wlc-15#
wlc-15# debug
wlc-15(debug)# show radius-debug username tester ip-address 100.129.56.1 timeout 600
(33) Thu Nov 21 15:34:09 2024: Debug: Received Access-Request Id 31 from 100.129.56.1:37236 to 100.129.58.1:1812 length 259
(33) Thu Nov 21 15:34:09 2024: Debug: User-Name = "tester"
(33) Thu Nov 21 15:34:09 2024: Debug: NAS-IP-Address = 100.129.56.1
(33) Thu Nov 21 15:34:09 2024: Debug: Eltex-Domain = "default"
(33) Thu Nov 21 15:34:09 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(33) Thu Nov 21 15:34:09 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(33) Thu Nov 21 15:34:09 2024: Debug: NAS-Port-Type = Wireless-802.11
(33) Thu Nov 21 15:34:09 2024: Debug: NAS-Port-Id = "10"
(33) Thu Nov 21 15:34:09 2024: Debug: Service-Type = Framed-User
(33) Thu Nov 21 15:34:09 2024: Debug: NAS-Port = 1
(33) Thu Nov 21 15:34:09 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(33) Thu Nov 21 15:34:09 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(33) Thu Nov 21 15:34:09 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(33) Thu Nov 21 15:34:09 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(33) Thu Nov 21 15:34:09 2024: Debug: WLAN-Group-Cipher = 1027076
(33) Thu Nov 21 15:34:09 2024: Debug: WLAN-AKM-Suite = 1027073
(33) Thu Nov 21 15:34:09 2024: Debug: Eltex-AP-Domain = "with-gre"
(33) Thu Nov 21 15:34:09 2024: Debug: Framed-MTU = 1400
(33) Thu Nov 21 15:34:09 2024: Debug: EAP-Message = 0x0285000b01746573746572
(33) Thu Nov 21 15:34:09 2024: Debug: Message-Authenticator = 0x204ffb9b5a0f9dcf0b9e1ca3cd13c639
(33) Thu Nov 21 15:34:09 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(33) Thu Nov 21 15:34:09 2024: Debug: authorize {
(33) Thu Nov 21 15:34:09 2024: Debug: policy filter_username {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) -> TRUE
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ / /) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ / /) -> FALSE
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.\./ ) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(33) Thu Nov 21 15:34:09 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(33) Thu Nov 21 15:34:09 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.$/) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@\./) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(33) Thu Nov 21 15:34:09 2024: Debug: } # if (&User-Name) = notfound
(33) Thu Nov 21 15:34:09 2024: Debug: } # policy filter_username = notfound
(33) Thu Nov 21 15:34:09 2024: Debug: [preprocess] = ok
(33) Thu Nov 21 15:34:09 2024: Debug: [chap] = noop
(33) Thu Nov 21 15:34:09 2024: Debug: [mschap] = noop
(33) Thu Nov 21 15:34:09 2024: Debug: [digest] = noop
(33) Thu Nov 21 15:34:09 2024: Debug: suffix: Checking for suffix after "@"
(33) Thu Nov 21 15:34:09 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(33) Thu Nov 21 15:34:09 2024: Debug: suffix: No such realm "NULL"
(33) Thu Nov 21 15:34:09 2024: Debug: [suffix] = noop
(33) Thu Nov 21 15:34:09 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(33) Thu Nov 21 15:34:09 2024: Debug: files_multi: users: Matched entry tester at line 5
(33) Thu Nov 21 15:34:09 2024: Debug: [files_multi] = ok
(33) Thu Nov 21 15:34:09 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(33) Thu Nov 21 15:34:09 2024: Debug: else {
(33) Thu Nov 21 15:34:09 2024: Debug: eap: Peer sent EAP Response (code 2) ID 133 length 11
(33) Thu Nov 21 15:34:09 2024: Debug: eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(33) Thu Nov 21 15:34:09 2024: Debug: [eap] = ok
(33) Thu Nov 21 15:34:09 2024: Debug: } # else = ok
(33) Thu Nov 21 15:34:09 2024: Debug: if (ok) {
(33) Thu Nov 21 15:34:09 2024: Debug: if (ok) -> TRUE
(33) Thu Nov 21 15:34:09 2024: Debug: if (ok) {
(33) Thu Nov 21 15:34:09 2024: Debug: return
(33) Thu Nov 21 15:34:09 2024: Debug: } # if (ok) = ok
(33) Thu Nov 21 15:34:09 2024: Debug: } # authorize = ok
(33) Thu Nov 21 15:34:09 2024: Debug: Found Auth-Type = eap
(33) Thu Nov 21 15:34:09 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(33) Thu Nov 21 15:34:09 2024: Debug: authenticate {
(33) Thu Nov 21 15:34:09 2024: Debug: eap: Peer sent packet with method EAP Identity (1)
(33) Thu Nov 21 15:34:09 2024: Debug: eap: Calling submodule eap_peap to process data
(33) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Initiating new session
(33) Thu Nov 21 15:34:09 2024: Debug: eap: Sending EAP Request (code 1) ID 134 length 6
(33) Thu Nov 21 15:34:09 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814d640c1da
(33) Thu Nov 21 15:34:09 2024: Debug: [eap] = handled
(33) Thu Nov 21 15:34:09 2024: Debug: } # authenticate = handled
(33) Thu Nov 21 15:34:09 2024: Debug: Using Post-Auth-Type Challenge
(33) Thu Nov 21 15:34:09 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(33) Thu Nov 21 15:34:09 2024: Debug: Challenge { ... } # empty sub-section is ignored
(33) Thu Nov 21 15:34:09 2024: Debug: session-state: Saving cached attributes
(33) Thu Nov 21 15:34:09 2024: Debug: Framed-MTU = 1004
(33) Thu Nov 21 15:34:09 2024: Debug: Sent Access-Challenge Id 31 from 100.129.58.1:1812 to 100.129.56.1:37236 length 76
(33) Thu Nov 21 15:34:09 2024: Debug: Eltex-Tls-Enabled = 0
(33) Thu Nov 21 15:34:09 2024: Debug: EAP-Message = 0x018600061920
(33) Thu Nov 21 15:34:09 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(33) Thu Nov 21 15:34:09 2024: Debug: State = 0xd6c6d814d640c1da517e6b54cde2f128
(33) Thu Nov 21 15:34:09 2024: Debug: Finished request
(34) Thu Nov 21 15:34:09 2024: Debug: Received Access-Request Id 32 from 100.129.56.1:37236 to 100.129.58.1:1812 length 427
(34) Thu Nov 21 15:34:09 2024: Debug: User-Name = "tester"
(34) Thu Nov 21 15:34:09 2024: Debug: NAS-IP-Address = 100.129.56.1
(34) Thu Nov 21 15:34:09 2024: Debug: Eltex-Domain = "default"
(34) Thu Nov 21 15:34:09 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(34) Thu Nov 21 15:34:09 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(34) Thu Nov 21 15:34:09 2024: Debug: NAS-Port-Type = Wireless-802.11
(34) Thu Nov 21 15:34:09 2024: Debug: NAS-Port-Id = "10"
(34) Thu Nov 21 15:34:09 2024: Debug: Service-Type = Framed-User
(34) Thu Nov 21 15:34:09 2024: Debug: NAS-Port = 1
(34) Thu Nov 21 15:34:09 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(34) Thu Nov 21 15:34:09 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(34) Thu Nov 21 15:34:09 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(34) Thu Nov 21 15:34:09 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(34) Thu Nov 21 15:34:09 2024: Debug: WLAN-Group-Cipher = 1027076
(34) Thu Nov 21 15:34:09 2024: Debug: WLAN-AKM-Suite = 1027073
(34) Thu Nov 21 15:34:09 2024: Debug: Eltex-AP-Domain = "with-gre"
(34) Thu Nov 21 15:34:09 2024: Debug: Framed-MTU = 1400
(34) Thu Nov 21 15:34:09 2024: Debug: EAP-Message = 0x028600a119800000009716030100920100008e0303673ef08120eff9f8ebe08572c925c8194ba8df959e2ec704e8933241538475fe00002c00ffc02cc02bc024c023c00ac009c008c030c02fc00
(34) Thu Nov 21 15:34:09 2024: Debug: State = 0xd6c6d814d640c1da517e6b54cde2f128
(34) Thu Nov 21 15:34:09 2024: Debug: Message-Authenticator = 0xe9d462619fab68ba99b3766d0517073d
(34) Thu Nov 21 15:34:09 2024: Debug: Restoring &session-state
(34) Thu Nov 21 15:34:09 2024: Debug: &session-state:Framed-MTU = 1004
(34) Thu Nov 21 15:34:09 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(34) Thu Nov 21 15:34:09 2024: Debug: authorize {
(34) Thu Nov 21 15:34:09 2024: Debug: policy filter_username {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) -> TRUE
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ / /) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ / /) -> FALSE
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.\./ ) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(34) Thu Nov 21 15:34:09 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(34) Thu Nov 21 15:34:09 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.$/) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@\./) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(34) Thu Nov 21 15:34:09 2024: Debug: } # if (&User-Name) = notfound
(34) Thu Nov 21 15:34:09 2024: Debug: } # policy filter_username = notfound
(34) Thu Nov 21 15:34:09 2024: Debug: [preprocess] = ok
(34) Thu Nov 21 15:34:09 2024: Debug: [chap] = noop
(34) Thu Nov 21 15:34:09 2024: Debug: [mschap] = noop
(34) Thu Nov 21 15:34:09 2024: Debug: [digest] = noop
(34) Thu Nov 21 15:34:09 2024: Debug: suffix: Checking for suffix after "@"
(34) Thu Nov 21 15:34:09 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(34) Thu Nov 21 15:34:09 2024: Debug: suffix: No such realm "NULL"
(34) Thu Nov 21 15:34:09 2024: Debug: [suffix] = noop
(34) Thu Nov 21 15:34:09 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(34) Thu Nov 21 15:34:09 2024: Debug: files_multi: users: Matched entry tester at line 5
(34) Thu Nov 21 15:34:09 2024: Debug: [files_multi] = ok
(34) Thu Nov 21 15:34:09 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(34) Thu Nov 21 15:34:09 2024: Debug: else {
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Peer sent EAP Response (code 2) ID 134 length 161
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Continuing tunnel setup
(34) Thu Nov 21 15:34:09 2024: Debug: [eap] = ok
(34) Thu Nov 21 15:34:09 2024: Debug: } # else = ok
(34) Thu Nov 21 15:34:09 2024: Debug: if (ok) {
(34) Thu Nov 21 15:34:09 2024: Debug: if (ok) -> TRUE
(34) Thu Nov 21 15:34:09 2024: Debug: if (ok) {
(34) Thu Nov 21 15:34:09 2024: Debug: return
(34) Thu Nov 21 15:34:09 2024: Debug: } # if (ok) = ok
(34) Thu Nov 21 15:34:09 2024: Debug: } # authorize = ok
(34) Thu Nov 21 15:34:09 2024: Debug: Found Auth-Type = eap
(34) Thu Nov 21 15:34:09 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(34) Thu Nov 21 15:34:09 2024: Debug: authenticate {
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Expiring EAP session with state 0xba2ef008bae3e943
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Expiring EAP session with state 0xd6c6d814d640c1da
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Finished EAP session with state 0xd6c6d814d640c1da
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814d640c1da, released from the list
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Calling submodule eap_peap to process data
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) EAP Peer says that the final record size will be 151 bytes
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) EAP Got all data (151 bytes)
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - before/accept initialization
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - Server before/accept initialization
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 read client hello A
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 write server hello A
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 write certificate A
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 write key exchange A
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 write server done A
