Re: Timeout and TLS handshake

Sam Hutchings <[email protected]>
Newsgroups gmane.comp.freeradius.user
Message-ID <CABAo4z==-hvYV5ebxNrL-kLENm015B+pVmed1BVdCPjcMoTNjA@mail.gmail.com>
Thank you for the advice.

I have flagged this with Azure support and we are currently in
discussions with enabling 'enable-udp-fragment-reordering'.

Ideally, we would not want to fragment UDP packets but as we are using
EAP, this seems to be expected. However, we are currently including
the root CA currently in the certificate_file variable in eap, which
as per the docs we should remove this to reduce the data exchange
during TLS negotiation. Therefore, I will test again without the root
CA cert, to see if we have a higher success rate.

Thanks again,
Sam

On Wed, Apr 2, 2025 at 1:54 AM George Benjin <[email protected]> wrote:
>
> I haven't run up FreeRADIUS in ACA or ACI but suspect it might be due
> to this: https://lists.freeradius.org/pipermail/freeradius-users/2024-September/104753.html
>
> >>>
>
> You need to be very careful running a RADIUS server in Azure if you're
> using RADIUS/UDP.
>
> Azure has a network security feature on by default that drops
> fragmented UDP packets that arrive out of order. This negatively
> impacts RADIUS/UDP traffic.
>
> To give you an example, at least 20% of EAP-TLS auth attempts were
> failing for us in the cert auth phase due to this issue.
>
> Azure support can turn on the 'enable-udp-fragment-reordering' feature
> by request after providing packet captures and use case info etc. They
> will also only turn it on in a brand new subscription that's dedicated
> to running VMs that require this feature. After we did this, our auth
> success rate increased to 100%.
>
>
> Another thing to be wary of is setting 'tls_max_version' to 1.3.
> Windows 11 supports TLS 1.3 by default for EAP-TLS etc but does not
> yet support session resumption when using this protocol (see
> https://learn.microsoft.com/en-us/windows-server/networking/technologies/extensible-authentication-protocol/windows-11-changes).
> It's worth dropping the Max version to 1.2.
>
> >>>
>
> Try implementing RadSec if your equipment supports it.
>
> On Wed, 2 Apr 2025 at 01:47, Sam Hutchings <[email protected]> wrote:
> >
> > Hi,
> >
> > Please can you advise why the connection is not succeeding?
> >
> > The Problem:
> > A Windows client is not succeeding authentication and the debug does
> > not show that the TLS handshake completes over WAN; the server is
> > hosted in Azure Container Instance. I have tested the same container
> > locally on the LAN which is working OK (docker container running on a
> > VM with a separate laptop with 802.1x configured with a switch set as
> > the NAC).
> >
> > I can see the TLS handshake when comparing to a working example seems
> > to be missing the below:
> >
> > (6)   &session-state:TLS-Session-Cipher-Suite = "TLS_AES_256_GCM_SHA384"
> > (6)   &session-state:TLS-Session-Version = "TLS 1.3"
> > (6)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Finished"
> >
> > What you are trying to do:  Authenticate a Windows client via 802.1X
> > with EAP-TLS over the internet to an Azure Container Instance running
> > freeRADIUS.
> >
> > This is behind a load balancer with a public IP, which includes a
> > health check on port 8080. This works when using eapol_test but not
> > when using Windows authentication. Although, this works for both
> > Windows and eapol_test when running the container on the local
> > network.
> >
> > why you are trying to do it: Understand why this fails the TLS
> > handshake over the internet.
> >
> > what you expect the server to do: TLS handshake to complete and
> > authentication request to receive an Access-Accept
> >
> > what the server does instead (i.e. debug output):
> >
> > FreeRADIUS Version 3.2.7
> > Copyright (C) 1999-2023 The FreeRADIUS server project and contributors
> > There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
> > PARTICULAR PURPOSE
> > You may redistribute copies of FreeRADIUS under the terms of the
> > GNU General Public License
> > For more information about these matters, see the file named COPYRIGHT
> > Starting - reading configuration files ...
> > including dictionary file /usr/share/freeradius/dictionary
> > including dictionary file /usr/share/freeradius/dictionary.dhcp
> > including dictionary file /usr/share/freeradius/dictionary.vqp
> > including dictionary file /etc/freeradius/dictionary
> > including configuration file /etc/freeradius/radiusd.conf
> > including configuration file /etc/freeradius/proxy.conf
> > including configuration file /etc/freeradius/clients.conf
> > including files in directory /etc/freeradius/mods-enabled/
> > including configuration file /etc/freeradius/mods-enabled/always
> > including configuration file /etc/freeradius/mods-enabled/attr_filter
> > including configuration file /etc/freeradius/mods-enabled/chap
> > including configuration file /etc/freeradius/mods-enabled/date
> > including configuration file /etc/freeradius/mods-enabled/detail
> > including configuration file /etc/freeradius/mods-enabled/detail.log
> > including configuration file /etc/freeradius/mods-enabled/digest
> > including configuration file /etc/freeradius/mods-enabled/dynamic_clients
> > including configuration file /etc/freeradius/mods-enabled/eap
> > including configuration file /etc/freeradius/mods-enabled/echo
> > including configuration file /etc/freeradius/mods-enabled/exec
> > including configuration file /etc/freeradius/mods-enabled/expiration
> > including configuration file /etc/freeradius/mods-enabled/expr
> > including configuration file /etc/freeradius/mods-enabled/files
> > including configuration file /etc/freeradius/mods-enabled/linelog
> > including configuration file /etc/freeradius/mods-enabled/logintime
> > including configuration file /etc/freeradius/mods-enabled/mschap
> > including configuration file /etc/freeradius/mods-enabled/ntlm_auth
> > including configuration file /etc/freeradius/mods-enabled/pap
> > including configuration file /etc/freeradius/mods-enabled/passwd
> > including configuration file /etc/freeradius/mods-enabled/preprocess
> > including configuration file /etc/freeradius/mods-enabled/proxy_rate_limit
> > including configuration file /etc/freeradius/mods-enabled/radutmp
> > including configuration file /etc/freeradius/mods-enabled/realm
> > including configuration file /etc/freeradius/mods-enabled/replicate
> > including configuration file /etc/freeradius/mods-enabled/soh
> > including configuration file /etc/freeradius/mods-enabled/sradutmp
> > including configuration file /etc/freeradius/mods-enabled/totp
> > including configuration file /etc/freeradius/mods-enabled/unix
> > including configuration file /etc/freeradius/mods-enabled/unpack
> > including configuration file /etc/freeradius/mods-enabled/utf8
> > including files in directory /etc/freeradius/policy.d/
> > including configuration file /etc/freeradius/policy.d/abfab-tr
> > including configuration file /etc/freeradius/policy.d/accounting
> > including configuration file /etc/freeradius/policy.d/canonicalization
> > including configuration file /etc/freeradius/policy.d/control
> > including configuration file /etc/freeradius/policy.d/cui
> > including configuration file /etc/freeradius/policy.d/debug
> > including configuration file /etc/freeradius/policy.d/dhcp
> > including configuration file /etc/freeradius/policy.d/eap
> > including configuration file /etc/freeradius/policy.d/filter
> > including configuration file /etc/freeradius/policy.d/moonshot-targeted-ids
> > including configuration file /etc/freeradius/policy.d/operator-name
> > including configuration file /etc/freeradius/policy.d/rfc7542
> > including files in directory /etc/freeradius/sites-enabled/
> > including configuration file /etc/freeradius/sites-enabled/default
> > including configuration file /etc/freeradius/sites-enabled/inner-tunnel
> > including configuration file /etc/freeradius/sites-enabled/check-eap-tls
> > including configuration file /etc/freeradius/sites-enabled/status
> > main {
> >  security {
> >          allow_core_dumps = no
> >  }
> >         name = "radiusd"
> >         prefix = "@prefix@"
> >         localstatedir = "@localstatedir@"
> >         logdir = "@logdir@"
> >         run_dir = "@localstatedir@/run/radiusd"
> > }
> > main {
> >         name = "radiusd"
> >         prefix = "@prefix@"
> >         localstatedir = "@localstatedir@"
> >         sbindir = "@sbindir@"
> >         logdir = "@logdir@"
> >         run_dir = "@localstatedir@/run/radiusd"
> >         libdir = "@libdir@"
> >         radacctdir = "@radacctdir@"
> >         hostname_lookups = no
> >         max_request_time = 30
> >         proxy_dedup_window = 1
> >         cleanup_delay = 30
> >         max_requests = 16384
> >         max_fds = 512
> >         postauth_client_lost = no
> >         pidfile = "@localstatedir@/run/radiusd/radiusd.pid"
> >         checkrad = "@sbindir@/checkrad"
> >         debug_level = 0
> >         proxy_requests = yes
> >  log {
> >          stripped_names = no
> >          auth = no
> >          auth_badpass = no
> >          auth_goodpass = no
> >          colourise = yes
> >          msg_denied = "You are already logged in - access denied"
> >  }
> >  resources {
> >  }
> >  security {
> >          max_attributes = 200
> >          reject_delay = 1.000000
> >          status_server = yes
> >          require_message_authenticator = "auto"
> >          limit_proxy_state = "auto"
> >  }
> >  unlang {
> >          group_stop_return = no
> >          policy_stop_return = no
> >  }
> > }
> > radiusd: #### Loading Realms and Home Servers ####
> >  proxy server {
> >          retry_delay = 5
> >          retry_count = 3
> >          default_fallback = no
> >          dead_time = 120
> >          wake_all_if_all_dead = no
> >  }
> >  home_server localhost {
> >          nonblock = no
> >          ipaddr = 127.0.0.1
> >          port = 1812
> >          type = "auth"
> >          secret = <<< secret >>>
> >          response_window = 20.000000
> >          response_timeouts = 1
> >          max_outstanding = 65536
> >          zombie_period = 40
> >          status_check = "status-server"
> >          ping_interval = 30
> >          check_interval = 30
> >          check_timeout = 4
> >          num_answers_to_alive = 3
> >          revive_interval = 120
> >   limit {
> >          max_connections = 16
> >          max_requests = 0
> >          lifetime = 0
> >          idle_timeout = 0
> >   }
> >   coa {
> >          irt = 2
> >          mrt = 16
> >          mrc = 5
> >          mrd = 30
> >   }
> >  }
> >  home_server_pool my_auth_failover {
> >         type = fail-over
> >         home_server = localhost
> >  }
> >  realm example.com {
> >         auth_pool = my_auth_failover
> >  }
> >  realm LOCAL {
> >  }
> > radiusd: #### Loading Clients ####
> >  client localhost {
> >          ipaddr = 127.0.0.1
> >          require_message_authenticator = "auto"
> >          limit_proxy_state = "auto"
> >          secret = <<< secret >>>
> >          proto = "*"
> >   limit {
> >          max_connections = 16
> >          lifetime = 0
> >          idle_timeout = 30
> >   }
> >  }
> > Shared secret for client localhost is short, and likely can be broken
> > by an attacker.
> >  client localhost_ipv6 {
> >          ipv6addr = ::1
> >          secret = <<< secret >>>
> >   limit {
> >          max_connections = 16
> >          lifetime = 0
> >          idle_timeout = 30
> >   }
> >  }
> > Shared secret for client localhost_ipv6 is short, and likely can be
> > broken by an attacker.
> >  client radiustesting {
> >          ipaddr = 185.241.224.187
> >          secret = <<< secret >>>
> >   limit {
> >          max_connections = 16
> >          lifetime = 0
> >          idle_timeout = 30
> >   }
> >  }
> > Debug state unknown (cap_sys_ptrace capability not set)
> > Configuration version: 7161-5ad1-6c77-638f
> > systemd watchdog is disabled
> >  # Creating Auth-Type = mschap
> >  # Creating Auth-Type = digest
> >  # Creating Auth-Type = eap
> >  # Creating Auth-Type = PAP
> >  # Creating Auth-Type = CHAP
> >  # Creating Auth-Type = MS-CHAP
> >  # Creating Autz-Type = New-TLS-Connection
> >  # Creating Autz-Type = Status-Server
> > radiusd: #### Instantiating modules ####
> >  modules {
> >   # Loaded module rlm_always
> >   # Loading module "reject" from file /etc/freeradius/mods-enabled/always
> >   always reject {
> >          rcode = "reject"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loading module "fail" from file /etc/freeradius/mods-enabled/always
> >   always fail {
> >          rcode = "fail"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loading module "ok" from file /etc/freeradius/mods-enabled/always
> >   always ok {
> >          rcode = "ok"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loading module "handled" from file /etc/freeradius/mods-enabled/always
> >   always handled {
> >          rcode = "handled"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loading module "invalid" from file /etc/freeradius/mods-enabled/always
> >   always invalid {
> >          rcode = "invalid"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loading module "userlock" from file /etc/freeradius/mods-enabled/always
> >   always userlock {
> >          rcode = "userlock"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loading module "notfound" from file /etc/freeradius/mods-enabled/always
> >   always notfound {
> >          rcode = "notfound"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loading module "noop" from file /etc/freeradius/mods-enabled/always
> >   always noop {
> >          rcode = "noop"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loading module "updated" from file /etc/freeradius/mods-enabled/always
> >   always updated {
> >          rcode = "updated"
> >          simulcount = 0
> >          mpp = no
> >   }
> >   # Loaded module rlm_attr_filter
> >   # Loading module "attr_filter.post-proxy" from file
> > /etc/freeradius/mods-enabled/attr_filter
> >   attr_filter attr_filter.post-proxy {
> >          filename = "/etc/freeradius/mods-config/attr_filter/post-proxy"
> >          key = "%{Realm}"
> >          relaxed = no
> >   }
> >   # Loading module "attr_filter.pre-proxy" from file
> > /etc/freeradius/mods-enabled/attr_filter
> >   attr_filter attr_filter.pre-proxy {
> >          filename = "/etc/freeradius/mods-config/attr_filter/pre-proxy"
> >          key = "%{Realm}"
> >          relaxed = no
> >   }
> >   # Loading module "attr_filter.access_reject" from file
> > /etc/freeradius/mods-enabled/attr_filter
> >   attr_filter attr_filter.access_reject {
> >          filename = "/etc/freeradius/mods-config/attr_filter/access_reject"
> >          key = "%{User-Name}"
> >          relaxed = no
> >   }
> >   # Loading module "attr_filter.access_challenge" from file
> > /etc/freeradius/mods-enabled/attr_filter
> >   attr_filter attr_filter.access_challenge {
> >          filename = "/etc/freeradius/mods-config/attr_filter/access_challenge"
> >          key = "%{User-Name}"
> >          relaxed = no
> >   }
> >   # Loading module "attr_filter.accounting_response" from file
> > /etc/freeradius/mods-enabled/attr_filter
> >   attr_filter attr_filter.accounting_response {
> >          filename =
> > "/etc/freeradius/mods-config/attr_filter/accounting_response"
> >          key = "%{User-Name}"
> >          relaxed = no
> >   }
> >   # Loading module "attr_filter.coa" from file
> > /etc/freeradius/mods-enabled/attr_filter
> >   attr_filter attr_filter.coa {
> >          filename = "/etc/freeradius/mods-config/attr_filter/coa"
> >          key = "%{User-Name}"
> >          relaxed = no
> >   }
> >   # Loaded module rlm_chap
> >   # Loading module "chap" from file /etc/freeradius/mods-enabled/chap
> >   # Loaded module rlm_date
> >   # Loading module "date" from file /etc/freeradius/mods-enabled/date
> >   date {
> >          format = "%b %e %Y %H:%M:%S %Z"
> >          utc = no
> >   }
> >   # Loading module "wispr2date" from file /etc/freeradius/mods-enabled/date
> >   date wispr2date {
> >          format = "%Y-%m-%dT%H:%M:%S"
> >          utc = no
> >   }
> >   # Loaded module rlm_detail
> >   # Loading module "detail" from file /etc/freeradius/mods-enabled/detail
> >   detail {
> >          filename =
> > "@radacctdir@/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
> >          header = "%t"
> >          permissions = 384
> >          locking = no
> >          dates_as_integer = no
> >          escape_filenames = no
> >          log_packet_header = no
> >   }
> >   # Loading module "auth_log" from file /etc/freeradius/mods-enabled/detail.log
> >   detail auth_log {
> >          filename =
> > "@radacctdir@/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
> >          header = "%t"
> >          permissions = 384
> >          locking = no
> >          dates_as_integer = no
> >          escape_filenames = no
> >          log_packet_header = no
> >   }
> >   # Loading module "reply_log" from file /etc/freeradius/mods-enabled/detail.log
> >   detail reply_log {
> >          filename =
> > "@radacctdir@/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
> >          header = "%t"
> >          permissions = 384
> >          locking = no
> >          dates_as_integer = no
> >          escape_filenames = no
> >          log_packet_header = no
> >   }
> >   # Loading module "pre_proxy_log" from file
> > /etc/freeradius/mods-enabled/detail.log
> >   detail pre_proxy_log {
> >          filename =
> > "@radacctdir@/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
> >          header = "%t"
> >          permissions = 384
> >          locking = no
> >          dates_as_integer = no
> >          escape_filenames = no
> >          log_packet_header = no
> >   }
> >   # Loading module "post_proxy_log" from file
> > /etc/freeradius/mods-enabled/detail.log
> >   detail post_proxy_log {
> >          filename =
> > "@radacctdir@/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
> >          header = "%t"
> >          permissions = 384
> >          locking = no
> >          dates_as_integer = no
> >          escape_filenames = no
> >          log_packet_header = no
> >   }
> >   # Loaded module rlm_digest
> >   # Loading module "digest" from file /etc/freeradius/mods-enabled/digest
> >   # Loaded module rlm_dynamic_clients
> >   # Loading module "dynamic_clients" from file
> > /etc/freeradius/mods-enabled/dynamic_clients
> >   # Loaded module rlm_eap
> >   # Loading module "eap" from file /etc/freeradius/mods-enabled/eap
> >   eap {
> >          default_eap_type = "tls"
> >          timer_expire = 60
> >          max_eap_type = 52
> >          ignore_unknown_eap_types = no
> >          cisco_accounting_username_bug = no
> >          max_sessions = 16384
> >          dedup_key = "%{Calling-Station-Id}"
> >   }
> >   # Loaded module rlm_exec
> >   # Loading module "echo" from file /etc/freeradius/mods-enabled/echo
> >   exec echo {
> >          wait = yes
> >          program = "/bin/echo %{User-Name}"
> >          input_pairs = "request"
> >          output_pairs = "reply"
> >          shell_escape = yes
> >   }
> >   # Loading module "exec" from file /etc/freeradius/mods-enabled/exec
> >   exec {
> >          wait = no
> >          input_pairs = "request"
> >          shell_escape = yes
> >          timeout = 10
> >   }
> >   # Loaded module rlm_expiration
> >   # Loading module "expiration" from file
> > /etc/freeradius/mods-enabled/expiration
> >   # Loaded module rlm_expr
> >   # Loading module "expr" from file /etc/freeradius/mods-enabled/expr
> >   expr {
> >          safe_characters =
> > "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_:
> > /äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
> >   }
> >   # Loaded module rlm_files
> >   # Loading module "files" from file /etc/freeradius/mods-enabled/files
> >   files {
> >          filename = "/etc/freeradius/mods-config/files/authorize"
> >          acctusersfile = "/etc/freeradius/mods-config/files/accounting"
> >          preproxy_usersfile = "/etc/freeradius/mods-config/files/pre-proxy"
> >   }
> >   # Loaded module rlm_linelog
> >   # Loading module "linelog" from file /etc/freeradius/mods-enabled/linelog
> >   linelog {
> >          filename = "@logdir@/linelog"
> >          escape_filenames = no
> >          syslog_severity = "info"
> >          permissions = 384
> >          format = "This is a log message for %{User-Name}"
> >          reference = "messages.%{%{reply:Packet-Type}:-default}"
> >   }
> >   # Loading module "log_accounting" from file
> > /etc/freeradius/mods-enabled/linelog
> >   linelog log_accounting {
> >          filename = "@logdir@/linelog-accounting"
> >          escape_filenames = no
> >          syslog_severity = "info"
> >          permissions = 384
> >          format = ""
> >          reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
> >   }
> >   # Loaded module rlm_logintime
> >   # Loading module "logintime" from file /etc/freeradius/mods-enabled/logintime
> >   logintime {
> >          minimum_timeout = 60
> >   }
> >   # Loaded module rlm_mschap
> >   # Loading module "mschap" from file /etc/freeradius/mods-enabled/mschap
> >   mschap {
> >          use_mppe = yes
> >          require_encryption = no
> >          require_strong = no
> >          with_ntdomain_hack = yes
> >    passchange {
> >    }
> >          allow_retry = yes
> >          winbind_retry_with_normalised_username = no
> >   }
> >   # Loading module "ntlm_auth" from file /etc/freeradius/mods-enabled/ntlm_auth
> >   exec ntlm_auth {
> >          wait = yes
> >          program = "/path/to/ntlm_auth --request-nt-key
> > --domain=MYDOMAIN --username=%{mschap:User-Name}
> > --password=%{User-Password}"
> >          shell_escape = yes
> >   }
> >   # Loaded module rlm_pap
> >   # Loading module "pap" from file /etc/freeradius/mods-enabled/pap
> >   pap {
> >          normalise = yes
> >   }
> >   # Loaded module rlm_passwd
> >   # Loading module "etc_passwd" from file /etc/freeradius/mods-enabled/passwd
> >   passwd etc_passwd {
> >          filename = "/etc/passwd"
> >          format = "*User-Name:Crypt-Password:"
> >          delimiter = ":"
> >          ignore_nislike = no
> >          ignore_empty = yes
> >          allow_multiple_keys = no
> >          hash_size = 100
> >   }
> >   # Loaded module rlm_preprocess
> >   # Loading module "preprocess" from file
> > /etc/freeradius/mods-enabled/preprocess
> >   preprocess {
> >          huntgroups = "/etc/freeradius/mods-config/preprocess/huntgroups"
> >          hints = "/etc/freeradius/mods-config/preprocess/hints"
> >          with_ascend_hack = no
> >          ascend_channels_per_line = 23
> >          with_ntdomain_hack = no
> >          with_specialix_jetstream_hack = no
> >          with_cisco_vsa_hack = no
> >          with_alvarion_vsa_hack = no
> >   }
> >   # Loaded module rlm_proxy_rate_limit
> >   # Loading module "proxy_rate_limit" from file
> > /etc/freeradius/mods-enabled/proxy_rate_limit
> >   proxy_rate_limit {
> >          max_entries = 2048
> >          idle_timeout = 10
> >          num_subtables = 256
> >          window = 1
> >   }
> >   # Loaded module rlm_radutmp
> >   # Loading module "radutmp" from file /etc/freeradius/mods-enabled/radutmp
> >   radutmp {
> >          filename = "@logdir@/radutmp"
> >          username = "%{User-Name}"
> >          case_sensitive = yes
> >          check_with_nas = yes
> >          permissions = 384
> >          caller_id = yes
> >   }
> >   # Loaded module rlm_realm
> >   # Loading module "IPASS" from file /etc/freeradius/mods-enabled/realm
> >   realm IPASS {
> >          format = "prefix"
> >          delimiter = "/"
> >          ignore_default = no
> >          ignore_null = no
> >   }
> >   # Loading module "suffix" from file /etc/freeradius/mods-enabled/realm
> >   realm suffix {
> >          format = "suffix"
> >          delimiter = "@"
> >          ignore_default = no
> >          ignore_null = no
> >   }
> >   # Loading module "bangpath" from file /etc/freeradius/mods-enabled/realm
> >   realm bangpath {
> >          format = "prefix"
> >          delimiter = "!"
> >          ignore_default = no
> >          ignore_null = no
> >   }
> >   # Loading module "realmpercent" from file /etc/freeradius/mods-enabled/realm
> >   realm realmpercent {
> >          format = "suffix"
> >          delimiter = "%"
> >          ignore_default = no
> >          ignore_null = no
> >   }
> >   # Loading module "ntdomain" from file /etc/freeradius/mods-enabled/realm
> >   realm ntdomain {
> >          format = "prefix"
> >          delimiter = "\"
> >          ignore_default = no
> >          ignore_null = no
> >   }
> >   # Loaded module rlm_replicate
> >   # Loading module "replicate" from file /etc/freeradius/mods-enabled/replicate
> >   # Loaded module rlm_soh
> >   # Loading module "soh" from file /etc/freeradius/mods-enabled/soh
> >   soh {
> >          dhcp = yes
> >   }
> >   # Loading module "sradutmp" from file /etc/freeradius/mods-enabled/sradutmp
> >   radutmp sradutmp {
> >          filename = "@logdir@/sradutmp"
> >          username = "%{User-Name}"
> >          case_sensitive = yes
> >          check_with_nas = yes
> >          permissions = 420
> >          caller_id = no
> >   }
> >   # Loaded module rlm_totp
> >   # Loading module "totp" from file /etc/freeradius/mods-enabled/totp
> >   totp {
> >          time_step = 30
> >          otp_length = 6
> >          lookback_steps = 1
> >          lookback_interval = 30
> >          lookforward_steps = 0
> >   }
> >   # Loaded module rlm_unix
> >   # Loading module "unix" from file /etc/freeradius/mods-enabled/unix
> >   unix {
> >          radwtmp = "@logdir@/radwtmp"
> >   }
> > Creating attribute Unix-Group
> >   # Loaded module rlm_unpack
> >   # Loading module "unpack" from file /etc/freeradius/mods-enabled/unpack
> >   # Loaded module rlm_utf8
> >   # Loading module "utf8" from file /etc/freeradius/mods-enabled/utf8
> >   instantiate {
> >   }
> >   # Instantiating module "reject" from file /etc/freeradius/mods-enabled/always
> >   # Instantiating module "fail" from file /etc/freeradius/mods-enabled/always
> >   # Instantiating module "ok" from file /etc/freeradius/mods-enabled/always
> >   # Instantiating module "handled" from file /etc/freeradius/mods-enabled/always
> >   # Instantiating module "invalid" from file /etc/freeradius/mods-enabled/always
> >   # Instantiating module "userlock" from file
> > /etc/freeradius/mods-enabled/always
> >   # Instantiating module "notfound" from file
> > /etc/freeradius/mods-enabled/always
> >   # Instantiating module "noop" from file /etc/freeradius/mods-enabled/always
> >   # Instantiating module "updated" from file /etc/freeradius/mods-enabled/always
> >   # Instantiating module "attr_filter.post-proxy" from file
> > /etc/freeradius/mods-enabled/attr_filter
> > reading pairlist file /etc/freeradius/mods-config/attr_filter/post-proxy
> >   # Instantiating module "attr_filter.pre-proxy" from file
> > /etc/freeradius/mods-enabled/attr_filter
> > reading pairlist file /etc/freeradius/mods-config/attr_filter/pre-proxy
> >   # Instantiating module "attr_filter.access_reject" from file
> > /etc/freeradius/mods-enabled/attr_filter
> > reading pairlist file /etc/freeradius/mods-config/attr_filter/access_reject
> >   # Instantiating module "attr_filter.access_challenge" from file
> > /etc/freeradius/mods-enabled/attr_filter
> > reading pairlist file /etc/freeradius/mods-config/attr_filter/access_challenge
> >   # Instantiating module "attr_filter.accounting_response" from file
> > /etc/freeradius/mods-enabled/attr_filter
> > reading pairlist file
> > /etc/freeradius/mods-config/attr_filter/accounting_response
> >   # Instantiating module "attr_filter.coa" from file
> > /etc/freeradius/mods-enabled/attr_filter
> > reading pairlist file /etc/freeradius/mods-config/attr_filter/coa
> >   # Instantiating module "detail" from file /etc/freeradius/mods-enabled/detail
> >   # Instantiating module "auth_log" from file
> > /etc/freeradius/mods-enabled/detail.log
> > rlm_detail (auth_log): 'User-Password' suppressed, will not appear in
> > detail output
> >   # Instantiating module "reply_log" from file
> > /etc/freeradius/mods-enabled/detail.log
> >   # Instantiating module "pre_proxy_log" from file
> > /etc/freeradius/mods-enabled/detail.log
> >   # Instantiating module "post_proxy_log" from file
> > /etc/freeradius/mods-enabled/detail.log
> > /etc/freeradius/mods-enabled/eap[56]: Found dynamic expansion in
> > string which will not be dynamically expanded
> >   # Instantiating module "eap" from file /etc/freeradius/mods-enabled/eap
> >    # Linked to sub-module rlm_eap_md5
> >    # Linked to sub-module rlm_eap_gtc
> >    gtc {
> >          challenge = "Password: "
> >          auth_type = "PAP"
> >    }
> >    # Linked to sub-module rlm_eap_tls
> >    tls {
> >          tls = "tls-common"
> >          virtual_server = "check-eap-tls"
> >    }
> >    tls-config tls-common {
> >          verify_depth = 0
> >          ca_path = "/etc/freeradius/certs"
> >          pem_file_type = yes
> >          private_key_file = "/etc/freeradius/certs/server.pem"
> >          certificate_file = "/etc/freeradius/certs/server.pem"
> >          ca_file = "/etc/freeradius/certs/ca.pem"
> >          private_key_password = <<< secret >>>
> >          fragment_size = 1024
> >          include_length = yes
> >          auto_chain = yes
> >          check_crl = no
> >          check_all_crl = no
> >          ca_path_reload_interval = 0
> >          cipher_list = "DEFAULT"
> >          cipher_server_preference = no
> >          reject_unknown_intermediate_ca = no
> >          ecdh_curve = ""
> >          tls_max_version = "1.3"
> >          tls_min_version = "1.2"
> >     cache {
> >          enable = no
> >          lifetime = 24
