On 13.3.2015 18.19, RICHARD DUNNE wrote: > thats right my outer tunnel is PEAP with an inner tunnel of MS-CHAP-v2. > I dont know why clients being sent form an other radius server is > looking for MSCHAPv2. Should they not first create the PEAP tunnel , > then the inner
Can you post more log? If the previous hop is not terminating the tunnel, like Alan suggsted, then the log should show why it is not matching the intended Handler. One thing what might be happening is that the inner requests are not matching any of the Handlers. The reason might be that the Realm is not matching the User-Name in the request object generated for the tunnelled PEAP message. Thanks, Heikki -- Heikki Vatiainen <h...@open.com.au> Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA, Vasco, Yubikey, MOTP, HOTP, TOTP, DIAMETER etc. Full source on Unix, Windows, MacOSX, Solaris, VMS, NetWare etc. _______________________________________________ radiator mailing list radiator@open.com.au http://www.open.com.au/mailman/listinfo/radiator