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 flush data
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 read client certificate A
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Server : Need to read more data: SSLv3 read client key exchange A
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Server : Need to read more data: SSLv3 read client key exchange A
(34) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) In Handshake Phase
(34) Thu Nov 21 15:34:09 2024: Debug: eap: Sending EAP Request (code 1) ID 135 length 1014
(34) Thu Nov 21 15:34:09 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814d741c1da
(34) Thu Nov 21 15:34:09 2024: Debug: [eap] = handled
(34) Thu Nov 21 15:34:09 2024: Debug: } # authenticate = handled
(34) Thu Nov 21 15:34:09 2024: Debug: Using Post-Auth-Type Challenge
(34) Thu Nov 21 15:34:09 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(34) Thu Nov 21 15:34:09 2024: Debug: Challenge { ... } # empty sub-section is ignored
(34) Thu Nov 21 15:34:09 2024: Debug: session-state: Saving cached attributes
(34) Thu Nov 21 15:34:09 2024: Debug: Framed-MTU = 1004
(34) Thu Nov 21 15:34:09 2024: Debug: Sent Access-Challenge Id 32 from 100.129.58.1:1812 to 100.129.56.1:37236 length 1092
(34) Thu Nov 21 15:34:09 2024: Debug: Eltex-Tls-Enabled = 0
(34) Thu Nov 21 15:34:09 2024: Debug: EAP-Message = 0x018703f619c00000090f1603030039020000350303056c34d7a2cd4443bf84fdb3787baa9f1292763bb392ba213491760b839487e900c03000000dff01000100000b00040300010216030307710
(34) Thu Nov 21 15:34:09 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(34) Thu Nov 21 15:34:09 2024: Debug: State = 0xd6c6d814d741c1da517e6b54cde2f128
(34) Thu Nov 21 15:34:09 2024: Debug: Finished request
(35) Thu Nov 21 15:34:09 2024: Debug: Received Access-Request Id 33 from 100.129.56.1:37236 to 100.129.58.1:1812 length 272
(35) Thu Nov 21 15:34:09 2024: Debug: User-Name = "tester"
(35) Thu Nov 21 15:34:09 2024: Debug: NAS-IP-Address = 100.129.56.1
(35) Thu Nov 21 15:34:09 2024: Debug: Eltex-Domain = "default"
(35) Thu Nov 21 15:34:09 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(35) Thu Nov 21 15:34:09 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(35) Thu Nov 21 15:34:09 2024: Debug: NAS-Port-Type = Wireless-802.11
(35) Thu Nov 21 15:34:09 2024: Debug: NAS-Port-Id = "10"
(35) Thu Nov 21 15:34:09 2024: Debug: Service-Type = Framed-User
(35) Thu Nov 21 15:34:09 2024: Debug: NAS-Port = 1
(35) Thu Nov 21 15:34:09 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(35) Thu Nov 21 15:34:09 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(35) Thu Nov 21 15:34:09 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(35) Thu Nov 21 15:34:09 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(35) Thu Nov 21 15:34:09 2024: Debug: WLAN-Group-Cipher = 1027076
(35) Thu Nov 21 15:34:09 2024: Debug: WLAN-AKM-Suite = 1027073
(35) Thu Nov 21 15:34:09 2024: Debug: Eltex-AP-Domain = "with-gre"
(35) Thu Nov 21 15:34:09 2024: Debug: Framed-MTU = 1400
(35) Thu Nov 21 15:34:09 2024: Debug: EAP-Message = 0x028700061900
(35) Thu Nov 21 15:34:09 2024: Debug: State = 0xd6c6d814d741c1da517e6b54cde2f128
(35) Thu Nov 21 15:34:09 2024: Debug: Message-Authenticator = 0x9211bd5236d0093375733c66b58cd3c9
(35) Thu Nov 21 15:34:09 2024: Debug: Restoring &session-state
(35) Thu Nov 21 15:34:09 2024: Debug: &session-state:Framed-MTU = 1004
(35) Thu Nov 21 15:34:09 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(35) Thu Nov 21 15:34:09 2024: Debug: authorize {
(35) Thu Nov 21 15:34:09 2024: Debug: policy filter_username {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) -> TRUE
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ / /) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ / /) -> FALSE
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.\./ ) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(35) Thu Nov 21 15:34:09 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(35) Thu Nov 21 15:34:09 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.$/) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@\./) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(35) Thu Nov 21 15:34:09 2024: Debug: } # if (&User-Name) = notfound
(35) Thu Nov 21 15:34:09 2024: Debug: } # policy filter_username = notfound
(35) Thu Nov 21 15:34:09 2024: Debug: [preprocess] = ok
(35) Thu Nov 21 15:34:09 2024: Debug: [chap] = noop
(35) Thu Nov 21 15:34:09 2024: Debug: [mschap] = noop
(35) Thu Nov 21 15:34:09 2024: Debug: [digest] = noop
(35) Thu Nov 21 15:34:09 2024: Debug: suffix: Checking for suffix after "@"
(35) Thu Nov 21 15:34:09 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(35) Thu Nov 21 15:34:09 2024: Debug: suffix: No such realm "NULL"
(35) Thu Nov 21 15:34:09 2024: Debug: [suffix] = noop
(35) Thu Nov 21 15:34:09 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(35) Thu Nov 21 15:34:09 2024: Debug: files_multi: users: Matched entry tester at line 5
(35) Thu Nov 21 15:34:09 2024: Debug: [files_multi] = ok
(35) Thu Nov 21 15:34:09 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(35) Thu Nov 21 15:34:09 2024: Debug: else {
(35) Thu Nov 21 15:34:09 2024: Debug: eap: Peer sent EAP Response (code 2) ID 135 length 6
(35) Thu Nov 21 15:34:09 2024: Debug: eap: Continuing tunnel setup
(35) Thu Nov 21 15:34:09 2024: Debug: [eap] = ok
(35) Thu Nov 21 15:34:09 2024: Debug: } # else = ok
(35) Thu Nov 21 15:34:09 2024: Debug: if (ok) {
(35) Thu Nov 21 15:34:09 2024: Debug: if (ok) -> TRUE
(35) Thu Nov 21 15:34:09 2024: Debug: if (ok) {
(35) Thu Nov 21 15:34:09 2024: Debug: return
(35) Thu Nov 21 15:34:09 2024: Debug: } # if (ok) = ok
(35) Thu Nov 21 15:34:09 2024: Debug: } # authorize = ok
(35) Thu Nov 21 15:34:09 2024: Debug: Found Auth-Type = eap
(35) Thu Nov 21 15:34:09 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(35) Thu Nov 21 15:34:09 2024: Debug: authenticate {
(35) Thu Nov 21 15:34:09 2024: Debug: eap: Expiring EAP session with state 0xd6c6d814d741c1da
(35) Thu Nov 21 15:34:09 2024: Debug: eap: Finished EAP session with state 0xd6c6d814d741c1da
(35) Thu Nov 21 15:34:09 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814d741c1da, released from the list
(35) Thu Nov 21 15:34:09 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(35) Thu Nov 21 15:34:09 2024: Debug: eap: Calling submodule eap_peap to process data
(35) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Peer ACKed our handshake fragment
(35) Thu Nov 21 15:34:09 2024: Debug: eap: Sending EAP Request (code 1) ID 136 length 1010
(35) Thu Nov 21 15:34:09 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814d44ec1da
(35) Thu Nov 21 15:34:09 2024: Debug: [eap] = handled
(35) Thu Nov 21 15:34:09 2024: Debug: } # authenticate = handled
(35) Thu Nov 21 15:34:09 2024: Debug: Using Post-Auth-Type Challenge
(35) Thu Nov 21 15:34:09 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(35) Thu Nov 21 15:34:09 2024: Debug: Challenge { ... } # empty sub-section is ignored
(35) Thu Nov 21 15:34:09 2024: Debug: session-state: Saving cached attributes
(35) Thu Nov 21 15:34:09 2024: Debug: Framed-MTU = 1004
(35) Thu Nov 21 15:34:09 2024: Debug: Sent Access-Challenge Id 33 from 100.129.58.1:1812 to 100.129.56.1:37236 length 1086
(35) Thu Nov 21 15:34:09 2024: Debug: Eltex-Tls-Enabled = 0
(35) Thu Nov 21 15:34:09 2024: Debug: EAP-Message = 0x018803f21940300d06092a864886f70d01010b0500308181310b3009060355040613025255310f300d06035504080c065275737369613114301206035504070c0b4e6f766f7369626972736b314
(35) Thu Nov 21 15:34:09 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(35) Thu Nov 21 15:34:09 2024: Debug: State = 0xd6c6d814d44ec1da517e6b54cde2f128
(35) Thu Nov 21 15:34:09 2024: Debug: Finished request
(36) Thu Nov 21 15:34:09 2024: Debug: Received Access-Request Id 34 from 100.129.56.1:37236 to 100.129.58.1:1812 length 272
(36) Thu Nov 21 15:34:09 2024: Debug: User-Name = "tester"
(36) Thu Nov 21 15:34:09 2024: Debug: NAS-IP-Address = 100.129.56.1
(36) Thu Nov 21 15:34:09 2024: Debug: Eltex-Domain = "default"
(36) Thu Nov 21 15:34:09 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(36) Thu Nov 21 15:34:09 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(36) Thu Nov 21 15:34:09 2024: Debug: NAS-Port-Type = Wireless-802.11
(36) Thu Nov 21 15:34:09 2024: Debug: NAS-Port-Id = "10"
(36) Thu Nov 21 15:34:09 2024: Debug: Service-Type = Framed-User
(36) Thu Nov 21 15:34:09 2024: Debug: NAS-Port = 1
(36) Thu Nov 21 15:34:09 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(36) Thu Nov 21 15:34:09 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(36) Thu Nov 21 15:34:09 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(36) Thu Nov 21 15:34:09 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(36) Thu Nov 21 15:34:09 2024: Debug: WLAN-Group-Cipher = 1027076
(36) Thu Nov 21 15:34:09 2024: Debug: WLAN-AKM-Suite = 1027073
(36) Thu Nov 21 15:34:09 2024: Debug: Eltex-AP-Domain = "with-gre"
(36) Thu Nov 21 15:34:09 2024: Debug: Framed-MTU = 1400
(36) Thu Nov 21 15:34:09 2024: Debug: EAP-Message = 0x028800061900
(36) Thu Nov 21 15:34:09 2024: Debug: State = 0xd6c6d814d44ec1da517e6b54cde2f128
(36) Thu Nov 21 15:34:09 2024: Debug: Message-Authenticator = 0x4bf2d8459c4ec1c30e777a67d2369bc6
(36) Thu Nov 21 15:34:09 2024: Debug: Restoring &session-state
(36) Thu Nov 21 15:34:09 2024: Debug: &session-state:Framed-MTU = 1004
(36) Thu Nov 21 15:34:09 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(36) Thu Nov 21 15:34:09 2024: Debug: authorize {
(36) Thu Nov 21 15:34:09 2024: Debug: policy filter_username {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) -> TRUE
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ / /) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ / /) -> FALSE
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.\./ ) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(36) Thu Nov 21 15:34:09 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(36) Thu Nov 21 15:34:09 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.$/) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@\./) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(36) Thu Nov 21 15:34:09 2024: Debug: } # if (&User-Name) = notfound
(36) Thu Nov 21 15:34:09 2024: Debug: } # policy filter_username = notfound
(36) Thu Nov 21 15:34:09 2024: Debug: [preprocess] = ok
(36) Thu Nov 21 15:34:09 2024: Debug: [chap] = noop
(36) Thu Nov 21 15:34:09 2024: Debug: [mschap] = noop
(36) Thu Nov 21 15:34:09 2024: Debug: [digest] = noop
(36) Thu Nov 21 15:34:09 2024: Debug: suffix: Checking for suffix after "@"
(36) Thu Nov 21 15:34:09 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(36) Thu Nov 21 15:34:09 2024: Debug: suffix: No such realm "NULL"
(36) Thu Nov 21 15:34:09 2024: Debug: [suffix] = noop
(36) Thu Nov 21 15:34:09 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(36) Thu Nov 21 15:34:09 2024: Debug: files_multi: users: Matched entry tester at line 5
(36) Thu Nov 21 15:34:09 2024: Debug: [files_multi] = ok
