenticator = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; shortname = &amp;quot;xxxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; nastype = &amp;quot;other&amp;quot;
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;radiusd: #### Instantiating modules ####
&lt;br&gt;&amp;nbsp;instantiate {
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_exec
&lt;br&gt;&amp;nbsp;Module: Instantiating exec
&lt;br&gt;&amp;nbsp; exec {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; wait = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; input_pairs = &amp;quot;request&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; shell_escape = yes
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_expr
&lt;br&gt;&amp;nbsp;Module: Instantiating expr
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_expiration
&lt;br&gt;&amp;nbsp;Module: Instantiating expiration
&lt;br&gt;&amp;nbsp; expiration {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; reply-message = &amp;quot;Password Has Expired &amp;nbsp;&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_logintime
&lt;br&gt;&amp;nbsp;Module: Instantiating logintime
&lt;br&gt;&amp;nbsp; logintime {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; reply-message = &amp;quot;You are calling outside your allowed timespan &amp;nbsp;&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; minimum-timeout = 60
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;radiusd: #### Loading Virtual Servers ####
&lt;br&gt;server inner-tunnel {
&lt;br&gt;&amp;nbsp;modules {
&lt;br&gt;&amp;nbsp;Module: Checking authenticate {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_pap
&lt;br&gt;&amp;nbsp;Module: Instantiating pap
&lt;br&gt;&amp;nbsp; pap {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; encryption_scheme = &amp;quot;auto&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auto_header = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_chap
&lt;br&gt;&amp;nbsp;Module: Instantiating chap
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_mschap
&lt;br&gt;&amp;nbsp;Module: Instantiating mschap
&lt;br&gt;&amp;nbsp; mschap {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use_mppe = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_encryption = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; require_strong = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_ntdomain_hack = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_unix
&lt;br&gt;&amp;nbsp;Module: Instantiating unix
&lt;br&gt;&amp;nbsp; unix {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; radwtmp = &amp;quot;/usr/local/var/log/radius/radwtmp&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_eap
&lt;br&gt;&amp;nbsp;Module: Instantiating eap
&lt;br&gt;&amp;nbsp; eap {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; default_eap_type = &amp;quot;md5&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; timer_expire = 60
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ignore_unknown_eap_types = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cisco_accounting_username_bug = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_sessions = 2048
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_md5
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-md5
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_leap
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-leap
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_gtc
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-gtc
&lt;br&gt;&amp;nbsp; &amp;nbsp;gtc {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; challenge = &amp;quot;Password: &amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auth_type = &amp;quot;PAP&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_tls
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-tls
&lt;br&gt;&amp;nbsp; &amp;nbsp;tls {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; rsa_key_exchange = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dh_key_exchange = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; rsa_key_length = 512
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dh_key_length = 512
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; verify_depth = 0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pem_file_type = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; private_key_file = &amp;quot;/usr/local/etc/raddb/certs/server.pem&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; certificate_file = &amp;quot;/usr/local/etc/raddb/certs/server.pem&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CA_file = &amp;quot;/usr/local/etc/raddb/certs/ca.pem&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; private_key_password = &amp;quot;xxxxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dh_file = &amp;quot;/usr/local/etc/raddb/certs/dh&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; random_file = &amp;quot;/usr/local/etc/raddb/certs/random&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; fragment_size = 1024
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; include_length = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; check_crl = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cipher_list = &amp;quot;DEFAULT&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; make_cert_command = &amp;quot;/usr/local/etc/raddb/certs/bootstrap&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; cache {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; enable = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lifetime = 24
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; max_entries = 255
&lt;br&gt;&amp;nbsp; &amp;nbsp; }
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_ttls
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-ttls
&lt;br&gt;&amp;nbsp; &amp;nbsp;ttls {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; default_eap_type = &amp;quot;md5&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; copy_request_to_tunnel = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use_tunneled_reply = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; virtual_server = &amp;quot;inner-tunnel&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; include_length = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_peap
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-peap
&lt;br&gt;&amp;nbsp; &amp;nbsp;peap {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; default_eap_type = &amp;quot;mschapv2&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; copy_request_to_tunnel = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use_tunneled_reply = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; proxy_tunneled_request_as_eap = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; virtual_server = &amp;quot;inner-tunnel&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Linked to sub-module rlm_eap_mschapv2
&lt;br&gt;&amp;nbsp;Module: Instantiating eap-mschapv2
&lt;br&gt;&amp;nbsp; &amp;nbsp;mschapv2 {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_ntdomain_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;Module: Checking authorize {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_realm
&lt;br&gt;&amp;nbsp;Module: Instantiating suffix
&lt;br&gt;&amp;nbsp; realm suffix {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; format = &amp;quot;suffix&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; delimiter = &amp;quot;@&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ignore_default = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ignore_null = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_files
&lt;br&gt;&amp;nbsp;Module: Instantiating files
&lt;br&gt;&amp;nbsp; files {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; usersfile = &amp;quot;/usr/local/etc/raddb/users&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; acctusersfile = &amp;quot;/usr/local/etc/raddb/acct_users&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; preproxy_usersfile = &amp;quot;/usr/local/etc/raddb/preproxy_users&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; compat = &amp;quot;no&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking session {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_radutmp
&lt;br&gt;&amp;nbsp;Module: Instantiating radutmp
&lt;br&gt;&amp;nbsp; radutmp {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; filename = &amp;quot;/usr/local/var/log/radius/radutmp&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; username = &amp;quot;%{User-Name}&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; case_sensitive = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; check_with_nas = yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; perm = 384
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; callerid = yes
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking post-proxy {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Checking post-auth {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_attr_filter
&lt;br&gt;&amp;nbsp;Module: Instantiating attr_filter.access_reject
&lt;br&gt;&amp;nbsp; attr_filter attr_filter.access_reject {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; attrsfile = &amp;quot;/usr/local/etc/raddb/attrs.access_reject&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; key = &amp;quot;%{User-Name}&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;} # modules
&lt;br&gt;} # server
&lt;br&gt;server {
&lt;br&gt;&amp;nbsp;modules {
&lt;br&gt;&amp;nbsp;Module: Checking authenticate {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Checking authorize {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_preprocess
&lt;br&gt;&amp;nbsp;Module: Instantiating preprocess
&lt;br&gt;&amp;nbsp; preprocess {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; huntgroups = &amp;quot;/usr/local/etc/raddb/huntgroups&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hints = &amp;quot;/usr/local/etc/raddb/hints&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_ascend_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ascend_channels_per_line = 23
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_ntdomain_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_specialix_jetstream_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_cisco_vsa_hack = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; with_alvarion_vsa_hack = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking preacct {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_acct_unique
&lt;br&gt;&amp;nbsp;Module: Instantiating acct_unique
&lt;br&gt;&amp;nbsp; acct_unique {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; key = &amp;quot;User-Name, Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking accounting {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Linked to module rlm_detail
&lt;br&gt;&amp;nbsp;Module: Instantiating detail
&lt;br&gt;&amp;nbsp; detail {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; detailfile = &amp;quot;/usr/local/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; header = &amp;quot;%t&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; detailperm = 384
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dirperm = 493
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; locking = no
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; log_packet_header = no
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Instantiating attr_filter.accounting_response
&lt;br&gt;&amp;nbsp; attr_filter attr_filter.accounting_response {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; attrsfile = &amp;quot;/usr/local/etc/raddb/attrs.accounting_response&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; key = &amp;quot;%{User-Name}&amp;quot;
&lt;br&gt;&amp;nbsp; }
&lt;br&gt;&amp;nbsp;Module: Checking session {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Checking post-proxy {...} for more modules to load
&lt;br&gt;&amp;nbsp;Module: Checking post-auth {...} for more modules to load
&lt;br&gt;&amp;nbsp;} # modules
&lt;br&gt;} # server
&lt;br&gt;radiusd: #### Opening IP addresses and Ports ####
&lt;br&gt;listen {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = &amp;quot;auth&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipaddr = *
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; port = 0
&lt;br&gt;}
&lt;br&gt;listen {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = &amp;quot;acct&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipaddr = *
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; port = 0
&lt;br&gt;}
&lt;br&gt;listen {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = &amp;quot;control&amp;quot;
&lt;br&gt;&amp;nbsp;listen {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; socket = &amp;quot;/usr/local/var/run/radiusd/radiusd.sock&amp;quot;
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;}
&lt;br&gt;Listening on authentication address * port 1812
&lt;br&gt;Listening on accounting address * port 1813
&lt;br&gt;Listening on command file /usr/local/var/run/radiusd/radiusd.sock
&lt;br&gt;Listening on proxy address * port 1814
&lt;br&gt;Ready to process requests.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=118, length=188
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0202001501737761747a7930312e657372662e6672
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x54c3b407a4e5f674fdddef648d64929d
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 2 length 21
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;[pap] WARNING! No &amp;quot;known good&amp;quot; password found for the user. &amp;nbsp;Authentication may fail because of this.
