[strongSwan] IKEv2 with eap-radius does not work.

Noel Kuntze noel at familie-kuntze.de
Sat Mar 25 00:54:15 CET 2017


On 24.03.2017 02:05, 리눅스랩 wrote:
> 2.   radius.log
>  
>  
> Fri Mar 24 08:55:37 2017 : Info: Dropping packet without response because of error: P
> ossible DoS attack from host 127.0.0.1: Too many attributes in request (received 201,
> max 200 are allowed).
> Fri Mar 24 08:55:39 2017 : Info: Dropping packet without response because of error: P
> ossible DoS attack from host 127.0.0.1: Too many attributes in request (received 201,
> max 200 are allowed).
> Fri Mar 24 08:55:42 2017 : Info: Dropping packet without response because of error: P
> ossible DoS attack from host 127.0.0.1: Too many attributes in request (received 201,
> max 200 are allowed).
> Fri Mar 24 08:55:45 2017 : Info: Dropping packet without response because of error: P
> ossible DoS attack from host 127.0.0.1: Too many attributes in request (received 201,
> max 200 are allowed).
>  
> What is wrong?

Your radius obviously drops the packets from charon, because there are too many attributes in the request.
Raise the limit.

-- 

Mit freundlichen Grüßen/Kind Regards,
Noel Kuntze

GPG Key ID: 0x63EC6658
Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 866 bytes
Desc: OpenPGP digital signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20170325/8e96eb1a/attachment-0001.sig>


More information about the Users mailing list