RE: Radius Authentication

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Well,

 

I think GNUgk must have alias as user and password from h323 packet?

I have listen to radius iface and have`nt met any packet from gnugk.

 

Gk config (routed mode with proxy)

 

[Gatekeeper::Auth]

RadAliasAuth=required;Setup,RRQ,ARQ

default=reject

 

[RadAliasAuth]

Servers=xx.xx.xx.xx

DefaultAuthPort=1645

DefaultAcctPort=1646

SharedSecret=xxxxxxxxxxxxxxxxxx

AppendCiscoAttributes=1

 

Call`s are made from unregistered endpoint from openphone and from advanced dialer

 

The GK log

 

2005/06/13 18:03:15.043 4             RasSrv.cxx(211)   RAS     Receiving on xx.xx.xx.xx:1719(U)

2005/06/13 18:03:15.045 2             RasSrv.cxx(173)   RAS     Read from 192.168.2.5:3794

2005/06/13 18:03:15.046 3             RasSrv.cxx(219)   RAS

gatekeeperRequest {

    requestSeqNum = 27116

    protocolIdentifier = 0.0.8.2250.0.4

    rasAddress = ipAddress {

      ip =  4 octets {

        c0 a8 02 05                                        ....

      }

      port = 3794

    }

    endpointType = {

      vendor = {

        vendor = {

          t35CountryCode = 9

          t35Extension = 0

          manufacturerCode = 61

        }

        productId =  3 octets {

          00 00 00                                           ...

        }

        versionId =  26 octets {

          31 2e 30 2e 31 20 28 4f  70 65 6e 48 33 32 33 20   1.0.1 (OpenH323

          76 31 2e 31 32 2e 34 29  00 00                     v1.12.4)..

        }

      }

      terminal = {

      }

      mc = FALSE

      undefinedNode = FALSE

    }

    endpointAlias = 1 entries {

      [0]=dialedDigits "12312312"

    }

    authenticationCapability = 2 entries {

      [0]=pwdHash <<null>>

      [1]=authenticationBES radius <<null>>

    }

    algorithmOIDs = 2 entries {

      [0]=1.2.840.113549.2.5

      [1]=1.2.840.113548.10.1.2.1

    }

    supportsAltGK = <<null>>

  }

2005/06/13 18:03:15.047 5                job.cxx(352)   JOB     Worker threads: 6 total - 6 busy, 0 idle

2005/06/13 18:03:15.047 5                job.cxx(180)   JOB     Starting Job GRQ at Worker thread 0x81ca600

2005/06/13 18:03:15.047 1             RasSrv.cxx(343)   RAS     GRQ Received

2005/06/13 18:03:15.047 3               gkauth.h(836)   GKAUTH  default GRQ check failed

2005/06/13 18:03:15.048 2             RasSrv.cxx(388)   GRJ|192.168.2.5|12312312:dialedDigits|terminal|securityDenial;

2005/06/13 18:03:15.048 3             RasSrv.cxx(231)   RAS     Send to 192.168.2.5:3794

gatekeeperReject {

    requestSeqNum = 27116

    protocolIdentifier = 0.0.8.2250.0.4

    gatekeeperIdentifier =  12 characters {

      0053 004f 0056 0041 005f 0054 0045 0053   SOVA_TES

      0054 005f 0047 004b                       T_GK

    }

    rejectReason = securityDenial <<null>>

  }

2005/06/13 18:03:15.048 5             RasSrv.cxx(245)   RAS     Sent Successful

2005/06/13 18:03:15.049 5                job.cxx(415)   JOB     Job GRQ deleted

 

 

The idea is to let users to call via gatekeeper using existing billing with PIN auth.

 

-----Original Message-----
From: openh323gk-users-admin@xxxxxxxxxxxxxxxxxxxxx [mailto:openh323gk-users-admin@xxxxxxxxxxxxxxxxxxxxx] On Behalf Of Zygmuntowicz Michal
Sent: Tuesday, June 14, 2005 10:43 AM
To: openh323gk-users@xxxxxxxxxxxxxxxxxxxxx
Subject: Re: Radius Authentication

 

As far as I have tested, everything should work fine.

 

----- Original Message -----

From: "Glushenko Vladimir" <glushenko@xxxxxxxxxxxxxxx>

Sent: Monday, June 13, 2005 5:18 PM

 

 

> I`m trying to setup gnugk to process rrq and setup messages via billing

> system and have such problem

>

> When I try to register with gatekeeper

> 2.2.3 with RadAliasAuth for Setup, RRQ, ARQ I receives Reject "Security

> denial"

>

> Same I have in RadAuth

>

> May I have missconfig or feature is not supported in this version?

>

> Vladimir Glushenko

 

 

 

-------------------------------------------------------

This SF.Net email is sponsored by: NEC IT Guy Games.  How far can you shotput

a projector? How fast can you ride your desk chair down the office luge track?

If you want to score the big prize, get to know the little guy. 

Play to win an NEC 61" plasma display: http://www.necitguy.com/?r=20

_______________________________________________________

 

Posting: mailto:Openh323gk-users@xxxxxxxxxxxxxxxxxxxxx

Archive: http://sourceforge.net/mailarchive/forum.php?forum_id=8549

Unsubscribe: http://lists.sourceforge.net/lists/listinfo/openh323gk-users

Homepage: http://www.gnugk.org/


[Index of Archives]     [SIP]     [Open H.323]     [Gnu Gatekeeper]     [Asterisk PBX]     [ISDN Cause Codes]     [Yosemite News]

  Powered by Linux