...
A Shared Block | |||||
---|---|---|---|---|---|
| |||||
|
Description
The service is used to provide AAA mechanisms for Wi-Fi users connected with WPA-enterprise (EAP). Access points provide RADIUS authorization and authentication with the servers, and the servers request client data from a database. RADIUS also performs support functions for user authorization via ESR/BRAS.
Подсказка |
---|
The service is installed from the package eltex-radius. |
Starting/stopping procedure
To stop the service, the following command is used:
...
Без форматирования |
---|
eltex-radius stop/waiting |
if it is not.
Configuration
Configuration file is located in /etc/eltex-radius
. Of all the files, the following ones can be edited:
...
Start in debugging mode: eltex-radius -X
/etc/eltex-radius/local.conf
Main configuration file. Contains the following parameters:
...
Без форматирования |
---|
# Settings of runtime NAS discovery dynamic_clients=false dynamic_client_subnet=192.168.0.0/16 dynamic_client_lifetime=3600 dynamic_client_rate_limit=false |
NAS table
This table is included into radius database and contains addresses of clients (access points) that are allowed to send user authorization requests. If a client is not included into the table, authorization requests will be ignored. When the contents of the table is changed, restart eltex-radius. When EMS object tree is changed (access points are added/removed), the table is updated automatically, and eltex-radius is restarted.
Logging
Server logging can be configured in a section of /etc/eltex-radius/radiusd.conf
log file. By default, the section is as follows:
...
Parameter | Description |
destination | log destination that can take two values:
|
file | file path that is set by default to ${logdir}/radius.loglogdir = /var/log/eltex-radius thus, a log file is located in /var/log/eltex-radius/radius.log |
syslog_facility | facility, a log category for Syslog logging |
auth | to log authorization requests, values yes or no are accepted |
Log rotation
For log rotation using logrotate, a configuration file should be created, the following is the example:
...