Опыт установки 5.3 на боевом сервере
В общем приводить содержимое таблицы не буду, там 974 правила и все работающие.
Есть 25 строк где поле events=2 и 949 строк где events=1
+------------+--------------+------+-----+---------+----------------+
| Field | Type | Null | Key | Default | Extra |
+------------+--------------+------+-----+---------+----------------+
| id | int(11) | NO | PRI | NULL | auto_increment |
| flags | int(11) | NO | | NULL | |
| events | bigint(20) | NO | | NULL | |
| router_id | int(11) | NO | | NULL | |
| tariff_id | int(11) | NO | | NULL | |
| group_id | int(11) | NO | | NULL | |
| user_id | int(11) | NO | | NULL | |
| rule | varchar(255) | NO | | NULL | |
| comment | varchar(255) | NO | | NULL | |
| is_deleted | int(11) | NO | | NULL | |
+------------+--------------+------+-----+---------+----------------+
Могут быть проблемы если база на 64 битной машине с полем bigint?
Есть 25 строк где поле events=2 и 949 строк где events=1
+------------+--------------+------+-----+---------+----------------+
| Field | Type | Null | Key | Default | Extra |
+------------+--------------+------+-----+---------+----------------+
| id | int(11) | NO | PRI | NULL | auto_increment |
| flags | int(11) | NO | | NULL | |
| events | bigint(20) | NO | | NULL | |
| router_id | int(11) | NO | | NULL | |
| tariff_id | int(11) | NO | | NULL | |
| group_id | int(11) | NO | | NULL | |
| user_id | int(11) | NO | | NULL | |
| rule | varchar(255) | NO | | NULL | |
| comment | varchar(255) | NO | | NULL | |
| is_deleted | int(11) | NO | | NULL | |
+------------+--------------+------+-----+---------+----------------+
Могут быть проблемы если база на 64 битной машине с полем bigint?
Последний раз редактировалось tshadrin Ср окт 02, 2013 16:46, всего редактировалось 1 раз.
HELP!!!
Обновился на 1 базе с 5.2.1.008
и перестали авторизовываться пользователи 691 ошибка.
Вот mpd
Блин напоминает проблему с 1 страницы от kirush
Конфиг радиуса
UPD Наткнулся на это
Это баг. Зарегистрировал mantis ID 2095.
Если проблема не терпит до update1, обратитесь в техподдержку, сделаем оперативное исправление.
Обновился на 1 базе с 5.2.1.008
и перестали авторизовываться пользователи 691 ошибка.
Код: Выделить всё
?Debug : Oct 02 19:14:11 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:14:11 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:14:40 dc8fe700 SessionManager: periodic check started
?Debug : Oct 02 19:14:41 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:14:41 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:15:11 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:15:11 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:15:41 dc8fe700 SessionManager: periodic check started
?Debug : Oct 02 19:15:41 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:15:41 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:16:11 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:16:11 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:16:41 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:16:41 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:16:42 dc8fe700 SessionManager: periodic check started
?Debug : Oct 02 19:17:11 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:17:11 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:17:41 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:17:41 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:17:43 dc8fe700 SessionManager: periodic check started
?Debug : Oct 02 19:18:11 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:18:11 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:18:41 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:18:41 dc5fb700 Transport: got PING event
?Debug : Oct 02 19:18:44 dc8fe700 SessionManager: periodic check started
?Debug : Oct 02 19:18:52 dcb00700 AuthQueue: New request from 172.28.200.12:58478
--- RADIUS Pkt ---
Code: [1] ID: [-53]
Auth: Size 16; Data [0x0da54e6135c24d016e8ea3c42b835865]
Attr: [32] Vendor: [0] Size 7; Data [0x56504e5f4e4557]
(NAS-Identifier=STRING:VPN_NEW)
Attr: [4] Vendor: [0] Size 4; Data [0xac1cc80c]
(NAS-IP-Address=IP:172.28.200.12)
Attr: [80] Vendor: [0] Size 16; Data [0x717017c6d3d07b587b3e32c7a6616868]
(Message-Authenticator=HEX:...)