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] EAP Identity
&lt;br&gt;[eap] processing type md5
&lt;br&gt;rlm_eap_md5: Issuing Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 118 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0103001604107f7d11ec3b0ab49d581bf7b34c80c28a
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4636987ca6f7bd81569582da
&lt;br&gt;Finished request 0.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=119, length=191
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020300060319
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4636987ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x33129fee7264d338478ba2014579ff92
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 3 length 6
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;[pap] WARNING! No &amp;quot;known good&amp;quot; password found for the user. &amp;nbsp;Authentication may fail because of this.
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP NAK
&lt;br&gt;[eap] EAP-NAK asked for EAP-Type/peap
&lt;br&gt;[eap] processing type tls
&lt;br&gt;[tls] Initiate
&lt;br&gt;[tls] Start returned 1
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 119 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010400061920
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4731857ca6f7bd81569582da
&lt;br&gt;Finished request 1.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=120, length=312
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0204007f19800000007516030100700100006c03014b2f2f919f25d4d668184f7c5857cbe41cb1e31423aaaafee5a843885d02dcd8000018002f00350005000ac009c00ac013c01400320038001300040100002b000000150013000010737761747a7930312e657372662e6672000a00080006001700180019000b00020100
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4731857ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x36ee14e3f9fe3620c3a4daa7a0b3a833
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 4 length 127
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;&amp;nbsp; TLS Length 117
&lt;br&gt;[peap] Length Included
&lt;br&gt;[peap] eaptls_verify returned 11 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; (other): before/accept initialization 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: before/accept initialization 
&lt;br&gt;[peap] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 Handshake [length 0070], ClientHello &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 read client hello A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 002a], ServerHello &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write server hello A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 07d3], Certificate &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write certificate A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 0004], ServerHelloDone &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write server done A 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 flush data 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: Need to read more data: SSLv3 read client certificate A
&lt;br&gt;In SSL Handshake Phase 
&lt;br&gt;In SSL Accept mode &amp;nbsp;
&lt;br&gt;[peap] eaptls_process returned 13 
&lt;br&gt;[peap] EAPTLS_HANDLED
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 120 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0105040019c000000810160301002a0200002603014b2f2f91d2cd14e81cbd8b2062cf6afac049f6b57c2e90945e69a7ac38c1200c00002f0016030107d30b0007cf0007cc00035d3082035930820241a003020102020114300d06092a864886f70d0101040500307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672301e170d3039313232313038303833395a170d313031
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x3232313038303833395a3049310b3009060355040613024652310e300c060355040813054973657265310d300b060355040a130445535246311b301906035504031312726164697573736572762e657372662e667230820122300d06092a864886f70d01010105000382010f003082010a0282010100df65e73bb432b019abe63c0a455e5053aa65ee5cdebb77dba90300b7933a6e1ddc3b764bf3d4305ab36530461cc0ade6ca4a916bfeb68ec9103ef74b02dcefbbb5553ce4f88225f43a7ff26195b0c2fd70a4620ead334a2c5d3c6f576b3eec5229cac9ab7ce3a7ffed9d70ee905be62a351dd2ee354c22773dea7ab1eeed05316aa5f33c7ca4cd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x1c92b20e08f50bb97033f29eb4f40985a8857170ad6f857f78f12fe394111de60ff71eccdf912dfdd0fd0f153fc6fe9593e15d914725f9b0968acfffcb35a2fb91c5298ac632a38014c778b509531292171a42e8308efc729f02454eaf5c71c0a4384b51081e6ce67f769ec52a38397c87e3b1bbd012fdb4d70203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d010104050003820101001705f81c5cfb5f42fb060d784d6d4dda29ce188c6f0203ffc1382b0fb3bd755fedde13cb3010fa4c753409b525d172921a1c19ef77f49f6ab490c1bd751ab5f0aea4d702c4b92b5b2e45485d77e80114762d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x87c80af1b6c317546180ebf118b164616baaaad68601e6fdcc895e328f39ca693b551da66ba9a748e205e67fd05430eefd1ca8a204bb56994ac3a0abf00d546e19263b678b72b04e1286cf1db63e93c089c8072bfe446d1b5e9b08940c6b6fcec73c5953ceeccb4d53b3b2bae39878ef00597f96df75b59776e176ccf328f22312d696524d43a62a623dc9af8c13b270e932bc7afcc456b7574f719d6f21faf4669390cd604dc28d850bc3c349fa000469308204653082034da003020102020900c42387580a65a3a9300d06092a864886f70d0101050500307e310b3009060355040613024652310e300c0603550408130549736572653111300f0603
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x55040713084772656e6f626c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4430857ca6f7bd81569582da
&lt;br&gt;Finished request 2.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=121, length=191
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020500061900
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4430857ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x7282abc649eadba24affcf74b028b2a5
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 5 length 6
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] Received TLS ACK
&lt;br&gt;[peap] ACK handshake fragment handler
&lt;br&gt;[peap] eaptls_verify returned 1 
&lt;br&gt;[peap] eaptls_process returned 13 
&lt;br&gt;[peap] EAPTLS_HANDLED
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 121 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010603fc194065310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672301e170d3039313232313038303833395a170d3130313232313038303833395a307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e667230820122300d0609
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x2a864886f70d01010105000382010f003082010a0282010100c25f8b67f6b1f5aebce7e017fcf1dbd9e027cd040146f4c752c8429d861556ee71236f9926c7880f14bc905aec227e9436f0f02ee5131351f5f071b58d4d6202245bc1f2ae74bbd2c50a56808fe156b5ee6dde5820b60a891549c041e2f8665237ec3f0584317c72a8cb32b3becb163d4f5b4158e5e5e0dfe49de7d3a04cab4998cfaa2a72518b01567bc1fec46fa490e7eff48ac90ab70532c82853ca357cf4a1160345e449c99c87883ded457241389e8112d37c5526e9e8f08af8c1fd6f6c8fb353c91bba3c13efe18db05216c009ee8cc07999d5179eec2dd38953454f3b6cd6484b
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0055d4af83cc339028b218b6262a13ca67895896480f03327f83a51b0203010001a381e53081e2301d0603551d0e04160414dd265c63fcb0cc9c87e17c3e9885e845d3f01a003081b20603551d230481aa3081a78014dd265c63fcb0cc9c87e17c3e9885e845d3f01a00a18183a48180307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672820900c42387580a65a3a9300c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0603551d13040530030101ff300d06092a864886f70d010105050003820101000708462f6ec64718c578592e84ac1dbec8980249800450058e6fb7c852f778494710902fa631aded3df802be82f37a2b6e8423a236f635b22e2e4cc0735f05bf1445b7049b09becb46eedf0a5f4c79f94032503f35a6e35f95ea3a10a3668971c8d353edb4a8b3b9426804526922afa0ef25e7aa59a24b1c612182419df1ab9aab47fa49ce1e7d445d53110fe28ec7960bf4caee3f37b6f8114fb2bf8d048a7e89d7a8f3ed48363958dbf9075ce04811712d1b917bf9677c4998d68f903378795bf5998bd8f555bdf147acc156725c3009ed02af9a2a0d6fe91f303dca
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x6f8613faa3ea6a53
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4533857ca6f7bd81569582da
&lt;br&gt;Finished request 3.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=122, length=191
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020600061900
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4533857ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x0710c430239292b61d333bb41a1245e9
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 6 length 6
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] Received TLS ACK
&lt;br&gt;[peap] ACK handshake fragment handler
&lt;br&gt;[peap] eaptls_verify returned 1 
&lt;br&gt;[peap] eaptls_process returned 13 
&lt;br&gt;[peap] EAPTLS_HANDLED
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 122 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0107002a1900cc510e88825921db807711b7fe7fe9a180b6f46304e78cfbc168b616030100040e000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4232857ca6f7bd81569582da
&lt;br&gt;Finished request 4.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=123, length=523
