HELP!!! И снова наступаю на старые грабли

Ответить
andre13161
Сообщения: 30
Зарегистрирован: Вс сен 26, 2010 11:42 pm

HELP!!! И снова наступаю на старые грабли

Сообщение andre13161 »

Всем привет.
Уже несколько дней долблюсь с установкой билинга на новую машыну
Опишу свои проблемы
1.Скорость режется только через RADIUS Parameters в тарифном плане и никак не реагирует на параметр скорости который выставляется при настройке клиента.
в RADIUS Parameters пишу

Код: Выделить всё

mpd-limit+=in#1=all rate-limit 512000 64000 128000,
mpd-limit+=out#1=all rate-limit 1024000 192000 384000
Так скорость режет без проблем

2. Какой то трабл с правилами

ipfw show

Код: Выделить всё

00010  9874  3059110 netgraph 1 ip from 172.12.0.0/16 to not 10.0.0.1 via ng* in
00050 11414  8159806 netgraph 23 ip from any to any via bge0 in
00100  1178   216024 allow ip from any to any via lo0
00200     0        0 deny ip from any to 127.0.0.0/8
00300     0        0 deny ip from 127.0.0.0/8 to any
08801     0        0 fwd 127.0.0.1,80 tcp from table(32) to any dst-port 80 via ng*
08811     0        0 allow ip from table(32) to 178.210.128.3 dst-port 53 via ng*
08811     0        0 allow ip from table(32) to 178.210.128.5 dst-port 53 via ng*
08831     0        0 deny ip from table(32) to any via ng*
09970     0        0 skipto 10130 ip from table(14) to table(3) in recv ng
09975     0        0 skipto 10135 ip from table(3) to table(15) out xmit ng
09980     0        0 skipto 10120 ip from table(12) to table(2) in recv ng
09985     0        0 skipto 10125 ip from table(2) to table(13) out xmit ng
10000     0        0 netgraph tablearg ip from table(10) to any in recv ng
10010     0        0 netgraph tablearg ip from any to table(11) out xmit ng
10020     0        0 allow ip from table(9) to any in recv ng
10025     0        0 allow ip from any to table(9) out xmit ng
10120     0        0 netgraph tablearg ip from table(12) to any in recv ng
10125     0        0 netgraph tablearg ip from any to table(13) out xmit ng
10130     0        0 netgraph tablearg ip from table(14) to any in recv ng
10135     0        0 netgraph tablearg ip from any to table(15) out xmit ng
10220     0        0 allow ip from table(9) to table(2) in recv ng
10225     0        0 allow ip from table(2) to table(9) out xmit ng
10230     0        0 allow ip from table(9) to table(3) in recv ng
10235     0        0 allow ip from table(3) to table(9) out xmit ng
65535 24470 12993341 allow ip from any to any
Использую фильтр негативного депозита RAD:mpd-table-static="32=%IP%"
Но при подключении пользывателя з негативным депозитом он ходит в интернет без проблем и обрывов сесий нету.
При подключении не попадает в table(32)
правила перенаправления

Код: Выделить всё

08801     0        0 fwd 127.0.0.1,80 tcp from table(32) to any dst-port 80 via ng*
08811     0        0 allow ip from table(32) to 178.210.128.3 dst-port 53 via ng*
08811     0        0 allow ip from table(32) to 178.210.128.5 dst-port 53 via ng*
теперь немножко по системных параметрах и пакетах
uname -a

Код: Выделить всё

FreeBSD nas1.prostir.loc 8.3-RELEASE FreeBSD 8.3-RELEASE #0: Sun Feb 10 17:11:02 UTC 2013     admin@localhost:/usr/obj/usr/src/sys/ROUTER  i386
pkg_info | less

Код: Выделить всё

apache22-2.2.23_4   Version 2.2.x of Apache web server with prefork MPM.
apr-1.4.6.1.4.1_3   Apache Portability Library
autoconf-2.69       Automatically configure source code on many Un*x platforms
autoconf-wrapper-20101119 Wrapper script for GNU autoconf
automake-1.12.6     GNU Standards-compliant Makefile generator
automake-wrapper-20101119 Wrapper script for GNU automake
bdftopcf-1.0.3      Convert X font from BDF to PCF
bigreqsproto-1.1.1  BigReqs extension headers
bison-2.5.1,1       A parser generator from FSF, (mostly) compatible with Yacc
bitstream-vera-1.10_5 Bitstream Vera TrueType font collection
cairo-1.10.2_5,2    Vector graphics library with cross-device output support
cmake-2.8.9         A cross-platform Makefile generator
cmake-modules-2.8.9 Modules and Templates for CMake
db42-4.2.52_5       The Berkeley DB package, revision 4.2
encodings-1.0.4,1   X.Org Encoding fonts
expat-2.0.1_2       XML 1.0 parser written in C
font-bh-ttf-1.0.3   X.Org Bigelow & Holmes TTF font
font-misc-ethiopic-1.0.3 X.Org miscellaneous Ethiopic font
font-misc-meltho-1.0.3 X.Org miscellaneous Meltho font
font-util-1.2.0     Create an index of X font files in a directory
fontconfig-2.9.0,1  An XML-based font configuration API for X Windows
fontsproto-2.1.1    Fonts extension headers
freeradius-2.2.0    A free RADIUS server implementation
freetype2-2.4.11    A free and portable TrueType font rendering engine
gamin-0.1.10_4      A file and directory monitoring system
gdbm-1.9.1          The GNU database manager
gettext-0.18.1.1    GNU gettext package
gio-fam-backend-2.28.8_1 FAM backend for GLib\'s GIO library
glib-2.28.8_5       Some useful routines of C programming (current stable versi
gmake-3.82_1        GNU version of 'make' utility
gobject-introspection-0.10.8_3 Generate interface introspection data for GObject libraries
help2man-1.41.1     Automatically generating simple manual pages from program o
inputproto-2.0.2    Input extension headers
intltool-0.41.1     Tools to internationalize various kinds of data files
jpeg-8_4            IJG's jpeg compression utilities
kbproto-1.0.5       KB extension headers
libX11-1.4.4,1      X11 library
libXau-1.0.6        Authentication Protocol library for X11
libXdmcp-1.1.0      X Display Manager Control Protocol library
libXfont-1.4.4_1,1  X font library
libXft-2.1.14       A client-sided font API for X applications
libXrender-0.9.6    X Render extension library
libcheck-0.9.9      A unit test framework for C
libffi-3.0.11       Foreign Function Interface
libfontenc-1.1.0    The fontenc Library
libgcrypt-1.5.0_1   General purpose crypto library based on code used in GnuPG
libgpg-error-1.10   Common error values for all GnuPG components
libiconv-1.14       A character set conversion library
libltdl-2.4.2       System independent dlopen wrapper
libmcrypt-2.5.8     Multi-cipher cryptographic library (used in PHP)
libpthread-stubs-0.3_3 This library provides weak aliases for pthread functions
libslang2-2.2.4_4   Routines for rapid alpha-numeric terminal applications deve
libtool-2.4.2       Generic shared library support script
libxcb-1.7          The X protocol C-language Binding (XCB) library
libxml2-2.7.8_5     XML parser library for GNOME
libxslt-1.1.28      The XSLT C library for GNOME
m4-1.4.16_1,1       GNU m4
mc-4.8.1.7          Midnight Commander, a free Norton Commander Clone
mkfontdir-1.0.6     Create an index of X font files in a directory
mkfontscale-1.0.9   Creates an index of scalable font files for X
mpd-5.6             Multi-link PPP daemon based on netgraph(4)
mysql-client-5.1.68 Multithreaded SQL database (client)
mysql-server-5.1.68 Multithreaded SQL database (server)
oniguruma-4.7.1     A BSDL Regular Expressions library compatible with POSIX/GN
p5-DBD-mysql51-4.021 MySQL 5.1 driver for the Perl5 Database Interface (DBI)
p5-DBI-1.623        The perl5 Database Interface.  Required for DBD::* modules
p5-Digest-MD5-2.52  Perl5 interface to the MD5 algorithm
p5-Locale-gettext-1.05_3 Message handling functions
p5-Module-Build-0.4003 Build and install Perl modules
p5-RRD-Simple-1.44_5 Simple interface to create and store data in RRD files
p5-Time-HiRes-1.9725,1 A perl5 module implementing High resolution time, sleep, an
p5-XML-Parser-2.41_1 Perl extension interface to James Clark's XML parser, expat
pango-1.28.4_1      An open-source framework for the layout and rendering of i1
pcre-8.32           Perl Compatible Regular Expressions library
pdflib-7.0.5_2      A C library for dynamically generating PDF
pecl-APC-3.1.14_1   Alternative PHP Cache
pecl-pdflib-2.1.9   A PECL extension to create PDF on the fly
perl-5.14.2_2       Practical Extraction and Report Language
php5-5.4.11         PHP Scripting Language
php5-bz2-5.4.11     The bz2 shared extension for php
php5-ctype-5.4.11   The ctype shared extension for php
php5-filter-5.4.11  The filter shared extension for php
php5-gd-5.4.11      The gd shared extension for php
php5-json-5.4.11    The json shared extension for php
php5-mbstring-5.4.11 The mbstring shared extension for php
php5-mcrypt-5.4.11  The mcrypt shared extension for php
php5-mysqli-5.4.11  The mysqli shared extension for php
php5-openssl-5.4.11 The openssl shared extension for php
php5-session-5.4.11 The session shared extension for php
php5-zip-5.4.11     The zip shared extension for php
php5-zlib-5.4.11    The zlib shared extension for php
phpMyAdmin-3.5.6    A set of PHP-scripts to manage MySQL over the web
pixman-0.24.2       Low-level pixel manipulation library
pkgconf-0.8.9       Utility to help to configure compiler and linker flags
png-1.5.14          Library for manipulating PNG images
python27-2.7.3_6    An interpreted object-oriented programming language
renderproto-0.11.1  RenderProto protocol headers
rrdtool-1.4.7_2     Round Robin Database Tools
xcb-proto-1.7.1     The X protocol C-language Binding (XCB) protocol
xcb-util-0.3.9_1,1  A module with libxcb/libX11 extension/replacement libraries
xcb-util-renderutil-0.3.8 Convenience functions for the Render extension
xcmiscproto-1.2.1   XCMisc extension headers
xextproto-7.2.0     XExt extension headers
xf86bigfontproto-1.2.0 XFree86-Bigfont extension headers
xorg-fonts-truetype-7.5.1 X.Org TrueType fonts
xorg-macros-1.16.1  X.Org development aclocal macros
xproto-7.0.22       X11 protocol headers
xtrans-1.2.6        Abstract network code for X

