[CENTER][SIZE=3]اخي العزيز Natty Dreed[/SIZE] [SIZE=3]مشكور بداية علي مرورك ومحاولة إفادتي[/SIZE] [SIZE=3]وبارك الله فيك علي جهدك[/SIZE] [SIZE=3][/SIZE] [SIZE=3]لكي أفيدك[/SIZE] [SIZE=3]هذا البرنامج مختص بالشبكات وموزعي خدمة الانترنت[/SIZE] [SIZE=3]يسمح للموزع بتحديد سرعات الانترنت وعرض المستخدمين الاون لاين والحجب والترافيك وغيرها الكثيير[/SIZE] [SIZE=3][/SIZE] [SIZE=3]ويعد من أفضل أفضل البرامج[/SIZE] [SIZE=3][/SIZE] [SIZE=3]أكثر خطوة محتاج أفهم شرحها بالتفصيل وأعني بالتفصيل جيدا هذه الخطوة[/SIZE] [SIZE=3]``` [/SIZE] [SIZE=3]sudo vi /etc/freeradius/radius.conf[/SIZE] **[SIZE=3][COLOR=red]there will be a section in there reguarding instantiate for authorize. Just search for sql1 above that create a line with sql. Save and exit.[/COLOR]
**[SIZE=3][/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3]ما هو الكود المطلوب مني وضعه ؟؟[/SIZE]**
**[SIZE=3]هل كلمة sql فقط[/SIZE]**
**[SIZE=3]ام كود معين ؟؟ أرجو التوضيح[/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3]أما بالنسبة للخطوة الثانية[/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3]```
[/SIZE]**
**[SIZE=3]/etc/freeradius/sites-enabled/default[/SIZE]**
[B][SIZE=3][COLOR=red]uncomment all the sql tags in here (or the ones you want to use with mysql)[/COLOR]
[/SIZE][/B]
**[SIZE=3][COLOR=red]with that done make the following directory and file. Otherwise you won't authenticate[/COLOR].
[SIZE=3][/SIZE] [SIZE=3]أعرف انه مطلوب مني أزالة علامة #[/SIZE] [SIZE=3]لكن من أي سطر فيهم فكل الملف يحتوي علي هذه العلامة #[/SIZE] [SIZE=3][/SIZE] [SIZE=3]ونسخت لكم جزء من الملف علشان تشوفوه[/SIZE] [SIZE=3]``` GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE] [SIZE=3][/SIZE] [B][SIZE=3]###################################################################### #
As of 2.0.0, FreeRADIUS supports virtual hosts using the
"server" section, and configuration directives.
#
Virtual hosts should be put into the "sites-available"
directory. Soft links should be created in the "sites-enabled"
directory to these files. This is done in a normal installation.
#
$Id$
# ###################################################################### #
Read "man radiusd" before editing this file. See the section
titled DEBUGGING. It outlines a method where you can quickly
obtain the configuration you want, without running into
trouble. See also "man unlang", which documents the format
of this file.
# GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3]###################################################################### #
As of 2.0.0, FreeRADIUS supports virtual hosts using the
"server" section, and configuration directives.
#
Virtual hosts should be put into the "sites-available"
directory. Soft links should be created in the "sites-enabled"
directory to these files. This is done in a normal installation.
#
$Id$
# ###################################################################### #
Read "man radiusd" before editing this file. See the section
titled DEBUGGING. It outlines a method where you can quickly
obtain the configuration you want, without running into
trouble. See also "man unlang", which documents the format
of this file.
# GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3]# of this file. #
This configuration is designed to work in the widest possible
set of circumstances, with the widest possible number of
authentication methods. This means that in general, you should
need to make very few changes to this file.
#
The best way to configure the server for your local system
is to CAREFULLY edit this file. Most attempts to make large
edits to this file will BREAK THE SERVER. Any edits should
be small, and tested by running the server with "radiusd -X".
Once the edits have been verified to work, save a copy of these
configuration files somewhere. (e.g. as a "tar" file). Then,
make more edits, and test, as above.
#
There are many "commented out" references to modules such
as ldap, sql, etc. These references serve as place-holders.
If you need the functionality of that module, then configure
it in radiusd.conf, and un-comment the references to it in
[ line 18/594 (3%), col 1/22 (4%), char 707/16594 (4%) ] GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3]# If you need the functionality of that module, then configure
it in radiusd.conf, and un-comment the references to it in
this file. In most cases, those small changes will result
in the server being able to connect to the DB, and to
authenticate users.
# ######################################################################[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3]#
In 1.x, the "authorize", etc. sections were global in
radiusd.conf. As of 2.0, they SHOULD be in a server section.
