<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: StrongSWAN (IKE2&#092;EAP) + freeradius авторизация (Framed-IP-Addre</title>
    <link>https://opennet.dev/openforum/vsluhforumID10/5620.html</link>
    <description>Добрый день!&lt;br&gt;Столкнулся с проблемой.&lt;br&gt;На VDS поднят strongswan + freeradius. &lt;br&gt;Авторизация проходит, но radius атрибуты не срабатывают для статического IP.&lt;br&gt;&lt;br&gt;/etc/freeradius/3.0/users&lt;br&gt;&#037;radius-username&#037;   Cleartext-Password := &quot;&#037;radius-password&#037;&quot;&lt;br&gt;        NAS-Port-Type = Virtual,&lt;br&gt;        Service-Type = Framed-User,&lt;br&gt;        Framed-IP-Address = 10.255.24.12,&lt;br&gt;        Framed-IP-Netmask = 255.255.255.0,&lt;br&gt;        MS-Primary-DNS-Server = 8.8.8.8&lt;br&gt;&lt;br&gt;В запросе четко видны радиус атрибуты, но они не срабатывают (радиус их получает, и игнорирует их)&lt;br&gt;&lt;br&gt;Кусок дебага:&lt;br&gt;Sent Access-Accept Id 106 from 127.0.0.1:1812 to 127.0.0.1:34540 length 0&lt;br&gt;(4)   NAS-Port-Type = Virtual&lt;br&gt;(4)   Service-Type = Framed-User&lt;br&gt;(4)   Framed-IP-Address = 10.255.24.12&lt;br&gt;(4)   Framed-IP-Netmask = 255.255.255.0&lt;br&gt;(4)   MS-Primary-DNS-Server = 8.8.8.8&lt;br&gt;(4)   MS-MPPE-Encryption-Policy = Encryption-Allowed&lt;br&gt;(4)   MS-MPPE-Encryption-Types = RC4-40or128-bit-Allowed&lt;br&gt;(4)   MS-MPPE-Send-Key = 0x7bbb8b987de7d0dfc120c24433fb2083&lt;br&gt;(4)   MS-MPPE-Recv-Key </description>

<item>
    <title>StrongSWAN (IKE2&#092;EAP) + freeradius авторизация (Framed-IP-Addre (sysgloster)</title>
    <link>https://opennet.dev/openforum/vsluhforumID10/5620.html#2</link>
    <pubDate>Sat, 19 Mar 2022 14:30:43 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;         Acct-Input-Octets = 140713 &lt;br&gt;&amp;gt;         Acct-Input-Packets = 348 &lt;br&gt;&amp;gt;         Acct-Session-Time = 390 &lt;br&gt;&amp;gt;         Acct-Terminate-Cause = User-Request &lt;br&gt;&amp;gt;         NAS-Identifier = &quot;strongSwan&quot; &lt;br&gt;&amp;gt;         Event-Timestamp = &quot;Mar 19 &lt;br&gt;&amp;gt; 2022 13:25:24 UTC&quot; &lt;br&gt;&amp;gt;         Tmp-String-9 = &quot;ai:&quot; &lt;br&gt;&amp;gt;         Acct-Unique-Session-Id = &quot;87126f7fa0835846260efa39b8e90656&quot; &lt;br&gt;&amp;gt;         Timestamp = 1647696324 &lt;br&gt;&lt;br&gt;Разобрался.&lt;br&gt;https://wiki.debian.org/ru/strongSWAN/VirtualIP#RADIUS_.2BBD0EMA_backend&lt;br&gt;&lt;br&gt;/etc/ipsec.conf&lt;br&gt;rightsourceip=&#037;radius&lt;br&gt;&lt;br&gt;В официальной доке этого нет. Возможно искал плохо.&lt;br&gt;</description>
</item>

<item>
    <title>StrongSWAN (IKE2&#092;EAP) + freeradius авторизация (Framed-IP-Addre (sysgloster)</title>
    <link>https://opennet.dev/openforum/vsluhforumID10/5620.html#1</link>
    <pubDate>Sat, 19 Mar 2022 13:33:52 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt; (5)   NAS-Port-Id = &quot;IKEv2+EAP&quot; &lt;br&gt;&amp;gt; (5)   NAS-IP-Address = &#037;EXT-IP-VDS&#037; &lt;br&gt;&amp;gt; (5)   Called-Station-Id = &quot;&#037;EXT-IP-VDS&#037;&#091;500&#093;&quot; &lt;br&gt;&amp;gt; (5)   Calling-Station-Id = &quot;&#037;EXT-IP-CLIENT&#037;&#091;500&#093;&quot; &lt;br&gt;&amp;gt; (5)   User-Name = &quot;&#037;radius-username&#037;&quot; &lt;br&gt;&amp;gt; (5)   Framed-IP-Address = 10.255.24.2 &lt;br&gt;&amp;gt; (5)   NAS-Identifier = &quot;strongSwan&quot; &lt;br&gt;&amp;gt; IP адреса, логины и пароли изменены.&lt;br&gt;&amp;gt; Буду рад совету.&lt;br&gt;&amp;gt; Заранее благодарен.&lt;br&gt;&lt;br&gt;В дополнение, кусок лога. Атрибут дублируется:&lt;br&gt;Framed-IP-Address = 10.255.24.2&lt;br&gt;Framed-IP-Address = 10.255.24.12&lt;br&gt;&lt;br&gt;Sat Mar 19 13:25:24 2022&lt;br&gt;        Acct-Status-Type = Stop&lt;br&gt;        Acct-Session-Id = &quot;1647688010-74&quot;&lt;br&gt;        NAS-Port-Type = Virtual&lt;br&gt;        Service-Type = Framed-User&lt;br&gt;        NAS-Port = 74&lt;br&gt;        NAS-Port-Id = &quot;IKEv2+EAP&quot;&lt;br&gt;        NAS-IP-Address = &#037;EXT-IP-VDS&#037;&lt;br&gt;        Called-Station-Id = &quot;&#037;EXT-IP-VDS&#037;&#091;500&#093;&quot;&lt;br&gt;        Calling-Station-Id = &quot;&#037;EXT-IP-CLIENT&#037;&#091;500&#093;&quot;&lt;br&gt;        User-Name = &quot;&#037;radius-username&#037;&quot;&lt;br&gt;        Framed-IP-Address = 10.255.24.2&lt;br&gt;        Framed-IP-Address = 10.255.24.12&lt;br&gt;</description>
</item>

</channel>
</rss>
