[RadiusNT Digest]

radiusnt-digest-request@iea-software.com
Fri, 24 Jul 1998 00:02:30 -0700

Message 1: Re: Cisco filters and IP Pool
from "Mohammed Ersan" <ersan@first.net.jo>

Message 2: No CISCO logins are displayed on CallOnL
from siglesias@nec.com.ar

Message 3: Y2K and Radius: maExpireDate above 12-31-1999 (year 2000)
produces login failures
from Mike Miller <michael@abraxis.com>

Message 4: unsubscribe
from Gary Austin <gaustin@camcomp.com>

..------ ------ ------ ------ ------ ------ ------ ------ ------ ------.
| Message 1 |
'------ ------ ------ ------ ------ ------ ------ ------ ------ ------'
Subject: Re: Cisco filters and IP Pool
From: "Mohammed Ersan" <ersan@first.net.jo>
Date: Thu, 23 Jul 1998 08:58:35 +0300

I did assign a framed filter in the defaults for every service, it works ok on the portmaster but on the Cisco it would not assign the filter that is already defined in Cisco which of course got the same name.

--------------

What I meant in the second part is that in the Win DUN if the user has configured it not to take a dynamic IP address and assigns an address from my network, he would be able to login...does this have to do with the filter that is not working.

thanks

At 11:25 AM 07/22/98 -0700, you wrote:

>Mohammed Ersan wrote:

>>

>> we have a number Portmasters + Cisco 3640 working as Access Servers for

>> Local and remote sites, on the Cisco I've created the required filters

>> (same names on the PM & Cisco) but how do I make radius to assign the

>> filter on the cisco and how could i prevent some one from assigning his

>> address because if a dial-in user assigns his address he will be

>> authenticated normally.....

>

>To assign the filter in RadiusNT (assuming ODBC Mode) you need to add the

>Framed-Filter attribute to the AccountType defaults in the RadATConfigs

>table (or to the specific users's accountID in the RadConfigs Table).

>

>I'm really not sure what you are asking in the second part about

>"assigning his address" and "authenticated normally".

>

>--

>Dale E. Reed Jr. (daler@iea-software.com)

>_________________________________________________________________

> IEA Software, Inc. | RadiusNT, Emerald, and NT FAQs

> Internet Solutions for Today | http://www.iea-software.com

>

<center>Mohammed Ersan

ersan@first.net.jo

firstnet

</center>

..------ ------ ------ ------ ------ ------ ------ ------ ------ ------.
| Message 2 |
'------ ------ ------ ------ ------ ------ ------ ------ ------ ------'
Subject: No CISCO logins are displayed on CallOnL
From: siglesias@nec.com.ar
Date: Thu, 23 Jul 1998 8:27:51 -0400

Message is sent with MIME. Attachments are base64 encoded
--TFS-with-MIME-and-DIME
Content-Type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: quoted-printable

Dear Dale:

Hello again. I have more questions for you.

1) Regarding to CISCO OnLine Calls, I followed your suggestions (repeat =20=
=20
the Server's entries for the LAN's IP addresses), but it worked only for =20
one NAS (200.16.186.222), which calls were displayed in the OnLine tab. =20
With the rest of the CISCOs happened the following:

a) One of them (200.16.186.237) was writing the events on the calls =20
table, but there was no way to watch them in the OnLine tab.

b) The other neither were looged into the calls table nor were showed in =20=
=20
the OnLine tab.

I am attaching a partial query of the Calls table to let you analyze teh =20=
=20
differences between the case of the 200.16.186.237 and the 200.16.186.222 =20=
=20
(PS look at the NASPortType column of the attached query). Besides, do =20
you have any other idea about the rest of the[[ CALLS0~1.RPT : 5674 en =20
CALLS0~1.RPT ]]CISCOs?

=20

2) When I try to perform a Summary on the Batch tab I get the following =20
message:

No consolidation needed

What does it mean? How can I get the consolidation so as to bill the =20
services?

3) I have implemented the email-only filter by using the =20
Ascend-DataFilter attribute. It works properly when you access the node =20
throught the MAX 4000, of course; but it doesn't work if you access using =20=
=20
one o the CISCOs. Does anyone know if CISCO IOS support such attributes, =20
and which version it is? I suppose that this filter may be built using =20
the standard RADIUS attributes. Is it correct?

Thank for your support.

Ing. Sergio Iglesias
System Development Department
Technology Division
NEC Argentina S.A.
Av. San Martin 5020 (1601) Florida Pcia. Bs. As. Argentina
TE +54-1-7306067
FX +54-1-7306060
EM siglesias@nec.com.ar

--TFS-with-MIME-and-DIME
Content-Type: application/octet-stream; name="CALLS0~1.RPT"
Content-transfer-encoding: base64

TkFTSWRlbnRpZmllciAgICBOQVNQb3J0ICAgICBBY2N0U2Vzc2lvbklEIEFj
Y3RTdGF0dXNUeXBlIENhbGxEYXRlICAgICAgICAgICAgICAgICAgICBVc2Vy
TmFtZSAgICAgICAgICAgICAgICAgICAgICAgICBVc2VyU2VydmljZSBBY2N0
RGVsYXlUaW1lIEFjY3RTZXNzaW9uVGltZSBGcmFtZWRQcm90b2NvbCBGcmFt
ZWRBZGRyZXNzICAgIEFjY3RJbnB1dE9jdGV0cyBBY2N0T3V0cHV0T2N0ZXRz
IEFjY3RUZXJtaW5hdGVDYXVzZSBOQVNQb3J0VHlwZSBOQVNQb3J0RE5JUyAN
Ci0tLS0tLS0tLS0tLS0tLS0gLS0tLS0tLS0tLS0gLS0tLS0tLS0tLS0tLSAt
LS0tLS0tLS0tLS0tLSAtLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0gLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0gLS0tLS0tLS0tLS0gLS0t
LS0tLS0tLS0tLSAtLS0tLS0tLS0tLS0tLS0gLS0tLS0tLS0tLS0tLS0gLS0t
LS0tLS0tLS0tLS0tLSAtLS0tLS0tLS0tLS0tLS0gLS0tLS0tLS0tLS0tLS0t
LSAtLS0tLS0tLS0tLS0tLS0tLS0gLS0tLS0tLS0tLS0gLS0tLS0tLS0tLS0g
DQoyMDAuMTYuMTg2LjIzNyAgIDEgICAgICAgICAgIDAwMDAyNCAgICAgICAg
MSAgICAgICAgICAgICAgSnVsIDIxIDE5OTggMTI6NTVQTSAgICAgICAgIHF1
ZWFuZGUgICAgICAgICAgICAgICAgICAgICAgICAgIDIgICAgICAgICAgIDAg
ICAgICAgICAgICAgMCAgICAgICAgICAgICAgIDEgICAgICAgICAgICAgIChu
dWxsKSAgICAgICAgICAgKG51bGwpICAgICAgICAgIChudWxsKSAgICAgICAg
ICAgKG51bGwpICAgICAgICAgICAgIChudWxsKSAgICAgIChudWxsKSAgICAg
IA0KMjAwLjE2LjE4Ni4yMzcgICAxICAgICAgICAgICAwMDAwMjQgICAgICAg
IDMgICAgICAgICAgICAgIEp1bCAyMSAxOTk4IDEyOjU1UE0gICAgICAgICBx
dWVhbmRlICAgICAgICAgICAgICAgICAgICAgICAgICAyICAgICAgICAgICAw
ICAgICAgICAgICAgIDAgICAgICAgICAgICAgICAxICAgICAgICAgICAgICAy
MDAuMTYuMTg2LjIyNSAgIChudWxsKSAgICAgICAgICAobnVsbCkgICAgICAg
ICAgIChudWxsKSAgICAgICAgICAgICAobnVsbCkgICAgICAobnVsbCkgICAg
ICANCjIwMC4xNi4xODYuMjM3ICAgMSAgICAgICAgICAgMDAwMDI0ICAgICAg
ICAyICAgICAgICAgICAgICBKdWwgMjEgMTk5OCAxMjo1OVBNICAgICAgICAg
cXVlYW5kZSAgICAgICAgICAgICAgICAgICAgICAgICAgMiAgICAgICAgICAg
MCAgICAgICAgICAgICAyMzMgICAgICAgICAgICAgMSAgICAgICAgICAgICAg
MjAwLjE2LjE4Ni4yMjUgICAxNDUgICAgICAgICAgICAgMTI1ICAgICAgICAg
ICAgICAobnVsbCkgICAgICAgICAgICAgKG51bGwpICAgICAgKG51bGwpICAg
ICAgDQoyMDAuMTYuMTg2LjIzNyAgIDUgICAgICAgICAgIDAwMDAzMyAgICAg
ICAgMSAgICAgICAgICAgICAgSnVsIDIxIDE5OTggIDE6NTVQTSAgICAgICAg
IHF1ZWFuZGUgICAgICAgICAgICAgICAgICAgICAgICAgIDIgICAgICAgICAg
IDAgICAgICAgICAgICAgMCAgICAgICAgICAgICAgIDEgICAgICAgICAgICAg
IChudWxsKSAgICAgICAgICAgKG51bGwpICAgICAgICAgIChudWxsKSAgICAg
ICAgICAgKG51bGwpICAgICAgICAgICAgIChudWxsKSAgICAgIChudWxsKSAg
ICAgIA0KMjAwLjE2LjE4Ni4yMzcgICA1ICAgICAgICAgICAwMDAwMzMgICAg
ICAgIDMgICAgICAgICAgICAgIEp1bCAyMSAxOTk4ICAxOjU1UE0gICAgICAg
ICBxdWVhbmRlICAgICAgICAgICAgICAgICAgICAgICAgICAyICAgICAgICAg
ICAwICAgICAgICAgICAgIDAgICAgICAgICAgICAgICAxICAgICAgICAgICAg
ICAyMDAuMTYuMTg2LjIyOSAgIChudWxsKSAgICAgICAgICAobnVsbCkgICAg
ICAgICAgIChudWxsKSAgICAgICAgICAgICAobnVsbCkgICAgICAobnVsbCkg
ICAgICANCjIwMC4xNi4xODYuMjM3ICAgNSAgICAgICAgICAgMDAwMDMzICAg
ICAgICAyICAgICAgICAgICAgICBKdWwgMjEgMTk5OCAgMjowNVBNICAgICAg
ICAgcXVlYW5kZSAgICAgICAgICAgICAgICAgICAgICAgICAgMiAgICAgICAg
ICAgMCAgICAgICAgICAgICA2MTggICAgICAgICAgICAgMSAgICAgICAgICAg