ядро

Код: Выделить всё

options         IPFIREWALL
options         IPFIREWALL_DEFAULT_TO_ACCEPT
options         IPFIREWALL_FORWARD
options         IPFIREWALL_VERBOSE
options         IPFIREWALL_VERBOSE_LIMIT=1000
options         IPFIREWALL_NAT

options         IPFILTER
options         IPSTEALTH

options         LIBALIAS
options         ROUTETABLES=2
options         DUMMYNET
options         DEVICE_POLLING
options         HZ="1000"
options         IPFILTER
options         IPFILTER_LOG
options         IPDIVERT

options         NETGRAPH
options         NETGRAPH_PPP
options         NETGRAPH_PPPOE
options         NETGRAPH_PPTPGRE
options         NETGRAPH_ETHER

#lissyara
options         NETGRAPH_IPFW
options         NETGRAPH_NAT
options         NETGRAPH_NETFLOW
options         NETGRAPH_SPLIT
options         NETGRAPH_ECHO
options         NETGRAPH_TEE
options         NETGRAPH_BPF
options         NETGRAPH_IFACE
options         NETGRAPH_KSOCKET
options         NETGRAPH_MPPC_ENCRYPTION
options         NETGRAPH_PPTPGRE
options         NETGRAPH_SOCKET
options         NETGRAPH_TCPMSS
options         NETGRAPH_VJC
/etc/rc.conf

