免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 2270 | 回复: 1
打印 上一主题 下一主题

[网络管理] 请教两个问题:关于无线局域网和Radius+MD5认证 [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2007-09-05 21:53 |只看该作者 |倒序浏览
5可用积分
1,要完成一个WLAN接入过程的模拟,现在的问题是客户端发出来的EAP-MD5数据包只能发送到AP上,我希望AP把这些MAC层的广播包转发到通过网线与AP相连的服务器上,请大侠们指点一二!!!

如果有WDS功能是否能够实现??


2,现在已经搭建了一套radius+mysql的认证环境,进行eap-md5验证,
但是不管客户端发送的用户名是什么radius得到的总是:User-Name = "\025\004"
以下是radiusd -X 时候打印的结果,很奇怪,是不是我的配置有问题??
客户端截包证明客户端没有问题。
请各位指教!!!

rad_recv: Access-Request packet from host 192.168.1.1:65474, id=13, length=106
        User-Name = "\025\004"
        NAS-Port-Type = Wireless-802.11
        NAS-IP-Address = 192.168.1.1
        Framed-MTU = 1400
        State = 0x71c37a927721937df22ef09493641486
        EAP-Message = 0x0202001a0410ee0c60f285703ba80e6448dbabe0ed0674657374
        Message-Authenticator = 0xac2574c87e3704b2711eff04cde3a7d7
  Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 11
  modcall[authorize]: module "preprocess" returns ok for request 11
  modcall[authorize]: module "chap" returns noop for request 11
  modcall[authorize]: module "mschap" returns noop for request 11
    rlm_realm: No '@' in User-Name = "??", looking up realm NULL
    rlm_realm: No such realm "NULL"
  modcall[authorize]: module "suffix" returns noop for request 11
  rlm_eap: EAP packet type response id 2 length 26
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
  modcall[authorize]: module "eap" returns updated for request 11
  modcall[authorize]: module "files" returns notfound for request 11
radius_xlat:  '\025\004'
rlm_sql (sql): sql_set_user escaped user --> '\025\004'
radius_xlat:  'SELECT id, UserName, Attribute, Value, op           FROM radcheck           WHERE Username =

'=5C=5C025=5C=5C004'           ORDER BY id'
rlm_sql (sql): Reserving sql socket id: 3
rlm_sql (sql): User \025\004 not found in radcheck
radius_xlat:  'SELECT radgroupcheck.id,radgroupcheck.GroupName,radgroupcheck.Attribute,radgroupcheck.Value,radgroupcheck.op  

FROM radgroupcheck,usergroup WHERE usergroup.Username = '=5C=5C025=5C=5C004' AND usergroup.GroupName =

radgroupcheck.GroupName ORDER BY radgroupcheck.id'
radius_xlat:  'SELECT radgroupreply.id,radgroupreply.GroupName,radgroupreply.Attribute,radgroupreply.Value,radgroupreply.op  

FROM radgroupreply,usergroup WHERE usergroup.Username = '=5C=5C025=5C=5C004' AND usergroup.GroupName =

radgroupreply.GroupName ORDER BY radgroupreply.id'
rlm_sql (sql): User \025\004 not found in radgroupcheck
rlm_sql (sql): Released sql socket id: 3
rlm_sql (sql): User not found
  modcall[authorize]: module "sql" returns notfound for request 11
rlm_pap: WARNING! No "known good" password found for the user.  Authentication may fail because of this.
  modcall[authorize]: module "pap" returns noop for request 11
modcall: leaving group authorize (returns updated) for request 11
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
  Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 11
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/md5
  rlm_eap: processing type md5
rlm_eap_md5: User-Password is required for EAP-MD5 authentication
rlm_eap: Handler failed in EAP/md5
  rlm_eap: Failed in EAP select
  modcall[authenticate]: module "eap" returns invalid for request 11
modcall: leaving group authenticate (returns invalid) for request 11
auth: Failed to validate the user.
Delaying request 11 for 1 seconds
Finished request 11
Going to the next request
Waking up in 6 seconds...
--- Walking the entire request list ---
Cleaning up request 10 ID 12 with timestamp 46dc1473
Sending Access-Reject of id 13 to 192.168.1.1 port 65474
        EAP-Message = 0x04020004
        Message-Authenticator = 0x00000000000000000000000000000000
Cleaning up request 11 ID 13 with timestamp 46dc1473
Nothing to do.  Sleeping until we see a request.

论坛徽章:
5
IT运维版块每日发帖之星
日期:2015-08-06 06:20:00IT运维版块每日发帖之星
日期:2015-08-10 06:20:00IT运维版块每日发帖之星
日期:2015-08-23 06:20:00IT运维版块每日发帖之星
日期:2015-08-24 06:20:00IT运维版块每日发帖之星
日期:2015-11-12 06:20:00
2 [报告]
发表于 2007-09-08 21:43 |只看该作者
Free Radius中可以配置客户端类型。
并且确信你客户端配置正确。
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP