logo       

Re: Simultaneous-Use clarification: msg#00012

gnu.radius.general

Subject: Re: Simultaneous-Use clarification

Hi Scott,

> I'm a bit fuzzy on the description provided in the manual. If a
> username should only be allowed on connection to the NAS box should
> Simultaneous-Use have an integer value of 0? That is the way I have
> interpreted it, though my boss has interpreted it as meaning it should
> have a value of 1. I ask this because it currently is set to 1 and we had
> a user logged in twice over the weekend.

Simultaneous-Use attribute limits the number of sessions a user is able
to open simultaneously. It does not restrict in any way the total number
of logins each user may have. The minimal value for this attribute is 1.

Two parameters in the configuration are tightly connected with this
attribute:

1) Third field ('nas-type') of each record in raddb/naslist defines
the method that will be used for checking sessions currently
opened by the given user. Setting this field to 'false' effectively
disables Simultaneous-Use attribute.

2) The 'checkrad-assume-logged' statement in raddb/config file
controls actions of radius in cases when the checking procedure
fails.

Regards,
Sergey


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise