Questions tagged [radius]

Remote Authentication Dial In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for computers to connect and use a network service.

Remote Authentication Dial In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for computers to connect and use a network service.

RADIUS is a client/server protocol that runs in the application layer, using UDP as transport. The Remote Access Server, the Virtual Private Network server, the Network switch with port-based authentication, and the Network Access Server (NAS), are all gateways that control access to the network, and all have a RADIUS client component that communicates with the RADIUS server. The RADIUS server is usually a background process running on a UNIX or Microsoft Windows server.[3] RADIUS serves three functions:

  • to authenticate users or devices before granting them access to a network
  • to authorize those users or devices for certain network services and
  • to account for usage of those services.

Source: wikipedia

355 questions
2
votes
1 answer

Users loggin to 3Com switches authenticated by radius not getting admin priv and no access available with radius service down

Following the setup that I have for my Cisco devices, I got some basic level of functionality authenticating users that loggin to 3Com switches authenticated against a RADIUS server. Problem is that I can not get the user to obtain admin privileges.…
3D1L
  • 109
  • 3
  • 7
  • 13
2
votes
2 answers

RADIUS Protocol - Sending more than 255 bytes in vendor-specific field

I am using the RADIUS protocol to for sending some values from client to server. I am using vendor specific value pairs, and defining our own types. But the value length for Vendor-specific data is 255 and our data length is crossing it. Can any one…
Vijay.J055
  • 31
  • 2
2
votes
1 answer

NPS will not add Radius client

I've just installed a fresh copy of NPS on a new 2008 R2 Std server. When I go to add a Radius client, I get "NPS Error: The service being accessed is licensed for a particular number of connections. No more connections can be made to the service at…
Neobyte
  • 3,179
  • 1
  • 26
  • 31
2
votes
0 answers

NPS policy for external firm?

Can NPS be used in the following scenario: We (FIRM-A) are sharing some office space with another firm (FIRM-B). We would like their laptops to connect to our "Internet Only" SSID. Those laptops already have a working computer certificate for their…
2
votes
0 answers

Fortigate and RADIUS Wifi authentication for domain and non-domain devices

We're setting up RADIUS authentication for wireless network connections through a Windows Server 2012 R2 (NPS). We have to allow both domain computers (registered in Active directory) and non-domain devices, typically Android smartphones. Following…
wiltomap
  • 75
  • 10
2
votes
0 answers

OpenVPN auth with Freeradius fails with error message: Module is unknown

I have installed an OpenVPN server with Easy-RSA. I generated the certificate and signed it on my CA Server and copied it back to VPN server. I can establish the client-server connection via certificate (without username/password) without any…
Houman
  • 1,545
  • 4
  • 22
  • 36
2
votes
1 answer

Radius + SSH Key Authentication

Does anyone know if it is possible to configure pam to require both radius AND ssh-key to successfully authenticate ?
Hilton D
  • 279
  • 5
  • 15
1
vote
2 answers

How to monitor freeradius using EAP-MSCHAP v2 authentication method with Nagios?

How to monitor freeradius using EAP-MSCHAP v2 authentication method with Nagios? Do you know any nagios plugins for such monitoring?
Kazimieras Aliulis
  • 2,324
  • 2
  • 26
  • 46
1
vote
1 answer

Behaviour of authentication when using multiple Radius servers on RRAS

I've tried looking this up for hours but my google-fu is failing me it seems. The question is rather simple, if I configure multiple Radius servers in RRAS, if they're all ballanced equally, how are requests treated? Say, if the different RADIUS…
1
vote
1 answer

WPA2 Enterprise: no risks for preconfigured clients when it comes to Rogue APs?

We are using, as default, PEAP and MS-CHAPv2 as inner authentication. I was concerned with security risks when it comes to rogue APs but a colleague told me that there are no risks for preconfigured clients. He told me there are risks only for…
Jade Kush
  • 11
  • 2
1
vote
1 answer

Suddenly RADIUS authentication is gone on macOS server (TLS session fails)

Suddenly my RADIUS authentication is gone on my MacOS Server running 10.13.6 and Server Version 5.6.1 (17S2109. I already restored the Open Directory Server. $ host name.domain.tld name.domain.tld has address xxx.xxx.xxx.xxx host…
SEJU
  • 111
  • 5
1
vote
1 answer

Is it ok to use PAP with TTLS on radius server?

We have deployed Radius server ( Freeradius 3.x ) and connected it to our LDAP database (ForgeRock OpenDJ). We have successfully configured EAP-TTLS with valid certificates and set it as default connection method. ( almost all other settings are…
pagep
  • 137
  • 2
  • 9
1
vote
2 answers

802.1X EAP authentication in Cisco switches with certificate

I am currently planning to implement 802.1X authentication for all the wired computers at the office where I work at currently. We have successfully implemented 802.1X authentication with login/password credentials. It authenticates against a RADIUS…
Antoine Benkemoun
  • 7,314
  • 3
  • 42
  • 60
1
vote
1 answer

Use CHAP with NPS and a Domain Controller in Core

I've noticed a difference on the authentication behavior of Active Directory where the Core version failed to authenticate properly when using CHAP from the NPS server. I have reproduct the problem on a dedicated network as following: 1 domain…
Veovis
  • 163
  • 1
  • 1
  • 6
1
vote
2 answers

FreeRADIUS with LDAP vs Kerberos

The following site discusses how to setup FreeRADIUS to authenticate against an LDAP backend (it goes through a tutorial showing how to expose NT hashed passwords in FreeIPA so that FreeRADIUS can read…
user3814483
  • 183
  • 1
  • 10