(RADIATOR) Problems after upgrading to 3.0
Hugh Irvine
hugh at open.com.au
Tue Apr 30 01:25:06 CDT 2002
Hello Ashley -
There is a bug in the "Radius/AuthNT.pm" module.
The web site has a patched version and I will send you a copy seperately.
regards
Hugh
On Tue, 30 Apr 2002 15:52, Kent, Ashley wrote:
> I've just upgrade one of my NT radiator boxes from 2.18 to 3.0 and hit a
> snag.
> To upgrade all I did was stop the radiator service, do a "perl makefile.pl
> install", and restart radiator.
> Once I restart I see in the log:
>
> Tue Apr 30 15:29:22 2002: ERR: Unknown keyword 'Domain' in
> d:\radiator\configs\radiator.cfg line 75
> Tue Apr 30 15:29:22 2002: ERR: Unknown keyword 'DomainController' in
> d:\radiator\configs\radiator.cfg line 76
> Tue Apr 30 15:29:22 2002: ERR: Unknown keyword 'Domain' in
> d:\radiator\configs\radiator.cfg line 81
> Tue Apr 30 15:29:22 2002: ERR: Unknown keyword 'DomainController' in
> d:\radiator\configs\radiator.cfg line 82
> Tue Apr 30 15:29:22 2002: DEBUG: Reading users file
> ./Configs/InVPN-United.cfg
> Tue Apr 30 15:29:22 2002: DEBUG: Reading users file
> ./Configs/InVPN-External.cfg
> Tue Apr 30 15:29:22 2002: DEBUG: Reading users file
> ./Configs/OutPIX-United.cfg
> Tue Apr 30 15:29:22 2002: DEBUG: Reading users file
> ./Configs/HomeUsersRtr-United.cfg
> Tue Apr 30 15:29:22 2002: DEBUG: Reading users file
> ./Configs/RASDialup-United.cfg
> Tue Apr 30 15:29:22 2002: DEBUG: Reading users file
> ./Configs/RASDialup-United.cfg
> Tue Apr 30 15:29:22 2002: DEBUG: Reading users file
> ./Configs/DMSRASDialup-United.cfg
> Tue Apr 30 15:29:23 2002: INFO: Server started: Radiator 3.0 on infprd08
>
>
> It looks like radiator doesn't know how to interpret AuthByNT directives.
> When I check out my /perl/site/lib/radius/ directory I see that the
> authbynt.pm file is there (version 1.25).
> What gives?
>
>
>
>
> Thanks,
>
>
> Ash.
>
>
>
> Here my primary radiator config file:
>
> #
> ---------------------------------------------------------------------------
>- ---
> # Globals
> #
> #
> ---------------------------------------------------------------------------
>- ---
>
> Foreground
> LogDir ./Logs
> LogFile %L/radiatorlog.txt
> DbDir .
