linux-ppp.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* RE: [Poptop-server] Restrict user access
@ 2008-05-06  7:25 Sascha Kiefer
  2008-05-07 11:46 ` Sascha Kiefer
                   ` (4 more replies)
  0 siblings, 5 replies; 6+ messages in thread
From: Sascha Kiefer @ 2008-05-06  7:25 UTC (permalink / raw)
  To: linux-ppp

Thanks for the hint.
For what i would like to do i probably will go for radius.
I know thats not the right list, but maybe you (or somebody else) can help
me out:
- installing radius server on the poptop server? Okay/Not okay?
- accessing one radius server from different poptop servers - which means
havin one authentication server for different vpn/physical servers? 
- ensure that only my vpn servers can access the radius server? Probably ip
restrictions?
Any source that i might have to read?

Regards,
Sascha Kiefer


-----Original Message-----
From: james.cameron@hp.com [mailto:james.cameron@hp.com] 
Sent: Dienstag, 6. Mai 2008 10:42
To: Sascha Kiefer
Cc: poptop-server@lists.sourceforge.net
Subject: Re: [Poptop-server] Restrict user access


This would be a pppd configuration issue, not pptpd.  I've heard of various
ways to implement it ... a RADIUS server, or pppd ip-up.d scripting, or pppd
authentication plugins.

You would have to assume that an originating IP address identified a
workstation (which isn't always true).

But yes, certainly *possible*.  Just lacking in implementation
documentation.

-- 
James Cameron                         http://quozl.netrek.org/
HP Open Source, Volunteer             http://opensource.hp.com/
PPTP Client Project, Release Engineer http://pptpclient.sourceforge.net/


^ permalink raw reply	[flat|nested] 6+ messages in thread

* RE: [Poptop-server] Restrict user access
  2008-05-06  7:25 [Poptop-server] Restrict user access Sascha Kiefer
@ 2008-05-07 11:46 ` Sascha Kiefer
  2008-05-07 23:03 ` James Cameron
                   ` (3 subsequent siblings)
  4 siblings, 0 replies; 6+ messages in thread
From: Sascha Kiefer @ 2008-05-07 11:46 UTC (permalink / raw)
  To: linux-ppp

Ok.
I setup a radius server with mysql on a different server.
But i think i'm far from having everything playing together.

I found some howto on the web:
http://poptop.sourceforge.net/dox/radius_mysql.html
So: the client will get the ip from the radius server??? Not from the server
that has poptop running?



-----Original Message-----
From: Sascha Kiefer [mailto:sk@intertivity.com] 
Sent: Dienstag, 6. Mai 2008 11:26
To: 'james.cameron@hp.com'
Cc: 'poptop-server@lists.sourceforge.net'; 'linux-ppp@vger.kernel.org'
Subject: RE: [Poptop-server] Restrict user access


Thanks for the hint.
For what i would like to do i probably will go for radius.
I know thats not the right list, but maybe you (or somebody else) can help
me out:
- installing radius server on the poptop server? Okay/Not okay?
- accessing one radius server from different poptop servers - which means
havin one authentication server for different vpn/physical servers? 
- ensure that only my vpn servers can access the radius server? Probably ip
restrictions? Any source that i might have to read?

Regards,
Sascha Kiefer


-----Original Message-----
From: james.cameron@hp.com [mailto:james.cameron@hp.com] 
Sent: Dienstag, 6. Mai 2008 10:42
To: Sascha Kiefer
Cc: poptop-server@lists.sourceforge.net
Subject: Re: [Poptop-server] Restrict user access


This would be a pppd configuration issue, not pptpd.  I've heard of various
ways to implement it ... a RADIUS server, or pppd ip-up.d scripting, or pppd
authentication plugins.

You would have to assume that an originating IP address identified a
workstation (which isn't always true).

But yes, certainly *possible*.  Just lacking in implementation
documentation.

-- 
James Cameron                         http://quozl.netrek.org/
HP Open Source, Volunteer             http://opensource.hp.com/
PPTP Client Project, Release Engineer http://pptpclient.sourceforge.net/


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [Poptop-server] Restrict user access
  2008-05-06  7:25 [Poptop-server] Restrict user access Sascha Kiefer
  2008-05-07 11:46 ` Sascha Kiefer
@ 2008-05-07 23:03 ` James Cameron
  2008-05-08  5:27 ` Sascha Kiefer
                   ` (2 subsequent siblings)
  4 siblings, 0 replies; 6+ messages in thread
From: James Cameron @ 2008-05-07 23:03 UTC (permalink / raw)
  To: linux-ppp

On Wed, May 07, 2008 at 03:46:38PM +0400, Sascha Kiefer wrote:
> I found some howto on the web:
> http://poptop.sourceforge.net/dox/radius_mysql.html

Edits welcome.  It is getting old.