> >          max_entries = 255
> >     }
> >     verify {
> >          skip_if_ocsp_ok = no
> >     }
> >     ocsp {
> >          enable = no
> >          override_cert_url = yes
> >          url = "http://127.0.0.1/ocsp/"
> >          use_nonce = yes
> >          timeout = 0
> >          softfail = no
> >     }
> >    }
> >    # Linked to sub-module rlm_eap_ttls
> >    ttls {
> >          tls = "tls-common"
> >          default_eap_type = "md5"
> >          copy_request_to_tunnel = no
> >          use_tunneled_reply = no
> >          virtual_server = "inner-tunnel"
> >          include_length = yes
> >          require_client_cert = no
> >    }
> > tls: Using cached TLS configuration from previous invocation
> >    # Linked to sub-module rlm_eap_peap
> >    peap {
> >          tls = "tls-common"
> >          default_eap_type = "mschapv2"
> >          copy_request_to_tunnel = no
> >          use_tunneled_reply = no
> >          proxy_tunneled_request_as_eap = yes
> >          virtual_server = "inner-tunnel"
> >          soh = no
> >          require_client_cert = no
> >    }
> > tls: Using cached TLS configuration from previous invocation
> >    # Linked to sub-module rlm_eap_mschapv2
> >    mschapv2 {
> >          with_ntdomain_hack = no
> >          send_error = no
> >    }
> >   # Instantiating module "expiration" from file
> > /etc/freeradius/mods-enabled/expiration
> >   # Instantiating module "files" from file /etc/freeradius/mods-enabled/files
> > reading pairlist file /etc/freeradius/mods-config/files/authorize
> > reading pairlist file /etc/freeradius/mods-config/files/accounting
> > reading pairlist file /etc/freeradius/mods-config/files/pre-proxy
> >   # Instantiating module "linelog" from file
> > /etc/freeradius/mods-enabled/linelog
> >   # Instantiating module "log_accounting" from file
> > /etc/freeradius/mods-enabled/linelog
> >   # Instantiating module "logintime" from file
> > /etc/freeradius/mods-enabled/logintime
> >   # Instantiating module "mschap" from file /etc/freeradius/mods-enabled/mschap
> > rlm_mschap (mschap): using internal authentication
> >   # Instantiating module "pap" from file /etc/freeradius/mods-enabled/pap
> >   # Instantiating module "etc_passwd" from file
> > /etc/freeradius/mods-enabled/passwd
> > rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
> >   # Instantiating module "preprocess" from file
> > /etc/freeradius/mods-enabled/preprocess
> > reading pairlist file /etc/freeradius/mods-config/preprocess/huntgroups
> > reading pairlist file /etc/freeradius/mods-config/preprocess/hints
> >   # Instantiating module "proxy_rate_limit" from file
> > /etc/freeradius/mods-enabled/proxy_rate_limit
> >   # Instantiating module "IPASS" from file /etc/freeradius/mods-enabled/realm
> >   # Instantiating module "suffix" from file /etc/freeradius/mods-enabled/realm
> >   # Instantiating module "bangpath" from file /etc/freeradius/mods-enabled/realm
> >   # Instantiating module "realmpercent" from file
> > /etc/freeradius/mods-enabled/realm
> >   # Instantiating module "ntdomain" from file /etc/freeradius/mods-enabled/realm
> >   # Instantiating module "totp" from file /etc/freeradius/mods-enabled/totp
> >  } # modules
> > radiusd: #### Loading Virtual Servers ####
> > server { # from file /etc/freeradius/radiusd.conf
> > } # server
> > server default { # from file /etc/freeradius/sites-enabled/default
> >  # Loading authenticate {...}
> > Compiling Auth-Type PAP for attr Auth-Type
> > Compiling Auth-Type CHAP for attr Auth-Type
> > Compiling Auth-Type MS-CHAP for attr Auth-Type
> >  # Loading authorize {...}
> > Ignoring "sql" (see raddb/mods-available/README.rst)
> > Ignoring "ldap" (see raddb/mods-available/README.rst)
> > Compiling Autz-Type New-TLS-Connection for attr Autz-Type
> >  # Loading preacct {...}
> >  # Loading accounting {...}
> >  # Loading post-auth {...}
> > Compiling Post-Auth-Type REJECT for attr Post-Auth-Type
> > Compiling Post-Auth-Type Challenge for attr Post-Auth-Type
> > Compiling Post-Auth-Type Client-Lost for attr Post-Auth-Type
> > } # server default
> > server inner-tunnel { # from file /etc/freeradius/sites-enabled/inner-tunnel
> >  # Loading authenticate {...}
> > Compiling Auth-Type PAP for attr Auth-Type
> > Compiling Auth-Type CHAP for attr Auth-Type
> > Compiling Auth-Type MS-CHAP for attr Auth-Type
> >  # Loading authorize {...}
> >  # Loading post-proxy {...}
> >  # Loading post-auth {...}
> >  # Skipping contents of 'if' as it is always 'false' --
> > /etc/freeradius/sites-enabled/inner-tunnel:366
> > Compiling Post-Auth-Type REJECT for attr Post-Auth-Type
> > } # server inner-tunnel
> > server check-eap-tls { # from file /etc/freeradius/sites-enabled/check-eap-tls
> >  # Loading authorize {...}
> > } # server check-eap-tls
> > server status { # from file /etc/freeradius/sites-enabled/status
> >  # Loading authorize {...}
> > Compiling Autz-Type Status-Server for attr Autz-Type
> > } # server status
> > radiusd: #### Opening IP addresses and Ports ####
> > listen {
> >          type = "auth"
> >          ipaddr = *
> >          port = 0
> >    limit {
> >          max_connections = 128
> >          lifetime = 30
> >          idle_timeout = 60
> >    }
> > Setting idle_timeout to 0
> > }
> > listen {
> >          type = "acct"
> >          ipaddr = *
> >          port = 0
> >    limit {
> >          max_connections = 16
> >          lifetime = 0
> >          idle_timeout = 30
> >    }
> > }
> > listen {
> >          type = "auth"
> >          ipv6addr = ::
> >          port = 0
> >    limit {
> >          max_connections = 16
> >          lifetime = 0
> >          idle_timeout = 30
> >    }
> > }
> > listen {
> >          type = "acct"
> >          ipv6addr = ::
> >          port = 0
> >    limit {
> >          max_connections = 16
> >          lifetime = 0
> >          idle_timeout = 30
> >    }
> > }
> > listen {
> >          type = "auth"
> >          ipaddr = 127.0.0.1
> >          port = 18120
> > }
> > listen {
> >          type = "status"
> >          ipaddr = *
> >          port = 8080
> >          proto = "tcp"
> >    limit {
> >          max_connections = 64
> >          lifetime = 15
> >          idle_timeout = 30
> >    }
> > Setting idle_timeout to 0
> >          clients = "azure_lb"
> >   client azure_lb {
> >          ipaddr = 168.63.129.16
> >          secret = <<< secret >>>
> >          proto = "tcp"
> >    limit {
> >          max_connections = 16
> >          lifetime = 0
> >          idle_timeout = 30
> >    }
> >   }
> > }
> > Listening on auth address * port 1812 bound to server default
> > Listening on acct address * port 1813 bound to server default
> > Listening on auth address :: port 1812 bound to server default
> > Listening on acct address :: port 1813 bound to server default
> > Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
> > Listening on status proto tcp address * port 8080 bound to server status
> > Listening on proxy address * port 47097
> > Listening on proxy address :: port 33982
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Listening on status from client (168.63.129.16, 54790) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.8 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 54790) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 54858) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.8 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 54858) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 54946) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.8 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 54946) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55023) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.8 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55023) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55116) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.8 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55116) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55188) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.8 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55188) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55271) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.8 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55271) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55341) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55341) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55411) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55411) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55486) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55486) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55575) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55575) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55631) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55631) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55721) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55721) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55790) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55790) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 55987) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 55987) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Failed inserting TCP socket into parent list.