Attr: [44] Vendor: [0] Size 10; Data [0x3732373030312d4d2d32]
(Acct-Session-Id=STRING:727001-M-2)
Attr: [5] Vendor: [0] Size 4; Data [0x00000002]
(NAS-Port=INT:2)
Attr: [61] Vendor: [0] Size 4; Data [0x00000005]
(NAS-Port-Type=INT:5)
Attr: [6] Vendor: [0] Size 4; Data [0x00000002]
(Service-Type=INT:2)
Attr: [7] Vendor: [0] Size 4; Data [0x00000001]
(Framed-Protocol=INT:1)
Attr: [31] Vendor: [0] Size 13; Data [0x3137322e32302e3235342e3235]
(Calling-Station-Id=STRING:172.20.254.25)
Attr: [30] Vendor: [0] Size 0; Data [0x]
(Called-Station-Id=STRING:)
Attr: [12] Vendor: [12341] Size 3; Data [0x4d2d32]
Attr: [19] Vendor: [12341] Size 51; Data [0x4d5352415356352e3230204d535241532d302d57494e2d4f32455230464a47545137205e4ac1ee5aee6e4ea18049541715465d]
Attr: [64] Vendor: [0] Size 4; Data [0x00000001]
(Tunnel-Type=INT:1)
Attr: [65] Vendor: [0] Size 4; Data [0x00000001]
(Tunnel-Medium-Type=INT:1)
Attr: [67] Vendor: [0] Size 13; Data [0x3137322e32382e3230302e3132]
(Tunnel-Server-Endpoint=STRING:172.28.200.12)
Attr: [66] Vendor: [0] Size 13; Data [0x3137322e32302e3235342e3235]
(Tunnel-Client-Endpoint=STRING:172.20.254.25)
Attr: [91] Vendor: [0] Size 7; Data [0x56504e5f4e4557]
(Tunnel-Server-Auth-Id=STRING:VPN_NEW)
Attr: [1] Vendor: [0] Size 5; Data [0x626f6f6b31]
(User-Name=STRING:book1)
Attr: [11] Vendor: [311] Size 16; Data [0xbb1e68687fba34c715d150a7f17fbd87]
(Microsoft:MS-CHAP-Challenge=HEX:...)
Attr: [25] Vendor: [311] Size 50; Data [0x010083e3bca9c137abb17df7861b1b3a5c050000000000000000abaf81cef41e8bf816a2a25c7670a3d32a18cb8b162b2d4d]
(Microsoft:MS-CHAP2-Response=HEX:...)
?Debug : Oct 02 19:18:52 dcb00700 AuthQueue: Login 'book1'
?Debug : Oct 02 19:18:52 dcb00700 AuthQueue: Using MSCHAPv2 authentication method
ERROR : Oct 02 19:18:52 dcb00700 MSCHAPv2 Authenticator: Login not found, rejecting
?Debug : Oct 02 19:18:52 dcb00700 AuthQueue: Guest authorization is not enabled
ERROR : Oct 02 19:18:52 dcb00700 AuthQueue: MSCHAPv2 authentication failed
?Debug : Oct 02 19:18:52 dcb00700 AcctQueue: lookup: session ID 4 closed
?Debug : Oct 02 19:18:52 dcb00700 SessionManager: put: sessiond ID 4 from NAS 30 is closed
?Debug : Oct 02 19:18:52 dcb00700 AuthQueue: Reply
--- RADIUS Pkt ---
Code: [3] ID: [-53]
Auth: Size 16; Data [0x0da54e6135c24d016e8ea3c42b835865]
?Debug : Oct 02 19:19:11 dc5fb700 StreamConnection: Got message ID 0x2129
?Debug : Oct 02 19:19:11 dc5fb700 Transport: got PING event
Код: Выделить всё
Oct 2 19:17:13 VPN_NEW mpd: [M-2] Name: "book1"
Oct 2 19:17:13 VPN_NEW mpd: [M-2] AUTH: Trying RADIUS
Oct 2 19:17:13 VPN_NEW mpd: [M-2] RADIUS: Authenticating user 'book1'
Oct 2 19:17:13 VPN_NEW mpd: [M-2] RADIUS: Rec'd RAD_ACCESS_REJECT for user 'book1'
Oct 2 19:17:13 VPN_NEW mpd: [M-2] AUTH: RADIUS returned: failed
Oct 2 19:17:13 VPN_NEW mpd: [M-2] AUTH: Trying INTERNAL
