# attr_filter - filters the attributes received in replies from
# proxied servers, to make sure we send back to our RADIUS client
# only allowed attributes.
- attr_filter {
+ attr_filter attr_filter.post-proxy {
attrsfile = ${confdir}/attrs
}
+ # attr_filter - filters the attributes in the packets we send to
+ # the RADIUS home servers.
+ attr_filter attr_filter.pre-proxy {
+ attrsfile = ${confdir}/attrs.pre-proxy
+ }
+
# counter module:
# This module takes an attribute (count-attribute).
# It also takes a key, and creates a counter for each unique
# un-comment the following line, and the 'detail auth_log'
# section, above.
# auth_log
-
-# attr_filter
#
# The chap module will set 'Auth-Type := CHAP' if we are
# server, un-comment the following line, and the
# 'detail pre_proxy_log' section, above.
# pre_proxy_log
+
+ # Uncomment the following line if you want to filter requests
+ # sent to remote servers based on the rules defined in the
+ # 'attrs.pre-proxy' file.
+# attr_filter.pre-proxy
}
#
# post-proxy stage.
#
post-proxy {
- #
# If you want to have a log of replies from a home server,
# un-comment the following line, and the 'detail post_proxy_log'
# Uncomment the following line if you want to filter replies from
# remote proxies based on the rules defined in the 'attrs' file.
-
-# attr_filter
+# attr_filter.post-proxy
#
# If you are proxying LEAP, you MUST configure the EAP