> Trace 4
>
> #
> ---------------------------------------------------------------------------
>- ---
> # Clients
> #
> #
> ---------------------------------------------------------------------------
>- ---
>
> # Dialup router
> <Client 146.178.79.25>
> Identifier HOMEUSERSRTR
> Secret xxxxxxx
> </Client>
>
> # Burwood internet firewall (burpix01)
> <Client 192.168.205.2>
> Identifier PIX
> Secret xxxxxxx
> </Client>
>
> # Pinwood internet firewall (pinpix01)
> <Client 192.168.204.2>
> Identifier PIX
> Secret xxxxxxx
> </Client>
>
> # UEComm firewall (burpix02)
> <Client 10.11.92.10>
> Identifier PIX
> Secret xxxxxxx
> </Client>
>
> # RAS router (pinras01)
> <Client 10.11.89.10>
> Identifier RAS
> Secret xxxxxxx
> # convert domain\username to username at domain
> RewriteUsername s/^(.*)\\(.*)/$2\@$1/
> </Client>
>
>
> # DMS RAS router (pinras02)
> <Client 10.11.9.15>
> Identifier DMSRAS
> Secret xxxxxxx
> # convert domain\username to username at domain
> RewriteUsername s/^(.*)\\(.*)/$2\@$1/
> </Client>
>
>
> #
> ---------------------------------------------------------------------------
>- ---
> # AuthBy Clauses
> #
> #
> ---------------------------------------------------------------------------
>- ---
>
> <AuthBy NT>
> Identifier CheckInfprd08
> Domain UNITED
> DomainController \\infprd08
> </AuthBy>
>
> <AuthBy NT>
> Identifier CheckSouthgate02
> Domain IKON
> DomainController \\southgate02
> </AuthBy>
>
> <AuthBy FILE>
> Identifier CheckInVPN-United
> Filename ./Configs/InVPN-United.cfg
> </AuthBy>
>
> <AuthBy FILE>
> Identifier CheckInVPN-External
> Filename ./Configs/InVPN-External.cfg
> </AuthBy>
>
> <AuthBy FILE>
> Identifier CheckOutPIX-United
> Filename ./Configs/OutPIX-United.cfg
> </AuthBy>
>
> <AuthBy FILE>
> Identifier HomeUsersRtr-United
> Filename ./Configs/HomeUsersRtr-United.cfg
> </AuthBy>
>
> <AuthBy FILE>
> Identifier RASDialup-United
> Filename ./Configs/RASDialup-United.cfg
> </AuthBy>
>
>
> <AuthBy FILE>
> Identifier RASDialup-Pulse
> Filename ./Configs/RASDialup-United.cfg
> </AuthBy>
>
>
> <AuthBy FILE>
> Identifier DMSRASDialup-United
> Filename ./Configs/DMSRASDialup-United.cfg
> </AuthBy>
>
>
> #
> ---------------------------------------------------------------------------
>- ---
> # AuthLog Clauses
> #
> #
> ---------------------------------------------------------------------------
>- ---
>
> <AuthLog FILE>
> Identifier VPN-External
> Filename %L/VPN/External-authlog.txt
> LogSuccess 1
> LogFailure 1
> SuccessFormat External VPN Logon Success %H:%M:%S %v %d %Y %U
> FailureFormat External VPN Logon Failure %H:%M:%S %v %d %Y %U
> </AuthLog>
>
> <AuthLog FILE>
> Identifier VPN-UE
> Filename %L/VPN/UE-authlog.txt
> LogSuccess 1
> LogFailure 1
> SuccessFormat UE VPN Logon Success %H:%M:%S %v %d %Y %U
> FailureFormat UE VPN Logon Failure %H:%M:%S %v %d %Y %U
> </AuthLog>
>
> <AuthLog FILE>
> Identifier VPN-UEComm
> Filename %L/VPN/UEComm-authlog.txt
> LogSuccess 1
> LogFailure 1
> SuccessFormat UEComm VPN Logon Success %H:%M:%S %v %d %Y %U
> FailureFormat UEComm VPN Logon Failure %H:%M:%S %v %d %Y %U
> </AuthLog>
>
> <AuthLog FILE>
> Identifier UnitedInternetAccess
> Filename %L/Internet/united-authfailure.txt
> LogSuccess 0
> LogFailure 1
> FailureFormat United Internet Logon Fail %H:%M:%S %v %d %Y %U
> </AuthLog>
>
> <AuthLog FILE>
> Identifier IkonInternetAccess
> Filename %L/Internet/ikon-authfailure.txt
> LogSuccess 0
> LogFailure 1
> FailureFormat Ikon Internet Logon Fail %H:%M:%S %v %d %Y %U
> </AuthLog>
>
> <AuthLog FILE>
> Identifier Dialup
> Filename %L/Dialup/dialup-authlog.txt
> LogSuccess 1
> LogFailure 1
> SuccessFormat Dialup Logon Success %H:%M:%S %v %d %Y %U
