Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
18.7 Legacy Series
»
Radius Authentication over IPSec VPN
« previous
next »
Print
Pages: [
1
]
Author
Topic: Radius Authentication over IPSec VPN (Read 4784 times)
Slacky85
Newbie
Posts: 3
Karma: 1
Radius Authentication over IPSec VPN
«
on:
January 29, 2019, 12:19:44 pm »
Hello,
I'm facing a problem with the access authentication via a remote Radius server reachable on an IPSEC VPN between OPNSense and another firewall in different location. Basically I have the same problem also for the internal DNS and NTP but one problem at time.
What I can see is that the OPNSense send the authentication request with its WAN IP Address so there is no rule to the remote host and also if I add it of course there isn't route for the traffic to come back over the tunnel.
I made several search but really don't know how I can change this behaviour that seems be the default one. Any idea?
Thanks
Logged
bartjsmit
Hero Member
Posts: 2018
Karma: 194
Re: Radius Authentication over IPSec VPN
«
Reply #1 on:
January 29, 2019, 02:42:14 pm »
Sounds like a general connectivity issue. Make sure there are no firewalls (network or host) to block the traffic and that there are routes in place at both ends.
Bart...
Logged
Slacky85
Newbie
Posts: 3
Karma: 1
Re: Radius Authentication over IPSec VPN
«
Reply #2 on:
January 30, 2019, 09:53:25 am »
No connectivity issue, the VPN is UP and all the traffic pass without problem.
I just need to make OPNSense present itself with the LAN IP address instead of the WAN when it send RADIUS authentication to the RADIUS server that is reachable only through one of the IPSEC VPN.
|--LAN--OPNSense|-----IPSEC-VPN----|SITE_B_FIREWALL--RADIUS_Server|
what I can see from the log is that opnsense send the request with its own wan address so it can't work. No idea if I miss some settings or if there is a trick to modify this.
Thanks
Logged
franco
Administrator
Hero Member
Posts: 17669
Karma: 1612
Re: Radius Authentication over IPSec VPN
«
Reply #3 on:
January 30, 2019, 12:24:14 pm »
Same as
https://forum.opnsense.org/index.php?topic=11357.msg51419#msg51419
IPsec is in the way
Cheers,
Franco
Logged
Slacky85
Newbie
Posts: 3
Karma: 1
Re: Radius Authentication over IPSec VPN
«
Reply #4 on:
February 01, 2019, 03:31:18 pm »
Thanks Franco!
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
18.7 Legacy Series
»
Radius Authentication over IPSec VPN