Код: Выделить всё

hostname="nas1.prostir.loc"
defaultrouter="192.168.24.1"
ifconfig_bge0="inet 192.168.24.2 netmask 255.255.255.0"
ifconfig_bge1="inet 10.0.0.1 netmask 255.255.0.0"
ifconfig_lo0="inet 127.0.0.1"

sshd_enable="YES"

mysql_enable="YES"
apache22_enable="YES"
accf_http_load="YES"
radiusd_enable="YES"
mpd_enable="YES"
firewall_enable="YES"
gateway_enable="YES"
#firewall_nat_enable="YES"
#dummynet_enable="YES"

abills_shaper_enable="YES"
abills_nas_id="1"
abills_shaper_if="ng"  # По умолчанию ng

ngnat_enable="YES"
ngnat_aliasaddr1="192.168.24.2"


#webmin_enable="YES"
sendmail_enable="YES"


/usr/local/etc/mpd5/mpd.conf

Код: Выделить всё

startup:
        set global enable tcp-wrapper
        # configure the console
        set console self 127.0.0.1 5000
        set user nasuser qwerty admin
        set console open
        #WEB managment
        #set web self 0.0.0.0 5006
        #set web open
        #Netflow options
        #set netflow peer 127.0.0.1 9996
        #set netflow self 127.0.0.1 9990
        #set netflow timeouts 15 15
        #set netflow hook 9000
        #set netflow node netflow
        log -echo -radius -rep

default:
  load pppoe_server

pppoe_server:
        create bundle template C
        set iface idle 0
        set iface enable tcpmssfix proxy-arp
        set ipcp no vjcomp
        set iface up-script  "/usr/abills/libexec/linkupdown mpd up"
        set iface down-script "/usr/abills/libexec/linkupdown mpd down"
        set ipcp ranges 192.168.24.1 ippool pool1
        set ipcp dns 178.210.128.3 178.210.128.5

        create link template D pppoe
        set link action bundle C
        set link enable peer-as-calling
        set link enable report-mac
        set pppoe acname "Lan"
        set pppoe iface bge1
        set pppoe service "*"
        load server_common

server_common:
      set link no pap eap
      set link yes chap-md5
      set link keep-alive 30 120
      set link enable incoming
      set link no acfcomp protocomp
      load radius

radius:
     set radius server 127.0.0.1 mpd 1812 1813
     set radius config /etc/radius.conf
     set radius retries 3
     set radius timeout 10
     set auth acct-update 300
     set auth enable radius-auth
     set auth enable radius-acct
     set auth disable internal
Настройки радиуса скопировал как написано в мануале

Код: Выделить всё

cp /usr/abills/misc/freeradius/v2/radiusd.conf /usr/local/etc/raddb/radiusd.conf
rm /usr/local/etc/raddb/sites-enabled/*
cp /usr/abills/misc/freeradius/v2/users_perl /usr/local/etc/raddb/users
cp /usr/abills/misc/freeradius/v2/default_rlm_perl /usr/local/etc/raddb/sites-enabled/abills_default
cp /usr/abills/misc/freeradius/v2/perl /usr/local/etc/raddb/modules/

