Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple PfSense accesing one Freeradius server

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 301 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • PierreFrenchP
      PierreFrench
      last edited by

      Hello
      Maybe some of you have the same network topology.
      Please see below the drawing
      I have 4 pfsenses labeled A,B,C,M
      Behind M I setup a Freeradius server on a dedicated machine.
      When I try to identify a user from M to the Freeradius it work ok
      but when I try to identify a user from A, B or C it failed?
      I have done the NAT redirection on M to have port 1812 and 1813 point from the WAN to the server.
      Any idea will be great
      Thanks
      5417dbdf-db9f-4168-bb81-3a3c7c8c94be-image.png

      NogBadTheBadN 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @PierreFrench
        last edited by NogBadTheBad

        @PierreFrench Have you set up A, B & C as a NAS/Clients on the Freeradius server, if you have are the shared secrets correct ?

        If you run radsniff-x on the cli of the Freeradius server that might give you some hints why it isn't working when trying to auth from A, B & C.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        PierreFrenchP 1 Reply Last reply Reply Quote 1
        • PierreFrenchP
          PierreFrench @NogBadTheBad
          last edited by

          @NogBadTheBad
          Thanks, I am sure it's something related to the setup of the NAS part versus the remote firewall part
          On the NAS and Pfsense setting pages there is the following:

          e7a813c0-a608-4a18-8a94-723730e2e143-image.png

          Populating the NAS side with the share secret and the NAS IP/host with on of th value found from the pfsense drop down NAS IP attribute list,, that list will be different of each A/B/C firewalls

          Do I miss something else or misunderstand the fields?????

          Thanks
          Pierre

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            How do you have it configured for the 'M' pfSense? If should be no different for the others unless you are NATing the source IP of the traffic perhaps. Which you probably shouldn't be.

            What error is shown in pfSense? What error is shown in the Radius server?

            NogBadTheBadN 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @stephenw10
              last edited by

              Did you try running radsniff -x on the cli of your freeradius box?

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.