Sziasztok!
Most ismerkedek a freeradiussal is és az openwrt-vel is...
Adott egy Tp-link 1043nd router amin openwrt AA 12.09 van és egy freeradius 2.2.0 szerver, amire így első körben sima mac szűrés van beállítva. Elvileg működni kellene, más Ap-kal (cisco) működik is, de valamiért a tp-linkel nem, és fogalmam sincs miért. Van valakinek ötlete?
Íme a logok:
freeradius:
rad_recv: Access-Request packet from host 10.10.15.1 port 45313, id=20, length=169
User-Name = "xy"
Called-Station-Id = "74-EA-3A-C2-76-EC"
NAS-Port-Type = Wireless-802.11
NAS-Port = 2
Calling-Station-Id = "38-59-F9-1E-08-1F"
Connect-Info = "CONNECT 54Mbps 802.11g"
Framed-MTU = 1400
EAP-Message = 0x027c001401686f73742f544d2d44656c6c2d5043
Message-Authenticator = 0xe7c8eb651a47cc086737f7e69b03a6ed
# Executing section authorize from file ../etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++- entering policy rewrite_calling_station_id {...}
+++? if blablabla....
++++[request] returns ok
+++- if blablabla... returns ok
+++ ... skipping else for request 894: Preceding "if" was taken
++- policy rewrite_calling_station_id returns ok
[authorized_macs] expand: %{Calling-Station-ID} -> 38-59-f9-1e-08-1f
[authorized_macs] users: Matched entry 38-59-f9-1e-08-1f at line 1
++[authorized_macs] returns ok
++? if (!ok)
? Evaluating !(ok) -> FALSE
++? if (!ok) -> FALSE
++- entering else else {...}
+++[control] returns ok
++- else else returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
++[wimax] returns ok
[suffix] No '@' in User-Name = "xy", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING: Auth-Type already set. Not setting to PAP
++[pap] returns noop
Found Auth-Type = Accept
Auth-Type = Accept, accepting the user
# Executing section post-auth from file ../etc/raddb/sites-enabled/default
+- entering group post-auth {...}
++[exec] returns noop
Sending Access-Accept of id 20 to 10.10.15.1 port 45313
Finished request 894.
Going to the next request
Waking up in 4.9 seconds.
Cleaning up request 894 ID 20 with timestamp +64770
Ready to process requests.
Openwrt:
Sep 6 10:23:09 TP-Link daemon.info hostapd: wlan0: STA 38:59:f9:1e:08:1f IEEE 802.11: authenticated
Sep 6 10:23:09 TP-Link daemon.info hostapd: wlan0: STA 38:59:f9:1e:08:1f IEEE 802.11: associated (aid 2)
...
Sep 6 10:23:45 TP-Link daemon.info hostapd: wlan0: STA 38:59:f9:1e:08:1f IEEE 802.11: disassociated
Sep 6 10:23:46 TP-Link daemon.info hostapd: wlan0: STA 38:59:f9:1e:08:1f IEEE 802.11: deauthenticated due to inactivity (timer DEAUTH/REMOVE)
- 4790 megtekintés