(36) Thu Nov 21 15:34:09 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(36) Thu Nov 21 15:34:09 2024: Debug: else {
(36) Thu Nov 21 15:34:09 2024: Debug: eap: Peer sent EAP Response (code 2) ID 136 length 6
(36) Thu Nov 21 15:34:09 2024: Debug: eap: Continuing tunnel setup
(36) Thu Nov 21 15:34:09 2024: Debug: [eap] = ok
(36) Thu Nov 21 15:34:09 2024: Debug: } # else = ok
(36) Thu Nov 21 15:34:09 2024: Debug: if (ok) {
(36) Thu Nov 21 15:34:09 2024: Debug: if (ok) -> TRUE
(36) Thu Nov 21 15:34:09 2024: Debug: if (ok) {
(36) Thu Nov 21 15:34:09 2024: Debug: return
(36) Thu Nov 21 15:34:09 2024: Debug: } # if (ok) = ok
(36) Thu Nov 21 15:34:09 2024: Debug: } # authorize = ok
(36) Thu Nov 21 15:34:09 2024: Debug: Found Auth-Type = eap
(36) Thu Nov 21 15:34:09 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(36) Thu Nov 21 15:34:09 2024: Debug: authenticate {
(36) Thu Nov 21 15:34:09 2024: Debug: eap: Expiring EAP session with state 0xd6c6d814d44ec1da
(36) Thu Nov 21 15:34:09 2024: Debug: eap: Finished EAP session with state 0xd6c6d814d44ec1da
(36) Thu Nov 21 15:34:09 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814d44ec1da, released from the list
(36) Thu Nov 21 15:34:09 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(36) Thu Nov 21 15:34:09 2024: Debug: eap: Calling submodule eap_peap to process data
(36) Thu Nov 21 15:34:09 2024: Debug: eap_peap: (TLS) Peer ACKed our handshake fragment
(36) Thu Nov 21 15:34:09 2024: Debug: eap: Sending EAP Request (code 1) ID 137 length 317
(36) Thu Nov 21 15:34:09 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814d54fc1da
(36) Thu Nov 21 15:34:09 2024: Debug: [eap] = handled
(36) Thu Nov 21 15:34:09 2024: Debug: } # authenticate = handled
(36) Thu Nov 21 15:34:09 2024: Debug: Using Post-Auth-Type Challenge
(36) Thu Nov 21 15:34:09 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(36) Thu Nov 21 15:34:09 2024: Debug: Challenge { ... } # empty sub-section is ignored
(36) Thu Nov 21 15:34:09 2024: Debug: session-state: Saving cached attributes
(36) Thu Nov 21 15:34:09 2024: Debug: Framed-MTU = 1004
(36) Thu Nov 21 15:34:09 2024: Debug: Sent Access-Challenge Id 34 from 100.129.58.1:1812 to 100.129.56.1:37236 length 389
(36) Thu Nov 21 15:34:09 2024: Debug: Eltex-Tls-Enabled = 0
(36) Thu Nov 21 15:34:09 2024: Debug: EAP-Message = 0x0189013d1900e90c33a738cccf02dda76e56ee53e2d612e830debd251974be17a02cf62e886c47c93fc1456ba275123e040101005b94113a376be5c27367f6df21134e38b494e5442b45800d7a0
(36) Thu Nov 21 15:34:09 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(36) Thu Nov 21 15:34:09 2024: Debug: State = 0xd6c6d814d54fc1da517e6b54cde2f128
(36) Thu Nov 21 15:34:09 2024: Debug: Finished request
(37) Thu Nov 21 15:34:14 2024: Debug: Received Access-Request Id 35 from 100.129.56.1:37236 to 100.129.58.1:1812 length 402
(37) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(37) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(37) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(37) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(37) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(37) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(37) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(37) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(37) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(37) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(37) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(37) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(37) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(37) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(37) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(37) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(37) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(37) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x0289008819800000007e1603030046100000424104062f114b734c6fa21c06e87a7576c15cbf6f7f8dbf30c1c52d6f726e78f24d06bd1b075797550030c6117b5d1ce0f5b9a41b13705938f833d
(37) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d54fc1da517e6b54cde2f128
(37) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0xef09f27e663784fbc4d7fb0b23be3fdd
(37) Thu Nov 21 15:34:14 2024: Debug: Restoring &session-state
(37) Thu Nov 21 15:34:14 2024: Debug: &session-state:Framed-MTU = 1004
(37) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(37) Thu Nov 21 15:34:14 2024: Debug: authorize {
(37) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(37) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(37) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(37) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(37) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(37) Thu Nov 21 15:34:14 2024: Debug: [preprocess] = ok
(37) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(37) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(37) Thu Nov 21 15:34:14 2024: Debug: [digest] = noop
(37) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(37) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(37) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(37) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(37) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(37) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry tester at line 5
(37) Thu Nov 21 15:34:14 2024: Debug: [files_multi] = ok
(37) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(37) Thu Nov 21 15:34:14 2024: Debug: else {
(37) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 137 length 136
(37) Thu Nov 21 15:34:14 2024: Debug: eap: Continuing tunnel setup
(37) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(37) Thu Nov 21 15:34:14 2024: Debug: } # else = ok
(37) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(37) Thu Nov 21 15:34:14 2024: Debug: if (ok) -> TRUE
(37) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(37) Thu Nov 21 15:34:14 2024: Debug: return
(37) Thu Nov 21 15:34:14 2024: Debug: } # if (ok) = ok
(37) Thu Nov 21 15:34:14 2024: Debug: } # authorize = ok
(37) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(37) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(37) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(37) Thu Nov 21 15:34:14 2024: Debug: eap: Expiring EAP session with state 0xd6c6d814d54fc1da
(37) Thu Nov 21 15:34:14 2024: Debug: eap: Finished EAP session with state 0xd6c6d814d54fc1da
(37) Thu Nov 21 15:34:14 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814d54fc1da, released from the list
(37) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(37) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_peap to process data
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) EAP Peer says that the final record size will be 126 bytes
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) EAP Got all data (126 bytes)
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 read client key exchange A
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 read certificate verify A
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 read finished A
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 write change cipher spec A
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 write finished A
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Handshake state - Server SSLv3 flush data
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Handshake state - SSL negotiation finished successfully
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Connection Established
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(37) Thu Nov 21 15:34:14 2024: Debug: eap_peap: TLS-Session-Version = "TLS 1.2"
(37) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Request (code 1) ID 138 length 57
(37) Thu Nov 21 15:34:14 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814d24cc1da
(37) Thu Nov 21 15:34:14 2024: Debug: [eap] = handled
(37) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = handled
(37) Thu Nov 21 15:34:14 2024: Debug: Using Post-Auth-Type Challenge
(37) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(37) Thu Nov 21 15:34:14 2024: Debug: Challenge { ... } # empty sub-section is ignored
(37) Thu Nov 21 15:34:14 2024: Debug: session-state: Saving cached attributes
(37) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1004
(37) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(37) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Version = "TLS 1.2"
(37) Thu Nov 21 15:34:14 2024: Debug: Sent Access-Challenge Id 35 from 100.129.58.1:1812 to 100.129.56.1:37236 length 127
(37) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(37) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x018a00391900140303000101160303002889966e719344ac9746988eefda7798137249678c7732156f51c4a6312581ae9dfb5cab5b1ab182eb
(37) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(37) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d24cc1da517e6b54cde2f128
(37) Thu Nov 21 15:34:14 2024: Debug: Finished request
(38) Thu Nov 21 15:34:14 2024: Debug: Received Access-Request Id 36 from 100.129.56.1:37236 to 100.129.58.1:1812 length 272
(38) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(38) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(38) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(38) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(38) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(38) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(38) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(38) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(38) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(38) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(38) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(38) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(38) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(38) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(38) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(38) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(38) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(38) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x028a00061900
(38) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d24cc1da517e6b54cde2f128
(38) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x55540bd1180d2b71ccb2613611147157
(38) Thu Nov 21 15:34:14 2024: Debug: Restoring &session-state
(38) Thu Nov 21 15:34:14 2024: Debug: &session-state:Framed-MTU = 1004
(38) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(38) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Version = "TLS 1.2"
(38) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(38) Thu Nov 21 15:34:14 2024: Debug: authorize {
(38) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(38) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(38) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(38) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(38) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(38) Thu Nov 21 15:34:14 2024: Debug: [preprocess] = ok
