Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2FA / Radius/ Challenge-Response without "State"

    Scheduled Pinned Locked Moved OpenVPN
    1 Posts 1 Posters 290 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bergerf
      last edited by bergerf

      Hi,

      I have a FreeRadius3 which is doing Auth with 2FA with PrivacyIdea.
      Testing with radclient is working fine:

      1. Access-Request with Username/Password
        Access-Challenge (11) came back from FreeRadius after 1st contact to UserDirectory (including "state")
      2. Access-Request with "state" and Username and OTP
        Access-Accept from FreeRadius...

      Now I'm using pfsense with OpenVPN, which is working for Users without deployed Token, via the same FreeRadius.
      But the 2nd AcessRequest (which is now send by pfSense) is without the radius attribute "state" (which came with the Challenge Response by the FreeRadius).
      So without matching "state" the Freeradius is rejecting the request (of course).

      Any hints?
      Thanks!

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.