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0207015019800000014616030101061000010201009c87a815535c3457d6915d93e5cfaa1a1ae764ec4225c1eda185ff9fc193d3f0526941d3419418a340ed490f4b84f35aa9c3477dc8845d8740b89b69954cfc39185da0784e3d01e556dd6a013ca1f9bd2b369bfe2f24105c3da50cfa49f07206017441a0de9eeb6f42d5fec6833889b1c7e94c8f09e7b3eaf70ab81297d2bf3b88b985256262bf63b55519dbb6a2ae4e1e0192e458113fc413cd69f5b10cd7dc1c881c59d91ad4496f701b87e1463918c4bd6f1dc834d39af949d11b9b02b823c16fbc82c80c21beadec5d68f8d3d34a210d5395fb161c4c02a7c94e311bc911dcb7294c2f33bfa9
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0xeb08e8e300c8eb82a8a3f2fd13cb4191d5c00dc8b7f9edd814030100010116030100303cef0d4fe6b2882e1fa19eeb636a5a63cb986b1ba3cc3110db4c11750477f27b59fd3cbdb644f93da1b486fa8276abd0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4232857ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x560336581ffd72d0e6e2ecbb437d3cab
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 7 length 253
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;&amp;nbsp; TLS Length 326
&lt;br&gt;[peap] Length Included
&lt;br&gt;[peap] eaptls_verify returned 11 
&lt;br&gt;[peap] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 Handshake [length 0106], ClientKeyExchange &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 read client key exchange A 
&lt;br&gt;[peap] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 ChangeCipherSpec [length 0001] &amp;nbsp;
&lt;br&gt;[peap] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 Handshake [length 0010], Finished &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 read finished A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 ChangeCipherSpec [length 0001] &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write change cipher spec A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 0010], Finished &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write finished A 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 flush data 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; (other): SSL negotiation finished successfully 
&lt;br&gt;SSL Connection Established 
&lt;br&gt;[peap] eaptls_process returned 13 
&lt;br&gt;[peap] EAPTLS_HANDLED
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 123 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0108004119001403010001011603010030d069d412a34b6a0b26c3c38a980446a97e02c024df348da0b869c5f5ade2c7b8598179ef787821e8215b7ebf412ee2ac
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d433d857ca6f7bd81569582da
&lt;br&gt;Finished request 5.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=124, length=191
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020800061900
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d433d857ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0xec5fd30fa1b5b90002d609171cc0cda9
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 8 length 6
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] Received TLS ACK
&lt;br&gt;[peap] ACK handshake is finished
&lt;br&gt;[peap] eaptls_verify returned 3 
&lt;br&gt;[peap] eaptls_process returned 3 
&lt;br&gt;[peap] EAPTLS_SUCCESS
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 124 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0109002b1900170301002038848f6cbb0bee715a49cfd809074a5bcca13224be315b374d60a0a444c90cd9
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d403c857ca6f7bd81569582da
&lt;br&gt;Finished request 6.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=125, length=244
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0209003b190017030100304b728cd734f9da6b5b67f6830edb3cccf6815843a45e65c9e465d2756a895e361a1a6fd80dec223de521348349791609
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d403c857ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0xc5c43156063130ebd6e28b2d5219efc7
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 9 length 59
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] eaptls_verify returned 7 
&lt;br&gt;[peap] Done initial handshake
&lt;br&gt;[peap] eaptls_process returned 7 
&lt;br&gt;[peap] EAPTLS_OK
&lt;br&gt;[peap] Session established. &amp;nbsp;Decoding tunneled attributes.
&lt;br&gt;[peap] Identity - client.example.com
&lt;br&gt;[peap] Got tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0209001501737761747a7930312e657372662e6672
&lt;br&gt;server &amp;nbsp;{
&lt;br&gt;&amp;nbsp; PEAP: Got tunneled identity of client.example.com
&lt;br&gt;&amp;nbsp; PEAP: Setting default EAP type for tunneled EAP session.
&lt;br&gt;&amp;nbsp; PEAP: Setting User-Name to client.example.com
&lt;br&gt;Sending tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0209001501737761747a7930312e657372662e6672
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS-Proxied-To = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;server inner-tunnel {
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[control] returns noop
&lt;br&gt;[eap] EAP packet type response id 9 length 21
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] EAP Identity
&lt;br&gt;[eap] processing type mschapv2
&lt;br&gt;rlm_eap_mschapv2: Issuing Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;} # server inner-tunnel
&lt;br&gt;[peap] Got tunneled reply code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010a002a1a010a00251070aeff47a14f6016c9d19acee5b09bbd737761747a7930312e657372662e6672
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x9dc695d19dcc8f1400b4f084f7eacc22
&lt;br&gt;[peap] Got tunneled reply RADIUS code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010a002a1a010a00251070aeff47a14f6016c9d19acee5b09bbd737761747a7930312e657372662e6672
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x9dc695d19dcc8f1400b4f084f7eacc22
&lt;br&gt;[peap] Got tunneled Access-Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 125 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010a004b190017030100409a732f0a95380f8915554a7049f6ca123b5ec8082c19d38261e2df58127e9383fd0b95e94694594d4e2ebb98e38558e0bafb40194ec767ca5125409caf7c9187
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d413f857ca6f7bd81569582da
&lt;br&gt;Finished request 7.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=126, length=228
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020a002b190017030100204261c50537c3a175f949869fc579790700757ca2edf3fe4ecc43fd8fa16849c8
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d413f857ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x7dd04cbb26e2690166ee675fc0c54fe2
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 10 length 43
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] eaptls_verify returned 7 
&lt;br&gt;[peap] Done initial handshake
&lt;br&gt;[peap] eaptls_process returned 7 
&lt;br&gt;[peap] EAPTLS_OK
&lt;br&gt;[peap] Session established. &amp;nbsp;Decoding tunneled attributes.
&lt;br&gt;[peap] EAP type nak
&lt;br&gt;[peap] Got tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020a0006030d
&lt;br&gt;server &amp;nbsp;{
&lt;br&gt;&amp;nbsp; PEAP: Setting User-Name to client.example.com
&lt;br&gt;Sending tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020a0006030d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS-Proxied-To = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x9dc695d19dcc8f1400b4f084f7eacc22
&lt;br&gt;server inner-tunnel {
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[control] returns noop
&lt;br&gt;[eap] EAP packet type response id 10 length 6
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP NAK
&lt;br&gt;[eap] EAP-NAK asked for EAP-Type/tls
&lt;br&gt;[eap] processing type tls
&lt;br&gt;[tls] Requiring client certificate
&lt;br&gt;[tls] Initiate
&lt;br&gt;[tls] Start returned 1
&lt;br&gt;++[eap] returns handled
&lt;br&gt;} # server inner-tunnel
&lt;br&gt;[peap] Got tunneled reply code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010b00060d20
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x9dc695d19ccd981400b4f084f7eacc22
&lt;br&gt;[peap] Got tunneled reply RADIUS code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010b00060d20
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x9dc695d19ccd981400b4f084f7eacc22
&lt;br&gt;[peap] Got tunneled Access-Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 126 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010b002b190017030100207de3853f28e8a60d509e0e8103d2f98e08f35e08266254dd4a93fe3e5751150a
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4e3e857ca6f7bd81569582da
&lt;br&gt;Finished request 8.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=127, length=340
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020b009b19001703010090a04fea07b30ca56bdaebf98e6225b2f955813991d8bb99e6213d8c6fd905972e8086eec1ac01df372544961fa89ae0cd0f95f83d90dff8457667d9e39f9b2b7252fe107296afb377526c19464794c56ba77385d6c44c1cae140119da9cad1d89ceabc3841f9c67a4fbb65644d1a3d85b6bad4c6a22c687c399c3eeced63321eaa630674609996e98d6a44c1d6e1be0fc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4e3e857ca6f7bd81569582da
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x8961cb15acfbd5a45fd18af3a47e7904
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 11 length 155
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] eaptls_verify returned 7 
&lt;br&gt;[peap] Done initial handshake
&lt;br&gt;[peap] eaptls_process returned 7 
&lt;br&gt;[peap] EAPTLS_OK
&lt;br&gt;[peap] Session established. &amp;nbsp;Decoding tunneled attributes.