> > Listening on status from client (168.63.129.16, 56081) -> (*, 8080,
> > virtual-server=status)
> > Waking up in 0.7 seconds.
> > Waking up in 14.4 seconds.
> > Client has closed connection
> >  ... shutting down socket status from client (168.63.129.16, 56081) ->
> > (*, 8080, virtual-server=status)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Ready to process requests
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Ready to process requests
> > (0) Received Access-Request Id 225 from 185.241.224.187:35356 to
> > 10.0.0.5:1812 length 195
> > (0)   NAS-IP-Address = 192.168.1.112
> > (0)   NAS-Port-Type = Ethernet
> > (0)   NAS-Port = 4
> > (0)   User-Name = "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352"
> > (0)   Acct-Session-Id = "0500003F"
> > (0)   Called-Station-Id = "A4-B2-39-CD-FE-3F"
> > (0)   Calling-Station-Id = "28-00-AF-0F-A8-32"
> > (0)   EAP-Message =
> > 0x0201002e01686f73742f33353365633031342d356337302d346534632d613763382d623963386235383630333532
> > (0)   Message-Authenticator = 0xfd9f875e95feb822675be4ee23747c02
> > (0) # Executing section authorize from file
> > /etc/freeradius/sites-enabled/default
> > (0)   authorize {
> > (0)     policy filter_username {
> > (0)       if (&User-Name) {
> > (0)       if (&User-Name)  -> TRUE
> > (0)       if (&User-Name)  {
> > (0)         if (&User-Name =~ / /) {
> > (0)         if (&User-Name =~ / /)  -> FALSE
> > (0)         if (&User-Name =~ /@[^@]*@/ ) {
> > (0)         if (&User-Name =~ /@[^@]*@/ )  -> FALSE
> > (0)         if (&User-Name =~ /\.\./ ) {
> > (0)         if (&User-Name =~ /\.\./ )  -> FALSE
> > (0)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))  {
> > (0)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))
> >   -> FALSE
> > (0)         if (&User-Name =~ /\.$/)  {
> > (0)         if (&User-Name =~ /\.$/)   -> FALSE
> > (0)         if (&User-Name =~ /@\./)  {
> > (0)         if (&User-Name =~ /@\./)   -> FALSE
> > (0)       } # if (&User-Name)  = notfound
> > (0)     } # policy filter_username = notfound
> > (0)     [preprocess] = ok
> > (0)     [chap] = noop
> > (0)     [mschap] = noop
> > (0)     [digest] = noop
> > (0) suffix: Checking for suffix after "@"
> > (0) suffix: No '@' in User-Name =
> > "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352", looking up realm NULL
> > (0) suffix: No such realm "NULL"
> > (0)     [suffix] = noop
> > (0) eap: Peer sent EAP Response (code 2) ID 1 length 46
> > (0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit
> > the rest of authorize
> > (0)     [eap] = ok
> > (0)   } # authorize = ok
> > (0) Found Auth-Type = eap
> > (0) # Executing group from file /etc/freeradius/sites-enabled/default
> > (0)   authenticate {
> > (0) eap: EXPAND %{Calling-Station-Id}
> > (0) eap:    --> 28-00-AF-0F-A8-32
> > (0) eap: Peer sent packet with method EAP Identity (1)
> > (0) eap: Using default_eap_type = TLS
> > (0) eap: Calling submodule eap_tls to process data
> > (0) eap_tls: (TLS) TLS -Initiating new session
> > (0) eap_tls: (TLS) TLS - Setting verify mode to require certificate from client
> > (0) eap: Sending EAP Request (code 1) ID 2 length 6
> > (0) eap: EAP session adding &reply:State = 0xa960c76da962ca67
> > (0)     [eap] = handled
> > (0)   } # authenticate = handled
> > (0) Using Post-Auth-Type Challenge
> > (0) # Executing group from file /etc/freeradius/sites-enabled/default
> > (0)   Challenge { ... } # empty sub-section is ignored
> > (0) session-state: Saving cached attributes
> > (0)   Framed-MTU = 994
> > (0) Sent Access-Challenge Id 225 from 10.0.0.5:1812 to
> > 185.241.224.187:35356 length 64
> > (0)   EAP-Message = 0x010200060d20
> > (0)   Message-Authenticator = 0x00000000000000000000000000000000
> > (0)   State = 0xa960c76da962ca67c033c547c41b2362
> > (0) Finished request
> > Waking up in 29.9 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 25.3 seconds.
> > (1) Received Access-Request Id 226 from 185.241.224.187:35356 to
> > 10.0.0.5:1812 length 436
> > (1)   NAS-IP-Address = 192.168.1.112
> > (1)   NAS-Port-Type = Ethernet
> > (1)   NAS-Port = 4
> > (1)   User-Name = "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352"
> > (1)   Acct-Session-Id = "0500003F"
> > (1)   State = 0xa960c76da962ca67c033c547c41b2362
> > (1)   Called-Station-Id = "A4-B2-39-CD-FE-3F"
> > (1)   Calling-Station-Id = "28-00-AF-0F-A8-32"
> > (1)   EAP-Message =
> > 0x0202010b0d800000010116030100fc010000f803038005f5c1f744d3396f887f73d0f6ee32038ac5ea916872900f35e3a30829a89920a00f349108c0a3d8a1825562e0cfc7691b328ffe45f9025dc72d0170776b431f002813021301c02cc02bc030c02fc024c023c028c027c00ac009c014c013009d009c003d003c0035002f01000087000500050100000000002b0009080304030303020301000d001a001808040805080604010501020104030503020302020601060300230000000a00080006001d00170018000b00020100003300260024001d00200d9fc1fc2438e7552301836ca01472e47d655008f1650ff4e35dd57955b80b590031000000170000ff01000100002d00020101
> > (1)   Message-Authenticator = 0xcc559b3212a95756ea6a742fc1963909
> > (1) Restoring &session-state
> > (1)   &session-state:Framed-MTU = 994
> > (1) # Executing section authorize from file
> > /etc/freeradius/sites-enabled/default
> > (1)   authorize {
> > (1)     policy filter_username {
> > (1)       if (&User-Name) {
> > (1)       if (&User-Name)  -> TRUE
> > (1)       if (&User-Name)  {
> > (1)         if (&User-Name =~ / /) {
> > (1)         if (&User-Name =~ / /)  -> FALSE
> > (1)         if (&User-Name =~ /@[^@]*@/ ) {
> > (1)         if (&User-Name =~ /@[^@]*@/ )  -> FALSE
> > (1)         if (&User-Name =~ /\.\./ ) {
> > (1)         if (&User-Name =~ /\.\./ )  -> FALSE
> > (1)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))  {
> > (1)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))
> >   -> FALSE
> > (1)         if (&User-Name =~ /\.$/)  {
> > (1)         if (&User-Name =~ /\.$/)   -> FALSE
> > (1)         if (&User-Name =~ /@\./)  {
> > (1)         if (&User-Name =~ /@\./)   -> FALSE
> > (1)       } # if (&User-Name)  = notfound
> > (1)     } # policy filter_username = notfound
> > (1)     [preprocess] = ok
> > (1)     [chap] = noop
> > (1)     [mschap] = noop
> > (1)     [digest] = noop
> > (1) suffix: Checking for suffix after "@"
> > (1) suffix: No '@' in User-Name =
> > "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352", looking up realm NULL
> > (1) suffix: No such realm "NULL"
> > (1)     [suffix] = noop
> > (1) eap: Peer sent EAP Response (code 2) ID 2 length 267
> > (1) eap: No EAP Start, assuming it's an on-going EAP conversation
> > (1)     [eap] = updated
> > (1)     [files] = noop
> > (1)     [expiration] = noop
> > (1)     [logintime] = noop
> > (1)     [pap] = noop
> > (1)   } # authorize = updated
> > (1) Found Auth-Type = eap
> > (1) # Executing group from file /etc/freeradius/sites-enabled/default
> > (1)   authenticate {
> > (1) eap: Removing EAP session with state 0xa960c76da962ca67
> > (1) eap: Previous EAP request found for state 0xa960c76da962ca67,
> > released from the list
> > (1) eap: Peer sent packet with method EAP TLS (13)
> > (1) eap: Calling submodule eap_tls to process data
> > (1) eap_tls: (TLS) EAP Peer says that the final record size will be 257 bytes
> > (1) eap_tls: (TLS) EAP Got all data (257 bytes)
> > (1) eap_tls: (TLS) TLS - Handshake state - before SSL initialization
> > (1) eap_tls: (TLS) TLS - Handshake state - Server before SSL initialization
> > (1) eap_tls: (TLS) TLS - Handshake state - Server before SSL initialization
> > (1) eap_tls: (TLS) TLS - recv TLS 1.3 Handshake, ClientHello
> > (1) eap_tls: (TLS) TLS - Handshake state - Server SSLv3/TLS read client hello
> > (1) eap_tls: (TLS) TLS - send TLS 1.3 Handshake, ServerHello
> > (1) eap_tls: (TLS) TLS - Handshake state - Server SSLv3/TLS write server hello
> > (1) eap_tls: (TLS) TLS - send TLS 1.3 ChangeCipherSpec
> > (1) eap_tls: (TLS) TLS - Handshake state - Server SSLv3/TLS write
> > change cipher spec
> > (1) eap_tls: (TLS) TLS - send TLS 1.3 Handshake, EncryptedExtensions
> > (1) eap_tls: (TLS) TLS - Handshake state - Server TLSv1.3 write
> > encrypted extensions
> > (1) eap_tls: (TLS) TLS - send TLS 1.3 Handshake, CertificateRequest
> > (1) eap_tls: (TLS) TLS - Handshake state - Server SSLv3/TLS write
> > certificate request
> > (1) eap_tls: (TLS) TLS - send TLS 1.3 Handshake, Certificate
> > (1) eap_tls: (TLS) TLS - Handshake state - Server SSLv3/TLS write certificate
