Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Enabling RADIUS as authentication server spams NPS every second

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 2 Posters 626 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jackyaz
      last edited by

      I've set up RADIUS to my Microsoft NPS instance, and have noticed pfsense immediately starts spamming it with authentication requests for the local admin user even when no actual authentication attempts are occurring. Is this expected?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        No, I would not expect that. What are you doing at the time? Is there anything logged in pfSense?

        J 1 Reply Last reply Reply Quote 0
        • J
          jackyaz @stephenw10
          last edited by

          @stephenw10 To test it just now, I re-enabled RADIUS server as the Authentication server then logged out of the WebUI. I still saw the NPS instance being flooded with requests from pfSense. Changing the authentication server back to Local Database immediately stops the requests

          J 1 Reply Last reply Reply Quote 0
          • J
            jackyaz @jackyaz
            last edited by jackyaz

            @jackyaz said in Enabling RADIUS as authentication server spams NPS every second:

            @stephenw10 To test it just now, I re-enabled RADIUS server as the Authentication server then logged out of the WebUI. I still saw the NPS instance being flooded with requests from pfSense. Changing the authentication server back to Local Database immediately stops the requests

            Ah, I realised I'd recently set up HomeAssistant to integrate with pfSense...disabling the integration stopped the requests. Since the HA integration grabs so many metrics, I wonder if its sending an auth attempt for every single one

            Linking in case useful to anyone else https://github.com/travisghansen/hass-pfsense/issues/71

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Ah, if it's using an xml-rpc call for each metric I guess that would do it. Interesting.

              J 1 Reply Last reply Reply Quote 1
              • J
                jackyaz @stephenw10
                last edited by

                @stephenw10 I don't know enough about the integration (I haven't had time to read through the code), but I have seen xml-rpc mentioned

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.