&lt;br&gt;[peap] EAP type tls
&lt;br&gt;[peap] Got tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020b007f0d800000007516030100700100006c03014b2f2f92d5aef8573e86787f0410ed66e074505158fd3465df76f6a5db6d0aa4000018002f00350005000ac009c00ac013c01400320038001300040100002b000000150013000010737761747a7930312e657372662e6672000a00080006001700180019000b00020100
&lt;br&gt;server &amp;nbsp;{
&lt;br&gt;&amp;nbsp; PEAP: Setting User-Name to client.example.com
&lt;br&gt;Sending tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020b007f0d800000007516030100700100006c03014b2f2f92d5aef8573e86787f0410ed66e074505158fd3465df76f6a5db6d0aa4000018002f00350005000ac009c00ac013c01400320038001300040100002b000000150013000010737761747a7930312e657372662e6672000a00080006001700180019000b00020100
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS-Proxied-To = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x9dc695d19ccd981400b4f084f7eacc22
&lt;br&gt;server inner-tunnel {
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[control] returns noop
&lt;br&gt;[eap] EAP packet type response id 11 length 127
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/tls
&lt;br&gt;[eap] processing type tls
&lt;br&gt;[tls] Authenticate
&lt;br&gt;[tls] processing EAP-TLS
&lt;br&gt;&amp;nbsp; TLS Length 117
&lt;br&gt;[tls] Length Included
&lt;br&gt;[tls] eaptls_verify returned 11 
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; (other): before/accept initialization 
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: before/accept initialization 
&lt;br&gt;[tls] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 Handshake [length 0070], ClientHello &amp;nbsp;
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 read client hello A 
&lt;br&gt;[tls] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 002a], ServerHello &amp;nbsp;
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write server hello A 
&lt;br&gt;[tls] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 07d3], Certificate &amp;nbsp;
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write certificate A 
&lt;br&gt;[tls] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 008f], CertificateRequest &amp;nbsp;
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write certificate request A 
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 flush data 
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: Need to read more data: SSLv3 read client certificate A
&lt;br&gt;In SSL Handshake Phase 
&lt;br&gt;In SSL Accept mode &amp;nbsp;
&lt;br&gt;[tls] eaptls_process returned 13 
&lt;br&gt;++[eap] returns handled
&lt;br&gt;} # server inner-tunnel
&lt;br&gt;[peap] Got tunneled reply code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010c04000dc00000089b160301002a0200002603014b2f2f91474c71c1cdb3329748a1007493635a1d09b4d8a8c22170eb24b8147900002f0016030107d30b0007cf0007cc00035d3082035930820241a003020102020114300d06092a864886f70d0101040500307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672301e170d3039313232313038303833395a170d313031
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x3232313038303833395a3049310b3009060355040613024652310e300c060355040813054973657265310d300b060355040a130445535246311b301906035504031312726164697573736572762e657372662e667230820122300d06092a864886f70d01010105000382010f003082010a0282010100df65e73bb432b019abe63c0a455e5053aa65ee5cdebb77dba90300b7933a6e1ddc3b764bf3d4305ab36530461cc0ade6ca4a916bfeb68ec9103ef74b02dcefbbb5553ce4f88225f43a7ff26195b0c2fd70a4620ead334a2c5d3c6f576b3eec5229cac9ab7ce3a7ffed9d70ee905be62a351dd2ee354c22773dea7ab1eeed05316aa5f33c7ca4cd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x1c92b20e08f50bb97033f29eb4f40985a8857170ad6f857f78f12fe394111de60ff71eccdf912dfdd0fd0f153fc6fe9593e15d914725f9b0968acfffcb35a2fb91c5298ac632a38014c778b509531292171a42e8308efc729f02454eaf5c71c0a4384b51081e6ce67f769ec52a38397c87e3b1bbd012fdb4d70203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d010104050003820101001705f81c5cfb5f42fb060d784d6d4dda29ce188c6f0203ffc1382b0fb3bd755fedde13cb3010fa4c753409b525d172921a1c19ef77f49f6ab490c1bd751ab5f0aea4d702c4b92b5b2e45485d77e80114762d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x87c80af1b6c317546180ebf118b164616baaaad68601e6fdcc895e328f39ca693b551da66ba9a748e205e67fd05430eefd1ca8a204bb56994ac3a0abf00d546e19263b678b72b04e1286cf1db63e93c089c8072bfe446d1b5e9b08940c6b6fcec73c5953ceeccb4d53b3b2bae39878ef00597f96df75b59776e176ccf328f22312d696524d43a62a623dc9af8c13b270e932bc7afcc456b7574f719d6f21faf4669390cd604dc28d850bc3c349fa000469308204653082034da003020102020900c42387580a65a3a9300d06092a864886f70d0101050500307e310b3009060355040613024652310e300c0603550408130549736572653111300f0603
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x55040713084772656e6f626c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x9dc695d19fca981400b4f084f7eacc22
&lt;br&gt;[peap] Got tunneled reply RADIUS code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010c04000dc00000089b160301002a0200002603014b2f2f91474c71c1cdb3329748a1007493635a1d09b4d8a8c22170eb24b8147900002f0016030107d30b0007cf0007cc00035d3082035930820241a003020102020114300d06092a864886f70d0101040500307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672301e170d3039313232313038303833395a170d313031
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x3232313038303833395a3049310b3009060355040613024652310e300c060355040813054973657265310d300b060355040a130445535246311b301906035504031312726164697573736572762e657372662e667230820122300d06092a864886f70d01010105000382010f003082010a0282010100df65e73bb432b019abe63c0a455e5053aa65ee5cdebb77dba90300b7933a6e1ddc3b764bf3d4305ab36530461cc0ade6ca4a916bfeb68ec9103ef74b02dcefbbb5553ce4f88225f43a7ff26195b0c2fd70a4620ead334a2c5d3c6f576b3eec5229cac9ab7ce3a7ffed9d70ee905be62a351dd2ee354c22773dea7ab1eeed05316aa5f33c7ca4cd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x1c92b20e08f50bb97033f29eb4f40985a8857170ad6f857f78f12fe394111de60ff71eccdf912dfdd0fd0f153fc6fe9593e15d914725f9b0968acfffcb35a2fb91c5298ac632a38014c778b509531292171a42e8308efc729f02454eaf5c71c0a4384b51081e6ce67f769ec52a38397c87e3b1bbd012fdb4d70203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d010104050003820101001705f81c5cfb5f42fb060d784d6d4dda29ce188c6f0203ffc1382b0fb3bd755fedde13cb3010fa4c753409b525d172921a1c19ef77f49f6ab490c1bd751ab5f0aea4d702c4b92b5b2e45485d77e80114762d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x87c80af1b6c317546180ebf118b164616baaaad68601e6fdcc895e328f39ca693b551da66ba9a748e205e67fd05430eefd1ca8a204bb56994ac3a0abf00d546e19263b678b72b04e1286cf1db63e93c089c8072bfe446d1b5e9b08940c6b6fcec73c5953ceeccb4d53b3b2bae39878ef00597f96df75b59776e176ccf328f22312d696524d43a62a623dc9af8c13b270e932bc7afcc456b7574f719d6f21faf4669390cd604dc28d850bc3c349fa000469308204653082034da003020102020900c42387580a65a3a9300d06092a864886f70d0101050500307e310b3009060355040613024652310e300c0603550408130549736572653111300f0603
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x55040713084772656e6f626c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x9dc695d19fca981400b4f084f7eacc22
&lt;br&gt;[peap] Got tunneled Access-Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 127 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010c040019c000000425170301042095608ecabdb44109836f43847ba8be704bcb51264fb229b78a304f52101bf7d8f9f0e415cf115a0bd8d90d847f02ef231dc6189d81869a40cc791434e8a9775a00f23e35a025e6846e1ecbad74d7813a0f28be5c3cc50644735884a653e3f94571ca692f65fe77061a1e5f1e03c3691a600eeb04497ecf944a803ecc26e23bf276e23f37b9dc9cc548abdabdf8a630ee605dabeb4e3239456882d85a469985f1e06f9668502668e7f7aae97d23076873b760e3c5e463133158d4057087114935217f2c5ef69b4b079b881e9275dc5c4554495a0ff8cf9189303b52cc305d6c80cb799f4e2522ceb617e674ecf102
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x80379ab65f330e250b9d57fd02b45d0c5d07a6f64e8920618475b6d967110ea714d851ed7064bdb4e2c01e6044ab34b387bcc6eea78a7fc216d75973f26c1b0cbcc08ded2f74ec4f432f4c27febb552934c6db5df2906deb0946496f5cd9bc726b456bc4c51b2d2e48df35e6dfa6147f20c6549c310ef46406543e2326460f98236efb95a7d645b023b5e4da894b5e3e7f51578cb62b87e82a0583eb2ef1351d38e6e6d01e4f4064a5296aa25505f054ae1c3288e3362f391e074dae98fdce29cf7a9993d5454b217cd860d94629450189f85106dbebdce40a8afa50935ac0122f6b31d1ff65a8c9dda0356a5fce6521ed5ab6980e6e142b8e0c1c2f44
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x50315eb5d5b31c218c2a4dfbcb996a8e760f3c426619433d34edd4abaaaeba09f8a560a91b088af45a703925c38a00c986241c9edf2fe6c58e7c0ecbb71bf3a6a167856d3ec48002a4a5458a3cd332c59eca4a8f70274474e74689b2620525f3d298fed9b4d6ce521171403b6227885ace8a36ae6f754a0f8f8e5f37f23161792caeff79be28e182e1f07f14abee8ddfce71ad251a22a1966fdefc2634926f38bf202444aa252d078469d60c4a5fd9f55e915cb7bda216a146c80410a75ec292cc39d291be03511da8397aeefaf7f4653a0961c652628051af27fb7f32b637fb8b2a047d579c89ced314bd4def14fd51bf4057dc28c2a043a63bbd055c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x9293ea3c188f7654975adea976d64cdd57a3698fd24026686aed02de2438bd914db7bc209b2ccd3ee15c7e7b174b86be42905800b1a463867dac4a05f5e4d57c9eda5bb338aba5b963900e994ea521814c2e197df24b45b58c188f2a15e31f32d9eb1237fc1392e2813dd6d08b3f43005e1011f6f8e1ea7d0acca6e906a955540a8c67473113fac899d39254a2f2d558335bc6507bdc64175afbc6d3aac2bea4f20ae8b18f0a0670a31a4af836e441b6f53efaf119beb641fbeeec62077b0bb62dae32af34ab2fcfe4fade6cc87d223fd6f54b41ef94657821350d8757cf6a8d3e462febfa289e5700a5445160ea69c238b412e93ada97d6b045fc73ea
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x06588ed8fb2a427c1e2399f2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x46359c0d4f39857ca6f7bd81569582da
&lt;br&gt;Finished request 9.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;Cleaning up request 0 ID 118 with timestamp +9
&lt;br&gt;Cleaning up request 1 ID 119 with timestamp +9
&lt;br&gt;Cleaning up request 2 ID 120 with timestamp +9
&lt;br&gt;Cleaning up request 3 ID 121 with timestamp +9
&lt;br&gt;Cleaning up request 4 ID 122 with timestamp +9
&lt;br&gt;Cleaning up request 5 ID 123 with timestamp +9
&lt;br&gt;Cleaning up request 6 ID 124 with timestamp +9
&lt;br&gt;Cleaning up request 7 ID 125 with timestamp +9
&lt;br&gt;Cleaning up request 8 ID 126 with timestamp +9
&lt;br&gt;Cleaning up request 9 ID 127 with timestamp +9
&lt;br&gt;Ready to process requests.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=128, length=188
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0202001501737761747a7930312e657372662e6672
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x74a8efb3e526fbc354da58481f383cb8
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 2 length 21
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;[pap] WARNING! No &amp;quot;known good&amp;quot; password found for the user. &amp;nbsp;Authentication may fail because of this.
