Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    User Authentication - Radius

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 1 Posters 793 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jhardin80
      last edited by

      I'm trying to get user authentication working on pfsense 2.2.2.

      We have a radius server that I have added the pfsense boxes to as clients

      We have two groups in AD, one for managers and one for operators

      I have created both groups in pfsense with the same names as in AD and I have assigned the appropriate privs to each of those groups in pfsense.

      I can test the authentication and it is successful but there are no pages displayed.

      I double checked the the privs for my group in pfsense and I have the same privs as the admin account but it's still not working for me.

      Even if I take out the groups in pfsense it still authenticates my user account. So that tells me it's not seeing my user account as being in that group in pfsense.

      How do I get it to associate my user account with the pfsense group? The pfsense group name is the exact same as the group name in AD that my user account is in.

      1 Reply Last reply Reply Quote 0
      • J
        jhardin80
        last edited by

        There has to be something simple that I'm missing.

        Even if I create a group called Domain Users in pfsense (the same group my user account is in AD) It gets authenticated but no pages so it's still not associating my account with the pfsense group that has the privs linked to it.

        1 Reply Last reply Reply Quote 0
        • J
          jhardin80
          last edited by

          So apparently they don't have the code in pfsense to do this just yet.

          You have to create a dummy account with the same user account name that is in AD and then add that dummy account to the group.

          Hope they get the code soon so you don't have to have dummy accounts.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.