RE: RADIUS Question

Phil Taylor (Phil@lansystems.co.uk)
Wed, 28 May 1997 15:23:35 +0100

You should be able to but probably a nicer way if you are using unix
passwords is to set shell type to a non existant shell, it really
depends whether you want the user to still be able to login on the unix
machine itself.

If it is radius 2 then this supports the concept of groups so your
default entry could be:

DEFAULT Password = "UNIX" Group = "dialup"
etc etc

and then add all of the dialup users to a unix group called dialup in
/etc/group

The users that you don't want access to the PM you simply remove from
the group dialup.

There is always more than one way to skin a cat :-)

Cheers

Phil

> ----------
> From: Scott Black[SMTP:admin@emporium.on.ca]
> Reply To: Scott Black
> Sent: Wednesday, May 28, 1997 2:43 PM
> To: portmaster-users@livingston.com
> Subject: RADIUS Question
>
> What is the minimum I can 'get away' with for such a user 'noauth' for
> whom
> I do not wish to allow radius authenticated access? Can I simply do a
> one-liner Password entry with no comma at the end? Below is a
> simplified
> representation of a users file.
>
> noauth Password = "*"
> User-Service-Type = Framed-User,
> Framed-Protocol = PPP,
> Framed-Address = 255.255.255.254,
> Framed-Netmask = 255.255.255.255,
> Framed-Routing = None,
> Framed-Compression = Van-Jacobsen-TCP-IP,
> Framed-MTU = 1500
>
> DEFAULT Password = "UNIX"
> User-Service-Type = Framed-User,
> Framed-Protocol = PPP,
> Framed-Address = 255.255.255.254,
> Framed-Netmask = 255.255.255.255,
> Framed-Routing = None,
> Framed-Compression = Van-Jacobsen-TCP-IP,
> Framed-MTU = 1500
>
>
> Thanks,
>
> Scott
>
>
> ****************************************************************
> 'Getting cards and letters from people I don't even know'
>