(38) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(38) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(38) Thu Nov 21 15:34:14 2024: Debug: [digest] = noop
(38) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(38) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(38) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(38) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(38) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(38) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry tester at line 5
(38) Thu Nov 21 15:34:14 2024: Debug: [files_multi] = ok
(38) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(38) Thu Nov 21 15:34:14 2024: Debug: else {
(38) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 138 length 6
(38) Thu Nov 21 15:34:14 2024: Debug: eap: Continuing tunnel setup
(38) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(38) Thu Nov 21 15:34:14 2024: Debug: } # else = ok
(38) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(38) Thu Nov 21 15:34:14 2024: Debug: if (ok) -> TRUE
(38) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(38) Thu Nov 21 15:34:14 2024: Debug: return
(38) Thu Nov 21 15:34:14 2024: Debug: } # if (ok) = ok
(38) Thu Nov 21 15:34:14 2024: Debug: } # authorize = ok
(38) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(38) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(38) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(38) Thu Nov 21 15:34:14 2024: Debug: eap: Expiring EAP session with state 0xd6c6d814d24cc1da
(38) Thu Nov 21 15:34:14 2024: Debug: eap: Finished EAP session with state 0xd6c6d814d24cc1da
(38) Thu Nov 21 15:34:14 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814d24cc1da, released from the list
(38) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(38) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_peap to process data
(38) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) Peer ACKed our handshake fragment. handshake is finished
(38) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Session established. Decoding tunneled attributes
(38) Thu Nov 21 15:34:14 2024: Debug: eap_peap: PEAP state TUNNEL ESTABLISHED
(38) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Request (code 1) ID 139 length 40
(38) Thu Nov 21 15:34:14 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814d34dc1da
(38) Thu Nov 21 15:34:14 2024: Debug: [eap] = handled
(38) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = handled
(38) Thu Nov 21 15:34:14 2024: Debug: Using Post-Auth-Type Challenge
(38) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(38) Thu Nov 21 15:34:14 2024: Debug: Challenge { ... } # empty sub-section is ignored
(38) Thu Nov 21 15:34:14 2024: Debug: session-state: Saving cached attributes
(38) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1004
(38) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(38) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Version = "TLS 1.2"
(38) Thu Nov 21 15:34:14 2024: Debug: Sent Access-Challenge Id 36 from 100.129.58.1:1812 to 100.129.56.1:37236 length 110
(38) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(38) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x018b00281900170303001d89966e719344ac98f850f361870d173ed36fe65f614390b1e5ab900f07
(38) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(38) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d34dc1da517e6b54cde2f128
(38) Thu Nov 21 15:34:14 2024: Debug: Finished request
(39) Thu Nov 21 15:34:14 2024: Debug: Received Access-Request Id 37 from 100.129.56.1:37236 to 100.129.58.1:1812 length 308
(39) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(39) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(39) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(39) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(39) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(39) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(39) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(39) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(39) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(39) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(39) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(39) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(39) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x028b002a1900170303001f126f9cc4d1f2f8310e2667957637c36ced32de7781959f814e57e1addc11c0
(39) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d34dc1da517e6b54cde2f128
(39) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0xd7700cfe8a99e9b13bb7d67c602ad766
(39) Thu Nov 21 15:34:14 2024: Debug: Restoring &session-state
(39) Thu Nov 21 15:34:14 2024: Debug: &session-state:Framed-MTU = 1004
(39) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(39) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Version = "TLS 1.2"
(39) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(39) Thu Nov 21 15:34:14 2024: Debug: authorize {
(39) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(39) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(39) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(39) Thu Nov 21 15:34:14 2024: Debug: [preprocess] = ok
(39) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(39) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(39) Thu Nov 21 15:34:14 2024: Debug: [digest] = noop
(39) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(39) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(39) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(39) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(39) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(39) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry tester at line 5
(39) Thu Nov 21 15:34:14 2024: Debug: [files_multi] = ok
(39) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: else {
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 139 length 42
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Continuing tunnel setup
(39) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(39) Thu Nov 21 15:34:14 2024: Debug: } # else = ok
(39) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (ok) -> TRUE
(39) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(39) Thu Nov 21 15:34:14 2024: Debug: return
(39) Thu Nov 21 15:34:14 2024: Debug: } # if (ok) = ok
(39) Thu Nov 21 15:34:14 2024: Debug: } # authorize = ok
(39) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(39) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(39) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Expiring EAP session with state 0xd6c6d814d34dc1da
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Finished EAP session with state 0xd6c6d814d34dc1da
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814d34dc1da, released from the list
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_peap to process data
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) EAP Done initial handshake
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Session established. Decoding tunneled attributes
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: PEAP state WAITING FOR INNER IDENTITY
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Identity - tester
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got inner identity 'tester'
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Setting default EAP type for tunneled EAP session
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got tunneled request
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x028b000b01746573746572
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Setting User-Name to tester
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Sending tunneled request to inner-tunnel
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x028b000b01746573746572
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: User-Name = "tester"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-IP-Address = 100.129.56.1
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-Domain = "default"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Identifier = "68:13:E2:35:D2:20"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port-Type = Wireless-802.11
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port-Id = "10"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Service-Type = Framed-User
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port = 1
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Connect-Info = "CONNECT 24Mbps 802.11a"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Acct-Session-Id = "073DA111-08E53DB2"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-Pairwise-Cipher = 1027076
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-Group-Cipher = 1027076
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-AKM-Suite = 1027073
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-AP-Domain = "with-gre"
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Framed-MTU = 1400
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Event-Timestamp = "Nov 21 2024 15:34:14 GMT+7"
(39) Thu Nov 21 15:34:14 2024: Debug: Virtual server inner-tunnel received request
(39) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x028b000b01746573746572
(39) Thu Nov 21 15:34:14 2024: Debug: FreeRADIUS-Proxied-To = 127.0.0.1
(39) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(39) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(39) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(39) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(39) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(39) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(39) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(39) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(39) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(39) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(39) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(39) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(39) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(39) Thu Nov 21 15:34:14 2024: Debug: Event-Timestamp = "Nov 21 2024 15:34:14 GMT+7"
(39) Thu Nov 21 15:34:14 2024: WARNING: Outer and inner identities are the same. User privacy is compromised.
(39) Thu Nov 21 15:34:14 2024: Debug: server inner-tunnel {
(39) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
(39) Thu Nov 21 15:34:14 2024: Debug: authorize {
(39) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(39) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(39) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(39) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(39) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(39) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(39) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(39) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(39) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(39) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(39) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 139 length 11
