Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Freeradius + EAP Certificates

    Scheduled Pinned Locked Moved General pfSense Questions
    32 Posts 4 Posters 26.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      Nachtfalke
      last edited by

      Hi,

      I think it would be enough with EAP. It will be better than only MAC address filtering I think.
      I tried with "other certificate or smartcard" but I think I missed some checkboxes there.
      Do you have a solution for me how to configure it the right way ?

      1 Reply Last reply Reply Quote 0
      • S
        seggerman
        last edited by

        Nachtfalke,

        here are my config screens … in the second screen the "intern-CA" is my CA that is used for the client and server certificate.

        I cannot test it on my LAN, since my radius isn't configed for this, but it is identical to my WLAN config. After connecting to the LAN, and aquiring an IP address you should be prompted for the certificate needed for the authentication.

        Additional on your Cisco switch can you explicitly config the authentication to EAP ? So that the switch explicitly uses this authentication method.

        If this doesn't work, could you post the config of the cisco and also the "radiusd -X" log (this then has the config and also the challenge/response during the authentication.

        Regards

        Alexander

        EAP1.png
        EAP1.png_thumb
        EAP2.png
        EAP2.png_thumb

        1 Reply Last reply Reply Quote 0
        • N
          Nachtfalke
          last edited by

          Hi,

          thanks for you help and screens. I think I did something close to your pics but not every checkboy is the same.
          I will try it on monday.

          Thanks.

          1 Reply Last reply Reply Quote 0
          • C
            chunk0r
            last edited by

            Hi,

            erm I understand you correctly, you use your own radius install and not the package from the pfsense gui?

            Thanks
            Chunk0r

            1 Reply Last reply Reply Quote 0
            • N
              Nachtfalke
              last edited by

              @chunk0r:

              Hi,

              erm I understand you correctly, you use your own radius install and not the package from the pfsense gui?

              Thanks
              Chunk0r

              seggerman is using his own RADIUS, I am using the pfsense package.

              1 Reply Last reply Reply Quote 0
              • C
                chunk0r
                last edited by

                Thanks,

                I'm also confused of wifi access, so I want connect my AP with the Radius server, so that my clients has to be auth with wpa2 against radius.
                So my wpa2 key is the secret share key of radius? Cauz if I activate wpa2+eap on my openwrt AP, I don't have any other key field.

                1 Reply Last reply Reply Quote 0
                • M
                  Metu69salemi
                  last edited by

                  Your ap is the authenticator for the radius ( so you add it like client at radius )
                  One place where you can have more info for that is (sorry guys) microsoft technet, there is quite well explained the roles of the devices

                  1 Reply Last reply Reply Quote 0
                  • N
                    Nachtfalke
                    last edited by

                    There is a difference between ENCRYPTION and AUTHENTICATION.

                    The WPA2 key is the key to encrypt the wireless traffic. It is used between the W-AP and the W-Client.

                    The password for AUTHENTICATION is between RADIUS and AP.

                    1 Reply Last reply Reply Quote 0
                    • M
                      Metu69salemi
                      last edited by

                      Quite easy photo, but it's written in Finnish

                      1 Reply Last reply Reply Quote 0
                      • C
                        chunk0r
                        last edited by

                        ah ok, but where I save my wpa key if the secret share is for the client auth?

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.