Freeradius NAS authentication only by secret

Viewed 204

I read some questions about NAS behind NAT and I haven't found the answer (if any) to my problem. I have access points behind a NAT and I want to authorize them one by one in Freeradius.

I want to authorize the NAS by secret only, and verify simultaneous usage by secret as well.

It is possible? If not, does anyone have a similar approach?

1 Answers

This setup is not particularly recommended, but it will work. FreeRADIUS (well, RADIUS in general) cares about the IP address the request came from and the Message Authenticator.

So you need a single clients.conf entry for the IP address that the requests are coming from (presumably the external NAT IP), and all the APs behind that NAT address must use the same shared secret.

At least two reasons it is not a great idea - firstly, the shared secret should ideally be unique per NAS and it can't be in this situation. Secondly, it may be harder to identify which AP the request is coming from. If you need to know then most NASes add a NAS-Identifier attribute with their name in. (Another issue may be that as all clients use the same entry then they will all have to use the same virtual server, but this may be less of an issue as it's often only used in more advanced setups).

Simultaneous Use is a different issue and unlikely to be affected by the above as it depends on the attributes to do with the client. However if you are in a Wifi environment then enabling Simultaneous Use can cause all sorts of problems if you are not careful, and is generally not a good way to go (think for example, a client roams out of range... they then re-authenticates on another AP, which is then denied because the first session is still active).

Related