(39) Thu Nov 21 15:34:14 2024: Debug: eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(39) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(39) Thu Nov 21 15:34:14 2024: Debug: } # authorize = ok
(39) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(39) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
(39) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP Identity (1)
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_mschapv2 to process data
(39) Thu Nov 21 15:34:14 2024: Debug: eap_mschapv2: Issuing Challenge
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Request (code 1) ID 140 length 43
(39) Thu Nov 21 15:34:14 2024: Debug: eap: EAP session adding &reply:State = 0x73c34f14734f5598
(39) Thu Nov 21 15:34:14 2024: Debug: [eap] = handled
(39) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = handled
(39) Thu Nov 21 15:34:14 2024: Debug: } # server inner-tunnel
(39) Thu Nov 21 15:34:14 2024: Debug: Virtual server sending reply
(39) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x018c002b1a018c00261029f35ca9eb06d27f3cb6a0fcbfbc9f98667265657261646975732d332e302e3235
(39) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(39) Thu Nov 21 15:34:14 2024: Debug: State = 0x73c34f14734f5598209f4f525a078ea5
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got tunneled reply code 11
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x018c002b1a018c00261029f35ca9eb06d27f3cb6a0fcbfbc9f98667265657261646975732d332e302e3235
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: State = 0x73c34f14734f5598209f4f525a078ea5
(39) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got tunneled Access-Challenge
(39) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Request (code 1) ID 140 length 74
(39) Thu Nov 21 15:34:14 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814d04ac1da
(39) Thu Nov 21 15:34:14 2024: Debug: [eap] = handled
(39) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = handled
(39) Thu Nov 21 15:34:14 2024: Debug: Using Post-Auth-Type Challenge
(39) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(39) Thu Nov 21 15:34:14 2024: Debug: Challenge { ... } # empty sub-section is ignored
(39) Thu Nov 21 15:34:14 2024: Debug: session-state: Saving cached attributes
(39) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1004
(39) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(39) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Version = "TLS 1.2"
(39) Thu Nov 21 15:34:14 2024: Debug: Sent Access-Challenge Id 37 from 100.129.58.1:1812 to 100.129.56.1:37236 length 144
(39) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(39) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x018c004a1900170303003f89966e719344ac99e939d773930e064bd033b593033706bea8aec6d4cd24d0bf543cbad16b9719d94345c1eab84515cb6dd852bb943f855b6f710a6337cb1d
(39) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(39) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d04ac1da517e6b54cde2f128
(39) Thu Nov 21 15:34:14 2024: Debug: Finished request
(40) Thu Nov 21 15:34:14 2024: Debug: Received Access-Request Id 38 from 100.129.56.1:37236 to 100.129.58.1:1812 length 362
(40) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(40) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(40) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(40) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(40) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(40) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(40) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(40) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(40) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(40) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(40) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(40) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(40) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x028c006019001703030055126f9cc4d1f2f83261a51a42029098784c64cb1d267f8fc01cc65f9eae5cc6ffb7b2ad1e394575d739bf9f12051c16b587a1247b3c1ba27b02d868c470842e31031dc
(40) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d04ac1da517e6b54cde2f128
(40) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x3c5f1f1b33a3d189d133901ba166f8e4
(40) Thu Nov 21 15:34:14 2024: Debug: Restoring &session-state
(40) Thu Nov 21 15:34:14 2024: Debug: &session-state:Framed-MTU = 1004
(40) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(40) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Version = "TLS 1.2"
(40) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(40) Thu Nov 21 15:34:14 2024: Debug: authorize {
(40) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(40) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(40) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(40) Thu Nov 21 15:34:14 2024: Debug: [preprocess] = ok
(40) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: [digest] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(40) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(40) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(40) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(40) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry tester at line 5
(40) Thu Nov 21 15:34:14 2024: Debug: [files_multi] = ok
(40) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: else {
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 140 length 96
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Continuing tunnel setup
(40) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(40) Thu Nov 21 15:34:14 2024: Debug: } # else = ok
(40) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (ok) -> TRUE
(40) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(40) Thu Nov 21 15:34:14 2024: Debug: return
(40) Thu Nov 21 15:34:14 2024: Debug: } # if (ok) = ok
(40) Thu Nov 21 15:34:14 2024: Debug: } # authorize = ok
(40) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(40) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(40) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Expiring EAP session with state 0x73c34f14734f5598
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Finished EAP session with state 0xd6c6d814d04ac1da
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814d04ac1da, released from the list
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_peap to process data
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) EAP Done initial handshake
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Session established. Decoding tunneled attributes
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: PEAP state phase2
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP method MSCHAPv2 (26)
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got tunneled request
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x028c00411a028c003c31f49491c79b94785aea350343b0b0e1910000000000000000c5ae22e446e2f7e9a56cfd03b5a5fd6d08ca17d41d1a5f0300746573746572
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Setting User-Name to tester
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Sending tunneled request to inner-tunnel
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x028c00411a028c003c31f49491c79b94785aea350343b0b0e1910000000000000000c5ae22e446e2f7e9a56cfd03b5a5fd6d08ca17d41d1a5f0300746573746572
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: User-Name = "tester"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: State = 0x73c34f14734f5598209f4f525a078ea5
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-IP-Address = 100.129.56.1
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-Domain = "default"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Identifier = "68:13:E2:35:D2:20"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port-Type = Wireless-802.11
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port-Id = "10"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Service-Type = Framed-User
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port = 1
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Connect-Info = "CONNECT 24Mbps 802.11a"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Acct-Session-Id = "073DA111-08E53DB2"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-Pairwise-Cipher = 1027076
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-Group-Cipher = 1027076
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-AKM-Suite = 1027073
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-AP-Domain = "with-gre"
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Framed-MTU = 1400
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Event-Timestamp = "Nov 21 2024 15:34:14 GMT+7"
(40) Thu Nov 21 15:34:14 2024: Debug: Virtual server inner-tunnel received request
(40) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x028c00411a028c003c31f49491c79b94785aea350343b0b0e1910000000000000000c5ae22e446e2f7e9a56cfd03b5a5fd6d08ca17d41d1a5f0300746573746572
(40) Thu Nov 21 15:34:14 2024: Debug: FreeRADIUS-Proxied-To = 127.0.0.1
(40) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(40) Thu Nov 21 15:34:14 2024: Debug: State = 0x73c34f14734f5598209f4f525a078ea5
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(40) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(40) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(40) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(40) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(40) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(40) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(40) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(40) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(40) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(40) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(40) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(40) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(40) Thu Nov 21 15:34:14 2024: Debug: Event-Timestamp = "Nov 21 2024 15:34:14 GMT+7"
(40) Thu Nov 21 15:34:14 2024: WARNING: Outer and inner identities are the same. User privacy is compromised.
(40) Thu Nov 21 15:34:14 2024: Debug: server inner-tunnel {
(40) Thu Nov 21 15:34:14 2024: Debug: session-state: No cached attributes
(40) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
(40) Thu Nov 21 15:34:14 2024: Debug: authorize {
(40) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(40) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(40) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(40) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(40) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(40) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(40) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(40) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(40) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 140 length 65
(40) Thu Nov 21 15:34:14 2024: Debug: eap: No EAP Start, assuming it's an on-going EAP conversation
(40) Thu Nov 21 15:34:14 2024: Debug: [eap] = updated
(40) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(40) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry tester at line 5