The server section with no virtual server name is the "default"
section. It is used when no server name is specified.
#
We don't indent the rest of this file, because doing so
would make it harder to read.
# GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [SIZE=3]# [/SIZE] [SIZE=3][/SIZE] [B][SIZE=3]# Authorization. First preprocess (hints and huntgroups files),
then realms, and finally look in the "users" file.
#
The order of the realm modules will determine the order that
we try to find a matching realm.
#
Make *sure* that 'preprocess' comes before any realm if you
need to setup hints for the remote radius server
authorize { # # The preprocess module takes care of sanitizing some bizarre # attributes in the request, and turning them into attributes # which are more standard. # # It takes care of processing the 'raddb/hints' and the # 'raddb/huntgroups' files. preprocess GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [SIZE=3]# [/SIZE] [SIZE=3][/SIZE] [B][SIZE=3]# Authorization. First preprocess (hints and huntgroups files),
then realms, and finally look in the "users" file.
#
The order of the realm modules will determine the order that
we try to find a matching realm.
#
Make *sure* that 'preprocess' comes before any realm if you
need to setup hints for the remote radius server
authorize { # # The preprocess module takes care of sanitizing some bizarre # attributes in the request, and turning them into attributes # which are more standard. # # It takes care of processing the 'raddb/hints' and the # 'raddb/huntgroups' files. preprocess # 'raddb/huntgroups' files. preprocess[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # If you want to have a log of authentication requests, # un-comment the following line, and the 'detail auth_log' # section, above.
auth_log[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # The chap module will set 'Auth-Type := CHAP' if we are # handling a CHAP request and Auth-Type has not already been set chap[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # If the users are logging in with an MS-CHAP-Challenge # attribute for authentication, the mschap module will find # the MS-CHAP-Challenge attribute, and add 'Auth-Type := MS-CHAP' # to the request, which will cause the server to then use[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # the MS-CHAP-Challenge attribute, and add 'Auth-Type := MS-CHAP' # to the request, which will cause the server to then use # the mschap module for authentication. mschap[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # If you have a Cisco SIP server authenticating against # FreeRADIUS, uncomment the following line, and the 'digest' # line in the 'authenticate' section.
digest[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # The WiMAX specification says that the Calling-Station-Id # is 6 octets of the MAC. This definition conflicts with # RFC 3580, and all common RADIUS practices. Un-commenting # the "wimax" module here means that it will fix the # Calling-Station-Id attribute to the normal format as # specified in RFC 3580 Section 3.21
wimax
GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # specified in RFC 3580 Section 3.21
wimax[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # Look for IPASS style 'realm/', and if not found, look for # [/SIZE][/B][EMAIL="'@realm'"][SIZE=3]'@realm'[/SIZE][/EMAIL][B][SIZE=3], and decide whether or not to proxy, based on # that.
IPASS[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # If you are using multiple kinds of realms, you probably # want to set "ignore_null = yes" for all of them. # Otherwise, when the first style of realm doesn't match, # the other styles won't be checked. # suffix
ntdomain[/SIZE][/B]
[SIZE=3][/SIZE] [SIZE=3] # GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE] [SIZE=3][/SIZE]
[B][SIZE=3] # # This module takes care of EAP-MD5, EAP-TLS, and EAP-LEAP # authentication. # # It also sets the EAP-Type attribute in the request # attribute list to the EAP type from the packet. # # As of 2.0, the EAP module returns "ok" in the authorize stage # for TTLS and PEAP. In 1.x, it never returned "ok" here, so # this change is compatible with older configurations. # # The example below uses module failover to avoid querying all # of the following modules if the EAP module returns "ok". # Therefore, your LDAP and/or SQL servers will not be queried # for the many packets that go back and forth to set up TTLS # or PEAP. The load on those servers will therefore be reduced. # eap { GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # eap { ok = return }[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # Pull crypt'd passwords from /etc/passwd or /etc/shadow, # using the system API's to get the password. If you want # to read /etc/passwd or /etc/shadow directly, see the # passwd module in radiusd.conf. # unix[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # Read the 'users' file files[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # Look in an SQL database. The schema of the database U nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # Look in an SQL database. The schema of the database # is meant to mirror the "users" file. # # See "Authorization Queries" in sql.conf
sql[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # If you are using /etc/smbpasswd, and are also doing # mschap authentication, the un-comment this line, and # configure the 'etc_smbpasswd' module, above.
etc_smbpasswd[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # The ldap module will set Auth-Type to LDAP if it has not # already been set
ldap[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE]
[B][SIZE=3] # # Enforce daily limits on time spent logged in.