> FailureFormat Dialup Logon Failure %H:%M:%S %v %d %Y %U
> </AuthLog>
>
> <AuthLog FILE>
> Identifier RasDialup
> Filename %L/Dialup/rasdialup-authlog.txt
> LogSuccess 1
> LogFailure 1
> SuccessFormat Dialup Logon Success %H:%M:%S %v %d %Y %U
> FailureFormat Dialup Logon Failure %H:%M:%S %v %d %Y %U
> </AuthLog>
>
> <AuthLog FILE>
> Identifier DMSRasDialup
> Filename %L/Dialup/dmsrasdialup-authlog.txt
> LogSuccess 1
> LogFailure 1
> SuccessFormat Dialup Logon Success %H:%M:%S %v %d %Y %U
> FailureFormat Dialup Logon Failure %H:%M:%S %v %d %Y %U
> </AuthLog>
>
>
>
> #
> ---------------------------------------------------------------------------
>- ---
> # SNMP
> #
> #
> ---------------------------------------------------------------------------
>- ---
>
> <SNMPAgent >
> ROCommunity xxxxxxx
> </SNMPAgent>
>
>
>
>
> #
> ---------------------------------------------------------------------------
>- ---
> # Mainloop
> #
> #
> ---------------------------------------------------------------------------
>- ---
>
> # Handlers for inbound requests through the PIX
>
> <Handler Client-Identifier = PIX, Realm = ue.com.au>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy CheckInVPN-United
> AuthLog VPN-UE
> </Handler>
>
> <Handler Client-Identifier = PIX, Realm = uecomm.com.au>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy CheckInVPN-United
> AuthLog VPN-UEComm
> </Handler>
>
> <Handler Client-Identifier = PIX, Realm = external>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy CheckInVPN-External
> AuthLog VPN-External
> </Handler>
>
>
> # Handlers for outbound requests through the PIX
>
> <Handler Client-Identifier = PIX, Realm = ikon>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy CheckSouthgate02
> AuthLog IkonInternetAccess
> </Handler>
>
> <Handler Client-Identifier = PIX>
> AuthBy CheckOutPIX-United
> AuthLog UnitedInternetAccess
> </Handler>
>
>
> # Handler for inbound Home Users dialup connections
>
> <Handler Client-Identifier = HOMEUSERSRTR>
> AuthBy HomeUsersRtr-United
> AuthLog Dialup
> </Handler>
>
>
> # Handler for RAS dialup connections
>
> <Handler Client-Identifier = RAS, Realm = UNITED>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy RASDialup-United
> AuthLog RasDialup
> AcctLogFileName %L/Dialup/rasdialup-acctlog.txt
> </Handler>
>
> <Handler Client-Identifier = RAS, Realm = PULSE>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy RASDialup-Pulse
> AuthLog RasDialup
> AcctLogFileName %L/Dialup/rasdialup-acctlog.txt
> </Handler>
>
> <Handler Client-Identifier = RAS>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy RASDialup-United
> AuthLog RasDialup
> AcctLogFileName %L/Dialup/rasdialup-acctlog.txt
> </Handler>
>
>
> # Handlers for DMS RAS dialup connections
>
> <Handler Client-Identifier = DMSRAS, Realm = UNITED>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy DMSRASDialup-United
> AuthLog DMSRasDialup
> </Handler>
>
> <Handler Client-Identifier = DMSRAS>
> RewriteUsername s/^([^@]+).*/$1/
> AuthBy DMSRASDialup-United
> AuthLog DMSRasDialup
> </Handler>
>
> ===
> Archive at http://www.open.com.au/archives/radiator/
> Announcements on radiator-announce at open.com.au
> To unsubscribe, email 'majordomo at open.com.au' with
> 'unsubscribe radiator' in the body of the message.
--
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows 95/98/2000, NT, MacOS X.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.
===
Archive at http://www.open.com.au/archives/radiator/
Announcements on radiator-announce at open.com.au
To unsubscribe, email 'majordomo at open.com.au' with
'unsubscribe radiator' in the body of the message.
More information about the radiator
mailing list