fix(radius): prevent devices from using sqlippool during accounting
This commit is contained in:
@@ -648,13 +648,24 @@ accounting {
|
|||||||
# Ensure that &control:Pool-Name is set to determine which pool of IPs are used.
|
# Ensure that &control:Pool-Name is set to determine which pool of IPs are used.
|
||||||
# sqlippool
|
# sqlippool
|
||||||
|
|
||||||
### rebuild Pool-Name
|
#
|
||||||
|
# Determine the client type.
|
||||||
|
# Devices use a fixed IP from radreply.
|
||||||
|
# Engineers use an IP from sqlippool/radippool.
|
||||||
|
#
|
||||||
|
update control {
|
||||||
|
Tmp-String-1 := "%{sql:SELECT client_type FROM node_assignments WHERE username='%{User-Name}'}"
|
||||||
|
}
|
||||||
|
|
||||||
|
#
|
||||||
|
# Return the IP to the pool only for engineers.
|
||||||
|
#
|
||||||
|
if (&control:Tmp-String-1 == "engineer") {
|
||||||
|
|
||||||
update control {
|
update control {
|
||||||
Pool-Name := "engineers-%{sql:SELECT split_part('%{User-Name}', '@', 2)}"
|
Pool-Name := "engineers-%{sql:SELECT split_part('%{User-Name}', '@', 2)}"
|
||||||
}
|
}
|
||||||
|
|
||||||
### apply only for engineers
|
|
||||||
if (&control:Pool-Name =~ /^engineers-/) {
|
|
||||||
sqlippool
|
sqlippool
|
||||||
}
|
}
|
||||||
# Log traffic to an SQL database.
|
# Log traffic to an SQL database.
|
||||||
|
|||||||
Reference in New Issue
Block a user