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] EAP Identity
&lt;br&gt;[eap] processing type md5
&lt;br&gt;rlm_eap_md5: Issuing Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 128 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x01030016041047a243aeb61433e9a1ca015aadee525b
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378e1dd5750acddef276754aa3
&lt;br&gt;Finished request 10.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=129, length=191
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020300060319
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378e1dd5750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0xb7dd923beddd491b003dfc078382cc51
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 3 length 6
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;[pap] WARNING! No &amp;quot;known good&amp;quot; password found for the user. &amp;nbsp;Authentication may fail because of this.
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP NAK
&lt;br&gt;[eap] EAP-NAK asked for EAP-Type/peap
&lt;br&gt;[eap] processing type tls
&lt;br&gt;[tls] Initiate
&lt;br&gt;[tls] Start returned 1
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 129 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010400061920
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378f1ac8750acddef276754aa3
&lt;br&gt;Finished request 11.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=130, length=312
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0204007f19800000007516030100700100006c03014b2f2fa403c18a1c536dd9c44b3943cbaeb85b77ae6bb1b934538031c0a160d8000018002f00350005000ac009c00ac013c01400320038001300040100002b000000150013000010737761747a7930312e657372662e6672000a00080006001700180019000b00020100
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378f1ac8750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0xf8af489b45178ea77e42bc439e9bc867
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 4 length 127
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;&amp;nbsp; TLS Length 117
&lt;br&gt;[peap] Length Included
&lt;br&gt;[peap] eaptls_verify returned 11 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; (other): before/accept initialization 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: before/accept initialization 
&lt;br&gt;[peap] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 Handshake [length 0070], ClientHello &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 read client hello A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 002a], ServerHello &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write server hello A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 07d3], Certificate &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write certificate A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 0004], ServerHelloDone &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write server done A 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 flush data 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: Need to read more data: SSLv3 read client certificate A
&lt;br&gt;In SSL Handshake Phase 
&lt;br&gt;In SSL Accept mode &amp;nbsp;
&lt;br&gt;[peap] eaptls_process returned 13 
&lt;br&gt;[peap] EAPTLS_HANDLED
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 130 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0105040019c000000810160301002a0200002603014b2f2fa473ae358614f6f782a1cc79ad60c38b750bc0665e32b1bfaa545cf04400002f0016030107d30b0007cf0007cc00035d3082035930820241a003020102020114300d06092a864886f70d0101040500307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672301e170d3039313232313038303833395a170d313031
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x3232313038303833395a3049310b3009060355040613024652310e300c060355040813054973657265310d300b060355040a130445535246311b301906035504031312726164697573736572762e657372662e667230820122300d06092a864886f70d01010105000382010f003082010a0282010100df65e73bb432b019abe63c0a455e5053aa65ee5cdebb77dba90300b7933a6e1ddc3b764bf3d4305ab36530461cc0ade6ca4a916bfeb68ec9103ef74b02dcefbbb5553ce4f88225f43a7ff26195b0c2fd70a4620ead334a2c5d3c6f576b3eec5229cac9ab7ce3a7ffed9d70ee905be62a351dd2ee354c22773dea7ab1eeed05316aa5f33c7ca4cd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x1c92b20e08f50bb97033f29eb4f40985a8857170ad6f857f78f12fe394111de60ff71eccdf912dfdd0fd0f153fc6fe9593e15d914725f9b0968acfffcb35a2fb91c5298ac632a38014c778b509531292171a42e8308efc729f02454eaf5c71c0a4384b51081e6ce67f769ec52a38397c87e3b1bbd012fdb4d70203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d010104050003820101001705f81c5cfb5f42fb060d784d6d4dda29ce188c6f0203ffc1382b0fb3bd755fedde13cb3010fa4c753409b525d172921a1c19ef77f49f6ab490c1bd751ab5f0aea4d702c4b92b5b2e45485d77e80114762d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x87c80af1b6c317546180ebf118b164616baaaad68601e6fdcc895e328f39ca693b551da66ba9a748e205e67fd05430eefd1ca8a204bb56994ac3a0abf00d546e19263b678b72b04e1286cf1db63e93c089c8072bfe446d1b5e9b08940c6b6fcec73c5953ceeccb4d53b3b2bae39878ef00597f96df75b59776e176ccf328f22312d696524d43a62a623dc9af8c13b270e932bc7afcc456b7574f719d6f21faf4669390cd604dc28d850bc3c349fa000469308204653082034da003020102020900c42387580a65a3a9300d06092a864886f70d0101050500307e310b3009060355040613024652310e300c0603550408130549736572653111300f0603
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x55040713084772656e6f626c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378c1bc8750acddef276754aa3
&lt;br&gt;Finished request 12.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=131, length=191
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020500061900
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378c1bc8750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x60967d8edd9706c379efc363d03f7831
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 5 length 6
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] Received TLS ACK
&lt;br&gt;[peap] ACK handshake fragment handler
&lt;br&gt;[peap] eaptls_verify returned 1 
&lt;br&gt;[peap] eaptls_process returned 13 
&lt;br&gt;[peap] EAPTLS_HANDLED
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 131 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010603fc194065310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672301e170d3039313232313038303833395a170d3130313232313038303833395a307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e667230820122300d0609
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x2a864886f70d01010105000382010f003082010a0282010100c25f8b67f6b1f5aebce7e017fcf1dbd9e027cd040146f4c752c8429d861556ee71236f9926c7880f14bc905aec227e9436f0f02ee5131351f5f071b58d4d6202245bc1f2ae74bbd2c50a56808fe156b5ee6dde5820b60a891549c041e2f8665237ec3f0584317c72a8cb32b3becb163d4f5b4158e5e5e0dfe49de7d3a04cab4998cfaa2a72518b01567bc1fec46fa490e7eff48ac90ab70532c82853ca357cf4a1160345e449c99c87883ded457241389e8112d37c5526e9e8f08af8c1fd6f6c8fb353c91bba3c13efe18db05216c009ee8cc07999d5179eec2dd38953454f3b6cd6484b
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0055d4af83cc339028b218b6262a13ca67895896480f03327f83a51b0203010001a381e53081e2301d0603551d0e04160414dd265c63fcb0cc9c87e17c3e9885e845d3f01a003081b20603551d230481aa3081a78014dd265c63fcb0cc9c87e17c3e9885e845d3f01a00a18183a48180307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672820900c42387580a65a3a9300c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0603551d13040530030101ff300d06092a864886f70d010105050003820101000708462f6ec64718c578592e84ac1dbec8980249800450058e6fb7c852f778494710902fa631aded3df802be82f37a2b6e8423a236f635b22e2e4cc0735f05bf1445b7049b09becb46eedf0a5f4c79f94032503f35a6e35f95ea3a10a3668971c8d353edb4a8b3b9426804526922afa0ef25e7aa59a24b1c612182419df1ab9aab47fa49ce1e7d445d53110fe28ec7960bf4caee3f37b6f8114fb2bf8d048a7e89d7a8f3ed48363958dbf9075ce04811712d1b917bf9677c4998d68f903378795bf5998bd8f555bdf147acc156725c3009ed02af9a2a0d6fe91f303dca
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x6f8613faa3ea6a53
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378d18c8750acddef276754aa3
&lt;br&gt;Finished request 13.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=132, length=191
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020600061900
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378d18c8750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x867d0a6b82f6ad0f2ef811154922500a
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 6 length 6
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] Received TLS ACK
&lt;br&gt;[peap] ACK handshake fragment handler
&lt;br&gt;[peap] eaptls_verify returned 1 
&lt;br&gt;[peap] eaptls_process returned 13 
&lt;br&gt;[peap] EAPTLS_HANDLED
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 132 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0107002a1900cc510e88825921db807711b7fe7fe9a180b6f46304e78cfbc168b616030100040e000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378a19c8750acddef276754aa3