(40) Thu Nov 21 15:34:14 2024: Debug: [files_multi] = ok
(40) Thu Nov 21 15:34:14 2024: Debug: [expiration] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: [logintime] = noop
(40) Thu Nov 21 15:34:14 2024: WARNING: pap: Auth-Type already set. Not setting to PAP
(40) Thu Nov 21 15:34:14 2024: Debug: [pap] = noop
(40) Thu Nov 21 15:34:14 2024: Debug: } # authorize = updated
(40) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(40) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
(40) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Expiring EAP session with state 0x73c34f14734f5598
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Finished EAP session with state 0x73c34f14734f5598
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Previous EAP request found for state 0x73c34f14734f5598, released from the list
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP MSCHAPv2 (26)
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_mschapv2 to process data
(40) Thu Nov 21 15:34:14 2024: Debug: eap_mschapv2: # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
(40) Thu Nov 21 15:34:14 2024: Debug: eap_mschapv2: authenticate {
(40) Thu Nov 21 15:34:14 2024: Debug: mschap: Found Cleartext-Password, hashing to create NT-Password
(40) Thu Nov 21 15:34:14 2024: Debug: mschap: Creating challenge hash with username: tester
(40) Thu Nov 21 15:34:14 2024: Debug: mschap: Client is using MS-CHAPv2
(40) Thu Nov 21 15:34:14 2024: Debug: mschap: Adding MS-CHAPv2 MPPE keys
(40) Thu Nov 21 15:34:14 2024: Debug: eap_mschapv2: [mschap] = ok
(40) Thu Nov 21 15:34:14 2024: Debug: eap_mschapv2: } # authenticate = ok
(40) Thu Nov 21 15:34:14 2024: Debug: eap_mschapv2: MSCHAP Success
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Request (code 1) ID 141 length 51
(40) Thu Nov 21 15:34:14 2024: Debug: eap: EAP session adding &reply:State = 0x73c34f14724e5598
(40) Thu Nov 21 15:34:14 2024: Debug: [eap] = handled
(40) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = handled
(40) Thu Nov 21 15:34:14 2024: Debug: } # server inner-tunnel
(40) Thu Nov 21 15:34:14 2024: Debug: Virtual server sending reply
(40) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(40) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x018d00331a038c002e533d39354232443738333534413844394239323646343137334234443336433636443346353239323633
(40) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(40) Thu Nov 21 15:34:14 2024: Debug: State = 0x73c34f14724e5598209f4f525a078ea5
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got tunneled reply code 11
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-Tls-Enabled = 0
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x018d00331a038c002e533d39354232443738333534413844394239323646343137334234443336433636443346353239323633
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: State = 0x73c34f14724e5598209f4f525a078ea5
(40) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got tunneled Access-Challenge
(40) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Request (code 1) ID 141 length 82
(40) Thu Nov 21 15:34:14 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814d14bc1da
(40) Thu Nov 21 15:34:14 2024: Debug: [eap] = handled
(40) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = handled
(40) Thu Nov 21 15:34:14 2024: Debug: Using Post-Auth-Type Challenge
(40) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(40) Thu Nov 21 15:34:14 2024: Debug: Challenge { ... } # empty sub-section is ignored
(40) Thu Nov 21 15:34:14 2024: Debug: session-state: Saving cached attributes
(40) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1004
(40) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(40) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Version = "TLS 1.2"
(40) Thu Nov 21 15:34:14 2024: Debug: Sent Access-Challenge Id 38 from 100.129.58.1:1812 to 100.129.56.1:37236 length 152
(40) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(40) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x018d00521900170303004789966e719344ac9af15a53fdbc7ddd326dbb2077c4408506c914b95ba44cd77fbb7e6cb22459ac676effd3c6f5765c6bd5c649e3c1d850390aa630ee9738d0ebfcae8
(40) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(40) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d14bc1da517e6b54cde2f128
(40) Thu Nov 21 15:34:14 2024: Debug: Finished request
(41) Thu Nov 21 15:34:14 2024: Debug: Received Access-Request Id 39 from 100.129.56.1:37236 to 100.129.58.1:1812 length 303
(41) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(41) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(41) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(41) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(41) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(41) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(41) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(41) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(41) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(41) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(41) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(41) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(41) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x028d00251900170303001a126f9cc4d1f2f833c2f45c7003974c78f59be6590bd4cd7aef19
(41) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814d14bc1da517e6b54cde2f128
(41) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0xdf7e4ecdc69f4f27b35460f818113c1b
(41) Thu Nov 21 15:34:14 2024: Debug: Restoring &session-state
(41) Thu Nov 21 15:34:14 2024: Debug: &session-state:Framed-MTU = 1004
(41) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(41) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Version = "TLS 1.2"
(41) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(41) Thu Nov 21 15:34:14 2024: Debug: authorize {
(41) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(41) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(41) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(41) Thu Nov 21 15:34:14 2024: Debug: [preprocess] = ok
(41) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: [digest] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(41) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(41) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(41) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(41) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry tester at line 5
(41) Thu Nov 21 15:34:14 2024: Debug: [files_multi] = ok
(41) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: else {
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 141 length 37
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Continuing tunnel setup
(41) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(41) Thu Nov 21 15:34:14 2024: Debug: } # else = ok
(41) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (ok) -> TRUE
(41) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(41) Thu Nov 21 15:34:14 2024: Debug: return
(41) Thu Nov 21 15:34:14 2024: Debug: } # if (ok) = ok
(41) Thu Nov 21 15:34:14 2024: Debug: } # authorize = ok
(41) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(41) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(41) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Expiring EAP session with state 0x73c34f14724e5598
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Finished EAP session with state 0xd6c6d814d14bc1da
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814d14bc1da, released from the list
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_peap to process data
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) EAP Done initial handshake
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Session established. Decoding tunneled attributes
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: PEAP state phase2
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP method MSCHAPv2 (26)
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got tunneled request
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x028d00061a03
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Setting User-Name to tester
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Sending tunneled request to inner-tunnel
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x028d00061a03
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: User-Name = "tester"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: State = 0x73c34f14724e5598209f4f525a078ea5
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-IP-Address = 100.129.56.1
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-Domain = "default"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Identifier = "68:13:E2:35:D2:20"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port-Type = Wireless-802.11
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port-Id = "10"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Service-Type = Framed-User
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: NAS-Port = 1
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Connect-Info = "CONNECT 24Mbps 802.11a"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Acct-Session-Id = "073DA111-08E53DB2"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-Pairwise-Cipher = 1027076
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-Group-Cipher = 1027076
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: WLAN-AKM-Suite = 1027073
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-AP-Domain = "with-gre"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Framed-MTU = 1400
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Event-Timestamp = "Nov 21 2024 15:34:14 GMT+7"
(41) Thu Nov 21 15:34:14 2024: Debug: Virtual server inner-tunnel received request
(41) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x028d00061a03
(41) Thu Nov 21 15:34:14 2024: Debug: FreeRADIUS-Proxied-To = 127.0.0.1
(41) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(41) Thu Nov 21 15:34:14 2024: Debug: State = 0x73c34f14724e5598209f4f525a078ea5
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(41) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(41) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(41) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(41) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(41) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(41) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(41) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(41) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(41) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(41) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(41) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(41) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(41) Thu Nov 21 15:34:14 2024: Debug: Event-Timestamp = "Nov 21 2024 15:34:14 GMT+7"
(41) Thu Nov 21 15:34:14 2024: WARNING: Outer and inner identities are the same. User privacy is compromised.