radiusd -X

Код: Выделить всё

FreeRADIUS Version 2.2.0, for host i386-portbld-freebsd8.3, built on Feb 10 2013 at 19:04:06
Copyright (C) 1999-2012 The FreeRADIUS server project and contributors.
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE.
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License v2.
Starting - reading configuration files ...
including configuration file /usr/local/etc/raddb/radiusd.conf
including configuration file /usr/local/etc/raddb/clients.conf
including files in directory /usr/local/etc/raddb/modules/
including configuration file /usr/local/etc/raddb/modules/wimax
including configuration file /usr/local/etc/raddb/modules/always
including configuration file /usr/local/etc/raddb/modules/attr_filter
including configuration file /usr/local/etc/raddb/modules/attr_rewrite
including configuration file /usr/local/etc/raddb/modules/cache
including configuration file /usr/local/etc/raddb/modules/chap
including configuration file /usr/local/etc/raddb/modules/checkval
including configuration file /usr/local/etc/raddb/modules/counter
including configuration file /usr/local/etc/raddb/modules/cui
including configuration file /usr/local/etc/raddb/modules/detail
including configuration file /usr/local/etc/raddb/modules/detail.example.com
including configuration file /usr/local/etc/raddb/modules/detail.log
including configuration file /usr/local/etc/raddb/modules/dhcp_sqlippool
including configuration file /usr/local/etc/raddb/sql/mysql/ippool-dhcp.conf
including configuration file /usr/local/etc/raddb/modules/digest
including configuration file /usr/local/etc/raddb/modules/dynamic_clients
including configuration file /usr/local/etc/raddb/modules/echo
including configuration file /usr/local/etc/raddb/modules/etc_group
including configuration file /usr/local/etc/raddb/modules/exec
including configuration file /usr/local/etc/raddb/modules/expiration
including configuration file /usr/local/etc/raddb/modules/expr
including configuration file /usr/local/etc/raddb/modules/files
including configuration file /usr/local/etc/raddb/modules/inner-eap
including configuration file /usr/local/etc/raddb/modules/ippool
including configuration file /usr/local/etc/raddb/modules/krb5
including configuration file /usr/local/etc/raddb/modules/ldap
including configuration file /usr/local/etc/raddb/modules/linelog
including configuration file /usr/local/etc/raddb/modules/otp
including configuration file /usr/local/etc/raddb/modules/logintime
including configuration file /usr/local/etc/raddb/modules/mac2ip
including configuration file /usr/local/etc/raddb/modules/mac2vlan
including configuration file /usr/local/etc/raddb/modules/mschap
including configuration file /usr/local/etc/raddb/modules/ntlm_auth
including configuration file /usr/local/etc/raddb/modules/opendirectory
including configuration file /usr/local/etc/raddb/modules/pam
including configuration file /usr/local/etc/raddb/modules/pap
including configuration file /usr/local/etc/raddb/modules/passwd
including configuration file /usr/local/etc/raddb/modules/perl
including configuration file /usr/local/etc/raddb/modules/policy
including configuration file /usr/local/etc/raddb/modules/preprocess
including configuration file /usr/local/etc/raddb/modules/radrelay
including configuration file /usr/local/etc/raddb/modules/radutmp
including configuration file /usr/local/etc/raddb/modules/realm
including configuration file /usr/local/etc/raddb/modules/redis
including configuration file /usr/local/etc/raddb/modules/rediswho
including configuration file /usr/local/etc/raddb/modules/replicate
including configuration file /usr/local/etc/raddb/modules/smbpasswd
including configuration file /usr/local/etc/raddb/modules/smsotp
including configuration file /usr/local/etc/raddb/modules/soh
including configuration file /usr/local/etc/raddb/modules/sql_log
including configuration file /usr/local/etc/raddb/modules/sqlcounter_expire_on_login
including configuration file /usr/local/etc/raddb/modules/sradutmp
including configuration file /usr/local/etc/raddb/modules/unix
including configuration file /usr/local/etc/raddb/modules/acct_unique
including configuration file /usr/local/etc/raddb/policy.conf
including configuration file /usr/local/etc/raddb/sites-enabled/abills_default
main {
        user = "freeradius"
        group = "freeradius"
        allow_core_dumps = no
}
including dictionary file /usr/local/etc/raddb/dictionary
main {
        name = "radiusd"
        prefix = "/usr/local"
        localstatedir = "/var"
        sbindir = "/usr/local/sbin"