&lt;br&gt;Finished request 14.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=133, length=523
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0207015019800000014616030101061000010201009cf2b38faff7076f26c3d0fe94a76398b8ea28eb945ed88810b70e2e64bb31fdd1349eaec0d41cdadc4f96f67462735680cfa5fc622103b84971c7d27a58e3d5186587dd63b5705e330a6c1cd3c0c186b8644a1337aea88fcaf15c2cf27ccffbe250a0281e239ee07fa22dca6ecf826aeb32e1ef47444b3ace42626aca72f57fc9564b171ce53d2a911fd9db57c2e3def8fe6cbb70c14c907e476328facbaa2081fa0f8f0f3309b466727c68761953758506e5f24f7b3011b6626b98cbccea3ab5783f79cd6bf29e476682cc80bf651052d5dd6abb48317d332137aa51cf7bb6c3d7ed19794907cc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x4d9d115848ae8e9680b690fc1a77ea70f4bf31d6cbb418b01403010001011603010030ff787676e10bd417e0324b3bc835f28aa381123c26afe55a224f911ffdef86a008f89309543deaceb9b0860476f8b873
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378a19c8750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x44ec9fc03737043834799e0d683989ec
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 7 length 253
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;&amp;nbsp; TLS Length 326
&lt;br&gt;[peap] Length Included
&lt;br&gt;[peap] eaptls_verify returned 11 
&lt;br&gt;[peap] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 Handshake [length 0106], ClientKeyExchange &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 read client key exchange A 
&lt;br&gt;[peap] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 ChangeCipherSpec [length 0001] &amp;nbsp;
&lt;br&gt;[peap] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 Handshake [length 0010], Finished &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 read finished A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 ChangeCipherSpec [length 0001] &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write change cipher spec A 
&lt;br&gt;[peap] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 0010], Finished &amp;nbsp;
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write finished A 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 flush data 
&lt;br&gt;[peap] &amp;nbsp; &amp;nbsp; (other): SSL negotiation finished successfully 
&lt;br&gt;SSL Connection Established 
&lt;br&gt;[peap] eaptls_process returned 13 
&lt;br&gt;[peap] EAPTLS_HANDLED
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 133 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0108004119001403010001011603010030fb8e93a4ea40e56bbbc6c7f664d2216a753417515ce8465b0e3bb40cb7482c5fb5c177e6a5703c4504509ff0dab8cc50
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378b16c8750acddef276754aa3
&lt;br&gt;Finished request 15.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=134, length=191
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020800061900
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378b16c8750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x448e4cae008e458991e1e5a40c8eae90
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 8 length 6
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] Received TLS ACK
&lt;br&gt;[peap] ACK handshake is finished
&lt;br&gt;[peap] eaptls_verify returned 3 
&lt;br&gt;[peap] eaptls_process returned 3 
&lt;br&gt;[peap] EAPTLS_SUCCESS
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 134 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0109002b19001703010020b50db97fab5cc7bed43d021d7b893a92180f1183b52eac9cdc95368efe95a457
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378817c8750acddef276754aa3
&lt;br&gt;Finished request 16.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=135, length=244
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0209003b190017030100306926f4ed02b49062761d0cb8562726a944dbb0bfaa444f01f67e9c8126a2558fc067654f856d2f951d96535c2df0b535
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378817c8750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0xbb33462fb6654a927be6b522b4cfb6bb
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 9 length 59
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] eaptls_verify returned 7 
&lt;br&gt;[peap] Done initial handshake
&lt;br&gt;[peap] eaptls_process returned 7 
&lt;br&gt;[peap] EAPTLS_OK
&lt;br&gt;[peap] Session established. &amp;nbsp;Decoding tunneled attributes.
&lt;br&gt;[peap] Identity - client.example.com
&lt;br&gt;[peap] Got tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0209001501737761747a7930312e657372662e6672
&lt;br&gt;server &amp;nbsp;{
&lt;br&gt;&amp;nbsp; PEAP: Got tunneled identity of client.example.com
&lt;br&gt;&amp;nbsp; PEAP: Setting default EAP type for tunneled EAP session.
&lt;br&gt;&amp;nbsp; PEAP: Setting User-Name to client.example.com
&lt;br&gt;Sending tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x0209001501737761747a7930312e657372662e6672
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS-Proxied-To = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;server inner-tunnel {
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[control] returns noop
&lt;br&gt;[eap] EAP packet type response id 9 length 21
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] EAP Identity
&lt;br&gt;[eap] processing type mschapv2
&lt;br&gt;rlm_eap_mschapv2: Issuing Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;} # server inner-tunnel
&lt;br&gt;[peap] Got tunneled reply code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010a002a1a010a002510204478db37cf99c8c84b00dfeffa2bd7737761747a7930312e657372662e6672
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xde734795de795d3c8b258f5d9a0478ed
&lt;br&gt;[peap] Got tunneled reply RADIUS code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010a002a1a010a002510204478db37cf99c8c84b00dfeffa2bd7737761747a7930312e657372662e6672
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xde734795de795d3c8b258f5d9a0478ed
&lt;br&gt;[peap] Got tunneled Access-Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 135 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010a004b19001703010040046a986768b916030ce5dc08d42e8c74176b9821274cd40c9cb674e3358447de1c5d1571713eca5b7af051da3da576080541861b3cb613481c3d2ee8981561d8
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378914c8750acddef276754aa3
&lt;br&gt;Finished request 17.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=136, length=228
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020a002b19001703010020d9e10c04760aade02739c6c0ca51102b3a3533099e9660d5463f4b17dfd043d7
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378914c8750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0xa8b64880f1705ab922726493e731dcf6
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 10 length 43
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] eaptls_verify returned 7 
&lt;br&gt;[peap] Done initial handshake
&lt;br&gt;[peap] eaptls_process returned 7 
&lt;br&gt;[peap] EAPTLS_OK
&lt;br&gt;[peap] Session established. &amp;nbsp;Decoding tunneled attributes.
&lt;br&gt;[peap] EAP type nak
&lt;br&gt;[peap] Got tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020a0006030d
&lt;br&gt;server &amp;nbsp;{
&lt;br&gt;&amp;nbsp; PEAP: Setting User-Name to client.example.com
&lt;br&gt;Sending tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020a0006030d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS-Proxied-To = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xde734795de795d3c8b258f5d9a0478ed
&lt;br&gt;server inner-tunnel {
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[control] returns noop
&lt;br&gt;[eap] EAP packet type response id 10 length 6
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP NAK
&lt;br&gt;[eap] EAP-NAK asked for EAP-Type/tls
&lt;br&gt;[eap] processing type tls
&lt;br&gt;[tls] Requiring client certificate
&lt;br&gt;[tls] Initiate
&lt;br&gt;[tls] Start returned 1
&lt;br&gt;++[eap] returns handled
&lt;br&gt;} # server inner-tunnel
&lt;br&gt;[peap] Got tunneled reply code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010b00060d20
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xde734795df784a3c8b258f5d9a0478ed
&lt;br&gt;[peap] Got tunneled reply RADIUS code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010b00060d20
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xde734795df784a3c8b258f5d9a0478ed
&lt;br&gt;[peap] Got tunneled Access-Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 136 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010b002b1900170301002093ef759481e6f76a647cfee24e43ee11e05a50261d13ee182e2af0c624f1f6d1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378615c8750acddef276754aa3
&lt;br&gt;Finished request 18.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.9 seconds.
