Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.5.0 Captive portal logging issue

    Scheduled Pinned Locked Moved Captive Portal
    26 Posts 8 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kzsk
      last edited by kzsk

      Replacing $PORTAL_ACTION$ with a string with an ip address didn't help. In the logs of radius. log when trying to log in with a username/password, these are the entries

      Fri Apr  9 08:40:26 2021 : Auth: (100984) Login incorrect (Failed retrieving values required to evaluate condition): [00-1c-25-36-8d-6b/raduissecret] (from client captiveportal port 2232 cli xx-xx-xx-xx-xx-xx) xx-xx-xx-xx-xx-xx
      

      radiussecret - RADIUS MAC Secret
      xx-xx-xx-xx-xx-xx - MAC of device

      For some reason, instead of a login-password pair, the captive portal passes to radius a mac-Radius MAC Secret pair

      S 1 Reply Last reply Reply Quote 0
      • S
        SEBBAC @kzsk
        last edited by

        @kzsk

        As a test - try creating Radius user with MAC addresses ( - separated) and see if that works.... It should.

        K 1 Reply Last reply Reply Quote 0
        • K
          kzsk @SEBBAC
          last edited by

          @sebbac it didn't work

          S 1 Reply Last reply Reply Quote 0
          • S
            seekerman @kzsk
            last edited by

            @kzsk i've same issue like you , the radius server send failed login error "Failed retrieving values required to evaluate condition): [xx-xx-xx-xx-xx-xx/<via Auth-Type = mschap>" , all configuration is correct but pfsense cannot retrive password from free radius.
            please guide.

            viktor_gV 1 Reply Last reply Reply Quote 0
            • viktor_gV
              viktor_g Netgate @seekerman
              last edited by

              @seekerman Unable to reproduce, working fine for me:

              May 15 09:27:53 pf41 logportalauth[346]: Zone: cpzone1 - ACCEPT: raduser1, de:5b:10:c5:bf:72, 192.168.88.7
              

              Are you using "RADIUS MAC Authentication"?
              How I can reproduce it step-by-step?

              S 1 Reply Last reply Reply Quote 0
              • S
                seekerman @viktor_g
                last edited by

                @viktor_g said in 2.5.0 Captive portal logging issue:

                Authentication

                hi @viktor_g
                tnx for reply
                yeh i've use radius mac authentication base on documentation but i got this error in radius log.
                please guide me for correct configuration
                i've use capitve portal and radius server on pfsense and make a user in free radius with mac address of my client as username and secret in captive portal as password . but the radius server show me an error "RADIUS MAC Authentication Failed."
                tnx

                viktor_gV 1 Reply Last reply Reply Quote 0
                • viktor_gV
                  viktor_g Netgate @seekerman
                  last edited by

                  @seekerman said in 2.5.0 Captive portal logging issue:

                  @viktor_g said in 2.5.0 Captive portal logging issue:

                  Authentication

                  hi @viktor_g
                  tnx for reply
                  yeh i've use radius mac authentication base on documentation but i got this error in radius log.
                  please guide me for correct configuration
                  i've use capitve portal and radius server on pfsense and make a user in free radius with mac address of my client as username and secret in captive portal as password . but the radius server show me an error "RADIUS MAC Authentication Failed."
                  tnx

                  You need to enable Plain MAC Auth on the FreeRADIUS settings page and fill in CP RADIUS MAC Secret with any value.
                  Or create a RADIUS user with MAC username and password.

                  (0) Login OK: [de:5b:10:c5:bf:72/pass123] (from client local port 2002 cli de-5b-10-c5-bf-72) 
                  (0) Sent Access-Accept Id 185 from 127.0.0.1:1812 to 127.0.0.1:24100 length 0
                  (0) Finished request
                  Waking up in 4.9 seconds.
                  
                  S 1 Reply Last reply Reply Quote 0
                  • S
                    seekerman @viktor_g
                    last edited by

                    @viktor_g said in 2.5.0 Captive portal logging issue:

                    (0) Login OK: [de:5b:10:c5:bf:72/pass123] (from client local port 2002 cli de-5b-10-c5-bf-72)

                    hi i'm already get right response from the free radius by command prompt just like you but in captive portal anything is wrong
                    please guide me.

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      seekerman @seekerman
                      last edited by

                      @seekerman user managment.JPG nas.JPG setting radius.JPG free radius.JPG user.JPG cp.JPG error.JPG errorrr.JPG

                      viktor_gV W 2 Replies Last reply Reply Quote 0
                      • viktor_gV
                        viktor_g Netgate @seekerman
                        last edited by

                        @seekerman Default Captive Portal MAC address syntax is "00:11:22:33:44:55", not "00-11-22-33-44-55"

                        also try to add MAC address on the FreeRADIUS / MACs page

                        1 Reply Last reply Reply Quote 0
                        • W
                          wissesolutions @seekerman
                          last edited by

                          @seekerman found somewere in the forum that this is a bug on version 2.5 fixed in development version.. ill try and let you guys know

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.