        logdir = "/var/log"
        run_dir = "/var/run/radiusd"
        libdir = "/usr/local/lib/freeradius-2.1.6"
        radacctdir = "/var/log/radacct"
        hostname_lookups = no
        max_request_time = 30
        cleanup_delay = 5
        max_requests = 512000
        pidfile = "/var/run/radiusd/radiusd.pid"
        checkrad = "/usr/local/sbin/checkrad"
        debug_level = 0
        proxy_requests = no
 log {
        stripped_names = no
        auth = no
        auth_badpass = no
        auth_goodpass = no
 }
 security {
        max_attributes = 200
        reject_delay = 1
        status_server = yes
 }
}
radiusd: #### Loading Realms and Home Servers ####
radiusd: #### Loading Clients ####
 client 127.0.0.1 {
        require_message_authenticator = no
        secret = "qwerty"
        shortname = "localhost"
 }
radiusd: #### Instantiating modules ####
 instantiate {
 Module: Linked to module rlm_exec
 Module: Instantiating module "exec" from file /usr/local/etc/raddb/modules/exec
  exec {
        wait = no
        input_pairs = "request"
        shell_escape = yes
  }
 Module: Linked to module rlm_expiration
 Module: Instantiating module "expiration" from file /usr/local/etc/raddb/modules/expiration
  expiration {
        reply-message = "Password Has Expired  "
  }
 Module: Linked to module rlm_logintime
 Module: Instantiating module "logintime" from file /usr/local/etc/raddb/modules/logintime
  logintime {
        reply-message = "You are calling outside your allowed timespan  "
        minimum-timeout = 60
  }
 }
radiusd: #### Loading Virtual Servers ####
server { # from file /usr/local/etc/raddb/radiusd.conf
 modules {
  Module: Creating Auth-Type = Perl
  Module: Creating Post-Auth-Type = REJECT
 Module: Checking authenticate {...} for more modules to load
 Module: Linked to module rlm_pap
 Module: Instantiating module "pap" from file /usr/local/etc/raddb/modules/pap
  pap {
        encryption_scheme = "auto"
        auto_header = no
  }
 Module: Linked to module rlm_mschap
 Module: Instantiating module "mschap" from file /usr/local/etc/raddb/modules/mschap
  mschap {
        use_mppe = yes
        require_encryption = no
        require_strong = no
        with_ntdomain_hack = no
        allow_retry = yes
  }
 Module: Linked to module rlm_perl
 Module: Instantiating module "perl" from file /usr/local/etc/raddb/modules/perl
  perl {
        module = "/usr/abills/libexec/rlm_perl.pl"
        func_authorize = "authorize"
        func_authenticate = "authenticate"
        func_accounting = "accounting"
        func_preacct = "preacct"
        func_checksimul = "checksimul"
        func_detach = "detach"
        func_xlat = "xlat"
        func_pre_proxy = "pre_proxy"
        func_post_proxy = "post_proxy"
        func_post_auth = "post_auth"
        func_recv_coa = "recv_coa"
        func_send_coa = "send_coa"
  }
 Module: Checking authorize {...} for more modules to load
 Module: Linked to module rlm_preprocess
 Module: Instantiating module "preprocess" from file /usr/local/etc/raddb/modules/preprocess
  preprocess {
        huntgroups = "/usr/local/etc/raddb/huntgroups"
        hints = "/usr/local/etc/raddb/hints"
        with_ascend_hack = no
        ascend_channels_per_line = 23
        with_ntdomain_hack = no
        with_specialix_jetstream_hack = no
        with_cisco_vsa_hack = no
        with_alvarion_vsa_hack = no
  }
reading pairlist file /usr/local/etc/raddb/huntgroups
reading pairlist file /usr/local/etc/raddb/hints
 Module: Linked to module rlm_files
 Module: Instantiating module "files" from file /usr/local/etc/raddb/modules/files
  files {
        usersfile = "/usr/local/etc/raddb/users"
        acctusersfile = "/usr/local/etc/raddb/acct_users"
        preproxy_usersfile = "/usr/local/etc/raddb/preproxy_users"
        compat = "no"
  }
reading pairlist file /usr/local/etc/raddb/users
reading pairlist file /usr/local/etc/raddb/acct_users
reading pairlist file /usr/local/etc/raddb/preproxy_users
 Module: Checking preacct {...} for more modules to load
 Module: Checking accounting {...} for more modules to load
 Module: Checking post-auth {...} for more modules to load
 } # modules
} # server
radiusd: #### Opening IP addresses and Ports ####
listen {
        type = "auth"
        ipaddr = *
        port = 0
}
listen {
        type = "acct"
        ipaddr = *
        port = 0
}
Listening on authentication address * port 1812
Listening on accounting address * port 1813
Ready to process requests.
Авторизую абонента с негативным депозитом

