Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Freeradius for added security? How?

    Scheduled Pinned Locked Moved General pfSense Questions
    2 Posts 2 Posters 261 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      Velcro
      last edited by

      I am trying to "up"(increase) my security to the max and Freeradius seems to be a popular package used by many. Will it increase my security on a(my) small network?

      My general setup is as follows:

      • Numerous seperate isolated VLANs Guest, IOT VLAN, Work, personal, etc…)
      • Each VLAN has clients(assigned by DHCP) with fixed IPs(with MAC addresses), all other clients are denied
      • Policy routing using the clients fixed IPs in aliases
      • Snort, pfBlocker
      • Traffic routed thru VPNs

      Would adding the/a Freeradius package enhance security? A lot more secure? If so how would it enhance the security?

      I found info on setting it up and benefits in very large networks but that was all...

      Thanks for any thoughts or advice...

      V

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        One way radius can be used to increase security is the ability to use say eap-tls to auth clients to a wireless network.  So now clients would have to have a different method of auth vs just a PSK.. This could be a username and password to auth to the network, or if something as secure as eap-tls.. Where now your clients have to have a cert issued by your CA, etc..

        Use of of eap allows for the functionality of different logins for different users, so if say a user creds have been compromised or believe to be compromised you could just change those specific creds or disable them without having to change all your devices to use a new PSK, etc.

        You could 802.1x with your radius server so that devices are not allowed on the network be it wired or wireless unless they pass the auth you setup with 802.1x

        As example - you state you have your personal wireless.. Which I assume has access to more of your network then any of your other wireless networks.  So in this case you could require eap-tls to get on this network.  So only devices you actual trust and have given the correct certs could get on this network.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.