Shunze ¾Ç¶é >¸ê°T³]³Æ±M°Ï >Extreme & Enterasys > ¡m¤À¨É¡nEnterasys Wifi·f°tRadiusÅçÃÒ «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]
« ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD » Åã¥Ü¦¨¦C¦L¼Ò¦¡ | ¼W¥[¨ì§Úªº³Ì·R
µoªí·s¥DÃD µoªí¦^ÂÐ
§@ªÌ
¥DÃD
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nEnterasys Wifi·f°tRadiusÅçÃҤޥΦ^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Enterasys Thin AP¬[ºc¥i³z¹LController¥»¨­ªºCaptive Portal·f°t¥~³¡Radius Server¨Ó¶i¦æ¨­¥÷ÅçÃÒ¡A
¥»¤å±N¤À¬° Radius Server¬[³] »P Enterasys Controller³]©w ¨â­Ó³¡¤À¡A³v¨B»¡©ú¦p¦ó«Ø¸mÀô¹Ò¡C

¥Ü½dÀô¹Ò
Radius Server 192.168.33.40 Ubuntu 14.04
Enterasys Controller 192.168.33.37 Version:8.32.10


  • ¬[³]Radius Server
    ¥HUbuntu 14.04¬°«Ø¸mRadius ServerÀô¹Ò¡A¦w¸ËRadius Server«ü¥O¦p¤U¡C
    apt-get install freeradius freeradius-utils

    ¦w¸Ë¦nFreeRadius«á¡A»Ý­n³]©w ¤¹³\ÅçÃÒªº«eºÝNAS¸Ë¸m »P ±b¸¹ÅçÃҤ覡 ¨â­Ó³¡¥÷¡C

    ¤¹³\ÅçÃÒªº«eºÝNAS¸Ë¸m ³]©wÀɬO /etc/freeradius/clients.conf¡C
    ©ó³]©wÀɤ¤¥[¤J¤¹³\ªº«eºÝNAS¸Ë¸mªºIP¤ÎShared Secret Key¡A¥H¥Ü½dÀô¹Ò¨Ó»¡´N¬O­n¥[¤JControllerªºIP 192.168.33.37¡C
    client 192.168.33.37 {
        secret = testing123
        shortname = Wireless-Controller
    }


    ±µµÛ´N¥i¥H¶i¦æ ±b¸¹ÅçÃҤ覡 ³o­Ó³¡¤Àªº³]©w¡C
    ¥HFreeRadius¨Ó»¡¡A¥¦°£¤F¤ä´©Ubuntu¥»¨­ªº±b/±KÅçÃÒ(System)¡A
    ¤]¥i¥H½s¿èRadius¦Û¤vªº±b¸¹/±K½X¨Ó´£¨ÑÅçÃÒ(Local)¡A
    ¥t¥~ÁÙ¥i¥H³z¹LLDAPªº±b/±K¸ê°T¨ÓÅçÃÒ(LDAP)¡C
    ¥»¤å±N¥H System ¤Î Local ³o¨âºØ¤è¦¡¨Ó°µ¥Ü½d¡C

    1. ¥HUbuntu¥»¨­ªº±b/±KÅçÃÒ(System)¨ÓÅçÃÒ
      ­n¥HUbuntu¥»¨­¨t²Îªº±b¸¹±K½X¨Ó°µÅçÃÒ¡A§Ú­Ì»Ý­n¥h½s¿è /etc/freeradius/users ÀɮסAµM«á¥[¤J¥H¤U³]©w¡C
      DEFAULT Auth-Type = System


      ¥Ñ©óFreeRadiusªº°õ¦æ±b¸¹¬O freerad¡A¦Ó¦¹±b¸¹¬°¤@¯ëÅv­­±b¸¹¡A
      ©Ò¥H¨S¦³Åv­­Åª¨ú¨t²Î±K½XÀÉ /etc/shadow¡AµLªk¶i¦æ±K½Xªº½T»{¤u§@¡A
      ¦]¦¹­n½á¤© freerad ¥i¥HŪ¨ú /etc/shadow ªºÅv­­¡A«ü¥O¦p¤U¡C
      chgrp freerad /etc/shadow
      chmod g+r /etc/shadow