Код: Выделить всё

rad_recv: Access-Request packet from host 127.0.0.1 port 37305, id=166, length=272
        NAS-Identifier = "nas1.prostir.loc"
        Acct-Session-Id = "721628-D-1"
        NAS-Port = 1
        NAS-Port-Type = Ethernet
        Service-Type = Framed-User
        Framed-Protocol = PPP
        Calling-Station-Id = "00:c0:9f:66:64:73 / 00:c0:9f:66:64:73 / bge1"
        NAS-Port-Id = "bge1"
        mpd-link = "D-1"
        mpd-peer-ident = "MSRASV5.10 MSRAS-0-INTEGRAL-E3DEF7"
        Tunnel-Medium-Type:0 = IEEE-802
        Tunnel-Client-Endpoint:0 = "00:c0:9f:66:64:73"
        User-Name = "serv"
        CHAP-Challenge = 0xbb1e68a5d4289e4839b2e6ebe868b675c5940c69b8bcca4c51e8565af690b25986cafe5af29ca3
        CHAP-Password = 0x01667f557a042de293d83540ec8cbb2790
# Executing section authorize from file /usr/local/etc/raddb/sites-enabled/abills_default
+- entering group authorize {...}
++[preprocess] returns ok
++[mschap] returns noop
[files] users: Matched entry DEFAULT at line 38
++[files] returns ok
Auth-Type := Accept
rlm_perl: Added pair NAS-Port-Type = Ethernet
rlm_perl: Added pair CHAP-Password = 0x01667f557a042de293d83540ec8cbb2790
rlm_perl: Added pair mpd-peer-ident = MSRASV5.10 MSRAS-0-INTEGRAL-E3DEF7
rlm_perl: Added pair Acct-Session-Id = 721628-D-1
rlm_perl: Added pair Service-Type = Framed-User
rlm_perl: Added pair CHAP-Challenge = 0xbb1e68a5d4289e4839b2e6ebe868b675c5940c69b8bcca4c51e8565af690b25986cafe5af29ca3
rlm_perl: Added pair Tunnel-Client-Endpoint = 00:c0:9f:66:64:73
rlm_perl: Added pair NAS-IP-Address = 127.0.0.1
rlm_perl: Added pair NAS-Port-Id = bge1
rlm_perl: Added pair Tunnel-Medium-Type = IEEE-802
rlm_perl: Added pair Calling-Station-Id = 00:c0:9f:66:64:73 / 00:c0:9f:66:64:73 / bge1
rlm_perl: Added pair Framed-Protocol = PPP
rlm_perl: Added pair User-Name = serv
rlm_perl: Added pair NAS-Identifier = nas1.prostir.loc
rlm_perl: Added pair mpd-link = D-1
rlm_perl: Added pair NAS-Port = 1
rlm_perl: Added pair Acct-Interim-Interval = 300
rlm_perl: Added pair Framed-IP-Address = 172.12.62.21
rlm_perl: Added pair mpd-table-static = "32=172.12.62.21"
rlm_perl: Added pair Auth-Type = Accept
++[perl] returns ok
Found Auth-Type = Accept
Auth-Type = Accept, accepting the user
  WARNING: Empty post-auth section.  Using default return values.
# Executing section post-auth from file /usr/local/etc/raddb/sites-enabled/abills_default
Sending Access-Accept of id 166 to 127.0.0.1 port 37305
        Acct-Interim-Interval = 300
        Framed-IP-Address = 172.12.62.21
        mpd-table-static = "\"32=172.12.62.21\""
Finished request 1.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Accounting-Request packet from host 127.0.0.1 port 46240, id=38, length=324
        NAS-Identifier = "nas1.prostir.loc"
