Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Freeradius3 accounting bugs

    Scheduled Pinned Locked Moved Captive Portal
    40 Posts 9 Posters 5.9k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK Offline
      KOM
      last edited by

      Those are placeholders from when the old forum transitioned to the new one. Images from old posts were lost.

      1 Reply Last reply Reply Quote 0
      • A Offline
        Aubin @jaspras
        last edited by

        @jaspras
        Can you help me with the settings for accounting with MySQL database?

        1 Reply Last reply Reply Quote 0
        • P Offline
          Pepito Payet @mke
          last edited by

          @mke or should we insert this parameter john | Simultaneous-use | := | 1 please ?

          1 Reply Last reply Reply Quote 0
          • P Offline
            Pepito Payet @Gertjan
            last edited by

            @Gertjan can you explain to me how you make it work please?

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG Online
              Gertjan @Pepito Payet
              last edited by Gertjan

              @Pepito-Payet

              For the Radius user that you want to limit to "5" max, add :

              44c0db99-8e3c-48e8-a850-a0bb83ff9275-image.png

              but don't take my words for it.
              Fact check this, as its easy to test : get 6 phones, login with all o them. The 6 phone/login should be refused (or way more funnier : it will be allowed, and the first one will be thrown of, the portal ^^).

              For myself, I actually don't use it anymore.
              Keep us posted.

              edit : I've read the thread again.
              My proposal - today, above, is : adding some stuff in the GUI.

              If you use MySQL (MariaDB) as a Radius "storage", and you know how to add / edit the SQL tables, you can also add the "Simultaneous-Use" criteria into of one the tables. For the format and how to, check with world's most notorious software manual : the one of freeradius.

              Take note that by default the freeradius users are not been taken from the SQL tables, but from a flat ASCI file : this one :

              3514d99f-193c-4b7d-a134-0ddf20307d08-image.png

              and you can see your

              DEFAULT Simultaneous-Use := 5 
               Fall-Through = Yes
              

              No "help me" PM's please. Use the forum, the community will thank you.

              P 2 Replies Last reply Reply Quote 0
              • P Offline
                Pepito Payet @Gertjan
                last edited by

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • P Offline
                  Pepito Payet @Gertjan
                  last edited by

                  @Gertjan I tried but it doesn't work... maybe I have a misconfiguration of the portal captive elsewhere?

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG Online
                    Gertjan @Pepito Payet
                    last edited by Gertjan

                    @Pepito-Payet

                    Gime 30 minutes and I'll post a step by step "what to do".


                    I created a user, just a use name "cuisine" and a password :

                    50503353-189f-4012-87ff-323ce924c5c0-image.png

                    and I added :

                    b529efb4-e965-443e-bbe0-6a3bc7718925-image.png a8dc8dce-da93-45d5-af8a-1881a0f5923e-image.png

                    DEFAULT Simultaneous-Use := 1 | Fall-Through = Yes
                    

                    and Save.

                    Check that FreeRadius successfully restarted. You can do this on the dashboard.

                    I presume you've set up the portal use the freeradius auth back-end, not the pfSense user database.

                    You can test drive the authentification here : Diagnostics -> Authentication
                    You have to select the Freeradius backend, not the "Local Database".

                    Now : connect one user to the portal using this user name and check he was logged in correctly (dash board and portal auth log).

                    A second user using the same user name should get the "portal error login page", this page is the same as the portal login page, but shows one thing more : an error message :
                    I made this error message stand out in red :

                    You are already logged in - access denied

                    And this was also logged :

                    Status > System Logs > Authentication > Captive Portal Auth

                    7a500c5c-d675-4e42-a88d-fbe64ad49b8c-image.png

                    No "help me" PM's please. Use the forum, the community will thank you.

                    P 4 Replies Last reply Reply Quote 0
                    • P Offline
                      Pepito Payet @Gertjan
                      last edited by

                      @Gertjan Thank you very much ๐Ÿ™

                      1 Reply Last reply Reply Quote 0
                      • P Offline
                        Pepito Payet @Gertjan
                        last edited by

                        @Gertjan Hello, I did exactly what you said but it doesn't work... Users can log in.

                        1 Reply Last reply Reply Quote 0
                        • P Offline
                          Pepito Payet @Gertjan
                          last edited by

                          @Gertjan Hello, Here is my configuration. Have I perhaps configured my captive portal incorrectly?

                          1.JPG

                          2.JPG

                          3.JPG

                          4.JPG

                          5.JPG

                          6.JPG

                          7.JPG

                          12.JPG

                          1 Reply Last reply Reply Quote 0
                          • P Offline
                            Pepito Payet @Gertjan
                            last edited by

                            @Gertjan And here is my user account configuration :

                            8.JPG

                            9.JPG

                            10.JPG

                            11.JPG

                            GertjanG 1 Reply Last reply Reply Quote 0
                            • GertjanG Online
                              Gertjan @Pepito Payet
                              last edited by Gertjan

                              @Pepito-Payet

                              These are suggestions :

                              Don't use this one.
                              17d2e57c-6f24-41f6-b159-750dda6e5242-image.png

                              See for your self : how can this be a "Pre-authentication" while it also says "Visitors will be redirected to this URL after authentication".
                              My advise : leave it empty.