(41) Thu Nov 21 15:34:14 2024: Debug: server inner-tunnel {
(41) Thu Nov 21 15:34:14 2024: Debug: session-state: No cached attributes
(41) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
(41) Thu Nov 21 15:34:14 2024: Debug: authorize {
(41) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(41) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(41) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(41) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(41) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(41) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(41) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 141 length 6
(41) Thu Nov 21 15:34:14 2024: Debug: eap: No EAP Start, assuming it's an on-going EAP conversation
(41) Thu Nov 21 15:34:14 2024: Debug: [eap] = updated
(41) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(41) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry tester at line 5
(41) Thu Nov 21 15:34:14 2024: Debug: [files_multi] = ok
(41) Thu Nov 21 15:34:14 2024: Debug: [expiration] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: [logintime] = noop
(41) Thu Nov 21 15:34:14 2024: WARNING: pap: Auth-Type already set. Not setting to PAP
(41) Thu Nov 21 15:34:14 2024: Debug: [pap] = noop
(41) Thu Nov 21 15:34:14 2024: Debug: } # authorize = updated
(41) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(41) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
(41) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Expiring EAP session with state 0x73c34f14724e5598
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Finished EAP session with state 0x73c34f14724e5598
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Previous EAP request found for state 0x73c34f14724e5598, released from the list
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP MSCHAPv2 (26)
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_mschapv2 to process data
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Success (code 3) ID 141 length 4
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Freeing handler
(41) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(41) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = ok
(41) Thu Nov 21 15:34:14 2024: Debug: # Executing section post-auth from file /etc/raddb/sites-enabled/inner-tunnel
(41) Thu Nov 21 15:34:14 2024: Debug: post-auth {
(41) Thu Nov 21 15:34:14 2024: Debug: if (0) {
(41) Thu Nov 21 15:34:14 2024: Debug: if (0) -> FALSE
(41) Thu Nov 21 15:34:14 2024: Debug: } # post-auth = noop
(41) Thu Nov 21 15:34:14 2024: Debug: } # server inner-tunnel
(41) Thu Nov 21 15:34:14 2024: Debug: Virtual server sending reply
(41) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(41) Thu Nov 21 15:34:14 2024: Debug: MS-MPPE-Encryption-Policy = Encryption-Allowed
(41) Thu Nov 21 15:34:14 2024: Debug: MS-MPPE-Encryption-Types = RC4-40or128-bit-Allowed
(41) Thu Nov 21 15:34:14 2024: Debug: MS-MPPE-Send-Key = 0xa1b0f8364771b07393ee9c7191c09627
(41) Thu Nov 21 15:34:14 2024: Debug: MS-MPPE-Recv-Key = 0xcf76ef2300c319b73c9c69ad346871db
(41) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x038d0004
(41) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(41) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Got tunneled reply code 2
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-Tls-Enabled = 0
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: MS-MPPE-Encryption-Policy = Encryption-Allowed
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: MS-MPPE-Encryption-Types = RC4-40or128-bit-Allowed
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: MS-MPPE-Send-Key = 0xa1b0f8364771b07393ee9c7191c09627
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: MS-MPPE-Recv-Key = 0xcf76ef2300c319b73c9c69ad346871db
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: EAP-Message = 0x038d0004
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: User-Name = "tester"
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Tunneled authentication was successful
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: SUCCESS
(41) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Saving tunneled attributes for later
(41) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Request (code 1) ID 142 length 46
(41) Thu Nov 21 15:34:14 2024: Debug: eap: EAP session adding &reply:State = 0xd6c6d814de48c1da
(41) Thu Nov 21 15:34:14 2024: Debug: [eap] = handled
(41) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = handled
(41) Thu Nov 21 15:34:14 2024: Debug: Using Post-Auth-Type Challenge
(41) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(41) Thu Nov 21 15:34:14 2024: Debug: Challenge { ... } # empty sub-section is ignored
(41) Thu Nov 21 15:34:14 2024: Debug: session-state: Saving cached attributes
(41) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1004
(41) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(41) Thu Nov 21 15:34:14 2024: Debug: TLS-Session-Version = "TLS 1.2"
(41) Thu Nov 21 15:34:14 2024: Debug: Sent Access-Challenge Id 39 from 100.129.58.1:1812 to 100.129.56.1:37236 length 116
(41) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(41) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x018e002e1900170303002389966e719344ac9b8267c67f9750e7bb519cb3f6257935d203dc4994d8e9d0d2b36a60
(41) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(41) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814de48c1da517e6b54cde2f128
(41) Thu Nov 21 15:34:14 2024: Debug: Finished request
(42) Thu Nov 21 15:34:14 2024: Debug: Received Access-Request Id 40 from 100.129.56.1:37236 to 100.129.58.1:1812 length 312
(42) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(42) Thu Nov 21 15:34:14 2024: Debug: NAS-IP-Address = 100.129.56.1
(42) Thu Nov 21 15:34:14 2024: Debug: Eltex-Domain = "default"
(42) Thu Nov 21 15:34:14 2024: Debug: NAS-Identifier = "68:13:E2:35:D2:20"
(42) Thu Nov 21 15:34:14 2024: Debug: Called-Station-Id = "68-13-E2-35-D2-20:TEST-SSID-WLC-15"
(42) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Type = Wireless-802.11
(42) Thu Nov 21 15:34:14 2024: Debug: NAS-Port-Id = "10"
(42) Thu Nov 21 15:34:14 2024: Debug: Service-Type = Framed-User
(42) Thu Nov 21 15:34:14 2024: Debug: NAS-Port = 1
(42) Thu Nov 21 15:34:14 2024: Debug: Calling-Station-Id = "DA-A7-8A-41-68-F5"
(42) Thu Nov 21 15:34:14 2024: Debug: Connect-Info = "CONNECT 24Mbps 802.11a"
(42) Thu Nov 21 15:34:14 2024: Debug: Acct-Session-Id = "073DA111-08E53DB2"
(42) Thu Nov 21 15:34:14 2024: Debug: WLAN-Pairwise-Cipher = 1027076
(42) Thu Nov 21 15:34:14 2024: Debug: WLAN-Group-Cipher = 1027076
(42) Thu Nov 21 15:34:14 2024: Debug: WLAN-AKM-Suite = 1027073
(42) Thu Nov 21 15:34:14 2024: Debug: Eltex-AP-Domain = "with-gre"
(42) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU = 1400
(42) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x028e002e19001703030023126f9cc4d1f2f83408287a1e257f531796457aef03f619f341ea20ffc3f42c04759a27
(42) Thu Nov 21 15:34:14 2024: Debug: State = 0xd6c6d814de48c1da517e6b54cde2f128
(42) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x48ba664f6a34ca3f75cf6dc1827a2fea
(42) Thu Nov 21 15:34:14 2024: Debug: Restoring &session-state
(42) Thu Nov 21 15:34:14 2024: Debug: &session-state:Framed-MTU = 1004