Oct 2 19:17:13 VPN_NEW mpd: [M-2] AUTH: User "book1" not found in secret file
Oct 2 19:17:13 VPN_NEW mpd: [M-2] AUTH: INTERNAL returned: failed
Oct 2 19:17:13 VPN_NEW mpd: [M-2] AUTH: ran out of backends
Oct 2 19:17:13 VPN_NEW mpd: [M-2] CHAP: Auth return status: failed
Oct 2 19:17:13 VPN_NEW mpd: [M-2] CHAP: Reply message: E=691 R=0 M=Login incorrect
Oct 2 19:17:13 VPN_NEW mpd: [M-2] CHAP: sending FAILURE #1 len: 31
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: authorization failed
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: parameter negotiation failed
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: state change Opened --> Stopping
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: SendTerminateReq #4
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: LayerDown
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: rec'd Terminate Ack #4 (Stopping)
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: state change Stopping --> Stopped
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: LayerFinish
Oct 2 19:17:13 VPN_NEW mpd: [M-2] device: CLOSE event
Oct 2 19:17:13 VPN_NEW mpd: pptp0-0: clearing call
Oct 2 19:17:13 VPN_NEW mpd: pptp0-0: killing channel
Oct 2 19:17:13 VPN_NEW mpd: [M-2] PPTP call terminated
Oct 2 19:17:13 VPN_NEW mpd: [M-2] device: DOWN event
Oct 2 19:17:13 VPN_NEW mpd: [M-2] Link: DOWN event
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: Close event
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: state change Stopped --> Closed
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: Down event
Oct 2 19:17:13 VPN_NEW mpd: [M-2] LCP: state change Closed --> Initial
Oct 2 19:17:13 VPN_NEW mpd: [M-2] Link: SHUTDOWN event
Oct 2 19:17:13 VPN_NEW mpd: [M-2] Link: Shutdown
Oct 2 19:17:13 VPN_NEW mpd: pptp0: CID 0x2d74 in SetLinkInfo not found
Oct 2 19:17:13 VPN_NEW mpd: pptp0: got StopCtrlConnRequest: reason=none
Oct 2 19:17:13 VPN_NEW mpd: pptp0: killing connection with 172.20.254.25 57214
Конфиг радиуса
Код: Выделить всё
core_host=127.0.0.1
core_port=12758
radius_ssl_type=none
radius_acct_host=172.28.100.9
radius_acct_port=1813
radius_auth_host=172.28.100.9
radius_auth_port=1812
radius_auth_vap=1
radius_card_autoadd=no
interim_update_interval=61
radius_default_session_timeout=86400
log_file_main=/netup/utm5/log/radius_main.log
log_file_debug=/netup/utm5/log/radius_debug.log
log_file_critical=/netup/utm5/log/radius_critical.log
rotate_logs=yes
max_logfile_count=30
Это баг. Зарегистрировал mantis ID 2095.
Если проблема не терпит до update1, обратитесь в техподдержку, сделаем оперативное исправление.
Я снял у пользователя в сервисной связке не применять правила firewall . И все пошло! Я уже голову вынес было.
В Настройках правила firewall ничего нет.
Где то еще надо глянуть?
Вот лог где все завелось
В Настройках правила firewall ничего нет.
Где то еще надо глянуть?
