Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 16 Jul 1999 11:25:32 -0700
From:      "Bryn Wm. Moslow" <bryn@nwlink.com>
To:        Ben Vaughn <bvaughn@prophetnetworks.net>
Cc:        freebsd-isp@FreeBSD.ORG
Subject:   Re: cistron and speed limiting?
Message-ID:  <378F791C.3132B7B4@nwlink.com>
References:  <Pine.BSF.4.10.9907161247440.43026-100000@shell01.prophetnetworks.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Ben Vaughn wrote:
> 
>         Hello,
>         We use cistron radius as our radius type and I was wondering if
> anyone on this list has used this to successfully limit users speeds? We
> have a default entry for anyone who shows up in passwd, but since our
> access server is a digital one, a customer paying for 33.6k can use 56k or
> even isdn! We can set port-limit to 1 to remove the problem of people
> using 128k isdn, but we still cannot speed limit people. I am trying to
> make the default entry 33.6k only, while if someone is a 56k or isdn user,
> they have to have a separate entry in users to be able to use it. Have
> tried setting NAS-Port-Type but to no avail. Anybody have a clue?
> 
> Thanks,
> Ben Vaughn
> 
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-isp" in the body of the message

I successfully use Port-Type with Livingston RADIUS 2.0 to at least keep
analog accounts from using ISDN, "NAS-Port-Type = Async" in my DEFAULT.
Your hardware may not accept the Port-Type response item. Check your
hardware manual against your RADIUS dictionary. I'm using
Livingston/Lucent Portmasters and 3Com/USR Total Control Chassis.

I don't see how you would do this without sending commands directly to
the modem the user is connecting to as the physical connection is
negotiated and made before authentication via RADIUS takes place. It
might be possible, hardware allowing, with a log-watching script or some
hacking of the RADIUS code itself which could get you more trouble than
it's worth if you have lots of short connections or allow Multi-PPP.
Sadly, I can think of many more reasons to not do it than do it that
way.

-- 

    /\        /\            /| Bryn Wm. Moslow         
   /  \      /  \          / | Manager of Systems Operations
  /    \    /    \        /  | Northwest Link
 /      \  /      \  /\  /   | (425) 451-1151 -or- (800) 390-1270 
/        \/        \/  \/    |_______ http://www.nwlink.com


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?378F791C.3132B7B4>