Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FreeRadius Interfaces

    Scheduled Pinned Locked Moved pfSense Packages
    6 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      WhiteTiger-IT
      last edited by WhiteTiger-IT

      I didn't know what address I need to put in the FreeRadius "Interface IP Address" field.
      I have three servers in DMZ. The IP Address of the NIC on pfSense corresponding to the DMZ is 192.168.103.1
      The users are in the LAN and to access the server they authenticate themselves on these. The IP Address of the NIC on pfSense corresponding to the LAN is 192.168.101.1
      So, in FreeRadius I have to create three clients, one for server.

      I didn't understand if in FreeRadius I need an interface on the LAN (192.168.101.1) to listen to the users' PCs or on the DMZ (192.168.103.1) to listen to the servers.

      Users also connect via OpenVPN, but I don't think this should be listened to too.

      NogBadTheBadN 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @WhiteTiger-IT
        last edited by

        @whitetiger-it I point mine to a virtual ip with a /32 mask.

        Firewall -> Virtual IPs

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        W 1 Reply Last reply Reply Quote 0
        • W
          WhiteTiger-IT @NogBadTheBad
          last edited by

          @nogbadthebad
          i didn't understand how to use them.

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad @WhiteTiger-IT
            last edited by

            @whitetiger-it

            Screenshot 2021-11-10 at 11.58.31.png

            Screenshot 2021-11-10 at 11.58.41.png

            Screenshot 2021-11-10 at 12.00.10.png

            Screenshot 2021-11-10 at 12.03.34.png

            https://docs.netgate.com/pfsense/en/latest/firewall/virtual-ip-address-comparison.html

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            W 1 Reply Last reply Reply Quote 0
            • W
              WhiteTiger-IT @NogBadTheBad
              last edited by

              @nogbadthebad
              Let's see if I understand correctly.
              The switch, instead of querying the RADIUS on the firewall IP, queries a virtual (and therefore non-existent) IP that you have associated with the localhost of the firewall itself.

              Good idea, but I didn't understand why.
              The IP of the firewall is however known, for example because it is the Gateway of the network, there is DHCP, DNS, etc.

              However, my question remains open.
              Is the RADIUS interface the network on which the users are located or the one on which the servers/devices interrogated by the user are located?

              From what you have posted, it seems to me that it is the second answer.

              NogBadTheBadN 1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad @WhiteTiger-IT
                last edited by NogBadTheBad

                @whitetiger-it said in FreeRadius Interfaces:

                @nogbadthebad
                Let's see if I understand correctly.
                The switch, instead of querying the RADIUS on the firewall IP, queries a virtual (and therefore non-existent) IP that you have associated with the localhost of the firewall itself.

                Nope its a virual address tied to the localhost interface, if I had bound my FreeRadius to the LAN interface IP and I had shut it down then devices couldn't authenticate.

                Screenshot 2021-11-11 at 11.24.29.png

                Good idea, but I didn't understand why.
                The IP of the firewall is however known, for example because it is the Gateway of the network, there is DHCP, DNS, etc.

                However, my question remains open.
                Is the RADIUS interface the network on which the users are located or the one on which the servers/devices interrogated by the user are located?

                From what you have posted, it seems to me that it is the second answer.

                The radius interface is the IP address that Radius requests are sent to, as per "Enter the IP address (e.g. 192.168.100.1) of the listening interface. If you choose * then it means all interfaces. (Default: *)"

                You can point your devices to any IP address any pfSense interface you want if you leave the IP address as the default of *

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.