      ­×§ïÅv­­«á¡A¥i³z¹L«ü¥O¨ÓÀ˵ø /etc/shadow ªºÅv­­¡C
      ls -l /etc/shadow
      -rw-r----- 1 root freerad 1145 Apr 23 13:42 /etc/shadow

      µM«á­«±Ò freeradius ªºªA°È¡AÅý³]©w¥Í®Ä¡C
      service freeradius restart


      ¦bUbuntu¥»¾÷ªº±b¸¹ºÞ²z¤W¡A½Ð¨Ï¥Î adduser/deluser ¦Ó¤£¬O useradd/userdel ¨Ó¶i¦æ¡C
      ³o¨â²Õ«ü¥O¶¡ªº¤£¦P¡A¦b©ó useradd ¬O¤ñ¸û©³¼hªº±b¸¹ºÞ²z¡C
      ³z¹L useradd «Ø¥ßªº±b¸¹ÁöµM¤@¼Ë¥i¥Hµn¤J¨t²Î¡A
      ¦ý¬O¤£·|«Ø¥ß®a¥Ø¿ý¡A¤]¤£·|¦b /etc/shadow ¤¤²£¥Í½s½X¹Lªº±K½X¡A
      ©Ò¥HµLªkÅýFreeRadius¨Ó¶i¦æ±b±KªºÅçÃÒ¡C

      ¦Ó adduser ªº±b¸¹«Ø¥ß¤è¦¡¡A·|²£¥ÍUbunutÀô¹Ò¤U¨Ï¥ÎªÌ§¹¾ãªºÀô¹Ò³]©w¡A
      ¥]§t¥þ¦W¡B®a¥Ø¿ý¸ô®|»P¹w³]¸ê®Æ¤Î±K½Xµ¥¡C
      ¥H³oºØ¤è¦¡©Ò«Ø¥ßªºuser±b¸¹´N¯à´£¨ÑFreeRadius¨Ó¶i¦æ±b±KÅçÃÒ¡C


      ¡ôuseradd »P adduser ¦b«Ø¥ß±b¸¹®Éªº®t²§¡C


      ¡ô/etc/shadow¤¤¡A¥Î useradd »P adduser ©Ò«Ø¥ß±b¸¹ªº®t²§¡C

      ¦b´ú¸Õ¥»¾÷System»{ÃҮɡA¶¶¤l¦b³oÃä¦Y¤FÂI­WÀY¡A¥d¤F¤£¤Ö®É¶¡¡C
      ¤À¨Éµ¹¤j®a¡A§Æ±æ¤j®a¤£­n¦A¹J¨ì¬Û¦Pªº§xÂZ¡C

      useradd »P adduser ªº®t²§¡A½Ð°Ñ¦Ò¥H¤U³sµ²
      What is the difference between adduser and useradd?


    2. ¥HRadius¦Û¤vªº±b¸¹/±K½X¨Ó´£¨ÑÅçÃÒ(Local)
      ¥HRadius¦Û¤vªº±b¸¹°µÅçÃÒ¬O¤@¼Ë¬O³z¹L½s¿è /etc/freeradius/users ªº³]©w¨Ó¹F¦¨¡C
      §Ú­Ì¥i¦b /etc/freeradius/users Àɮפ¤¨Ì»Ý­n¨Ó«Ø¥ß¨Ï¥ÎªÌªº±b¸¹¤Î±K½X¡C(±K½X¬O©ú¤åªº¡A«D¥[±K)
      ¨Ò¦p¥[¤Jtest»Pshunze¨â­Ó±b¸¹¡A±K½X¤À§O¬Otesting»Ppassword¡A¨ä³]©w¦p¤U¡C
      test Cleartext-Password := "testing"
      shunze Cleartext-Password := "password"

      ³]©w¦n«á¡A­«±ÒFreeRadius´N¥i¥HÅýRadius¥»¨­ªº±b±KÅçÃҥͮġC
      service freeradius restart

      ­n­«±ÒFreeRadiusªA°È¡H
      ¬Oªº¡A¨S¿ù¡A¥Ñ©ó³]©wÀɦb¸ü¤J«á´N¤£¦AŪ¨ú¡A
      ¦]¦¹³z¹L³oºØLocal±b¸¹ªº¤è¦¡¡A¨C·s¼W©Î§R°£±b¸¹¡A´N»Ý­n­«±ÒFreeRadiusªA°È¡C


