![]() |
![]()
| ![]() |
![]()
NAMErlm_attr_filter - FreeRADIUS ModuleDESCRIPTIONThe rlm_attr_filter module exists for filtering certain attributes and values in received ( or transmitted ) radius packets. It gives the server a flexible framework to filter the attributes we send to or receive from home servers or NASes. This makes sense, for example, in an out-sourced dialup situation to various policy decisions, such as restricting a client to certain ranges of Idle-Timeout or Session-Timeout.Filter rules are normally defined and applied on a per-realm basis, where the realm is anything that is defined and matched based on the configuration of the rlm_realm module. Filter rules can optionally be applied using another attribute, by editing the key configuration for this module. In 2.0.1 and earlier versions, the "accounting" section filtered the Accounting-Request, even though it was documented as filtering the response. This issue has been fixed in version 2.0.2 and later versions. The "preacct" section may now be used to filter Accounting-Request packets. The "accounting" section now filters Accounting-Response packets. Administrators using "attr_filter" in the "accounting" section SHOULD move the reference to "attr_filter" from "accounting" to "preacct". The file that defines the attribute filtering rules follows a similar syntax to the users file. There are a few differences however: There are no check-items allowed other than the name of the key. There can only be a single DEFAULT entry. The rules for each entry are parsed to top to bottom, and an attribute must pass *all* the rules which affect it in order to make it past the filter. Order of the rules is important. The operators and their purpose in defining the rules are as follows:
If regular expressions are enabled the following operators are also possible. ( Regular Expressions are included by default unless your system doesn't support them, which should be rare ). The value field uses standard regular expression syntax.
See the default /usr/local/share/examples/freeradius/raddb/mods-config/attr_filter/ for working examples of sample rule ordering and how to use the different operators. The configuration items are:
SECTIONS
FILES/usr/local/share/examples/freeradius/raddb/radiusd.conf /usr/local/share/examples/freeradius/raddb/mods-config/attr_filter/*SEE ALSOradiusd(8), radiusd.conf(5)AUTHORChris Parker, cparker@segv.org
|