PDA

View Full Version : Hotspotzz Great New Feature, but Bug in Radius


sploit
09-09-2003, 01:12 AM
Hey, I have installed the new version of Station Router with Hotspotzz support on a test wiress Access Point, and Connected, and I must say it is a great new feature!

I am only using the built in radius server right now, but I noticed a problem, and that is that the Radius Server will die if there is not this much space "..................." before each line after the password.

EXAMPLE Below

00:02:dd:33:97:95 Auth-Type := Local, User-Password == "00:02:dd:33:97:95"
Framed-IP-Address = 10.0.0.10,
MS-Primary-DNS-Server = 206.13.31.12,
MS-Secondary-DNS-Server = 206.13.28.12,
VNC-PPPoE-CBQ-RX = 256000,
VNC-PPPoE-CBQ-TX = 256000


It really wierd, because if you remove the space it stops the radius server. I can replicate this problem and show it to ya lonnie if ya like.

Anyways, Other than that I have a few questions about Hotspotzz.

Since it connects to verify though radius, it has the option to check against macaddress listed user authentication first, and then if that fails it will bring up a login page. I love this feature because of the Framed IP address will stop people from changing their IP address to aquire more bandwidth.

My questions are, can it check multiple radius servers, if one fails?

The sole purpose of this is to allow customers to try to authenticate to our primary radius servers first, then Try a secondary if that one is down, and then Try some partners if the mac address is not found (for static customers).

Their are several networks, (AuthDirect, Hotspottz, Airpath, etc...) that We can try to authenticate with, it would be cool if they could select what Kind of customer they were with the Login page, and then logon with their userID based upon the network.

I think the hotspottz already does this, but im not sure?

I havnt played around with it too much.

This is cool that this is now available, as We will be installing hundreds of your Boxes in places :D

Infact, I have a few orders to place tommorow with ya Lonnie :)
It's way overdue, and we were awaiting this feature before we deployed.

You guys are awesome!

O, PS

A Webpage Administration would be awesome to manager customers in the radius database, etc...
The AP 1000's have software to do this...

I am going to have a good few 100 servers to manage here pretty soon, it would be nice to be able to have a way to easily manage them all :P

thalaiva
09-09-2003, 06:56 AM
check against macaddress listed user authentication first,

Problem that we face ...

In the newer OS's MAC Address can be spoofed. I too did not beleive it until I checked and verified the same. :( Any idea how that can be beaten??

tony
09-09-2003, 07:54 AM
The only realy way around this problem is to avoid MAC-level authentication, and stick with username and password. If somebody on your networks spoofs their MAC address, this will cause more problems than not, if the original user is online as well.

tony
09-09-2003, 07:59 AM
sploit,

Glad you enjoy the new feature. Our implementation is not Hotspotzz, however we do provide Hotspotzz for those who wish to provide nation-wide roaming abilities.

The radius server does need one space before each attribute. If you wish to comment out a line, there must not be any spaces before the '#'.

We are working towards a Web-based user manager, which is our project for September.

You can specify up to 5 radius and accounting servers in the radius configuration file.

There are more authentication features in testing, and should be ready very soon.

Thanks!

lonnie
09-09-2003, 09:09 AM
There is an O'Reiley book on Radius, actually it uses FreeRadius as its example.

Paperback: 206 pages ; Dimensions (in inches): 0.54 x 9.20 x 7.02
Publisher: O'Reilly & Associates; (October 2002)
ISBN: 0596003226

It highly recommended - hey I'm going to start a Book Forum.

sploit
09-09-2003, 10:54 PM
You know whats funny about lonnie, is you know he actually took the time to find a measuring tape to measure the dimensions of this book.. :lol:

georgew
09-09-2003, 11:03 PM
I dunno... I think he used a micrometer...

lonnie
09-09-2003, 11:55 PM
Thanks to Amazon for the summary.