    3. System¥[Local½Æ¦X»{ÃÒ
      ¬JµMFreeRadius¤ä´©System»PLocal¨âºØÅçÃҤ覡¡A
      ¯à§_¨âºØ¨Ö¥Î¡A©óSystem§ä¤£¨ì¹ïÀ³±b¸¹®É¡A¦A¥hLocal»{ÃÒ¡H

      ¥i¥Hªº¡A¤@¼Ë½s¿è /etc/freeradius/users ÀɮסA
      µM«á¥[¤J Fall-Through = Yes ©ó DEFAULT Auth-Type := System «á¨ÃÁY±Æ¡A§Y¥i¹F¦¨¡C
      DEFAULT Auth-Type := System
          Fall-Through = Yes
      test Auth-Type:=Local, Cleartext-Password := "password"
      shunze Auth-Type:=Local, Cleartext-Password := "password"


    FreeRadius´ú¸Õ
    FreeRadiusªº±b¸¹ÅçÃҤ覡³]©w¦n«á¡A¥i¥HµÛ¤â¶i¦æ¥»¾÷´ú¸Õ¤F¡C
    ¦]¬°¦b clients.conf ³]©wÀɤ¤¡A¹w³]¦³client localhost°Ï¬q¡A©Ò¥H¦b¥»¾÷¤W¥i¥H°µÅçÃÒ´ú¸Õ¡C

    ©óUbuntu¥»¾÷¤¤¤U¹F radtest «ü¥O¤Î°Ñ¼Æ§Y¥i¶i¦æ´ú¸Õ¡A«ü¥O»P°Ñ¼Æ¦p¤U¡C
    radtest ±b¸¹ ±b¸¹ªº±K½X localhost port secret-key

    ´ú¸Õ¦¨¥\¡A·|±o¨ì Access-Accept ªº°T®§¡F
    ´ú¸Õ¥¢±Ñ¡A«h¬O Access-Reject ªº°T®§¡AµM«á¶}©l¥h°£¿ù§a¡C

    ¥Htest±b¸¹»P±K½Xpassword¥h´ú¸Õ¡A¥¿½Tªº¸Ü·|¬O¦p¤U°T®§¡C
    radtest test password localhost 0 testing123
    Sending Access-Request of id 172 to 127.0.0.1 port 1812
    User-Name = "test"
    User-Password = "password"
    NAS-IP-Address = 192.168.33.40
    NAS-Port = 0
    Message-Authenticator = 0x00000000000000000000000000000000
    rad_recv: Access-Accept packet from host 127.0.0.1 port 1812, id=172, length=20


    FreeRadius Debug
    ¸U¤@´ú¸Õ¥¢±Ñ¡A°£¤F¥i©ó /var/log/freeradius/radius.log ¤¤§ä½u¯Á¥~¡A
    ÁÙ¥i¥H°±¤îFreeRadiusªA°È¡AµM«á¶}±ÒDebug¼Ò¦¡¡A¥H¥þ°T®§ªº¤è¦¡°»¿ù¡C
    service freeradius stop
    freeradius -X


  • Enterasys Controller³]©w
    «áºÝRadius Serverªº³¡¤À³]©w¦n¤F¡A±µµÛ´N¨Ó¬Ý¬Ý«eºÝNAS­n¦p¦ó³]©w¡C
    ¥HEnterasys Wifi¬[ºc¨Ó»¡¡A°£¤F¤@¯ëªºµL½u³]©w¥~¡A«ØºcRadiusÅçÃÒ¦³¨â­Ó­«ÂI­n¯S§Oª`·N¡A
    ¤À§O¬O VNS¥²»ÝL3ªºTopology¬[ºc¡B°w¹ïÅçÃҤΥ¼ÅçÃÒªºRole³]©w¤£¦PPolicy(Åý¥¼ÅçÃÒªºRole¯à±j­¢¾É¦VÅçÃÒ­¶­±)¡C


    ¬JµM¬ORadiusÅçÃÒ¡A­º¥ý§Ú­Ì¥ý¨ìController¤¤ªº VNS Configuration / Global / Authentication ¤¤·s¼W¤@µ§Radius Server°O¿ý§a¡C



    Radius IP´N¥´¥Ü½dÀô¹Ò¤¤ªºFreeRadius IP 192.168.33.40¡A
    Shared Secret´N¥´FreeRadius¤¤³]©wªº testing123¡A¨ä¾l³]©w±Ä¹w³]­È§Y¥i¡C




    ¦b¨Ï¥ÎªÌªºÅçÃÒ¾÷¨î¤W¡A¬O³z¹LHTTPªº±j­¢¾É¦V¡A§â©|¥¼ÃÒÃÒªº¨Ï¥ÎªÌ¾É¦V»{ÃÒ­¶­±¡C
    ¥Ñ©ó¦¹»{ÃÒ¤u§@¥²»Ý¦bController¤W¶i¦æ¡A¥¼»{ÃÒªº¨Ï¥ÎªÌ¬y¶q¥²»Ý¸g¹LController¡A
    ©Ò¥H¦bTopologyªº¿ï¾Ü¤W¡A·f°tRadiusÅçÃÒ¾÷¨î®É¡A¥u¯à¿ï¥ÎL3ªºTopolgoy¡C
    ¦Ü©ó­n¥ÎBridge@Controller(L3)©ÎRouted Mode¡A¨âªÌ³£¥i¥H¡F
    ¦Ó¤w¸gÅçÃÒ¹Lªº¨Ï¥ÎªÌ«hµL¦¹­­¨î¡A­n¥ÎBridge@AP(L2)¡BBridge@Controller(L2/L3)©ÎRouted Mode³£¦æ¡AÀH§A°ª¿³¡C

    ¦b¥»½d¨Ò¤¤¡A¶¶¤l°t¸m¤F¨â­ÓTopology¡A
    ¤@­Ó¬OGuest_Vlan18¡A¨Ï¥Î¤FBridge@Controller(L3)¡Aµ¹©|¥¼ÅçÃÒªºRole¥Î¡F
    ¥t¤@­Ó«h¬OGuestTopology¡A¨Ï¥Î¤FBridge@AP(L2) ¡A´£¨Ñµ¹¤w¸gÅçÃÒ¹LªºRole¨Ó¨Ï¥Î¡A
    ÅçÃÒ¹Lªº¨Ï¥ÎªÌ¬y¶q¤£¦A¸g¹LController¡A´£¤É®Ä²v¡C





    Topolgoy«Ø¦n«á¡A±µ§âÅçÃÒ»P¥¼ÅçÃÒ¨¤¦â¤À§O®M¥Î¨ìL2»PL3ªºTopology¡C


    ¡ôÅçÃÒ¹LªºRole·f°tL2ªºGuestTopology¡C


    ¡ô¥¼ÅçÃÒ¹LªºRole·f°tL3ªºGuest_Vlan18¡C

    ¤wÅç¹LªºRole¨äpolicy¥i¥H¥þ¶}¡A©Î¨Ì¹ê»Ú»Ý¨D¨Ó½Õ¾ã¡F
    ¦ý¥¼ÅçÃÒ¹LªºRole°£¤FDNS¡ADHCPªA°È¥²»Ý¶}©ñ¥~¡A§Ú­Ì¥²»Ý§â¨ä¥¦¹ï¥~³s½u«Êªý¡A
    ³o¼Ë¤~¯à±j­¢¨Ï¥ÎªÌ¾É¦VControllerªº»{ÃÒ­¶­±Captive Portal¡A
    ³o¬O¾ã­ÓÅçÃÒ¾÷¨î¤¤«Ü­«­nªº¤@Àô¡A
    ¤Ö¤F³o³¡¤À¡AHTTPªº±j­¢¾É¦V»{ÃÒ´N¤£·|¶i¦æ¡ARadiusªºÅçÃÒ¾÷¨î¤]´N¥¢±Ñ¤F¡C


    ¡ô¤Ö¤F³o¤@µ§ dest -> none 0.0.0.0/0 deny ¥i¬O¨S¦³±j­¢»{ÃÒªº®ÄªG³á¡I


    ±µµÛ·s¼W¤@­ÓWLAN - GuestNew¡A³]©wTopology¬°Bridge@Controller(L3) - Guest_Vlan18¡C



    µM«á¦b Auth & Acct ¤¤±Ò¥ÎÅçÃÒ¡A±NMode¿ï¬°Internal (³z¹LController¥»¨­ªºCaptive Portal¨Ó»{ÃÒ)¡A
    ¥[¤J­è¤~ªºRadius Server°O¿ý¡C



