OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Multiple Radius Server for OpenVPN
« previous next »
  • Print
Pages: [1]

Author Topic: Multiple Radius Server for OpenVPN  (Read 3362 times)

sfty1

  • Newbie
  • *
  • Posts: 19
  • Karma: 0
    • View Profile
Multiple Radius Server for OpenVPN
« on: June 04, 2019, 04:57:53 pm »
Hi,

authentication trough radius server is working fine. I have two Microsoft NPS attached, for the case, when one goes down.

Now I tested to deactivate the first Radius server. The problem is, that OpenVPN is still waiting for the first Radius Server, forever. It's not asking the second one. Only when the first Radius Server is rejecting the access, the second one will be asked. But I like to use this in a HA Scenario.

Any clue?

config:
Code: [Select]
auth-user-pass-verify "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_auth_verify user 'Active Directory RADIUS DC1,Active Directory Radius DC2,Local Database' 'false' 'server1'" via-env
tls-verify "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_auth_verify tls ‘my+company+OpenVPN+Server' 1"

thanks
« Last Edit: June 05, 2019, 10:12:22 am by sfty1 »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Multiple Radius Server for OpenVPN
« Reply #1 on: June 05, 2019, 07:02:03 am »
You could try UDP loadbalancing via nginx plugin:
https://wiki.opnsense.org/manual/how-tos/nginx_streams.html
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

sfty1

  • Newbie
  • *
  • Posts: 19
  • Karma: 0
    • View Profile
Re: Multiple Radius Server for OpenVPN
« Reply #2 on: June 11, 2019, 09:58:45 am »
Thank you for the idea. But UDP via nginx is failing. Any access is denied. I don't know why. Maybe nginx is not the right tool to balance the radius protocol.

Backend NPS:
Only difference in the error log is:
Security ID:         NULL SID
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Multiple Radius Server for OpenVPN
« Reply #3 on: June 11, 2019, 10:24:28 am »
And did you also try relayd? Should also be capable of using UDP.
FreeRadius also has a proxy function but no idea if it's inteded to do loadbalancing/failover/HA
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Multiple Radius Server for OpenVPN
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2