ICAgMjAwLjE2LjE4Ni4yMjkgICAxNDUgICAgICAgICAgICAgMTI1ICAgICAg
ICAgICAgICAobnVsbCkgICAgICAgICAgICAgKG51bGwpICAgICAgKG51bGwp
ICAgICAgDQoyMDAuMTYuMTg2LjIzNyAgIDQgICAgICAgICAgIDAwMDIxNCAg
ICAgICAgMSAgICAgICAgICAgICAgSnVsIDIyIDE5OTggMTI6MTJQTSAgICAg
ICAgIHF1ZWFuZGUgICAgICAgICAgICAgICAgICAgICAgICAgIDIgICAgICAg
ICAgIDAgICAgICAgICAgICAgMCAgICAgICAgICAgICAgIDEgICAgICAgICAg
ICAgIChudWxsKSAgICAgICAgICAgKG51bGwpICAgICAgICAgIChudWxsKSAg
ICAgICAgICAgKG51bGwpICAgICAgICAgICAgIChudWxsKSAgICAgIChudWxs
KSAgICAgIA0KMjAwLjE2LjE4Ni4yMzcgICA0ICAgICAgICAgICAwMDAyMTQg
ICAgICAgIDMgICAgICAgICAgICAgIEp1bCAyMiAxOTk4IDEyOjEyUE0gICAg
ICAgICBxdWVhbmRlICAgICAgICAgICAgICAgICAgICAgICAgICAyICAgICAg
ICAgICAwICAgICAgICAgICAgIDAgICAgICAgICAgICAgICAxICAgICAgICAg
ICAgICAyMDAuMTYuMTg2LjIyOCAgIChudWxsKSAgICAgICAgICAobnVsbCkg
ICAgICAgICAgIChudWxsKSAgICAgICAgICAgICAobnVsbCkgICAgICAobnVs
bCkgICAgICANCjIwMC4xNi4xODYuMjM3ICAgNCAgICAgICAgICAgMDAwMjE0
ICAgICAgICAyICAgICAgICAgICAgICBKdWwgMjIgMTk5OCAxMjoxM1BNICAg
ICAgICAgcXVlYW5kZSAgICAgICAgICAgICAgICAgICAgICAgICAgMiAgICAg
ICAgICAgMCAgICAgICAgICAgICA0NyAgICAgICAgICAgICAgMSAgICAgICAg
ICAgICAgMjAwLjE2LjE4Ni4yMjggICAxNDUgICAgICAgICAgICAgMTI1ICAg
ICAgICAgICAgICAobnVsbCkgICAgICAgICAgICAgKG51bGwpICAgICAgKG51
bGwpICAgICAgDQoyMDAuMTYuMTg2LjIyMiAgIDYgICAgICAgICAgIDAwMDAw
MDZFICAgICAgMSAgICAgICAgICAgICAgSnVsIDIyIDE5OTggMTI6MTVQTSAg
ICAgICAgIHF1ZWFuZGUgICAgICAgICAgICAgICAgICAgICAgICAgIDIgICAg
ICAgICAgIDAgICAgICAgICAgICAgMCAgICAgICAgICAgICAgIDEgICAgICAg
ICAgICAgIChudWxsKSAgICAgICAgICAgKG51bGwpICAgICAgICAgIChudWxs
KSAgICAgICAgICAgKG51bGwpICAgICAgICAgICAgIDAgICAgICAgICAgIChu
dWxsKSAgICAgIA0KMjAwLjE2LjE4Ni4yMjIgICA2ICAgICAgICAgICAwMDAw
MDA2RSAgICAgIDIgICAgICAgICAgICAgIEp1bCAyMiAxOTk4IDEyOjE1UE0g
ICAgICAgICBxdWVhbmRlICAgICAgICAgICAgICAgICAgICAgICAgICAyICAg
ICAgICAgICAwICAgICAgICAgICAgIDI3ICAgICAgICAgICAgICAxICAgICAg
ICAgICAgICAyMDAuMTYuMTg2LjIxNCAgIDIyNyAgICAgICAgICAgICAyMzQ3
ICAgICAgICAgICAgIChudWxsKSAgICAgICAgICAgICAwICAgICAgICAgICAo
bnVsbCkgICAgICANCjIwMC4xNi4xODYuMjM3ICAgMSAgICAgICAgICAgMDAw
MjIyICAgICAgICAxICAgICAgICAgICAgICBKdWwgMjIgMTk5OCAxMjo1OFBN
ICAgICAgICAgcXVlYW5kZSAgICAgICAgICAgICAgICAgICAgICAgICAgMiAg
ICAgICAgICAgMCAgICAgICAgICAgICAwICAgICAgICAgICAgICAgMSAgICAg
ICAgICAgICAgKG51bGwpICAgICAgICAgICAobnVsbCkgICAgICAgICAgKG51
bGwpICAgICAgICAgICAobnVsbCkgICAgICAgICAgICAgKG51bGwpICAgICAg
KG51bGwpICAgICAgDQoyMDAuMTYuMTg2LjIzNyAgIDEgICAgICAgICAgIDAw
MDIyMiAgICAgICAgMyAgICAgICAgICAgICAgSnVsIDIyIDE5OTggMTI6NThQ
TSAgICAgICAgIHF1ZWFuZGUgICAgICAgICAgICAgICAgICAgICAgICAgIDIg
ICAgICAgICAgIDAgICAgICAgICAgICAgMCAgICAgICAgICAgICAgIDEgICAg
ICAgICAgICAgIDIwMC4xNi4xODYuMjI1ICAgKG51bGwpICAgICAgICAgIChu
dWxsKSAgICAgICAgICAgKG51bGwpICAgICAgICAgICAgIChudWxsKSAgICAg
IChudWxsKSAgICAgIA0KMjAwLjE2LjE4Ni4yMzcgICAxICAgICAgICAgICAw
MDAyMjIgICAgICAgIDIgICAgICAgICAgICAgIEp1bCAyMiAxOTk4ICAxOjAy
UE0gICAgICAgICBxdWVhbmRlICAgICAgICAgICAgICAgICAgICAgICAgICAy
ICAgICAgICAgICAwICAgICAgICAgICAgIDIwMiAgICAgICAgICAgICAxICAg
ICAgICAgICAgICAyMDAuMTYuMTg2LjIyNSAgIDE0NSAgICAgICAgICAgICAx
MjUgICAgICAgICAgICAgIChudWxsKSAgICAgICAgICAgICAobnVsbCkgICAg
ICAobnVsbCkgICAgICANCg0KKDE0IHJvdyhzKSBhZmZlY3RlZCkNCg0K

