Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FREERADIUS - Filter User to login to a certain SSID

    Scheduled Pinned Locked Moved pfSense Packages
    4 Posts 2 Posters 561 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fmroeira86
      last edited by

      Hi!

      I've configured the freeradius package and everything is working (EAP MSCHAPv2).

      I want some users to be allowed to connect only to a specific SSID.

      I tried something like:

      Called-Station-Id =~ ".*(:MY SSID)$"

      On CHECK-ITEM but as soon as I do that the user can't authenticate:

      (8) Login incorrect (mschap: FAILED: No NT/LM-Password. Cannot perform authentication): [my.user] (from client AP01 port 0 via TLS tunnel)

      Any hint?

      Thank you!

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by NogBadTheBad

        @fmroeira86 said in FREERADIUS - Filter User to login to a certain SSID:

        I want some users to be allowed to connect only to a specific SSID.

        What do the others that use FreeRADIUS use their ID's for VPN ?

        If the above is the case you could add as a check item on the VPN users NAS-Identifier == strongSwan

        Try doing a radsnif -x from a ssh to the router you may get some clues.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        F 1 Reply Last reply Reply Quote 0
        • F
          fmroeira86 @NogBadTheBad
          last edited by

          @nogbadthebad

          Hi!

          I don't use that for VPN access, only for WIFI access.

          As I described I'm using this Check-item:

          Called-Station-Id =~ ".*(:MY SSID)$"

          When I use it the authentication fails:
          Login incorrect (mschap: FAILED: No NT/LM-Password. Cannot perform authentication): [my.user] (from client AP01 port 0 via TLS tunnel)

          When I remove that the user authenticates.

          1 Reply Last reply Reply Quote 0
          • F
            fmroeira86
            last edited by

            No Ideas? :(

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.