> So: the client will get the ip from the radius server??? Not from the server
> that has poptop running?

The IP address is allocated by the RADIUS server, passed in a message to
the pppd RADIUS plugin which was selected by pptpd, and pppd then passes
it to the client within IPCP.  The client perceives it has got it from
the server running pptpd.  But you know that it has come from the RADIUS
server.

-- 
James Cameron                         http://quozl.netrek.org/
HP Open Source, Volunteer             http://opensource.hp.com/
PPTP Client Project, Release Engineer http://pptpclient.sourceforge.net/

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [Poptop-server] Restrict user access
  2008-05-06  7:25 [Poptop-server] Restrict user access Sascha Kiefer
  2008-05-07 11:46 ` Sascha Kiefer
  2008-05-07 23:03 ` James Cameron
@ 2008-05-08  5:27 ` Sascha Kiefer
  2008-05-08  5:28 ` Sascha Kiefer
  2008-05-08  6:26 ` James Cameron
  4 siblings, 0 replies; 6+ messages in thread
From: Sascha Kiefer @ 2008-05-08  5:27 UTC (permalink / raw)
  To: linux-ppp

James Cameron wrote:
> On Wed, May 07, 2008 at 03:46:38PM +0400, Sascha Kiefer wrote:
>   
> The IP address is allocated by the RADIUS server, passed in a message to
> the pppd RADIUS plugin which was selected by pptpd, and pppd then passes
> it to the client within IPCP.  The client perceives it has got it from
> the server running pptpd.  But you know that it has come from the RADIUS
> server.
>
>   
thanks
. i do not do it this way. i let the pptpd server decide whar it address 
to use.
somehow the pptpd server tells that the radius server. which is fine for me.
can this lead to any problems?

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [Poptop-server] Restrict user access
  2008-05-06  7:25 [Poptop-server] Restrict user access Sascha Kiefer
                   ` (2 preceding siblings ...)
  2008-05-08  5:27 ` Sascha Kiefer
@ 2008-05-08  5:28 ` Sascha Kiefer
  2008-05-08  6:26 ` James Cameron
  4 siblings, 0 replies; 6+ messages in thread
From: Sascha Kiefer @ 2008-05-08  5:28 UTC (permalink / raw)
  To: linux-ppp

James Cameron wrote:
> On Wed, May 07, 2008 at 03:46:38PM +0400, Sascha Kiefer wrote:
>   
>> I found some howto on the web:
>> http://poptop.sourceforge.net/dox/radius_mysql.html
>>     
>
> Edits welcome.  It is getting old.
>   

i found a nice one: http://wiki.freeradius.org/PopTop


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [Poptop-server] Restrict user access
  2008-05-06  7:25 [Poptop-server] Restrict user access Sascha Kiefer
                   ` (3 preceding siblings ...)
  2008-05-08  5:28 ` Sascha Kiefer
@ 2008-05-08  6:26 ` James Cameron
  4 siblings, 0 replies; 6+ messages in thread
From: James Cameron @ 2008-05-08  6:26 UTC (permalink / raw)
  To: linux-ppp

On Thu, May 08, 2008 at 09:27:24AM +0400, Sascha Kiefer wrote:
> i do not do it this way. i let the pptpd server decide whar it address
> to use. somehow the pptpd server tells that the radius server. which
> is fine for me.
> can this lead to any problems?

I stand corrected.  Nice to know it can be done that way too.

-- 
James Cameron                         http://quozl.netrek.org/
HP Open Source, Volunteer             http://opensource.hp.com/
PPTP Client Project, Release Engineer http://pptpclient.sourceforge.net/

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2008-05-08  6:26 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-05-06  7:25 [Poptop-server] Restrict user access Sascha Kiefer
2008-05-07 11:46 ` Sascha Kiefer
2008-05-07 23:03 ` James Cameron
2008-05-08  5:27 ` Sascha Kiefer
2008-05-08  5:28 ` Sascha Kiefer
2008-05-08  6:26 ` James Cameron

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).