<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Wireless Radius disconnect in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36990#M1828</link>
    <description>Hi all,&lt;BR /&gt;
&lt;BR /&gt;
I have approximately the same question as Andre : I would like to disconnect a 802.1X (EAP-PEAP) authenticated wireless user when the corresponding session expires.&lt;BR /&gt;
&lt;BR /&gt;
I use FreeRADIUS with the "Expiration" attribute for the user, that properly generates a "Session-Timeout" reply-attribute that is sent back to NAS. However, it doesn't seem to be properly interpreted as the user is not disconnected when the session expires.&lt;BR /&gt;
&lt;BR /&gt;
I don't use NAC so EWC directly interacts with FreeRADIUS. Is the "Session-Timeout" interpreted by the EWC (so I am missing something in my config) or is the only solution to rely on RFC3576 (which FreeRADIUS is doing from what I have read, although I never tempered with it myself)?&lt;BR /&gt;
&lt;BR /&gt;
Thanks in advance for your reply.&lt;BR /&gt;
&lt;BR /&gt;
Regards.&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 20 May 2014 13:43:00 GMT</pubDate>
    <dc:creator>gherbiet</dc:creator>
    <dc:date>2014-05-20T13:43:00Z</dc:date>
    <item>
      <title>Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36986#M1824</link>
      <description>Hi    Does the Enterasys Wireless controller (V2110) support the Radius disconnect attributes?  Disconnect-Request (40)  Disconnect-ACK (41)  Disconnect-NAK (42)    I have a scenario where clients connect and authenticate via a Radius server.  The radius accounting monitors the amount of data used, once the user have reach a specific limit I would like to disconnect the user using radius disconnect messages.    Thx</description>
      <pubDate>Tue, 12 Nov 2013 19:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36986#M1824</guid>
      <dc:creator>Andre_Brits_Kan</dc:creator>
      <dc:date>2013-11-12T19:58:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36988#M1826</link>
      <description>Andre, did you need additional information regarding configuring this?  If so, let me know and I can point you in the right direction.  Thanks!</description>
      <pubDate>Wed, 13 Nov 2013 20:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36988#M1826</guid>
      <dc:creator>Tamera_Rousseau</dc:creator>
      <dc:date>2013-11-13T20:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36989#M1827</link>
      <description>I do not see the disconnect attributes on the release notes. The release notes show all the supported RADIUS attributes.</description>
      <pubDate>Fri, 15 Nov 2013 03:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36989#M1827</guid>
      <dc:creator>Jon_Linton</dc:creator>
      <dc:date>2013-11-15T03:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36990#M1828</link>
      <description>Hi all,&lt;BR /&gt;
&lt;BR /&gt;
I have approximately the same question as Andre : I would like to disconnect a 802.1X (EAP-PEAP) authenticated wireless user when the corresponding session expires.&lt;BR /&gt;
&lt;BR /&gt;
I use FreeRADIUS with the "Expiration" attribute for the user, that properly generates a "Session-Timeout" reply-attribute that is sent back to NAS. However, it doesn't seem to be properly interpreted as the user is not disconnected when the session expires.&lt;BR /&gt;
&lt;BR /&gt;
I don't use NAC so EWC directly interacts with FreeRADIUS. Is the "Session-Timeout" interpreted by the EWC (so I am missing something in my config) or is the only solution to rely on RFC3576 (which FreeRADIUS is doing from what I have read, although I never tempered with it myself)?&lt;BR /&gt;
&lt;BR /&gt;
Thanks in advance for your reply.&lt;BR /&gt;
&lt;BR /&gt;
Regards.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 20 May 2014 13:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36990#M1828</guid>
      <dc:creator>gherbiet</dc:creator>
      <dc:date>2014-05-20T13:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36991#M1829</link>
      <description>Session-Timeout should work. Can you get a trace of the RADIUS accept packet?&lt;BR /&gt;
&lt;BR /&gt;
-Doug&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;&lt;BR /&gt;&lt;/I&gt;</description>
      <pubDate>Thu, 22 May 2014 16:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36991#M1829</guid>
      <dc:creator>Doug</dc:creator>
      <dc:date>2014-05-22T16:58:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36992#M1830</link>
      <description>Hello Doug,&lt;BR /&gt;
&lt;BR /&gt;
This is the relevant part of &lt;I&gt;users&lt;/I&gt; file on my FreeRADIUS setup:&lt;BR /&gt;
expuser Cleartext-Password := "exppasswd", Expiration := "23 May 2014 08:30:00"      Idle-Timeout = 60, Termination-Action = 1&lt;BR /&gt;
I have &lt;I&gt;expiration&lt;/I&gt; module enabled on the &lt;I&gt;authorize&lt;/I&gt; section in the &lt;I&gt;sites-enabled/default&lt;/I&gt; file.&lt;BR /&gt;
&lt;BR /&gt;
This is what I get from FreeRADIUS when I do a &lt;I&gt;radtest&lt;/I&gt;:&lt;BR /&gt;
# radtest expuser exppasswd 127.0.0.1 1812 testing123Sending Access-Request of id 23 to 127.0.0.1 port 1812&lt;BR /&gt;
User-Name = "expuser"&lt;BR /&gt;
User-Password = "exppasswd"&lt;BR /&gt;
NAS-IP-Address = 127.0.0.1&lt;BR /&gt;
NAS-Port = 1812&lt;BR /&gt;
