Re: Now I have problems with Radius

From: Simon White (simon@mtds.com)
Date: Fri Dec 21 2001 - 04:03:28 EST


I never did get it working myself.

Jared went some way to getting things debugged, then I guess he got bogged
down. I did a tcpdump and all that, there was a packet coming back, but I
never got so far as reading hex dumps myself...

I have implemented a separate radius check by a cron job which checks if
the radius process is running and will restart it if it is down. Then I
just ping the machine using sysmon.

I think somewhere the radius test is either not getting packets it can
understand back, or that the parsing on the packets has changed since the
version which works.

Jared?

On Thu, 20 Dec 2001, David Hamilton wrote:

> Did anything come of this?
>
> We are seeing the exact same behavior. The same machine is running a much older version (old conf file format) of sysmon that works fine with the same settings.
>
> Jared Mauch extolled:
> > On Fri, Sep 28, 2001 at 03:19:07PM +0000, Simon White wrote:
> > > > Are you getting any logs on your radius server?
> > > >
> > > > invalid secret, request from unknown client, or anything like
> > > > that?
> > >
> > > I'm not seeing anything in the radius logs at all.
> >
> > Can we do a tcpdump to find the packet data?
> >
> > from the sysmon host:
> > tcpdump -s1500 -vv -n host ip.radius.host and udp and port 1645
> >
> > > >
> > > > Which radius server are you using? I've tested this w/ the
> > > > Merit radiusd as well as Radiator.
> > >
> > >
> > > I'm using Cistron Radius (http://www.radius.cistron.nl/)
> > >
> > > NOTE: I compiled the source on my workstation, running exactly the same
> > > config as the sysmon box, and moved *just* the binary over to the sysmon
> > > box. This was because I don't have anything much on the sysmon box, no
> > > lex, flex, etc. If there's a support file needed for radius let me know,
> > > although I assumed all would be in the binary since all the other tests
> > > work...
> >
> > You are correct, there is nothing that you need other than
> > the binary as I built-in all the checks.
> >
> > --
> > Jared Mauch | pgp key available via finger from jared@puck.nether.net
> > clue++; | http://puck.nether.net/~jared/ My statements are only mine.
> >
>
>

-- 
|-Simon White
|-Internet Services Manager
|-MTDS S.A.
|-tel +212.3.767.4861
|-fax +212.3.767.4863
|-14, rue 16 novembre
|-Rabat, Kingdom of Morocco



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:14:07 EDT