Re: Radius 2 & Accounting

Mervyn Jack (mervynj@ace.cnl.com.au)
Tue, 22 Apr 1997 15:15:46 +1000 (EST)

On Tue, 22 Apr 1997, Paul Norton wrote:

> We have an shinny new PM2e on eval until the weekend.
> back in a couple of days:
Arrgh!! dont give it back! Buy it!

> 1. Where can we get Radius 2? (I can't find it on the Livingston site).

Buy the PM2 and you get Radius 2. However you don't need Radius 2 to
evaluate the PM2. We're still using 1.16.

> 2. I have installed accounting which produces a rather verbose log file.
> I'm intersted in hearing about any ISP style scripts for accounting and
> monitoring.

If you use grep creatively you can get enough for monitoring.

<ad> A collegue who works with us has developed an internet billing system
that can read multiple RADIUS log files and TACACS and UNIX log files and
send statements of usage and money owing by snail or email to your
customers. It also has a very well featured reporting system for you, the
isp. It uses access database so making adhoc queries is also easy. email
him at mjsmith@cnl.com.au or mjsmith@usa.net for more info.</ad>

>
> 3. For legacy reasons, we which to use the DEFAULT login with
> password="UNIX". This creates some sub-issues:
>
> a) Are there any scripts that let you monitor who is on line?
Get the program pmwho.
Check the links at the bottom of this page:
http://www.n2h2.com/useful_scripts/
http://www.msg.net/utility/PM/

>
> b) Is there a way to temporarily disable a users account (say when a
> monthly limit is reached) without manually modifying the /etc/passwd file?

For the few we lockout we do it by hand (passwd -l username) but you could
have a system that put's names in a file with a flag to lock or unlock,
then a cronjob could run a script every 10 minutes or so that loops
through the list of names and locks or unlocks them as required and
removes them from the list when dealt with.

>
> 4. Are there any major issues an ISP should know about with the PM2e
> before shelling out $5.5K?

Before we got our 3 PM2e for 3 POP's we used a Stallion 8 port board in a
Linux box and a Cisco 2509 8 port access server for 2 POP's. Changing to
the PM and using PPP and PAP for the customer logon process meant goodbye
to logon scripts and the phone support that goes with scripts. Only about
1% need something different than PPP so we just add them to the RADIUS
users file. You'll find there are solutions to most hurdles you might
encounter using a Portmaster. Others have been there done that.

regards.

Mervyn Jack, Technical Services, Country Netlink, Cobram, Vic, Australia.
Providing Internet access to the Cobram, Shepparton & Benalla local call
areas.
Phone 03 5871 1000 | Fax 03 5871 1874 | Mobile 019 438419
Work: http://www.cnl.com.au | Personal: http://www.cnl.com.au/~mervynj