Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FreeRADUIS not Authenticating with PFSense using OTP

    Scheduled Pinned Locked Moved pfSense Packages
    5 Posts 3 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • brunovicB
      brunovic
      last edited by

      Hello I am having issues with FreeRADUIS in that when you go to Diagnostic > Authentication it keeps failing whenever I use an account with OTP. However it works fine with static passwords. On the same token I have a Cisco switch that is authenticating with FreeRADIUS as well and that has no problem authenticating with OTP. Why is it that I can authenticate fine using OTP on a Cisco switch but it fails on pfSense?

      1 Reply Last reply Reply Quote 0
      • brunovicB
        brunovic
        last edited by

        I also want to add while looking through the logs I notice on the Cisco switch logins it passes the authentication to googleauth.py however when I try to log into pfSense it doesn't pass the authentication to googleauth.py. It just fails.

        Log from logging into pfSense:

        Oct 23 11:28:43 radiusd 16311 (18) Login incorrect (Failed retrieving values required to evaluate condition): [admin] (from client FamFirewall port 0)

        Log from logging into Cisco switch:

        Oct 23 11:23:40 radiusd 16311 (16) Login OK: [admin] (from client FamSwitch port 1 cli 10.10.10.2)
        Oct 23 11:23:40 googleauth.py freeRADIUS: Google Authenticator - Authentication successful for user: admin

        1 Reply Last reply Reply Quote 0
        • brunovicB
          brunovic
          last edited by

          So no one has any ideas on this? Why isn't pfSense passing the authentication to the py script like the other logins?

          1 Reply Last reply Reply Quote 0
          • H
            horstvogel
            last edited by

            https://forum.pfsense.org/index.php?topic=139142.0

            1 Reply Last reply Reply Quote 0
            • P
              profiler
              last edited by

              @brunovic:

              So no one has any ideas on this? Why isn't pfSense passing the authentication to the py script like the other logins?

              Check the link above this post, auth is successful now.

              (Also, check the RADIUS server entry under System > User Manager, Authentication Servers tab. It must be set to PAP.)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.