Date: Wed, 3 Nov 2004 08:41:56 +0700 (JAVT) From: SlavesZeroes <rino@melsa.net.id> To: freebsd-questions@freebsd.org Subject: WLAN Freeradius Auth Message-ID: <Pine.BSF.4.05.10411030841050.17987-100000@ns2.melsa.net.id>
next in thread | raw e-mail | index | archive | help
Dear all, I've setup my little hotspot for our office. And offcourse for security reason, only mac address listed in radius users can have internet access. With Lucent Orinoco AP-1000, i've checked enable radius access control and then setup my free radius. My radius setting : 00601d-f4ae15 Auth-Type = Local, Password = "testing123" Service-Type = Framed-User, Framed-Protocol = PPP, Framed-Routing = Broadcast-Listen, Framed-MTU = 1500, Framed-Compression = Van-Jacobson-TCP-IP but when i try to change the setting, for testing only : 00601d-f4ae15 Auth-Type = Reject, Password = "testing123" Service-Type = Framed-User, Framed-Protocol = PPP, Framed-Routing = Broadcast-Listen, Framed-MTU = 1500, Framed-Compression = Van-Jacobson-TCP-IP They still can have an access to outside, my radius log says : Auth: Login incorrect: [00601d-f4ae15/testing123] (from client ap port 0). and i try to ping to that station, it says reply : PING 192.168.0.254 (192.168.0.254): 56 data bytes 64 bytes from 192.168.0.254: icmp_seq=0 ttl=64 time=0.840 ms my question is, if mac address not listed in radius users or in REJECT mode, they shouldn't get an access to Access Point, and offcourse they can't have ip address, but in my case, they still have an static ip address and they can access to LAN and internet too. Can you help me ? Thanks
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.05.10411030841050.17987-100000>