daily[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # Use the checkval module
checkval[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] expiration logintime[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # If no other module has claimed responsibility for # authentication, then try to use PAP. This allows the # other modules listed above to add a "known good" password # to the request, and to do nothing else. The PAP module # will then see that password, and use it to do PAP # authentication. GNU nano 2.2.4 File: /etc/freeradius/sites-enabled/default [/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # will then see that password, and use it to do PAP # authentication. # # This module should be listed last, so that the other modules # get a chance to set Auth-Type for themselves. # pap[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # If "status_server = yes", then Status-Server messages are passed # through the following section, and ONLY the following section. # This permits you to do DB queries, for example. If the modules # listed here return "fail", then NO response is sent. #
Autz-Type Status-Server {
#
}
} }[/SIZE][/B] [SIZE=3][/SIZE]
[B][SIZE=3]# Authentication. # #
This section lists which modules are available for authentication.
Note that it does NOT mean 'try each module in order'. It means
that a module from the 'authorize' section adds a configuration
attribute 'Auth-Type := FOO'. That authentication type is then
used to pick the apropriate module from the list below.
#[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3]# In general, you SHOULD NOT set the Auth-Type attribute. The server
will figure it out on its own, and will do the right thing. The
most common side effect of erroneously setting the Auth-Type
attribute is that one authentication method will work, but the
others will not.
others will not.
#
The common reasons to set the Auth-Type attribute by hand
is to either forcibly reject the user (Auth-Type := Reject),
or to or forcibly accept the user (Auth-Type := Accept).
#
Note that Auth-Type := Accept will NOT work with EAP.
Please do not put "unlang" configurations into the "authenticate"
section. Put them in the "post-auth" section instead. That's what
the post-auth section is for.
# authenticate { # # PAP authentication, when a back-end database listed # in the 'authorize' section supplies a password. The # password can be clear-text, or encrypted. Auth-Type PAP { pap Auth-Type PAP { pap }[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # Most people want CHAP authentication # A back-end database listed in the 'authorize' section # MUST supply a CLEAR TEXT password. Encrypted passwords # won't work. Auth-Type CHAP { chap }[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # MSCHAP authentication. Auth-Type MS-CHAP { mschap } }[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # If you have a Cisco SIP server authenticating against # FreeRADIUS, uncomment the following line, and the 'digest' # line in the 'authorize' section.
digest[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # Pluggable Authentication Modules.
pam[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # See 'man getpwent' for information on how the 'unix' # module checks the users password. Note that packets # containing CHAP-Password attributes CANNOT be authenticated # against /etc/passwd! See the FAQ for details. # unix # unix[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # Uncomment it if you want to use ldap for authentication # # Note that this means "check plain-text password against # the ldap database", which means that EAP won't work, # as it does not supply a plain-text password.
Auth-Type LDAP {
ldap
}[/SIZE][/B]
[SIZE=3][/SIZE] [B][SIZE=3] # # Allow EAP authentication. eap[/SIZE][/B] [SIZE=3][/SIZE] [B][SIZE=3] # # The older configurations sent a number of attributes in # Access-Challenge packets, which wasn't strictly correct. # The older configurations sent a number of attributes in # Access-Challenge packets, which wasn't strictly correct. # If you want to filter out these attributes, uncomment # the following lines. #
Auth-Type eap {
eap {
handled = 1
}
if (handled && (Response-Packet-Type == Access-Challenge)) {
attr_filter.access_challenge.post-auth
handled # override the "updated" code from attr_filter
}
}
}[/SIZE][/B] [SIZE=3][/SIZE]
[B][SIZE=3]#
Pre-accounting. Decide which accounting type to use
**[SIZE=3][/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3]في هذه الخطوة لما انفذها بعطيني هذا الخطا مش عارف هل لاني مش مكمل الخطوات ام لا[/SIZE]**
**[SIZE=3]في شغله تانيه هل هذا الرابط الصحيح للدخول للبرنامج ام يوجد له تعديل ؟؟[/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3]```
Not Found[/SIZE]**
**[SIZE=3][/SIZE]**
[B][SIZE=3]The requested URL /daloradius was not found on this server.
Apache/2.2.16 (Ubuntu) Server at localhost Port 80
[SIZE=3][/SIZE] [SIZE=3]ما المقصود بهذه الخطوة[/SIZE] [SIZE=3][/SIZE] **[SIZE=3]``` [COLOR=#ff0000]and a nas if you are using one[/COLOR]
**[SIZE=3][/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3]ومشكورين جدا وأتمنى التفاعل معي[/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3]او ان تدلوني علي احد يساعدني في حل هذه المشكلة[/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3]بورك فيكم[/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3][/SIZE]**
**[SIZE=3][/SIZE]** [/CENTER]