--TFS-with-MIME-and-DIME--

..------ ------ ------ ------ ------ ------ ------ ------ ------ ------.
| Message 3 |
'------ ------ ------ ------ ------ ------ ------ ------ ------ ------'
Subject: Y2K and Radius: maExpireDate above 12-31-1999 (year 2000)
produces login failures
From: Mike Miller <michael@abraxis.com>
Date: Thu, 23 Jul 1998 17:18:25 -0400

Has anyone had any Y2K problems with Radius 2.2? I notice Dale says Radius
is year 2000 compliant, but have had a problem in testing it internally.
Our problem is this: If we set up a MasterAccount with a maExpireDate
greater than 12-31-1999, the user will always get rejected from
authenticating with the message in Radius Debug -x15 saying that thier
account is expired. Our platform is as follows:

RadiusNT 2.2 using ODBC for both accounting and authentication
MS SQL 6.5 sp 4 Database

The column in our database is set up properly to handle long dates. Please
help.

--

==================================================== /\ Mike A. Miller == /--\ \/ Abraxis Networks ==/ \ B R A /\ I S == / == N E T W O R K S michael@abraxis.com====================================================

..------ ------ ------ ------ ------ ------ ------ ------ ------ ------.| Message 4 |'------ ------ ------ ------ ------ ------ ------ ------ ------ ------'Subject: unsubscribeFrom: Gary Austin <gaustin@camcomp.com>Date: Wed, 15 Jul 1998 15:43:47 -0400

unsubscribe