&lt;br&gt;rad_recv: Access-Request packet from host X.X.X.252 port 32769, id=137, length=340
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Calling-Station-Id = &amp;quot;00-1d-e0-7f-c7-bd&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Called-Station-Id = &amp;quot;00-26-cb-4c-f7-c0:Bidon&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port = 13
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-IP-Address = X.X.X.252
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Identifier = &amp;quot;xxxxx&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id = 6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service-Type = Framed-User
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Framed-MTU = 1300
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NAS-Port-Type = Wireless-802.11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Type:0 = VLAN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Medium-Type:0 = IEEE-802
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tunnel-Private-Group-Id:0 = &amp;quot;82&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020b009b19001703010090c9fbe143e32e97dd4bb650fabbdc63bc2c76d23227aa5a414264dc29a31ce7849df85aa4d3126417464a8f11d379f801be1755d19ed5769bc5b6bc16f65c3e390464c78b56c5c91ae19ff2b0051bf8592328667265d66e1cbd77905c39d1544f2dc4b2556de35eefdff4357dd98e811c7a5429e1eeb9a3ddaeef0d4714780c7b0efab3e42cd601fccad521666b701288
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378615c8750acddef276754aa3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x50d09514f80922fe59a09136639bd436
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[preprocess] returns ok
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;[eap] EAP packet type response id 11 length 155
&lt;br&gt;[eap] Continuing tunnel setup.
&lt;br&gt;++[eap] returns ok
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/peap
&lt;br&gt;[eap] processing type peap
&lt;br&gt;[peap] processing EAP-TLS
&lt;br&gt;[peap] eaptls_verify returned 7 
&lt;br&gt;[peap] Done initial handshake
&lt;br&gt;[peap] eaptls_process returned 7 
&lt;br&gt;[peap] EAPTLS_OK
&lt;br&gt;[peap] Session established. &amp;nbsp;Decoding tunneled attributes.
&lt;br&gt;[peap] EAP type tls
&lt;br&gt;[peap] Got tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020b007f0d800000007516030100700100006c03014b2f2fa40ec7775cfa70ff805e35e0a846cc28429be6b506cd3094f1bd33f0c7000018002f00350005000ac009c00ac013c01400320038001300040100002b000000150013000010737761747a7930312e657372662e6672000a00080006001700180019000b00020100
&lt;br&gt;server &amp;nbsp;{
&lt;br&gt;&amp;nbsp; PEAP: Setting User-Name to client.example.com
&lt;br&gt;Sending tunneled request
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x020b007f0d800000007516030100700100006c03014b2f2fa40ec7775cfa70ff805e35e0a846cc28429be6b506cd3094f1bd33f0c7000018002f00350005000ac009c00ac013c01400320038001300040100002b000000150013000010737761747a7930312e657372662e6672000a00080006001700180019000b00020100
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FreeRADIUS-Proxied-To = 127.0.0.1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name = &amp;quot;client.example.com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xde734795df784a3c8b258f5d9a0478ed
&lt;br&gt;server inner-tunnel {
&lt;br&gt;+- entering group authorize {...}
&lt;br&gt;++[chap] returns noop
&lt;br&gt;++[mschap] returns noop
&lt;br&gt;++[unix] returns notfound
&lt;br&gt;[suffix] No '@' in User-Name = &amp;quot;client.example.com&amp;quot;, looking up realm NULL
&lt;br&gt;[suffix] No such realm &amp;quot;NULL&amp;quot;
&lt;br&gt;++[suffix] returns noop
&lt;br&gt;++[control] returns noop
&lt;br&gt;[eap] EAP packet type response id 11 length 127
&lt;br&gt;[eap] No EAP Start, assuming it's an on-going EAP conversation
&lt;br&gt;++[eap] returns updated
&lt;br&gt;++[files] returns noop
&lt;br&gt;++[expiration] returns noop
&lt;br&gt;++[logintime] returns noop
&lt;br&gt;++[pap] returns noop
&lt;br&gt;Found Auth-Type = EAP
&lt;br&gt;+- entering group authenticate {...}
&lt;br&gt;[eap] Request found, released from the list
&lt;br&gt;[eap] EAP/tls
&lt;br&gt;[eap] processing type tls
&lt;br&gt;[tls] Authenticate
&lt;br&gt;[tls] processing EAP-TLS
&lt;br&gt;&amp;nbsp; TLS Length 117
&lt;br&gt;[tls] Length Included
&lt;br&gt;[tls] eaptls_verify returned 11 
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; (other): before/accept initialization 
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: before/accept initialization 
&lt;br&gt;[tls] &amp;lt;&amp;lt;&amp;lt; TLS 1.0 Handshake [length 0070], ClientHello &amp;nbsp;
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 read client hello A 
&lt;br&gt;[tls] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 002a], ServerHello &amp;nbsp;
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write server hello A 
&lt;br&gt;[tls] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 07d3], Certificate &amp;nbsp;
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write certificate A 
&lt;br&gt;[tls] &amp;gt;&amp;gt;&amp;gt; TLS 1.0 Handshake [length 008f], CertificateRequest &amp;nbsp;
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 write certificate request A 
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: SSLv3 flush data 
&lt;br&gt;[tls] &amp;nbsp; &amp;nbsp; TLS_accept: Need to read more data: SSLv3 read client certificate A
&lt;br&gt;In SSL Handshake Phase 
&lt;br&gt;In SSL Accept mode &amp;nbsp;
&lt;br&gt;[tls] eaptls_process returned 13 
&lt;br&gt;++[eap] returns handled
&lt;br&gt;} # server inner-tunnel
&lt;br&gt;[peap] Got tunneled reply code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010c04000dc00000089b160301002a0200002603014b2f2fa4ae31c82430ef4091d8c8d39427242606cd13ffbd478f89cc5271eb1000002f0016030107d30b0007cf0007cc00035d3082035930820241a003020102020114300d06092a864886f70d0101040500307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672301e170d3039313232313038303833395a170d313031
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x3232313038303833395a3049310b3009060355040613024652310e300c060355040813054973657265310d300b060355040a130445535246311b301906035504031312726164697573736572762e657372662e667230820122300d06092a864886f70d01010105000382010f003082010a0282010100df65e73bb432b019abe63c0a455e5053aa65ee5cdebb77dba90300b7933a6e1ddc3b764bf3d4305ab36530461cc0ade6ca4a916bfeb68ec9103ef74b02dcefbbb5553ce4f88225f43a7ff26195b0c2fd70a4620ead334a2c5d3c6f576b3eec5229cac9ab7ce3a7ffed9d70ee905be62a351dd2ee354c22773dea7ab1eeed05316aa5f33c7ca4cd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x1c92b20e08f50bb97033f29eb4f40985a8857170ad6f857f78f12fe394111de60ff71eccdf912dfdd0fd0f153fc6fe9593e15d914725f9b0968acfffcb35a2fb91c5298ac632a38014c778b509531292171a42e8308efc729f02454eaf5c71c0a4384b51081e6ce67f769ec52a38397c87e3b1bbd012fdb4d70203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d010104050003820101001705f81c5cfb5f42fb060d784d6d4dda29ce188c6f0203ffc1382b0fb3bd755fedde13cb3010fa4c753409b525d172921a1c19ef77f49f6ab490c1bd751ab5f0aea4d702c4b92b5b2e45485d77e80114762d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x87c80af1b6c317546180ebf118b164616baaaad68601e6fdcc895e328f39ca693b551da66ba9a748e205e67fd05430eefd1ca8a204bb56994ac3a0abf00d546e19263b678b72b04e1286cf1db63e93c089c8072bfe446d1b5e9b08940c6b6fcec73c5953ceeccb4d53b3b2bae39878ef00597f96df75b59776e176ccf328f22312d696524d43a62a623dc9af8c13b270e932bc7afcc456b7574f719d6f21faf4669390cd604dc28d850bc3c349fa000469308204653082034da003020102020900c42387580a65a3a9300d06092a864886f70d0101050500307e310b3009060355040613024652310e300c0603550408130549736572653111300f0603