> > (1) eap_tls: (TLS) TLS - send TLS 1.3 Handshake, CertificateVerify
> > (1) eap_tls: (TLS) TLS - Handshake state - Server TLSv1.3 write server
> > certificate verify
> > (1) eap_tls: (TLS) TLS - send TLS 1.3 Handshake, Finished
> > (1) eap_tls: (TLS) TLS - Handshake state - Server SSLv3/TLS write finished
> > (1) eap_tls: (TLS) TLS - Handshake state - Server TLSv1.3 early data
> > (1) eap_tls: (TLS) TLS - Server : Need to read more data: TLSv1.3 early data
> > (1) eap_tls: (TLS) TLS - In Handshake Phase
> > (1) eap: Sending EAP Request (code 1) ID 3 length 1000
> > (1) eap: EAP session adding &reply:State = 0xa960c76da863ca67
> > (1)     [eap] = handled
> > (1)   } # authenticate = handled
> > (1) Using Post-Auth-Type Challenge
> > (1) # Executing group from file /etc/freeradius/sites-enabled/default
> > (1)   Challenge { ... } # empty sub-section is ignored
> > (1) session-state: Saving cached attributes
> > (1)   Framed-MTU = 994
> > (1)   TLS-Session-Information = "(TLS) TLS - recv TLS 1.3 Handshake,
> > ClientHello"
> > (1)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > ServerHello"
> > (1)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 ChangeCipherSpec"
> > (1)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > EncryptedExtensions"
> > (1)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateRequest"
> > (1)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > Certificate"
> > (1)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateVerify"
> > (1)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake, Finished"
> > (1) Sent Access-Challenge Id 226 from 10.0.0.5:1812 to
> > 185.241.224.187:35356 length 1064
> > (1)   EAP-Message =
> > 0x010303e80dc000000fdb160303007a02000076030315b4bdf959e77a819ca5b04ba62a57391745e7bed4ed82f5b2439560cdb8d77120a00f349108c0a3d8a1825562e0cfc7691b328ffe45f9025dc72d0170776b431f130200002e002b0002030400330024001d00209639f2611dd7535b4db2fac1f7709482f843443278af0b934076fcb02adb07691403030001011703030017409bded55c5fc8075b8e54990bb1a5ed4c42044db7684a17030301374e577f3a09d50eb88f0faf4977b2c27762b050bce58ac056b15c39776ebb5b95a26cc8196b755d2cd2665ac7259691a99366935a39332f8f5da1eaa7c78ff13526f4ae124707f879a230e68b0f59b2993186a86c41085634dd4933ac77d752db76cbe073ca19402ddbdea29e830e8be189b692b124b9d0edfd5968d6859b86ac53e0dea8edf11683fec7c989c11829bb3d06e3fcd860fbf9bca4031b34066ad035591aa696988e6a7b4594ad4d96da7cb139927f81cf8b75785e86eb9865c2ec939a558bd7da98
> > (1)   Message-Authenticator = 0x00000000000000000000000000000000
> > (1)   State = 0xa960c76da863ca67c033c547c41b2362
> > (1) Finished request
> > Waking up in 20.9 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 20.3 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 15.3 seconds.
> > (2) Received Access-Request Id 227 from 185.241.224.187:35356 to
> > 10.0.0.5:1812 length 173
> > (2)   NAS-IP-Address = 192.168.1.112
> > (2)   NAS-Port-Type = Ethernet
> > (2)   NAS-Port = 4
> > (2)   User-Name = "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352"
> > (2)   Acct-Session-Id = "0500003F"
> > (2)   State = 0xa960c76da863ca67c033c547c41b2362
> > (2)   Called-Station-Id = "A4-B2-39-CD-FE-3F"
> > (2)   Calling-Station-Id = "28-00-AF-0F-A8-32"
> > (2)   EAP-Message = 0x020300060d00
> > (2)   Message-Authenticator = 0xbf0af695bb5ac349944293a07a61472c
> > (2) Restoring &session-state
> > (2)   &session-state:Framed-MTU = 994
> > (2)   &session-state:TLS-Session-Information = "(TLS) TLS - recv TLS
> > 1.3 Handshake, ClientHello"
> > (2)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, ServerHello"
> > (2)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 ChangeCipherSpec"
> > (2)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, EncryptedExtensions"
> > (2)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, CertificateRequest"
> > (2)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Certificate"
> > (2)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, CertificateVerify"
> > (2)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Finished"
> > (2) # Executing section authorize from file
> > /etc/freeradius/sites-enabled/default
> > (2)   authorize {
> > (2)     policy filter_username {
> > (2)       if (&User-Name) {
> > (2)       if (&User-Name)  -> TRUE
> > (2)       if (&User-Name)  {
> > (2)         if (&User-Name =~ / /) {
> > (2)         if (&User-Name =~ / /)  -> FALSE
> > (2)         if (&User-Name =~ /@[^@]*@/ ) {
> > (2)         if (&User-Name =~ /@[^@]*@/ )  -> FALSE
> > (2)         if (&User-Name =~ /\.\./ ) {
> > (2)         if (&User-Name =~ /\.\./ )  -> FALSE
> > (2)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))  {
> > (2)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))
> >   -> FALSE
> > (2)         if (&User-Name =~ /\.$/)  {
> > (2)         if (&User-Name =~ /\.$/)   -> FALSE
> > (2)         if (&User-Name =~ /@\./)  {
> > (2)         if (&User-Name =~ /@\./)   -> FALSE
> > (2)       } # if (&User-Name)  = notfound
> > (2)     } # policy filter_username = notfound
> > (2)     [preprocess] = ok
> > (2)     [chap] = noop
> > (2)     [mschap] = noop
> > (2)     [digest] = noop
> > (2) suffix: Checking for suffix after "@"
> > (2) suffix: No '@' in User-Name =
> > "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352", looking up realm NULL
> > (2) suffix: No such realm "NULL"
> > (2)     [suffix] = noop
> > (2) eap: Peer sent EAP Response (code 2) ID 3 length 6
> > (2) eap: No EAP Start, assuming it's an on-going EAP conversation
> > (2)     [eap] = updated
> > (2)     [files] = noop
> > (2)     [expiration] = noop
> > (2)     [logintime] = noop
> > (2)     [pap] = noop
> > (2)   } # authorize = updated
> > (2) Found Auth-Type = eap
> > (2) # Executing group from file /etc/freeradius/sites-enabled/default
> > (2)   authenticate {
> > (2) eap: Removing EAP session with state 0xa960c76da863ca67
> > (2) eap: Previous EAP request found for state 0xa960c76da863ca67,
> > released from the list
> > (2) eap: Peer sent packet with method EAP TLS (13)
> > (2) eap: Calling submodule eap_tls to process data
> > (2) eap_tls: (TLS) Peer ACKed our handshake fragment
> > (2) eap: Sending EAP Request (code 1) ID 4 length 1000
> > (2) eap: EAP session adding &reply:State = 0xa960c76dab64ca67
> > (2)     [eap] = handled
> > (2)   } # authenticate = handled
> > (2) Using Post-Auth-Type Challenge
> > (2) # Executing group from file /etc/freeradius/sites-enabled/default
> > (2)   Challenge { ... } # empty sub-section is ignored
> > (2) session-state: Saving cached attributes
> > (2)   Framed-MTU = 994
> > (2)   TLS-Session-Information = "(TLS) TLS - recv TLS 1.3 Handshake,
> > ClientHello"
> > (2)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > ServerHello"
> > (2)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 ChangeCipherSpec"
> > (2)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > EncryptedExtensions"
> > (2)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateRequest"
> > (2)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > Certificate"
> > (2)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateVerify"
> > (2)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake, Finished"
> > (2) Sent Access-Challenge Id 227 from 10.0.0.5:1812 to
> > 185.241.224.187:35356 length 1064
> > (2)   EAP-Message =
> > 0x010403e80dc000000fdb84c7ccd063df8e12ce32a75073a57effe537a56c29818a6504d97dab790416413b46b17874bba4f1100faf0fc2d2794404aa403cb3fe415ae48beef376503db654447da19846fbc6dca88ff672bf7cf52411b8f42cd7ce4299213643779e3256bcc8b4209fd9fade5435a7e71b6d153be151825c1728fd9fe028c1c7fe9fe04fb257e10a2454579941cc4bef65d9df55242b70decd2f44985ee48067aee6da01461f7d86a46d0ecb29116e61491008a2cd180beca8f4321694f16a08f7644ac0eed1e86b62882ec874693f8a24c8f238edd83a65a8450ecd940d216eb93cf1be989493c72f316f39e9bd8b7c1e7eb504c51a94ce5ce4152d454a4132ce4cd4da25602148a1c9899b5dc3db9308da9b313a12707580e0185321c529dd5546826408b642fed98afee0181181f212df866466f4dfabaa6b1517e009b0c9af3ab43f0561fe38aa9bb2d02d85581f726562eac8099e62c51ec1575e1b19713a426667cbb555f02d0e14540ec47a4c65
> > (2)   Message-Authenticator = 0x00000000000000000000000000000000
> > (2)   State = 0xa960c76dab64ca67c033c547c41b2362
> > (2) Finished request
> > Waking up in 11.8 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 10.3 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 5.3 seconds.
