Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to enable 802.1x on wired lan interface?

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 4 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tiagosmx
      last edited by

      Hello gods of networks,

      how make clients willing to connect to the pfSense LAN wired interfaces network be forced to provide authentication (PEAP login/password or EAP SSL client certificate) before attempting connection?

      Is this possible?
      I'v seen some people talking about using 802.1x enabled layer 3 switches, but I got a feeling that there is a way doing it with pure pfSense way.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @tiagosmx
        last edited by

        @tiagosmx

        If they're connecting directly to the LAN, pfSense has no involvement at all, beyond DHCP. Typically, a domain controller is used to allow access to the various resources.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 1
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          The freerad package can be used to provide your auth, but you still need a switch that can do 802.1x

          What switch do you have?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          T 1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            You enable it in your L2 (the switch / AP)

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • T
              tiagosmx @johnpoz
              last edited by

              @johnpoz only a simple Layer 2 switch, and probably not manageable/configurable.
              I have installed freeradius and successfully configured 802.1x for WLAN access with WPA Enterprise, but now I want to achieve the same in a wired configuration.

              Is a layer 3 switch with 802.1x really a must?
              Can't that be achieved with just pfSense?

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                It has to be done at L2, it is too late to accomplish something like that once they have an L3 address. At that point your only option is Captive Portal, not 802.1x

                You don't need a "layer 3 switch", just a managed switch which supports 802.1x.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 1
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  As stated you need to do this at layer 2, so you do not need a L3 capable switch - but more than likely the entry level "smart" switches that you can get for like $40 will not support this.. You will need something with a few more features then the entry level ones.

                  So for example the dlink dgs-1100, does not seem to support 802.1x, the dgs-1210 does..

                  The 8 port gig 1100 on amazon is like $40, while the 1210 is more like 100.. And it also has 2 sfp ports along with the 8 gig ports.

                  When you want to start doing enterprise level stuff, the soho stuff doesn't really cut it any more ;)

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  T 1 Reply Last reply Reply Quote 2
                  • T
                    tiagosmx @johnpoz
                    last edited by

                    @johnpoz @jimp that's exactly what I was missing, thank you for pointing that out.

                    Lesson n.1: There are different types of layer 2 switches (managed and unmanaged), some of them support 802.1x protocol and some of them not.

                    Lesson n.2: The 802.1x authentication is done at the layer 2, before the IPs are handled to the devices. When packets reach the layer 3 is too late to do any kind of 802.1x authentication as the devices were already authorized to enter the network.

                    Cheers!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.