Radius Agent

rated by 0 users
Not Answered This post has 0 verified answers | 2 Replies | 2 Followers

Not Ranked
7 Posts
burbankmarc posted on 3 May 2012 5:29 AM

Hello all,

I have a ticket open with websense, but they have not been helpful at all. I was hoping maybe someone here could help me. I can't seem to get Radius Agent working properly. I have logging, and debugging turned on. This is the only log entry I get and it only shows up when I start Radius Agent.

 

2012-05-03 07:57:35 ERROR: Please check your configuration. AuthOutPort can't be the same as AccOutPort

However, I have it specified within wsradius.ini that the AuthOutPort is 1645 and the AccOutPort is 1646. The application knows this because here's the output if I start Radius Agent from the command line.
c:\Program Files (x86)\Websense\Web Security\bin>RadiusAgent.exe -c
Starting New Diagnostics...
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
   Starting Websense RADIUS Agent...
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Comm Framework listening on port 55822
Trying to connect to PolicyServer...
Connected to PolicyServer.
RadiusHost: 2013335724
AuthInPort: 12345
AuthOutPort: 1645
AccInPort: 12346
AccOutPort: 1646
XidPort: 30800
DiagPort: 30801
Timeout: 1000
HTTPAuth: 0
There is no password in ini file
Done getting RadiusAgent configurations!
DiagnosticManager listening on port 30801
Press Enter to quit
Yet, Radius Agent just dumps that log entry and does not work. I've tried reinstalling, and also applied the latest hotfix. This is on websense 7.6.2 on a Windows Server 2008 R2 server.
Does anyone know what might be the problem?

|

All Replies

Not Ranked
3 Posts

did you ever get an answer for this?  I am in the same boat.  I have (2) 10k triton applicances and can not get RADIUS Agent to work..

|
Not Ranked
7 Posts

Sort of. To make it so Radius Agent would work at all I had to move the NPS server to a different machine. You can't have Radius Agent and a Radius Server on the same box. Radius Agent IS a radius server, but it just proxies all requests to the actual radius server.

 

Once I moved the NPS to a different machine I was able to authenticate and hop on my wireless. However, Radius Agent keeps adding a \ to the username, so instead of jsmith it thinks the username is \jsmith. This makes the AD user lookup fail so the user doesn't get filtered at all. I don't have a fix for this yet, the ticket is currently with the dev team .

|
Page 1 of 1 (3 items)