Вот лог где все завелось
Код: Выделить всё
?Debug : Oct 02 19:48:10 31346700 AuthQueue: Login 'book1'
?Debug : Oct 02 19:48:10 31346700 LoginStorage: Acquire: login 'book1' used 1 times
?Debug : Oct 02 19:48:10 31346700 AuthQueue: Login info found, slink_id 6352
?Debug : Oct 02 19:48:10 31346700 AuthQueue: Using MSCHAPv2 authentication method
?Debug : Oct 02 19:48:10 31346700 MSCHAPv2 Authenticator: MS-CHAPv2: MPPE Keys send
?Debug : Oct 02 19:48:10 31346700 MSCHAPv2 Authenticator: MS-CHAPv2: Authorized user <book1>
?Debug : Oct 02 19:48:10 31346700 AuthQueue: MSCHAPv2 authentication OK
?Debug : Oct 02 19:48:10 31346700 AuthQueue: Service ID 121 type 3; account ID 1
?Debug : Oct 02 19:48:10 31346700 IPPoolManager: IP 109.197.119.140 is leased from LoginPool 'book1'
?Debug : Oct 02 19:48:10 31346700 ExtendedAttributeStorage: Attributes for type='SHAPING' not exist in RADIUS_server
?Debug : Oct 02 19:48:10 31346700 ExtendedAttributeStorage: Attributes for type='NAS' not exist in RADIUS_server
?Debug : Oct 02 19:48:10 31346700 ExtendedAttributeStorage: Attributes for type='SERVICE_LINK' and id='6352 not found
?Debug : Oct 02 19:48:10 31346700 AcctQueue: lookup: session ID 5 for login 'book1'
?Debug : Oct 02 19:48:10 31346700 AcctQueue: lookup: session ID 5 for IP 109.197.119.140
?Debug : Oct 02 19:48:10 31346700 SessionManager: put: session ID 5 timeout scheduled at 1380728920
?Debug : Oct 02 19:48:10 31346700 SessionManager: put: session ID 5 from NAS 30 OK
?Debug : Oct 02 19:48:10 31346700 AuthQueue: Reply
--- RADIUS Pkt ---
Code: [2] ID: [35]
Auth: Size 16; Data [0x84e191e07e7baf065fcd5b1d4986313e]
Attr: [26] Vendor: [311] Size 44; Data [0x81533d4435463839303141433542383533464543443443303437383541323234423341454337363031323700]
(Microsoft:MS-CHAP2-Success=HEX:...)
Attr: [16] Vendor: [311] Size 34; Data [0x8e19188afcdb17c4dd4d9d17a3f6d3f4d8c85089251d882dc09165bef39f6c1022a0]
(Microsoft:MS-MPPE-Send-Key=HEX:...)
Attr: [17] Vendor: [311] Size 34; Data [0x846f24a8d4255a1fe841f37b6aee2d744dd5e240c4681f092a7bf0bbee0019247d1f]
(Microsoft:MS-MPPE-Recv-Key=HEX:...)
Attr: [7] Vendor: [311] Size 4; Data [0x00000001]
(Microsoft:MS-MPPE-Encryption-Policy=HEX:...)
Attr: [8] Vendor: [311] Size 4; Data [0x00000006]
(Microsoft:MS-MPPE-Encryption-Type=HEX:...)
Attr: [6] Vendor: [0] Size 4; Data [0x00000002]
(Service-Type=INT:2)
Attr: [7] Vendor: [0] Size 4; Data [0x00000001]
(Framed-Protocol=INT:1)
Attr: [8] Vendor: [0] Size 4; Data [0x6dc5778c]
(Framed-IP-Address=IP:109.197.119.140)
Attr: [9] Vendor: [0] Size 4; Data [0xffffffff]
(Framed-IP-Netmask=IP:255.255.255.255)
Attr: [27] Vendor: [0] Size 4; Data [0x00015180]
(Session-Timeout=INT:86400)
Attr: [8] Vendor: [14988] Size 9; Data [0x3130304d2f3130304d]
(Mikrotik:Mikrotik-Rate-Limit=STRING:100M/100M)
Attr: [7] Vendor: [12341] Size 30; Data [0x6f757423313d616c6c207368617065203130323430303030302070617373]
Attr: [7] Vendor: [12341] Size 29; Data [0x696e23313d616c6c207368617065203130323430303030302070617373]
Attr: [85] Vendor: [0] Size 4; Data [0x0000003d]
(Acct-Interim-Interval=INT:61)
?Debug : Oct 02 19:48:10 31245700 AcctQueue: Request from 172.28.200.12:60536
--- RADIUS Pkt ---
Code: [4] ID: [-27]