                              be9cb646-dea0-4738-af42-baa6281503a1-image.png

                              Leave blank, or set it to the value needed by FreeRadius : Captiveportal-captiveportal, as suggested.

                              389127ed-c08e-4586-b0fd-ea2e6c248f37-image.png

                              Set to Interim if you want "bytes to be counted."

                              d2db4f58-ec03-4719-a350-a8c37e475725-image.png

                              I'm not sure about this one.
                              It has been years now that 'http' pages are being deprecated.
                              I use https. This means I (have to !) 'rent' a domain name, and I use that domain exclusively for my pfSense portal domain name. With the acme pfSense package I obtain a certificate.

                              11639dab-c4f0-4196-a046-665f82f67528-image.png

                              4ba564a1-d19f-46e9-be58-6d9f17abcf4f-image.png

                              Isn't that a 'voucher' setting ?

                              39b5f9d5-1fa9-4efa-a15f-347e067f9815-image.png

                              Disable the logout page.
                              I do not like browser popup pages.
                              You do not popup pages
                              Your portal users don't like popup pages.
                              And we all have popup page disabled in our browser these days.
                              So, useless to try to make one pop up - this is something of the old 'http' past.

                              35e0783d-1b46-4a09-870d-4b39881ae48c-image.png

                              Does that http google page still exists ?

                              No "help me" PM's please. Use the forum, the community will thank you.

                              P 2 Replies Last reply Reply Quote 0
                              • P Offline
                                Pepito Payet @Gertjan
                                last edited by

                                This post is deleted!
                                1 Reply Last reply Reply Quote 0
                                • P Offline
                                  Pepito Payet @Gertjan
                                  last edited by

                                  @Gertjan Thanks for your advice, but the certificate is free? I tried but I never managed to make the https work... but which parameter blocks the restriction of number of users?

                                  GertjanG 2 Replies Last reply Reply Quote 0
                                  • GertjanG Online
                                    Gertjan @Pepito Payet
                                    last edited by

                                    @Pepito-Payet

                                    Another one :

                                    For accounting (bandwith, traffic), the interim method must be set.
                                    And this field has to be set also :

                                    762c63ae-6b92-47e6-8a6d-9ef7f6337458-image.png

                                    for example : "600".

                                    No "help me" PM's please. Use the forum, the community will thank you.

                                    1 Reply Last reply Reply Quote 0
                                    • GertjanG Online
                                      Gertjan @Pepito Payet
                                      last edited by

                                      @Pepito-Payet said in Freeradius3 accounting bugs:

                                      but which parameter blocks the restriction of number of users?

                                      The pfSense FreeRadius package isn't FreeRadius made for pfSense.
                                      Freeradius by itself is massive, hundreds if not thousands of options and settings. pfSense surfaces just a couple of them in the GUI.
                                      I can't tell you why it doesn't work for you.
                                      Your captive portal is already not identical to mine.
                                      I use pfSense FreeRadius with the SQL option (I use a SQL database).

                                      Normally, when I want to see what(s going on, I stop Freeradius on the dashboard GUI, and then, on the SSH (console) I use

                                      radiusd -X
                                      

                                      which starts freeradius in debug mode with 'all the details' right in front of you.
                                      What you see then, is freeradius in all it's beauty ^^
                                      I wasn't able to spot the place where the "Simultaneous-Use" criteria was enforced .... and can't test everything right now as my portal is actively used by my hotel clients right now.

                                      No "help me" PM's please. Use the forum, the community will thank you.

                                      P 1 Reply Last reply Reply Quote 0
                                      • P Offline
                                        Pepito Payet @Gertjan
                                        last edited by

                                        @Gertjan ah you use SQL on pfsense itself or a separate server? that's why simultaneous client restriction works

                                        GertjanG 1 Reply Last reply Reply Quote 0
                                        • GertjanG Online
                                          Gertjan @Pepito Payet
                                          last edited by

                                          @Pepito-Payet said in Freeradius3 accounting bugs:

                                          ah you use SQL on pfsense itself or a separate server?

                                          Noop. A database server like MariadDB doesn't belong on a firewall. pfSEnse doesn't have a Database server package anyway. And installing the FreeBSD MariadDB package will probably break the system.
                                          ( one might say that even FreeRadius doesn't belong on a firewall neither ).
                                          I have a database engine (MariaDB) running on a NAS, and use that one for freeradius pfSense.

                                          No "help me" PM's please. Use the forum, the community will thank you.

                                          P 1 Reply Last reply Reply Quote 0
                                          • P Offline
                                            Pepito Payet @Gertjan
                                            last edited by

                                            @Gertjan ah so that's why mine won't work... I haven't found any solution yet... whereas with the old versions it worked...

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.