Re: (PM) RADIUS Question, but don't shoot.

Thomas Kinnen (tkinnen@livingston.com)
Fri, 19 Feb 1999 08:28:28 -0800

alex@nac.net wrote:

> The only reason I am posting this message is to ask the following
> question: Does the portmaster care if the source address of the
> access-reply packet is different than that of the ip address of "set auth
> x.x.x.x" ?

It Must come from the same address. If it was accepted from an another
address it would make hacking teh server just that much easier.

> I ask this because merit radius (and, in fact everyone I've seen except
> IEA RadiusNT) is stupid and won't let you specify what interface or ip to
> bind to on the machine.

Actually Lucent RADIUS ABM and RADIUS 2.1 allow you to bind to an IP
address.

----
Thomas C Kinnen - <tkinnen@livingston.com> <tkinnen@ra.lucent.com>
"All of the opinions stated above are my own and not my employer's,
unless they were given to me by my employer"

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.
Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>