RE: Proxying on Realm and NAS?

This is a discussion on RE: Proxying on Realm and NAS? within the FreeRADIUS Users forums, part of the Networking and Network Related category; Hi, Thanks for that Alan. :) I have been looking at this today but it doesn't appear that I can '...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-23-2005
Palmer J.D.F.
 
Posts: n/a
Default RE: Proxying on Realm and NAS?

Hi,

Thanks for that Alan. :)
I have been looking at this today but it doesn't appear that I can 'pass'
the user's realm (from the username foo@bar.com) into the users file as an
attribute?
Is that the case or am I looking in the wrong place?

For example I want to be able to do this but it doesn't work, is there a way
that I can achieve this?

foo.com and foobar.com are my two local realms, NULL realms are also used
locally. 10.0.0.1 and 10.0.0.2 are both local RADIUS servers, 192.168.0.1 is
a remote radius proxy server.

A Request from NAS 10.0.0.1 should get forwarded to rad1, unless the realm
is 'unknown' but not NULL, in which case it should be forwarded to rad3.

DEFAULT NAS-IP-Address==10.0.0.1, Realm==NULL, Proxy-To-Realm := rad1
DEFAULT NAS-IP-Address==10.0.0.1, Realm==foo.com, Proxy-To-Realm := rad1
DEFAULT NAS-IP-Address==10.0.0.1, Realm==foobar.com, Proxy-To-Realm := rad1
DEFAULT NAS-IP-Address==10.0.0.1, Realm==unknown, Proxy-To-Realm := rad3

Similarly, A Request from NAS 10.0.0.2 should get forwarded to rad2, unless
the realm is 'unknown' but not NULL, in which case it should be forwarded to
rad3.

DEFAULT NAS-IP-Address==10.0.0.2, Realm==NULL, Proxy-To-Realm := rad2
DEFAULT NAS-IP-Address==10.0.0.2, Realm==foo.com, Proxy-To-Realm := rad2
DEFAULT NAS-IP-Address==10.0.0.2, Realm==foobar.com, Proxy-To-Realm := rad2
DEFAULT NAS-IP-Address==10.0.0.2, Realm==unknown, Proxy-To-Realm := rad3

Finally, all incoming RADIUS requests from the external server (which is
actually Rad3) should get forwarded to rad2.

DEFAULT NAS-IP-Address==192.168.0.1, Realm==foo.com, Proxy-To-Realm := rad2
DEFAULT NAS-IP-Address==192.168.0.1, Realm==foobar.com, Proxy-To-Realm :=
rad2

In theory that is what I want to achieve, but unfortunately the Realm
attribute doesn't appear to work like that.

Any help would be gratefully received.

Many thanks,
Jezz Palmer.


> -----Original Message-----
> From: freeradius-users-admin@lists.freeradius.org [mailto:freeradius-
> users-admin@lists.freeradius.org] On Behalf Of Alan DeKok
> Sent: 19 May 2005 17:47
> To: freeradius-users@lists.freeradius.org
> Subject: Re: Proxying on Realm and NAS?
>
> "Palmer J.D.F." <J.D.F.Palmer@swansea.ac.uk> wrote:
> > Could someone tell me if it's possible to use Freeradius to proxy radius
> > requests to different radius servers depending on a combination of a

> user's
> > realm and the originating NAS-IP-Address; or any other distinguishable

> NAS
> > variable for that matter.

>
>
> DEFAULT Attribute-Foo == Value, Attribute-Bar == value, Proxy-To-
> Realm := foo.com
>
> Alan DeKok.
> ]
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:28 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0