Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Windows RADIUS Server

    Scheduled Pinned Locked Moved Captive Portal
    windows serverwindows radiuscaptive portalradius
    29 Posts 10 Posters 4.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • mohkhalifaM
      mohkhalifa @Xavi_IT
      last edited by

      @Xavi_IT said in Windows RADIUS Server:

      After writing the last message, I have successfully configured LDAP authentication server in the same PfSense device that points to the same Windows Server. This way everything works, including OpenVPN clients validation using allowed domain user accounts.

      Sounds good. Also, you can add custom attributes to control per user bandwidth. it's really amazing integration. ENJOY :)

      1 Reply Last reply Reply Quote 0
      • Y
        yanqian
        last edited by

        @mohkhalifa
        Could you please share the configuration tips with me?
        I did get your private message, but I am not able to let you do the configuration remotely.
        Thanks any way.

        @Xavi_IT
        May I know how did you solve this issue ?
        Thank you!

        1 Reply Last reply Reply Quote 0
        • X
          Xavi_IT
          last edited by

          Hello @yanqian,
          I could not configure a Radius server in PfSense "Authentication Servers". I followed several tutorials and Windows NPS event log was returning succesfull authentication attempts, but I could not figure out why didn't PfSense was not getting them.

          Finally I had success using LDAP instead of Radius in PfSense "Authentication server" to connect to Windows Active Directory. With LDAP It worked at first attempt.

          1 Reply Last reply Reply Quote 1
          • A
            anwarmoinudeen @yanqian
            last edited by

            @yanqian did ur issue got resolved .. i to have the same issue in pfsense

            A Y 3 Replies Last reply Reply Quote 0
            • A
              aspiringnetworkadmin @anwarmoinudeen
              last edited by

              @anwarmoinudeen Hi Sir did your issue got resolved already? i also have the same issue in pfsense

              1 Reply Last reply Reply Quote 0
              • Y
                yanqian @anwarmoinudeen
                last edited by

                @anwarmoinudeen As I recall, I hadn't solved this issue, and I gave up NPS radius server test. I hope @mohkhalifa would provide the guide in detail.

                1 Reply Last reply Reply Quote 0
                • J
                  jimmychoosshoes
                  last edited by jimmychoosshoes

                  Old topic but try this:

                  First you need to know the vendor code for PFSENSE which I found in https://github.com/pfsense/pfsense/blob/master/src/usr/share/doc/radius/dictionary.pfsense

                  VENDOR		pfSense				13644
                  
                  BEGIN-VENDOR	pfSense
                  
                  ATTRIBUTE	pfSense-Bandwidth-Max-Up		1	integer
                  ATTRIBUTE	pfSense-Bandwidth-Max-Down		2	integer
                  ATTRIBUTE	pfSense-Max-Total-Octets		3	integer
                  
                  END-VENDOR pfSense
                  

                  Now you can go to your network policy in NPS for the captive portal. Go to:
                  SETTINGS, VENDOR SPECIFIC, ADD, "custom", "Vendor specific/Radius standard", ADD,ADD:

                  • Enter Vendor Code = 13644
                  • Yes it conforms
                  • configure Attribute -> 1 for pfSense-Bandwidth-Max-Up with decimal and you bandwidth

                  repeat for 2 = pfSense-Bandwidth-Max-Down

                  Untested but this should work in theory.

                  D 1 Reply Last reply Reply Quote 1
                  • D
                    dochy @jimmychoosshoes
                    last edited by dochy

                    @jimmychoosshoes after that how can we limit bandwidth by users can you help me?

                    1 Reply Last reply Reply Quote 0
                    • Y yanqian referenced this topic on
                    • Y
                      yanqian @anwarmoinudeen
                      last edited by

                      @anwarmoinudeen I know this is old, just want to update here, I tried to use NPS on server 2016 as RADIUS server today, and it works without any issue.
                      Pfsense version is 2.7.0, RADIUS MS-CHAPv2 .

                      D 1 Reply Last reply Reply Quote 0
                      • D
                        dochy @yanqian
                        last edited by

                        @yanqian with FreeRadius?

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @dochy
                          last edited by

                          @dochy

                          FreeRadius is not " NPS on server 2016 as RADIUS server".

                          06287932-9d42-4da4-83b7-b7134765be43-image.png

                          Instead of install the FreeRadius pfSense package, @yanqian installed a Radius serves on a Micorsoft (server ?) and use that Radius server.
                          It isn't a free one (as it is from Microsoft) 😊

                          He probably used this :

                          a7f4a7ee-5f77-497a-bbdf-e2b3e2b3334d-image.png

                          to set up an external authorization/authentication (Radius) server.

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          D 1 Reply Last reply Reply Quote 0
                          • D
                            dochy @Gertjan
                            last edited by

                            @Gertjan )) i use this method too and it is not hard to configure

                            mohkhalifaM 2 Replies Last reply Reply Quote 0
                            • mohkhalifaM
                              mohkhalifa @dochy
                              last edited by

                              @dochy Yes it's hard but you have to prepare a good coffee and I trust that you will did it.

                              1 Reply Last reply Reply Quote 0
                              • mohkhalifaM
                                mohkhalifa @dochy
                                last edited by

                                This post is deleted!
                                1 Reply Last reply Reply Quote 0
                                • D
                                  dochy @mohkhalifa
                                  last edited by

                                  @mohkhalifa we are still waiting for that manual please can you help us

                                  GertjanG 1 Reply Last reply Reply Quote 0
                                  • GertjanG
                                    Gertjan @dochy
                                    last edited by

                                    @dochy said in Windows RADIUS Server:

                                    we are still waiting for that manual please

                                    Like these : microsoft nps ?

                                    You'll find the Documentation under Additional resources.
                                    Remember : this isn't open source and a Microsoft product. Manuals are most probably copyrighted.

                                    No "help me" PM's please. Use the forum, the community will thank you.
                                    Edit : and where are the logs ??

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.