> > (3) Received Access-Request Id 228 from 185.241.224.187:35356 to
> > 10.0.0.5:1812 length 173
> > (3)   NAS-IP-Address = 192.168.1.112
> > (3)   NAS-Port-Type = Ethernet
> > (3)   NAS-Port = 4
> > (3)   User-Name = "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352"
> > (3)   Acct-Session-Id = "0500003F"
> > (3)   State = 0xa960c76dab64ca67c033c547c41b2362
> > (3)   Called-Station-Id = "A4-B2-39-CD-FE-3F"
> > (3)   Calling-Station-Id = "28-00-AF-0F-A8-32"
> > (3)   EAP-Message = 0x020400060d00
> > (3)   Message-Authenticator = 0x038ead73ce4c8b0a455b6b5ffea2c726
> > (3) Restoring &session-state
> > (3)   &session-state:Framed-MTU = 994
> > (3)   &session-state:TLS-Session-Information = "(TLS) TLS - recv TLS
> > 1.3 Handshake, ClientHello"
> > (3)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, ServerHello"
> > (3)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 ChangeCipherSpec"
> > (3)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, EncryptedExtensions"
> > (3)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, CertificateRequest"
> > (3)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Certificate"
> > (3)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, CertificateVerify"
> > (3)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Finished"
> > (3) # Executing section authorize from file
> > /etc/freeradius/sites-enabled/default
> > (3)   authorize {
> > (3)     policy filter_username {
> > (3)       if (&User-Name) {
> > (3)       if (&User-Name)  -> TRUE
> > (3)       if (&User-Name)  {
> > (3)         if (&User-Name =~ / /) {
> > (3)         if (&User-Name =~ / /)  -> FALSE
> > (3)         if (&User-Name =~ /@[^@]*@/ ) {
> > (3)         if (&User-Name =~ /@[^@]*@/ )  -> FALSE
> > (3)         if (&User-Name =~ /\.\./ ) {
> > (3)         if (&User-Name =~ /\.\./ )  -> FALSE
> > (3)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))  {
> > (3)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))
> >   -> FALSE
> > (3)         if (&User-Name =~ /\.$/)  {
> > (3)         if (&User-Name =~ /\.$/)   -> FALSE
> > (3)         if (&User-Name =~ /@\./)  {
> > (3)         if (&User-Name =~ /@\./)   -> FALSE
> > (3)       } # if (&User-Name)  = notfound
> > (3)     } # policy filter_username = notfound
> > (3)     [preprocess] = ok
> > (3)     [chap] = noop
> > (3)     [mschap] = noop
> > (3)     [digest] = noop
> > (3) suffix: Checking for suffix after "@"
> > (3) suffix: No '@' in User-Name =
> > "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352", looking up realm NULL
> > (3) suffix: No such realm "NULL"
> > (3)     [suffix] = noop
> > (3) eap: Peer sent EAP Response (code 2) ID 4 length 6
> > (3) eap: No EAP Start, assuming it's an on-going EAP conversation
> > (3)     [eap] = updated
> > (3)     [files] = noop
> > (3)     [expiration] = noop
> > (3)     [logintime] = noop
> > (3)     [pap] = noop
> > (3)   } # authorize = updated
> > (3) Found Auth-Type = eap
> > (3) # Executing group from file /etc/freeradius/sites-enabled/default
> > (3)   authenticate {
> > (3) eap: Removing EAP session with state 0xa960c76dab64ca67
> > (3) eap: Previous EAP request found for state 0xa960c76dab64ca67,
> > released from the list
> > (3) eap: Peer sent packet with method EAP TLS (13)
> > (3) eap: Calling submodule eap_tls to process data
> > (3) eap_tls: (TLS) Peer ACKed our handshake fragment
> > (3) eap: Sending EAP Request (code 1) ID 5 length 1000
> > (3) eap: EAP session adding &reply:State = 0xa960c76daa65ca67
> > (3)     [eap] = handled
> > (3)   } # authenticate = handled
> > (3) Using Post-Auth-Type Challenge
> > (3) # Executing group from file /etc/freeradius/sites-enabled/default
> > (3)   Challenge { ... } # empty sub-section is ignored
> > (3) session-state: Saving cached attributes
> > (3)   Framed-MTU = 994
> > (3)   TLS-Session-Information = "(TLS) TLS - recv TLS 1.3 Handshake,
> > ClientHello"
> > (3)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > ServerHello"
> > (3)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 ChangeCipherSpec"
> > (3)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > EncryptedExtensions"
> > (3)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateRequest"
> > (3)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > Certificate"
> > (3)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateVerify"
> > (3)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake, Finished"
> > (3) Sent Access-Challenge Id 228 from 10.0.0.5:1812 to
> > 185.241.224.187:35356 length 1064
> > (3)   EAP-Message =
> > 0x010503e80dc000000fdbfdab766478f6463a45aa0725242e5aac5c6de5a81c7a5bcdf1125abf8d15a3d47dc9e78f5ce707fc1038b6db94138a1e4ec53dd19ab470e420b2a3dec644d03d54d4887375596eebf2da1fb12bd224812df10fdaa9894b56b6659ccfed8754f9a842fa5800b4d6a99b4ab4004ec005e25ba1301b74ada5d51589796de8e21b482c9d02032bad52ce8e9d8d5b066b6261bd66d0a002c791ed18ca56a88fce85f07832b6a056be190b627d74030116c2e68266791db3a65391cea7149b66175d06b1cf01ccc3c3ee33bc83b2fe395b682d460944a8cad5aa1c3ba1a8332f129ed93f9f6e1e62e4f3098c0c51b04bded8f76ccb41538f865cd38429bd1e1fd29e74b727fae988371d89bc377ddbd58d1999d9b4f5408953930d6f2a9d2db76791726388811710c247f124ce94bb4284c064883e3bb525e539f7957e373b7e6cffbbb8790f7f1ef52db19cf876950d4eeb9218bd396d4844b8c56f9752308fc3ec27716a6f3b3676a1f0655d717ef1
> > (3)   Message-Authenticator = 0x00000000000000000000000000000000
> > (3)   State = 0xa960c76daa65ca67c033c547c41b2362
> > (3) Finished request
> > Waking up in 2.8 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 0.2 seconds.
> > (0) Cleaning up request packet ID 225 with timestamp +1392 due to
> > cleanup_delay was reached
> > Waking up in 9.0 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 4.3 seconds.
