<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [radius_client] Host must be an IP Address in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/radius-client-host-must-be-an-ip-address/m-p/4880429#M596</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi &lt;A class="mention" href="https://community.duo.com/u/jozefrebjak"&gt;@jozefrebjak&lt;/A&gt; ,&lt;/P&gt;
&lt;P&gt;Using hostnames in the &lt;CODE&gt;host&lt;/CODE&gt; config for the &lt;CODE&gt;[radius_client]&lt;/CODE&gt; section is currently not supported and will cause the &lt;A href="https://duo.com/docs/authproxy-reference#using-the-connectivity-tool" rel="noopener nofollow ugc"&gt;Connectivity Tool&lt;/A&gt; to error.&lt;/P&gt;
&lt;P&gt;Please feel free to submit this and any future Feature Request via your Duo Account Executive, Customer Success Manager (if applicable), or our &lt;A href="https://duo.com/support" rel="noopener nofollow ugc"&gt;Support Team&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 27 Jan 2023 21:22:53 GMT</pubDate>
    <dc:creator>DuoPablo</dc:creator>
    <dc:date>2023-01-27T21:22:53Z</dc:date>
    <item>
      <title>[radius_client] Host must be an IP Address</title>
      <link>https://community.cisco.com/t5/managing-users/radius-client-host-must-be-an-ip-address/m-p/4880428#M595</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Is there any reason why &lt;CODE&gt;host&lt;/CODE&gt; in &lt;CODE&gt;radius_client&lt;/CODE&gt; must be an IPv4 Address ?  As I can see with &lt;CODE&gt;ad_client&lt;/CODE&gt; is possible to specify &lt;STRONG&gt;Hostname.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In &lt;A href="https://duo.com/docs/authproxy-reference" rel="noopener nofollow ugc"&gt;reference&lt;/A&gt; is described Host within &lt;CODE&gt;ad_client&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;host&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The hostname&lt;/STRONG&gt; or IP address of your domain controller or directory server. If this host doesn’t respond to a primary authentication request and no additional hosts are specified (as &lt;CODE&gt;host_2&lt;/CODE&gt; , &lt;CODE&gt;host_3&lt;/CODE&gt; , etc.) then the user’s login attempt fails.&lt;/P&gt;
&lt;P&gt;But with &lt;CODE&gt;radius_client&lt;/CODE&gt; it’s:&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;host&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;The IP address of your primary RADIUS server. If this host doesn’t respond to a primary authentication request and no additional hosts are specified (as &lt;CODE&gt;host_2&lt;/CODE&gt;, &lt;CODE&gt;host_3&lt;/CODE&gt;, etc.) then the user’s login attempt fails.&lt;/P&gt;
&lt;P&gt;We would like to have an option to specify &lt;STRONG&gt;Hostname&lt;/STRONG&gt; with Radius as well.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 26 Jan 2023 16:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/radius-client-host-must-be-an-ip-address/m-p/4880428#M595</guid>
      <dc:creator>jozefrebjak</dc:creator>
      <dc:date>2023-01-26T16:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: [radius_client] Host must be an IP Address</title>
      <link>https://community.cisco.com/t5/managing-users/radius-client-host-must-be-an-ip-address/m-p/4880429#M596</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi &lt;A class="mention" href="https://community.duo.com/u/jozefrebjak"&gt;@jozefrebjak&lt;/A&gt; ,&lt;/P&gt;
&lt;P&gt;Using hostnames in the &lt;CODE&gt;host&lt;/CODE&gt; config for the &lt;CODE&gt;[radius_client]&lt;/CODE&gt; section is currently not supported and will cause the &lt;A href="https://duo.com/docs/authproxy-reference#using-the-connectivity-tool" rel="noopener nofollow ugc"&gt;Connectivity Tool&lt;/A&gt; to error.&lt;/P&gt;
&lt;P&gt;Please feel free to submit this and any future Feature Request via your Duo Account Executive, Customer Success Manager (if applicable), or our &lt;A href="https://duo.com/support" rel="noopener nofollow ugc"&gt;Support Team&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 27 Jan 2023 21:22:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/radius-client-host-must-be-an-ip-address/m-p/4880429#M596</guid>
      <dc:creator>DuoPablo</dc:creator>
      <dc:date>2023-01-27T21:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: [radius_client] Host must be an IP Address</title>
      <link>https://community.cisco.com/t5/managing-users/radius-client-host-must-be-an-ip-address/m-p/4880430#M597</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;&lt;A class="mention" href="https://community.duo.com/u/duopablo"&gt;@DuoPablo&lt;/A&gt; Thanks for a quick answer.&lt;/P&gt;
&lt;P&gt;My use case is as follow:&lt;/P&gt;
&lt;P&gt;We would like to bring Duo Auth Proxy to a front of our FreeRadius deployment to authorise users which are connecting to various network devices. Our deployment is fully containerised in Docker Swarm.&lt;/P&gt;
&lt;P&gt;I successfully made an Docker Image of the Duo Auth Proxy for Linux.&lt;/P&gt;
&lt;P&gt;The only limit there is radius client host must be an IPv4 and it’s not accepting hostname at all and we can’t use overlay network to isolate communication between the services.&lt;/P&gt;
&lt;P&gt;Btw service will start as normal. This issue is there after first request from a user.&lt;/P&gt;
&lt;P&gt;From my troubleshooting the issue is in:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE class="lang-auto"&gt;  File "/opt/duoauthproxy/usr/local/lib/python3.8/site-packages/duoauthproxy/lib/radius/server.py", line 96, in datagramReceived
    yield self.handle_datagram_received(datagram, host, port)
  File "/opt/duoauthproxy/usr/local/lib/python3.8/site-packages/duoauthproxy/lib/radius/server.py", line 114, in handle_datagram_received
    request = yield server.protocol._handle_request(datagram, (host, port))
  File "/opt/duoauthproxy/usr/local/lib/python3.8/site-packages/Twisted-21.2.0-py3.8.egg/twisted/internet/defer.py", line 1443, in _inlineCallbacks
    result = current_context.run(result.throwExceptionIntoGenerator, g)
  File "/opt/duoauthproxy/usr/local/lib/python3.8/site-packages/Twisted-21.2.0-py3.8.egg/twisted/python/failure.py", line 500, in throwExceptionIntoGenerator
    return g.throw(self.type, self.value, self.tb)
  File "/opt/duoauthproxy/usr/local/lib/python3.8/site-packages/duoauthproxy/lib/radius/server.py", line 265, in _handle_request
    raise e
  File "/opt/duoauthproxy/usr/local/lib/python3.8/site-packages/duoauthproxy/lib/radius/server.py", line 237, in _handle_request
    request.response = yield self._get_response(request)
twisted.internet.error.InvalidAddressError: ('radius', 'write() only accepts IP addresses, not hostnames')
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;If &lt;CODE&gt;ad_client&lt;/CODE&gt; is accepting hostname then maybe there is not so hard to implement this feature also for Radius.&lt;/P&gt;
&lt;P&gt;I’ll try to look at that python code, maybe we should find a way how to handle also hostname. For now we will wait if this could be implemented in next releases.&lt;/P&gt;
&lt;P&gt;We will open an feature request as well.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 27 Jan 2023 22:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/radius-client-host-must-be-an-ip-address/m-p/4880430#M597</guid>
      <dc:creator>jozefrebjak</dc:creator>
      <dc:date>2023-01-27T22:09:51Z</dc:date>
    </item>
  </channel>
</rss>