(42) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(42) Thu Nov 21 15:34:14 2024: Debug: &session-state:TLS-Session-Version = "TLS 1.2"
(42) Thu Nov 21 15:34:14 2024: Debug: # Executing section authorize from file /etc/raddb/sites-enabled/_default
(42) Thu Nov 21 15:34:14 2024: Debug: authorize {
(42) Thu Nov 21 15:34:14 2024: Debug: policy filter_username {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) -> TRUE
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ / /) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.\./ ) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) {
(42) Thu Nov 21 15:34:14 2024: Debug: if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/)) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /\.$/) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&User-Name =~ /@\./) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: } # if (&User-Name) = notfound
(42) Thu Nov 21 15:34:14 2024: Debug: } # policy filter_username = notfound
(42) Thu Nov 21 15:34:14 2024: Debug: [preprocess] = ok
(42) Thu Nov 21 15:34:14 2024: Debug: [chap] = noop
(42) Thu Nov 21 15:34:14 2024: Debug: [mschap] = noop
(42) Thu Nov 21 15:34:14 2024: Debug: [digest] = noop
(42) Thu Nov 21 15:34:14 2024: Debug: suffix: Checking for suffix after "@"
(42) Thu Nov 21 15:34:14 2024: Debug: suffix: No '@' in User-Name = "tester", looking up realm NULL
(42) Thu Nov 21 15:34:14 2024: Debug: suffix: No such realm "NULL"
(42) Thu Nov 21 15:34:14 2024: Debug: [suffix] = noop
(42) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry DEFAULT at line 1
(42) Thu Nov 21 15:34:14 2024: Debug: files_multi: users: Matched entry tester at line 5
(42) Thu Nov 21 15:34:14 2024: Debug: [files_multi] = ok
(42) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&reply:Eltex-Tls-Enabled == 1) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: else {
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent EAP Response (code 2) ID 142 length 46
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Continuing tunnel setup
(42) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(42) Thu Nov 21 15:34:14 2024: Debug: } # else = ok
(42) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (ok) -> TRUE
(42) Thu Nov 21 15:34:14 2024: Debug: if (ok) {
(42) Thu Nov 21 15:34:14 2024: Debug: return
(42) Thu Nov 21 15:34:14 2024: Debug: } # if (ok) = ok
(42) Thu Nov 21 15:34:14 2024: Debug: } # authorize = ok
(42) Thu Nov 21 15:34:14 2024: Debug: Found Auth-Type = eap
(42) Thu Nov 21 15:34:14 2024: Debug: # Executing group from file /etc/raddb/sites-enabled/_default
(42) Thu Nov 21 15:34:14 2024: Debug: authenticate {
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Expiring EAP session with state 0xd6c6d814de48c1da
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Finished EAP session with state 0xd6c6d814de48c1da
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Previous EAP request found for state 0xd6c6d814de48c1da, released from the list
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Peer sent packet with method EAP PEAP (25)
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Calling submodule eap_peap to process data
(42) Thu Nov 21 15:34:14 2024: Debug: eap_peap: (TLS) EAP Done initial handshake
(42) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Session established. Decoding tunneled attributes
(42) Thu Nov 21 15:34:14 2024: Debug: eap_peap: PEAP state send tlv success
(42) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Received EAP-TLV response
(42) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Success
(42) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Using saved attributes from the original Access-Accept
(42) Thu Nov 21 15:34:14 2024: Debug: eap_peap: Eltex-Tls-Enabled = 0
(42) Thu Nov 21 15:34:14 2024: Debug: eap_peap: User-Name = "tester"
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Sending EAP Success (code 3) ID 142 length 4
(42) Thu Nov 21 15:34:14 2024: Debug: eap: Freeing handler
(42) Thu Nov 21 15:34:14 2024: Debug: [eap] = ok
(42) Thu Nov 21 15:34:14 2024: Debug: } # authenticate = ok
(42) Thu Nov 21 15:34:14 2024: Debug: # Executing section post-auth from file /etc/raddb/sites-enabled/_default
(42) Thu Nov 21 15:34:14 2024: Debug: post-auth {
(42) Thu Nov 21 15:34:14 2024: Debug: if (session-state:User-Name && reply:User-Name && request:User-Name && (reply:User-Name == request:User-Name)) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (session-state:User-Name && reply:User-Name && request:User-Name && (reply:User-Name == request:User-Name)) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: update {
(42) Thu Nov 21 15:34:14 2024: Debug: } # update = noop
(42) Thu Nov 21 15:34:14 2024: Debug: [exec] = noop
(42) Thu Nov 21 15:34:14 2024: Debug: policy remove_reply_message_if_eap {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&reply:EAP-Message && &reply:Reply-Message) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: else {
(42) Thu Nov 21 15:34:14 2024: Debug: [noop] = noop
(42) Thu Nov 21 15:34:14 2024: Debug: } # else = noop
(42) Thu Nov 21 15:34:14 2024: Debug: } # policy remove_reply_message_if_eap = noop
(42) Thu Nov 21 15:34:14 2024: Debug: if (EAP-Key-Name && &reply:EAP-Session-Id) {
(42) Thu Nov 21 15:34:14 2024: Debug: if (EAP-Key-Name && &reply:EAP-Session-Id) -> FALSE
(42) Thu Nov 21 15:34:14 2024: Debug: update reply {
(42) Thu Nov 21 15:34:14 2024: Debug: } # update reply = noop
(42) Thu Nov 21 15:34:14 2024: Debug: } # post-auth = noop
(42) Thu Nov 21 15:34:14 2024: Debug: Sent Access-Accept Id 40 from 100.129.58.1:1812 to 100.129.56.1:37236 length 198 <------------------------------------------------ Access-Accept пользователь успешно авторизован
(42) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(42) Thu Nov 21 15:34:14 2024: Debug: Eltex-Tls-Enabled = 0
(42) Thu Nov 21 15:34:14 2024: Debug: User-Name = "tester"
(42) Thu Nov 21 15:34:14 2024: Debug: MS-MPPE-Recv-Key = 0xf396c52ff7d711df6e4a0d232d3224dc45afe1533f7042754905fe2081b10869
(42) Thu Nov 21 15:34:14 2024: Debug: MS-MPPE-Send-Key = 0x37006c121c188e56215bda352b9806ea837ecd042cae84dfb7cc7815d5f15802
(42) Thu Nov 21 15:34:14 2024: Debug: EAP-Message = 0x038e0004
(42) Thu Nov 21 15:34:14 2024: Debug: Message-Authenticator = 0x00000000000000000000000000000000
(42) Thu Nov 21 15:34:14 2024: Debug: Framed-MTU += 1004
(42) Thu Nov 21 15:34:14 2024: Debug: Finished request
(33) Thu Nov 21 15:34:14 2024: Debug: Cleaning up request packet ID 31 with timestamp +8808
(34) Thu Nov 21 15:34:14 2024: Debug: Cleaning up request packet ID 32 with timestamp +8808
(35) Thu Nov 21 15:34:14 2024: Debug: Cleaning up request packet ID 33 with timestamp +8808
(36) Thu Nov 21 15:34:14 2024: Debug: Cleaning up request packet ID 34 with timestamp +8808
(37) Thu Nov 21 15:34:19 2024: Debug: Cleaning up request packet ID 35 with timestamp +8813
(38) Thu Nov 21 15:34:19 2024: Debug: Cleaning up request packet ID 36 with timestamp +8813
(39) Thu Nov 21 15:34:19 2024: Debug: Cleaning up request packet ID 37 with timestamp +8813
(40) Thu Nov 21 15:34:19 2024: Debug: Cleaning up request packet ID 38 with timestamp +8813
(41) Thu Nov 21 15:34:19 2024: Debug: Cleaning up request packet ID 39 with timestamp +8813
(42) Thu Nov 21 15:34:19 2024: Debug: Cleaning up request packet ID 40 with timestamp +8813 |