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x55040713084772656e6f626c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xde734795dc7f4a3c8b258f5d9a0478ed
&lt;br&gt;[peap] Got tunneled reply RADIUS code 11
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010c04000dc00000089b160301002a0200002603014b2f2fa4ae31c82430ef4091d8c8d39427242606cd13ffbd478f89cc5271eb1000002f0016030107d30b0007cf0007cc00035d3082035930820241a003020102020114300d06092a864886f70d0101040500307e310b3009060355040613024652310e300c0603550408130549736572653111300f060355040713084772656e6f626c65310d300b060355040a1304455352463120301e06092a864886f70d010901161161646d696e406578616d706c652e636f6d311b301906035504031312726164697573736572762e657372662e6672301e170d3039313232313038303833395a170d313031
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x3232313038303833395a3049310b3009060355040613024652310e300c060355040813054973657265310d300b060355040a130445535246311b301906035504031312726164697573736572762e657372662e667230820122300d06092a864886f70d01010105000382010f003082010a0282010100df65e73bb432b019abe63c0a455e5053aa65ee5cdebb77dba90300b7933a6e1ddc3b764bf3d4305ab36530461cc0ade6ca4a916bfeb68ec9103ef74b02dcefbbb5553ce4f88225f43a7ff26195b0c2fd70a4620ead334a2c5d3c6f576b3eec5229cac9ab7ce3a7ffed9d70ee905be62a351dd2ee354c22773dea7ab1eeed05316aa5f33c7ca4cd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x1c92b20e08f50bb97033f29eb4f40985a8857170ad6f857f78f12fe394111de60ff71eccdf912dfdd0fd0f153fc6fe9593e15d914725f9b0968acfffcb35a2fb91c5298ac632a38014c778b509531292171a42e8308efc729f02454eaf5c71c0a4384b51081e6ce67f769ec52a38397c87e3b1bbd012fdb4d70203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d010104050003820101001705f81c5cfb5f42fb060d784d6d4dda29ce188c6f0203ffc1382b0fb3bd755fedde13cb3010fa4c753409b525d172921a1c19ef77f49f6ab490c1bd751ab5f0aea4d702c4b92b5b2e45485d77e80114762d
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x87c80af1b6c317546180ebf118b164616baaaad68601e6fdcc895e328f39ca693b551da66ba9a748e205e67fd05430eefd1ca8a204bb56994ac3a0abf00d546e19263b678b72b04e1286cf1db63e93c089c8072bfe446d1b5e9b08940c6b6fcec73c5953ceeccb4d53b3b2bae39878ef00597f96df75b59776e176ccf328f22312d696524d43a62a623dc9af8c13b270e932bc7afcc456b7574f719d6f21faf4669390cd604dc28d850bc3c349fa000469308204653082034da003020102020900c42387580a65a3a9300d06092a864886f70d0101050500307e310b3009060355040613024652310e300c0603550408130549736572653111300f0603
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x55040713084772656e6f626c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0xde734795dc7f4a3c8b258f5d9a0478ed
&lt;br&gt;[peap] Got tunneled Access-Challenge
&lt;br&gt;++[eap] returns handled
&lt;br&gt;Sending Access-Challenge of id 137 to X.X.X.252 port 32769
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x010c040019c00000042517030104204d382413619f84e22d48330e6254f82f390b14c9c8b5511efe168d291cf3a8f7a5b9a7d87e3e81eb169aac580a4487917d33cd82df23a99457fee93913c787a13251d32618b7859009f5a5b8539c09a98307f933e742565c7f2c2768c1b95f6ba5e05b5bb5e92dadc6b399f8da7709f68e08fbf42dda43ff570d005ba980fe2c8e77be4bf6c19426f4787bc7a3613c9a82d2221d05a30a263d77f2d38d4b0d6774ff18b5e4696348189855d0e8140d62f9b83b941ad3d98881cfea337607e7223d85f9bd933fa3fc3862b16008f9b61f8d8ee651a79fdce9e19877b7a3b781d811ed54b2229d72c3e3fbe59dcfad
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0xe007cf32d6b1cc8d88f3408dca7406e67cbc50ab771b1cbe34ddb73ec24d78681715179b7c09013ebb2d174929964b84038fc04e500ebdebe7febbceda9ad4e1dee9b46158c45a6ee28ad0c9f685bea62ee3fc2978f4261c31b44b4dbdf8d35f9735589e1e651668473a7fc2c9e640ff0d0e0946afe1a2d41d8f06cabcb75f30901136cb5f40f15a23b969d4a4e72d31bd7aee93fc611742f63b47d1c0ef23629fc9ca21d88607d16ed83e1d1d55d5c064960c5bd3f78ffe6bcca77419499a7d9fd2bd2a6711825e0ae42cb5edc8267a3f2638f5ae370d0a0bcb00626599f6c82c6e8c38ae781ef8f96db0019c39f3acc56fdf5cb6c7caae1c9e5e97f2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0xc418e432012b8206c2fc66da4664402e8835a99f29c3988a9fd97f2fee1c569d806207ea660f7285a0d69d60979f9b425129edabd51c3d97870a7e94b019315eb3513bf77fa61237efc53e3d63640357b23712b0fe6ee274539f6c6e0bef8b0312a963c5ffa57aff3ba0968d500702b7330481f7f19b3bb2d191e478a44dd4bf179062939fae6f97e19c3b909a3f7f71cb0bb9630b905a46a81ee5b8a5af45244bba0968cc665254b00a522bf871174d42f9acb7f664f8ecba424fa1a79403603b6c627e7d55c1dc9d1208da3accfd55b33fef856a8bfeb22bd9ad4de3f87108866e36e65b2a041c0968e353c7f53aa30957ccca0b597c7ec9d70c0580
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x207cb2acbb749d514e3f6e30fa5097ab07f4ccf472b43a4bd5be7a93a906ce1b4c432c61cf1dfd9bac9c39b94f3db59a22dec7d2adfa9388d265295c8075becd872bed18eafa822343e44a2d4b8386d5fc0eeddb2249e832260661978c81e081d3b61a230c94a365af0b82b1f03edc8f7b135c4ea6921e7d2934f091d9830cc576fb222dd23755ad9c3e5e5b56507b81c4173a7d280454f31aaca99528a302d8e2189df59b7bffb36e8b8b0fcd87f0cea2e36663aac18ba250f8a3d883f05fe54f78e7c26102f1643fbd4c756b45a57fa5671e3a8da15fde58d541e5ac6cae0e1a4070f0313bb1811f01390d8946bebc730d2eb3eded6efc05aba91314
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; EAP-Message = 0x76b31a0a8bb72aa2e5b813ff
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Message-Authenticator = 0x00000000000000000000000000000000
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State = 0x8e1ed1378712c8750acddef276754aa3
&lt;br&gt;Finished request 19.
&lt;br&gt;Going to the next request
&lt;br&gt;Waking up in 4.8 seconds.
&lt;br&gt;Cleaning up request 10 ID 128 with timestamp +28
&lt;br&gt;Cleaning up request 11 ID 129 with timestamp +28
&lt;br&gt;Cleaning up request 12 ID 130 with timestamp +28
&lt;br&gt;Cleaning up request 13 ID 131 with timestamp +28
&lt;br&gt;Cleaning up request 14 ID 132 with timestamp +28
&lt;br&gt;Cleaning up request 15 ID 133 with timestamp +28
&lt;br&gt;Cleaning up request 16 ID 134 with timestamp +28
&lt;br&gt;Cleaning up request 17 ID 135 with timestamp +28
&lt;br&gt;Cleaning up request 18 ID 136 with timestamp +28
&lt;br&gt;Cleaning up request 19 ID 137 with timestamp +28
&lt;br&gt;Ready to process requests.
&lt;br&gt;&lt;br /&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Certificate-not-valid-in-PEAP-tp26871830p26871830.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26871672</id>
	<title>Re: Pre-release of Version 2.1.8</title>
	<published>2009-12-21T01:31:30Z</published>
	<updated>2009-12-21T01:31:30Z</updated>
	<author>
		<name>Bjørn Mork</name>
	</author>
	<content type="html">I'm probably stupid as I never learn, but I'm going to take my chances
&lt;br&gt;reporting succcess again....
&lt;br&gt;&lt;br&gt;The v2.1.x branch from github up to and including commit
&lt;br&gt;1d80707880c1bf94ad1e87be74221a6c7b4cb4c7 has now been running stable for
&lt;br&gt;more than 5 days for me. &amp;nbsp;All the previously reported problems seem to
&lt;br&gt;be gone. &amp;nbsp;So I'd say it makes a good 2.1.8 release for Christmas.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Bjørn
&lt;br&gt;&lt;br&gt;-
&lt;br&gt;List info/subscribe/unsubscribe? See &lt;a href=&quot;http://www.freeradius.org/list/users.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freeradius.org/list/users.html&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/FreeRadius---User-f1104.html&quot; embed=&quot;fixTarget[1104]&quot; target=&quot;_top&quot; &gt;FreeRadius - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Pre-release-of-Version-2.1.8-tp26643366p26871672.html" />
</entry>

</feed>
