OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • [SOLVED] Missing OpenVPN RADIUS Attr on "reconnection"
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] Missing OpenVPN RADIUS Attr on "reconnection"  (Read 682 times)

fabio

  • Newbie
  • *
  • Posts: 39
  • Karma: 2
    • View Profile
[SOLVED] Missing OpenVPN RADIUS Attr on "reconnection"
« on: August 03, 2018, 06:25:32 pm »
Hi All,

I've noticed that the RADIUS attributes are not pushed to the client if the server see the client connected

To reprocude the bethaviour
01- cliente connection
02- RADIUS auth reqeust
03- RADIUS reply with attributes
04- Framed-IP-Address and Framed-Route are assignes to the cliente
05- client disconnection / connection
07- RADIUS auth reqeust
08- RADIUS reply with attributes
09- Framed-IP-Address and Framed-Route are NOT assignes to the cliente

If you Kill client connection fom the GUI

11- cliente connection
12- RADIUS auth reqeust
13- RADIUS reply with attributes
14- Framed-IP-Address and Framed-Route are assignes to the cliente


At the moment as cliente I've only used "OpenVPN for Android"

Cheers,
« Last Edit: August 05, 2018, 12:00:58 pm by fabio »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 3065
  • Karma: 219
    • View Profile
Re: Missing OpenVPN RADIUS Attr on "reconnection"
« Reply #1 on: August 03, 2018, 06:52:26 pm »
This is an old version of the client which doesnt support disconnect. I had this too with OpenVPN 2.2
Logged
IRC: mimugmail
Twitter: mimu_muc
WWW: www.routerperformance.net

fabio

  • Newbie
  • *
  • Posts: 39
  • Karma: 2
    • View Profile
Re: Missing OpenVPN RADIUS Attr on "reconnection"
« Reply #2 on: August 03, 2018, 07:28:23 pm »
Just tryed the the last versione (2.4.6) of the community windows GUI and I see the same bethaviour.

In the server PUSH_REPLY logs are missing all the RADIUS attributes (if the client Common Name result already connected )

Do I need to set some specific server paramiters ?

Cheers,
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 3065
  • Karma: 219
    • View Profile
Re: Missing OpenVPN RADIUS Attr on "reconnection"
« Reply #3 on: August 03, 2018, 08:16:09 pm »
Normally this works when client logs off. When you disconnect, wait for two mins, then the client is timed out and you can relogin
Logged
IRC: mimugmail
Twitter: mimu_muc
WWW: www.routerperformance.net

fabio

  • Newbie
  • *
  • Posts: 39
  • Karma: 2
    • View Profile
Re: Missing OpenVPN RADIUS Attr on "reconnection"
« Reply #4 on: August 03, 2018, 10:35:20 pm »
Some additional tests,

Now I've remove the RADIUS configuraiton so I've only "loacal database" and local "Client Specific Overrides"

... same results;

With a fast disconnect/reconnect the CSO file on the filesystem is not created


I've the feeling that is something related to the direcrive
Code: [Select]
client-disconnect and the
Code: [Select]
/usr/local/etc/inc/plugins.inc.d/openvpn/attributes.sh script:

commenting out  "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_cleanup_cso.php $1" in that script
all works as aspected (at least by me) ... no idea of eventually side effects
 
Cheers,
Logged

fabio

  • Newbie
  • *
  • Posts: 39
  • Karma: 2
    • View Profile
Re: Missing OpenVPN RADIUS Attr on "reconnection"
« Reply #5 on: August 05, 2018, 12:00:45 pm »
Solved with patch cdb4b81

Thanks
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • [SOLVED] Missing OpenVPN RADIUS Attr on "reconnection"
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2019 All rights reserved
  • SMF 2.0.15 | SMF © 2017, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2