        Acct-Session-Id = "721628-D-1"
        NAS-Port = 1
        NAS-Port-Type = Ethernet
        Service-Type = Framed-User
        Framed-Protocol = PPP
        Calling-Station-Id = "00:c0:9f:66:64:73 / 00:c0:9f:66:64:73 / bge1"
        NAS-Port-Id = "bge1"
        mpd-link = "D-1"
        mpd-peer-ident = "MSRASV5.10 MSRAS-0-INTEGRAL-E3DEF7"
        Tunnel-Medium-Type:0 = IEEE-802
        Tunnel-Client-Endpoint:0 = "00:c0:9f:66:64:73"
        Acct-Status-Type = Start
        Framed-IP-Address = 172.12.62.21
        User-Name = "serv"
        Acct-Multi-Session-Id = "721629-C-1"
        mpd-bundle = "C-1"
        mpd-iface = "ng0"
        mpd-iface-index = 6
        mpd-peer-ident = "MSRASV5.10 MSRAS-0-INTEGRAL-E3DEF7"
        Acct-Link-Count = 1
        Acct-Authentic = RADIUS
# Executing section preacct from file /usr/local/etc/raddb/sites-enabled/abills_default
+- entering group preacct {...}
++[preprocess] returns ok
# Executing section accounting from file /usr/local/etc/raddb/sites-enabled/abills_default
+- entering group accounting {...}
rlm_perl: Added pair NAS-Port-Type = Ethernet
rlm_perl: Added pair mpd-peer-ident = MSRASV5.10 MSRAS-0-INTEGRAL-E3DEF7
rlm_perl: Added pair mpd-peer-ident = MSRASV5.10 MSRAS-0-INTEGRAL-E3DEF7
rlm_perl: Added pair Acct-Session-Id = 721628-D-1
rlm_perl: Added pair Service-Type = Framed-User
rlm_perl: Added pair Acct-Link-Count = 1
rlm_perl: Added pair mpd-iface = ng0
rlm_perl: Added pair Tunnel-Client-Endpoint = 00:c0:9f:66:64:73
rlm_perl: Added pair Acct-Authentic = RADIUS
rlm_perl: Added pair Acct-Status-Type = Start
rlm_perl: Added pair NAS-IP-Address = 127.0.0.1
rlm_perl: Added pair mpd-bundle = C-1
rlm_perl: Added pair NAS-Port-Id = bge1
rlm_perl: Added pair mpd-iface-index = 6
rlm_perl: Added pair Tunnel-Medium-Type = IEEE-802
rlm_perl: Added pair Calling-Station-Id = 00:c0:9f:66:64:73 / 00:c0:9f:66:64:73 / bge1
rlm_perl: Added pair Framed-Protocol = PPP
rlm_perl: Added pair User-Name = serv
rlm_perl: Added pair NAS-Identifier = nas1.prostir.loc
rlm_perl: Added pair Acct-Multi-Session-Id = 721629-C-1
rlm_perl: Added pair Framed-IP-Address = 172.12.62.21
rlm_perl: Added pair mpd-link = D-1
rlm_perl: Added pair NAS-Port = 1
++[perl] returns ok
Sending Accounting-Response of id 38 to 127.0.0.1 port 46240
Finished request 2.
Cleaning up request 2 ID 38 with timestamp +80
Going to the next request
Waking up in 4.9 seconds.
Спасибо за внимания жду предложений

~AsmodeuS~
Site Admin
Сообщения: 5749
Зарегистрирован: Пт янв 28, 2005 3:11 pm
Контактная информация:

Re: HELP!!! И снова наступаю на старые грабли

Сообщение ~AsmodeuS~ »

нужно проверить заполняются ли таблицы и можно также посмотреть чтоі билинг отдаёт при авторизации radtest.sh

Ответить