    ¥[¤JRadius Server°O¿ý«á¡A¤]¥i¥H¦b Auth & Acct ¥\¯à­¶­±¤¤¹ïRadiusÅçÃÒ¶i¦æ´ú¸Õ¡A
    µo§G¤§«e³Ì¦n¥ý½T»{RadiusªºÅçÃÒ¾÷¨î¥¿½TµL»~¡C






    VNS¤¸¥ó³£³]©w¦n¤F¡A±µµÛ´N«Ø¥ß¤@­ÓVNS¡A§âWLANh»PRoleÃöÁp°_¨Ó§a¡ã




    ³]©w¨ì¦¹¡A°ò¥»¤W´N§¹¦¨¤F¡A§Ú­Ì¨Ó³s½u°µ­Ó´ú¸Õ§a¡C
    ³z¹LSSID³s½u«á¡AÀH«K¶}¤@­Óºô­¶¡A³£·|³Q¾É¨ìControllerªºCaptive Portal¡C



    ¿é¤JRadius¤¤ªº±b¸¹/±K½X¶i¦æµn¤J¡A¦¨¥\«á·|¦³ÅçÃÒ¦¨¥\ªº°T®§µe­±¡C





    ¤wÅçÃÒ¹Lªº¨Ï¥ÎªÌ´N¥i¥H¥¿±`¤WºôÅo¡ã


    ¤°»ò¡Hı±oCaptive Portal«Ü¶§¬K¡H
    Captive Portalªº­¶­±¬O¥i¥H¦Û¦æ½Õ¾ãªº¡A¦bWLANªºAuthenticationùØ¡A«ö¤U¥hConfigureªº«ö¶s´N¥i¥H«È»s­¶­±­·®æ¡C
    ¦³¿³½ìªº¥i¥H¬ã¨s¬Ý¬Ý¡A³o³¡¤À´N¤£¦C¤J¥»¤åªº¤º®eÅo¡ã







°Ñ¦Ò¸ê®Æ
Freeradius ¬[³]¤ß±o°O­n
¬[³]RADIUS¦øªA¾¹¹ê°È
Getting Started with FreeRADIUS



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2015-04-23, 17:46 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nFreeRadius¾ã¦XOpenLDAP»{ÃҤޥΦ^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¤W¤å»¡¨ìFreeRadius¤ä´©¤FSystem¡BLocal¥H¤ÎLDAP¤TºØ¤è¦¡ªº±b¸¹¨Ó·½»{ÃÒ¡A
³o¤@½g´N¨Ó¬Ý¬Ý¦p¦ó¦bFreeRadius¤W¾ã¦XLDAP¨Ó´£¨ÑclientºÝ¸Ë¸m¶i¦æ»{ÃÒ¡C

  • ¦w¸ËOpenLDAP
    ©óUbuntu 14¤W¦w¸ËOpenLDAP«ü¥O¦p¤U¡C
    apt-get install slapd ldap-utils

    ¦w¸Ë®É·|­n¨D¿é¤Jadministratorªº±K½X¡A³o³¡¤À¤£¥Î¤Ó¦b·N¡F¦]¬°¸Ë¦n«á¡AÁÙ¬O­n­«·s³]©wLDAP²ÕºA¡C

    ­«·s³]©wLDAP²ÕºA«ü¥O¤U¡C
    dpkg-reconfigure slapd

    ­«³]²ÕºA®É¡A·|±Ä¸ß°Ý¦¡ªº¤è¦¡¨Ó³]©w²ÕºA¡A¥i°Ñ¦Ò¥H¤Uªº¶µ¥Ø³]©w­È¨Ó¶i¦æ¡C
    1. Omit OpenLDAP server configuration? No
    2. DNS domain name: ¿é¤J±zªºLDAP domain¡A¨Ò¦p demo.com
    3. Organization name: ¿é¤J±zªº²Õ´¦WºÙ¡A¨Ò¦p test
    4. Administrator password: ¿é¤JºÞ²z±b¸¹ªº±K½X¡C
    5. Confirm password: ¦A¿é¤J¤@¦¸ºÞ²z±b¸¹ªº±K½X¡A¶i¦æ½T»{¡C
    6. Database backend to use: HDB
    7. Do you want the database to be removed when slapd is purged? No
    8. Move old database? Yed
    9. Allow LDAPv2 protocol? No

