Questions tagged [radius]

Remote Authentication Dial In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for computers to connect and use a network service.

Remote Authentication Dial In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for computers to connect and use a network service.

RADIUS is a client/server protocol that runs in the application layer, using UDP as transport. The Remote Access Server, the Virtual Private Network server, the Network switch with port-based authentication, and the Network Access Server (NAS), are all gateways that control access to the network, and all have a RADIUS client component that communicates with the RADIUS server. The RADIUS server is usually a background process running on a UNIX or Microsoft Windows server.[3] RADIUS serves three functions:

  • to authenticate users or devices before granting them access to a network
  • to authorize those users or devices for certain network services and
  • to account for usage of those services.

Source: wikipedia

355 questions
2
votes
1 answer

Radius Client IP Address when setting up Wifi with WPA2 Enterprise?

I have taken over a server setup (as part of my job) which is setup of the following: Server setup with Threat Management Gateway (serving as the firewall) - 192.168.1.1 Server with Domain Controller Role - 192.168.1.10 Server with Radius and NAP…
Jeff Kranenburg
  • 149
  • 1
  • 1
  • 10
2
votes
0 answers

NPS RADIUS authentication fails due to user account

We're in the process of migrating our wireless network, adding in 802.11x-based RADIUS authentication. The set up is as follows: Client connects to router01 Client authenticates through RADIUS on a Windows Server Client should get connected (.. or…
Robbietjuh
  • 205
  • 3
  • 14
2
votes
0 answers

FreeRadius Error reading /etc/freeradius/huntgroups

I've configured freeradius to use sql, everything was working fine, I was doing some tests with the users, and suddenly I cannot start the debugger because of this error : rlm_preprocess: Error reading…
AlvaroAV
  • 151
  • 2
  • 11
2
votes
0 answers

£ sign in password fails Windows NPS Radius authentication against Sonicwall SRA

We have a Sonicwall SRA server configured to authenticate users using RADIUS to a Windows NPS Server running on Windows Server 2012 R2. It all works fine EXCEPT when passwords contain the "£" character. According to the RADIUS spec on page 24 the…
Phil
  • 3,168
  • 1
  • 22
  • 29
2
votes
1 answer

FreeRadius - Authenticate any User & Password

I am trying to help a facility who's radius server crashed - no recoverable data. The clients are all installed (buried) in vehicles and are not readily accessible (need to tear stuff apart). Access Point is an Orinoco AP-700, FreeRadius running on…
Justin60047
  • 21
  • 1
  • 2
2
votes
1 answer

Setting up NPS with a certificate that is valid to both AD and non-AD machines

I'm trying to setup an AD server running the NPS service so that both AD and non-AD machines see the certificate as valid when authenticating to the wireless network. I picked up a cert from GoDaddy and the non-AD machines are happy with it, but the…
flickerfly
  • 2,753
  • 3
  • 25
  • 27
2
votes
2 answers

NPS - RADIUS - Active Directory Authentication

Is it possible to use NPS RADIUS as an intermediary between an application that only supports RADIUS authentication and an active directory server which is used for authentication across the network? I feel like all the settings are very much…
RikuXan
  • 217
  • 1
  • 3
  • 11
2
votes
1 answer

How to use Calling-Station-Id on a per user basis in freeRADIUS?

I am trying to limit every user to a small set of Mac-IDs in RADIUS, by directly including the appropriate information in the users file. It would be acceptable even if every user was limited to one mac. The server is running FreeRADIUS version…
ronno
  • 123
  • 1
  • 1
  • 7
2
votes
1 answer

Freeradius server is not accepting accounting packets through tcpreplay

I am running a free radius server on system A. I am sending test accounting requests using radclient radclient -x systemA acct testing123 from system B. I can see that the radius server recieved these requests from its debug logs. I had saved these…
woodstok
  • 131
  • 5
2
votes
2 answers

WPA2-Enterprise vs. Captive Portal, which is more preferable?

My school runs our WiFi network on Aruba Controllers, some of the access points are Aruba-branded and is managed. Others are D-Link branded, and need configuration one by one if needed. We run our authentication on Captive Portal now, and is now…
Shane Hsu
  • 131
  • 1
  • 3
  • 10
2
votes
1 answer

How to enable two factor authentication

I am using CentOS 6.3 and want to enable ssh RADIUS authentication. Right now my server is directly authenticated with RADIUS server. I want the server to authenticate with unix credentials first and after that to do authentication via RADIUS. I'm…
user178834
  • 19
  • 2
2
votes
1 answer

Radius connection with Windows 7 computers

I have many Ubiquiti Unifi APs connected to a Windows Server 2012 NPS radius server. I configured security policies to let domain users connect to the local network. I'm having some trouble with Windows 7 clients. I get a message Impossible to…
Tobia
  • 1,272
  • 9
  • 41
  • 81
2
votes
1 answer

Allowing multiple IP addresses for a single VPN user

Currently for one of the company I am using ASA 5505 as an VPN server with freeradius (mysql module) as an authentication backend. User authenticatin is based on the group password, user password and IP address. My database entries looks like…
golja
  • 1,621
  • 10
  • 14
2
votes
1 answer

openvpn refusing connections with freeradius

I installed openvpn and freeradius from yum and I installed the radiusplugin_v2.1a_beta1.tar.gz but I am having connection issues with the error: XML-RPC: ConnectionRefusedError: 10061: No connection could be made because the target machine actively…
Tiffany Walker
  • 6,681
  • 14
  • 56
  • 82
2
votes
1 answer

PEAP validation against a different, secondary domain?

Probably a little bit confusing, so let me explain the situation. Our company wants to implement a corporate wireless LAN with PEAP authentication. Unfortunately, someone made a big mistake in our Active Directory design 10 years ago. The domain…
sam
  • 155
  • 2
  • 5
  • 17