> > (4) Received Access-Request Id 229 from 185.241.224.187:35356 to
> > 10.0.0.5:1812 length 173
> > (4)   NAS-IP-Address = 192.168.1.112
> > (4)   NAS-Port-Type = Ethernet
> > (4)   NAS-Port = 4
> > (4)   User-Name = "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352"
> > (4)   Acct-Session-Id = "0500003F"
> > (4)   State = 0xa960c76daa65ca67c033c547c41b2362
> > (4)   Called-Station-Id = "A4-B2-39-CD-FE-3F"
> > (4)   Calling-Station-Id = "28-00-AF-0F-A8-32"
> > (4)   EAP-Message = 0x020500060d00
> > (4)   Message-Authenticator = 0xd41b050c3a3def192db05fd631f14607
> > (4) Restoring &session-state
> > (4)   &session-state:Framed-MTU = 994
> > (4)   &session-state:TLS-Session-Information = "(TLS) TLS - recv TLS
> > 1.3 Handshake, ClientHello"
> > (4)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, ServerHello"
> > (4)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 ChangeCipherSpec"
> > (4)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, EncryptedExtensions"
> > (4)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, CertificateRequest"
> > (4)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Certificate"
> > (4)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, CertificateVerify"
> > (4)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Finished"
> > (4) # Executing section authorize from file
> > /etc/freeradius/sites-enabled/default
> > (4)   authorize {
> > (4)     policy filter_username {
> > (4)       if (&User-Name) {
> > (4)       if (&User-Name)  -> TRUE
> > (4)       if (&User-Name)  {
> > (4)         if (&User-Name =~ / /) {
> > (4)         if (&User-Name =~ / /)  -> FALSE
> > (4)         if (&User-Name =~ /@[^@]*@/ ) {
> > (4)         if (&User-Name =~ /@[^@]*@/ )  -> FALSE
> > (4)         if (&User-Name =~ /\.\./ ) {
> > (4)         if (&User-Name =~ /\.\./ )  -> FALSE
> > (4)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))  {
> > (4)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))
> >   -> FALSE
> > (4)         if (&User-Name =~ /\.$/)  {
> > (4)         if (&User-Name =~ /\.$/)   -> FALSE
> > (4)         if (&User-Name =~ /@\./)  {
> > (4)         if (&User-Name =~ /@\./)   -> FALSE
> > (4)       } # if (&User-Name)  = notfound
> > (4)     } # policy filter_username = notfound
> > (4)     [preprocess] = ok
> > (4)     [chap] = noop
> > (4)     [mschap] = noop
> > (4)     [digest] = noop
> > (4) suffix: Checking for suffix after "@"
> > (4) suffix: No '@' in User-Name =
> > "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352", looking up realm NULL
> > (4) suffix: No such realm "NULL"
> > (4)     [suffix] = noop
> > (4) eap: Peer sent EAP Response (code 2) ID 5 length 6
> > (4) eap: No EAP Start, assuming it's an on-going EAP conversation
> > (4)     [eap] = updated
> > (4)     [files] = noop
> > (4)     [expiration] = noop
> > (4)     [logintime] = noop
> > (4)     [pap] = noop
> > (4)   } # authorize = updated
> > (4) Found Auth-Type = eap
> > (4) # Executing group from file /etc/freeradius/sites-enabled/default
> > (4)   authenticate {
> > (4) eap: Removing EAP session with state 0xa960c76daa65ca67
> > (4) eap: Previous EAP request found for state 0xa960c76daa65ca67,
> > released from the list
> > (4) eap: Peer sent packet with method EAP TLS (13)
> > (4) eap: Calling submodule eap_tls to process data
> > (4) eap_tls: (TLS) Peer ACKed our handshake fragment
> > (4) eap: Sending EAP Request (code 1) ID 6 length 1000
> > (4) eap: EAP session adding &reply:State = 0xa960c76dad66ca67
> > (4)     [eap] = handled
> > (4)   } # authenticate = handled
> > (4) Using Post-Auth-Type Challenge
> > (4) # Executing group from file /etc/freeradius/sites-enabled/default
> > (4)   Challenge { ... } # empty sub-section is ignored
> > (4) session-state: Saving cached attributes
> > (4)   Framed-MTU = 994
> > (4)   TLS-Session-Information = "(TLS) TLS - recv TLS 1.3 Handshake,
> > ClientHello"
> > (4)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > ServerHello"
> > (4)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 ChangeCipherSpec"
> > (4)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > EncryptedExtensions"
> > (4)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateRequest"
> > (4)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > Certificate"
> > (4)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateVerify"
> > (4)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake, Finished"
> > (4) Sent Access-Challenge Id 229 from 10.0.0.5:1812 to
> > 185.241.224.187:35356 length 1064
> > (4)   EAP-Message =
> > 0x010603e80dc000000fdbe1eb6d5ccf7a723ba08e36e26cc364e3deb8d6a570bf850795cab4233696941f9631498e9c58b86901eb823cd8b9a6c479d350dde4ce24b459b27012d0784767279b319e50647f62280123ba9f59784873b7adf37470625b66682b6074d34ed54a620756b34d798ea85c9cbd42cda44701be40ef5b6bb3b570530225344fa2062790bdb7f8ff1e107336771e0692f5e335e845b5f518a4cae2d4020cdb84e0faf68d26a7c335894fec424289a9188d141a1c9db099c6695c6201ecf88a3859d396441695dab5920e9ffc39488580ffe4a8631abf86e18838128d72317aea08617286bd7f2f0495be883e0ce8b15df6ad7be59c40e08081f324c89653320d697861b2a81b1cb9d917560ed71164f704dc0921aad85e80683672ee66ccdffd1faf573e4bd49b223f16ce62335ae5e423d1ef816de71f77ea19585566ad22f1de9b6488a425a2d78aa387929d435c21f229ba698d79b0073e4c3b382abbbfbfcb3ad815b8d472398f53d6048ea3f4
> > (4)   Message-Authenticator = 0x00000000000000000000000000000000
> > (4)   State = 0xa960c76dad66ca67c033c547c41b2362
> > (4) Finished request
> > Waking up in 2.8 seconds.
> > (1) Cleaning up request packet ID 226 with timestamp +1401 due to
> > cleanup_delay was reached
> > Waking up in 9.0 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 8.3 seconds.
> >  ... new connection request on TCP socket
> > Ignoring new connection due to client max_connections (16)
> > Waking up in 3.3 seconds.
> > (5) Received Access-Request Id 230 from 185.241.224.187:35356 to
> > 10.0.0.5:1812 length 173
> > (5)   NAS-IP-Address = 192.168.1.112
> > (5)   NAS-Port-Type = Ethernet
> > (5)   NAS-Port = 4
> > (5)   User-Name = "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352"
> > (5)   Acct-Session-Id = "0500003F"
> > (5)   State = 0xa960c76dad66ca67c033c547c41b2362
> > (5)   Called-Station-Id = "A4-B2-39-CD-FE-3F"
> > (5)   Calling-Station-Id = "28-00-AF-0F-A8-32"
> > (5)   EAP-Message = 0x020600060d00
> > (5)   Message-Authenticator = 0x0dc4ca0033f30b31ea12f0a84c3615c3
> > (5) Restoring &session-state
> > (5)   &session-state:Framed-MTU = 994
> > (5)   &session-state:TLS-Session-Information = "(TLS) TLS - recv TLS
> > 1.3 Handshake, ClientHello"
> > (5)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, ServerHello"
> > (5)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 ChangeCipherSpec"
> > (5)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, EncryptedExtensions"
> > (5)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, CertificateRequest"
> > (5)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Certificate"
> > (5)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, CertificateVerify"
> > (5)   &session-state:TLS-Session-Information = "(TLS) TLS - send TLS
> > 1.3 Handshake, Finished"
> > (5) # Executing section authorize from file
> > /etc/freeradius/sites-enabled/default
> > (5)   authorize {
> > (5)     policy filter_username {
> > (5)       if (&User-Name) {
> > (5)       if (&User-Name)  -> TRUE
> > (5)       if (&User-Name)  {
> > (5)         if (&User-Name =~ / /) {
> > (5)         if (&User-Name =~ / /)  -> FALSE
> > (5)         if (&User-Name =~ /@[^@]*@/ ) {
> > (5)         if (&User-Name =~ /@[^@]*@/ )  -> FALSE
> > (5)         if (&User-Name =~ /\.\./ ) {
> > (5)         if (&User-Name =~ /\.\./ )  -> FALSE
> > (5)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))  {
> > (5)         if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\.(.+)$/))
> >   -> FALSE
> > (5)         if (&User-Name =~ /\.$/)  {
> > (5)         if (&User-Name =~ /\.$/)   -> FALSE
> > (5)         if (&User-Name =~ /@\./)  {
> > (5)         if (&User-Name =~ /@\./)   -> FALSE
> > (5)       } # if (&User-Name)  = notfound
> > (5)     } # policy filter_username = notfound
> > (5)     [preprocess] = ok
> > (5)     [chap] = noop
> > (5)     [mschap] = noop
> > (5)     [digest] = noop
> > (5) suffix: Checking for suffix after "@"
> > (5) suffix: No '@' in User-Name =
> > "host/353ec014-5c70-4e4c-a7c8-b9c8b5860352", looking up realm NULL
> > (5) suffix: No such realm "NULL"
> > (5)     [suffix] = noop
> > (5) eap: Peer sent EAP Response (code 2) ID 6 length 6
> > (5) eap: No EAP Start, assuming it's an on-going EAP conversation
> > (5)     [eap] = updated
> > (5)     [files] = noop
> > (5)     [expiration] = noop
> > (5)     [logintime] = noop
> > (5)     [pap] = noop
> > (5)   } # authorize = updated
> > (5) Found Auth-Type = eap
> > (5) # Executing group from file /etc/freeradius/sites-enabled/default
> > (5)   authenticate {
> > (5) eap: Removing EAP session with state 0xa960c76dad66ca67
> > (5) eap: Previous EAP request found for state 0xa960c76dad66ca67,
> > released from the list
> > (5) eap: Peer sent packet with method EAP TLS (13)
> > (5) eap: Calling submodule eap_tls to process data
> > (5) eap_tls: (TLS) Peer ACKed our handshake fragment
> > (5) eap: Sending EAP Request (code 1) ID 7 length 109
> > (5) eap: EAP session adding &reply:State = 0xa960c76dac67ca67
> > (5)     [eap] = handled
> > (5)   } # authenticate = handled
> > (5) Using Post-Auth-Type Challenge
> > (5) # Executing group from file /etc/freeradius/sites-enabled/default
> > (5)   Challenge { ... } # empty sub-section is ignored
> > (5) session-state: Saving cached attributes
> > (5)   Framed-MTU = 994
> > (5)   TLS-Session-Information = "(TLS) TLS - recv TLS 1.3 Handshake,
> > ClientHello"
> > (5)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > ServerHello"
> > (5)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 ChangeCipherSpec"
> > (5)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > EncryptedExtensions"
> > (5)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateRequest"
> > (5)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > Certificate"
> > (5)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake,
> > CertificateVerify"
> > (5)   TLS-Session-Information = "(TLS) TLS - send TLS 1.3 Handshake, Finished"
> > (5) Sent Access-Challenge Id 230 from 10.0.0.5:1812 to
> > 185.241.224.187:35356 length 167
> > (5)   EAP-Message =
> > 0x0107006d0d8000000fdbe33d32c6d71228255ebeafdd018899878a8fe0a80f886c4eb5170303004513e76f1ad52ae44957d10ac939c3d9a463013e536725fa716af274ae1ca18448ac2820e8abb26835729ebf1a1e0cca06c6553bba22f0249caa9e90802e54b60b89891323cb
> > (5)   Message-Authenticator = 0x00000000000000000000000000000000
> > (5)   State = 0xa960c76dac67ca67c033c547c41b2362
> > (5) Finished request
> > Waking up in 2.9 seconds.
> > (2) Cleaning up request packet ID 227 with timestamp +1410 due to
> > cleanup_delay was reached
> > Ready to process requests
> > -
> > List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.