    ³]©w§¹«á´N¥i¥H¥Î§A¼ô±xªº¤u¨ã¨Ó«Ø¸mLDAP¤WªºOU¡BGroup¥H¤ÎUser Account¤F¡C

    ­Y¤£¼ô±xLDAP¡A¶¶¤l±ÀÂˤ@´ÚWindows¤U§K¶O¡B§K¦w¸ËªººÞ²z¤u¨ã - LdapAdmin










  • FreeRadius¾ã¦XOpenLDAP»{ÃÒ
    OpenLDAP¸Ë¦n«á¡A±µµÛ´N¨Ó¬Ý¬Ý¦p¦ó¦bFreeRadius¤W¾ã¦XOpenLDAP§a¡ã

    ­º¥ý¦w¸ËFreeRadiusªºLDAP®M¥ó¡A«ü¥O¦p¤U¡C
    apt-get install freeradius-ldap


    µM«á³v¨B³]©wLDAPªº¬ÛÃö³]©w¡C
    1. ­×§ïFreeRadiusªºLDAP¼Ò²Õ¤º®e /etc/freeradius/modules/ldap¡A
      #©ó¥H¤Uldap°Ï¬q¤¤¡A­×§ï¥H¤U¤º®e
      ldap {
          server = "127.0.0.1"
          identity = "cn=admin,dc=demo,dc=com"
          password = adminªº±K½X
          basedn = "dc=demo,dc=com"
          filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
          ...
          ...
          set_auth_type = yes
          ...
      }


    2. ­×§ï /etc/freeradius/sites-available/default »P /etc/freeradius/sites-available/inner-tunnel ªº¤º®e¡A
      ¨âªÌ­n­×§ïªº¤º®e¬Û¦P¡A´N©ñ¦b¤@°_¬Ý§a¡ã
      #©óauthorize°Ï¬q¤¤¡A§âldapªº³¡¤À¨ú®øµù¸Ñ¡C
      authorize {
          ...
          ldap
          ...
      }

      #©óauthenticate°Ï¬q¤¤¡A§âldapªº³¡¤À¨ú®øµù¸Ñ¡C
      authenticate {
          ...
          Auth-Type LDAP {
              ldap
          }
          ...
      }


    3. ­×§ï /etc/freeradius/users¡AÅýFreeRadiusªº»{ÃÒ«ü¦VOpenLDAPªºdomain¡C
      DEFAULT Ldap-Group == "cn=admin,dc=demo,dc=com"


    LDAPªº¬ÛÃö³]©w¥[¤J«á¡A±µµÛ´N¥i¥H¶i¦æRadiusªº´ú¸Õ¡C
    radtest ±b¸¹ ±b¸¹ªº±K½X localhost port secret-key

    ´ú¸Õ¦¨¥\¡A·|±o¨ì Access-Accept ªº°T®§¡F
    ´ú¸Õ¥¢±Ñ¡A«h¬O Access-Reject ªº°T®§¡A³o¨Ç¸ò¤W¤åªº´ú¸Õ¬O¬Û¦P¡C




  • ClientºÝ­n°t¦Xªº­×§ï
    ¦bFreeRadius·f°tOpenLDAPªº¬[ºc¤¤¡A¦b /etc/freeradius/modules/ldap ªº³]©wÀɦ³´£¨ì¡A
    ³z¹LLDAPªº»{ÃÒ¡A¥u¯à±µ¨ü©ú½Xªº¶Ç¿é¡C



    ©Ò¥H¦bClientºÝªº³]©w¤W¡AÅçÃÒªº¤è¦¡¤]­n¿ï¾Ü¬°PAPªº¤è¦¡¡C



    ­Y¬O¿ï¾Ü¤FCHAPªº»{ÃҤ覡¡A·|¾É­P¦s¨ú³Q©ÚACCESS_REJECTED¡C




°Ñ¦Ò¸ê®Æ
Configure ISC DHCP Server with OpenLDAP
Configure Radius with LDAP for network authentication
CONFIGURING FREERADIUS FOR LDAP OVER SSL AUTHENTICATION



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2015-04-28, 18:29 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
  « ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD »
µoªí·s¥DÃD µoªí¦^ÂÐ
¸õ¨ì:

Powered by: Burning Board 1.1.1 2001 WoltLab GbR