Auth: Size 16; Data [0xdf126f6407d9e6fdf498372e4a42cd23]
Attr: [32] Vendor: [0] Size 7; Data [0x56504e5f4e4557]
(NAS-Identifier=STRING:VPN_NEW)
Attr: [4] Vendor: [0] Size 4; Data [0xac1cc80c]
(NAS-IP-Address=IP:172.28.200.12)
Attr: [44] Vendor: [0] Size 10; Data [0x3732383735392d4d2d32]
(Acct-Session-Id=STRING:728759-M-2)
Attr: [5] Vendor: [0] Size 4; Data [0x00000002]
(NAS-Port=INT:2)
Attr: [61] Vendor: [0] Size 4; Data [0x00000005]
(NAS-Port-Type=INT:5)
Attr: [6] Vendor: [0] Size 4; Data [0x00000002]
(Service-Type=INT:2)
Attr: [7] Vendor: [0] Size 4; Data [0x00000001]
(Framed-Protocol=INT:1)
Attr: [31] Vendor: [0] Size 13; Data [0x3137322e32302e3235342e3235]
(Calling-Station-Id=STRING:172.20.254.25)
Attr: [30] Vendor: [0] Size 0; Data [0x]
(Called-Station-Id=STRING:)
Attr: [12] Vendor: [12341] Size 3; Data [0x4d2d32]
Attr: [19] Vendor: [12341] Size 51; Data [0x4d5352415356352e3230204d535241532d302d57494e2d4f32455230464a4754513720cf41425129601f44b169eb9546c5a562]
Attr: [64] Vendor: [0] Size 4; Data [0x00000001]
(Tunnel-Type=INT:1)
Attr: [65] Vendor: [0] Size 4; Data [0x00000001]
(Tunnel-Medium-Type=INT:1)
Attr: [67] Vendor: [0] Size 13; Data [0x3137322e32382e3230302e3132]
(Tunnel-Server-Endpoint=STRING:172.28.200.12)
Attr: [66] Vendor: [0] Size 13; Data [0x3137322e32302e3235342e3235]
(Tunnel-Client-Endpoint=STRING:172.20.254.25)
Attr: [91] Vendor: [0] Size 7; Data [0x56504e5f4e4557]
(Tunnel-Server-Auth-Id=STRING:VPN_NEW)
Attr: [40] Vendor: [0] Size 4; Data [0x00000001]
(Acct-Status-Type=INT:1)
Attr: [8] Vendor: [0] Size 4; Data [0x6dc5778c]
(Framed-IP-Address=IP:109.197.119.140)
Attr: [9] Vendor: [0] Size 4; Data [0xffffffff]
(Framed-IP-Netmask=IP:255.255.255.255)
Attr: [1] Vendor: [0] Size 5; Data [0x626f6f6b31]
(User-Name=STRING:book1)
Attr: [50] Vendor: [0] Size 10; Data [0x3732383735392d432d32]
(Acct-Multi-Session-Id=STRING:728759-C-2)
Attr: [13] Vendor: [12341] Size 3; Data [0x432d32]
Attr: [14] Vendor: [12341] Size 3; Data [0x6e6730]
Attr: [15] Vendor: [12341] Size 4; Data [0x00000010]
Attr: [19] Vendor: [12341] Size 51; Data [0x4d5352415356352e3230204d535241532d302d57494e2d4f32455230464a4754513720cf41425129601f44b169eb9546c5a562]
Attr: [51] Vendor: [0] Size 4; Data [0x00000001]
(Acct-Link-Count=INT:1)
Attr: [45] Vendor: [0] Size 4; Data [0x00000001]
(Acct-Authentic=INT:1)
?Debug : Oct 02 19:48:10 31245700 SessionManager: get: session ID 5
?Debug : Oct 02 19:48:10 31245700 AcctQueue: found session ID 5 for IP 109.197.119.140
?Debug : Oct 02 19:48:10 31245700 AcctQueue: sid_insert: session ID 5 for SID 728759-M-2
Info : Oct 02 19:48:10 31245700 AcctQueue: Accounting-Start for SID 728759-M-2 user 'book1' slink ID 6352 from NAS 172.28.200.12
?Debug : Oct 02 19:48:10 31245700 Transport: sending traffic/dialup session ID 5
?Debug : Oct 02 19:48:10 31245700 StreamConnection: Sending message ID 0x1107
?Debug : Oct 02 19:48:10 31245700 SessionManager: put: session ID 5 timeout scheduled at 2000000000
?Debug : Oct 02 19:48:10 31245700 SessionManager: put: session ID 5 from NAS 30 OK
?Debug : Oct 02 19:48:10 31245700 AcctQueue: Reply
--- RADIUS Pkt ---
Code: [5] ID: [-27]
Auth: Size 16; Data [0xdf126f6407d9e6fdf498372e4a42cd23]