• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[Solved] Freeradius, WAP2-Enterprise & IKEv2 Clients

Scheduled Pinned Locked Moved pfSense Packages
2 Posts 1 Posters 546 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N Offline
    NogBadTheBad
    last edited by Oct 18, 2017, 5:05 PM Oct 16, 2017, 1:40 PM

    Following on from assigning my IKEv2 clients a fixed IP addres via Freeradius.

    Is there any way of stopping the IKEv2 Clients IDs  andy-ipad, andy-iphone, etc …. from connecting via Wi-Fi ?

    My /usr/local/etc/raddb/users file looks like this :-

    "andy" Cleartext-Password := "PASSWORDHERE"

    Service-Type = Administrative-User

    "andy-ipad" Cleartext-Password := "PASSWORDHERE", Simultaneous-Use := "1"

    Framed-IP-Address = 172.16.9.1,
    Framed-IP-Netmask = 255.255.255.0,
    Framed-Route = "0.0.0.0/0 172.16.0.1 1"

    "andy-iphone" Cleartext-Password := "PASSWORDHERE", Simultaneous-Use := "1"

    Framed-IP-Address = 172.16.9.2,
    Framed-IP-Netmask = 255.255.255.0,
    Framed-Route = "0.0.0.0/0 172.16.0.1 1"

    Etc ...

    Andy

    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

    1 Reply Last reply Reply Quote 0
    • N Offline
      NogBadTheBad
      last edited by Oct 17, 2017, 8:18 PM Oct 17, 2017, 7:34 PM

      Had a poke round the freeradius web pages and came across radsniff.

      http://freeradius.org/radiusd/man/radsniff.html

      Output from radsniff shows the following when connecting via vpn :-

      NAS-Identifier == strongSwan

      Answer to my issue add NAS-Identifier == strongSwan as a check item

      "andy-ipad" Cleartext-Password := "PASSWORDHERE", Simultaneous-Use := "1", NAS-Identifier == strongSwan

      Framed-IP-Address = 172.16.9.1,
      Framed-IP-Netmask = 255.255.255.0,
      Framed-Route = "0.0.0.0/0 172.16.0.1 1"

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received