Message-Authenticator = 0x00000000000000000000000000000000&lt;BR /&gt;
rad_recv: Access-Accept packet from host 127.0.0.1 port 1812, id=23, length=38&lt;BR /&gt;
Idle-Timeout = 60&lt;BR /&gt;
Termination-Action = RADIUS-Request&lt;BR /&gt;
Session-Timeout = 512And the output of &lt;I&gt;freeradius -X&lt;/I&gt;:&lt;BR /&gt;
ad_recv: Access-Request packet from host 127.0.0.1 port 38807, id=119, length=88        User-Name = "expuser"&lt;BR /&gt;
        User-Password = "exppasswd"&lt;BR /&gt;
        NAS-IP-Address = 127.0.0.1&lt;BR /&gt;
        NAS-Port = 1812&lt;BR /&gt;
        Message-Authenticator = 0x9cefec4ec23437b14f8b94d0a7630ac2&lt;BR /&gt;
# Executing section authorize from file /etc/freeradius/sites-enabled/default&lt;BR /&gt;
+- entering group authorize {...}&lt;BR /&gt;
++[preprocess] returns ok&lt;BR /&gt;
++[chap] returns noop&lt;BR /&gt;
++[mschap] returns noop&lt;BR /&gt;
++[digest] returns noop&lt;BR /&gt;
[eap] No EAP-Message, not doing EAP&lt;BR /&gt;
++[eap] returns noop&lt;BR /&gt;
[files] users: Matched entry expuser at line 207&lt;BR /&gt;
++[files] returns ok&lt;BR /&gt;
[expiration] Checking Expiration time: '23 May 2014 08:30:00'&lt;BR /&gt;
++[expiration] returns ok&lt;BR /&gt;
++[logintime] returns noop&lt;BR /&gt;
++[pap] returns updated&lt;BR /&gt;
Found Auth-Type = PAP&lt;BR /&gt;
# Executing group from file /etc/freeradius/sites-enabled/default&lt;BR /&gt;
+- entering group PAP {...}&lt;BR /&gt;
[pap] login attempt with password "exppasswd"&lt;BR /&gt;
[pap] Using clear text password "exppasswd"&lt;BR /&gt;
[pap] User authenticated successfully&lt;BR /&gt;
++[pap] returns ok&lt;BR /&gt;
# Executing section post-auth from file /etc/freeradius/sites-enabled/default&lt;BR /&gt;
+- entering group post-auth {...}&lt;BR /&gt;
++[exec] returns noop&lt;BR /&gt;
Sending Access-Accept of id 23 to 127.0.0.1 port 38807&lt;BR /&gt;
        Idle-Timeout = 60&lt;BR /&gt;
        Termination-Action = RADIUS-Request&lt;BR /&gt;
        Session-Timeout = 512&lt;BR /&gt;
Finished request 46.&lt;BR /&gt;
Going to the next request&lt;BR /&gt;
Waking up in 4.9 seconds.&lt;BR /&gt;
Cleaning up request 46 ID 119 with timestamp +457&lt;BR /&gt;
Ready to process requests.  &lt;BR /&gt;
I also tested from my EWC (the FreeRADIUS output is much more verbose so I pasted it there : &lt;A href="http://pastebin.com/xFu6AdbL" target="_blank" rel="nofollow noreferrer noopener"&gt;http://pastebin.com/xFu6AdbL&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
I can successfully authenticate before the expiration date and not after (which is great) but the device I connected via the controller is not disconnected when the session expires.&lt;BR /&gt;
&lt;BR /&gt;
Does that bring any idea up?</description>
      <pubDate>Fri, 23 May 2014 11:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36992#M1830</guid>
      <dc:creator>gherbiet</dc:creator>
      <dc:date>2014-05-23T11:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36993#M1831</link>
      <description>Have you been able to make any progress on this? I would try including the session-timeout in the return attributes that get included in the RADIUS accept.&lt;BR /&gt;
&lt;BR /&gt;
-Doug</description>
      <pubDate>Fri, 23 May 2014 11:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36993#M1831</guid>
      <dc:creator>Doug</dc:creator>
      <dc:date>2014-05-23T11:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36994#M1832</link>
      <description>Sorry for the late reply, If you view the client report on the controller is the client on longer than the 512 seconds?&lt;BR /&gt;
&lt;BR /&gt;
-Doug</description>
      <pubDate>Tue, 27 May 2014 22:00:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36994#M1832</guid>
      <dc:creator>Doug</dc:creator>
      <dc:date>2014-05-27T22:00:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36995#M1833</link>
      <description>Also unless I missed it, the verbose trace showed the Access-Challenge is where the session-timeout was. I could not find it in the Access-Accept at all.  While that should be valid, I have only seen it work when in the Access-Accept from the RADIUS server. If the session time on the controller shows the client connecting after 8 min we can review the session table on the controller to see if it does have the session-timeout value properly defined but my guess is it's ignoring it in the challenge and needs to see it in the accept packet. &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 27 May 2014 22:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36995#M1833</guid>
      <dc:creator>Doug</dc:creator>
      <dc:date>2014-05-27T22:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Radius disconnect</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36996#M1834</link>
      <description>Regarding this topic, we are seeing the same behaviour when freeradius sends "Disconnect-Request (40)" the C25 Controller (v9.21.09.0004) receives the request we can see it from the traces but never replies back and the user session is not terminated.</description>
      <pubDate>Thu, 26 May 2016 15:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-radius-disconnect/m-p/36996#M1834</guid>
      <dc:creator>Emre_Kurtman</dc:creator>
      <dc:date>2016-05-26T15:43:00Z</dc:date>
    </item>
  </channel>
</rss>

