Community discussions

 
migmac
just joined
Topic Author
Posts: 5
Joined: Sat Nov 17, 2012 5:33 pm
Reputation: 0

Mikrotik and Freeradius

Fri Mar 15, 2013 5:49 pm

Hello,

I was able to connect the Mikrotik to a Freeradius server, it works fine with PPTP but it does not work with SSTP and L2TP. Is there anyway I can make it work with SSTP and L2TP?

thnak you
 
telepro
newbie
Posts: 44
Joined: Sun Apr 03, 2011 7:50 pm
Reputation: 0

Re: Mikrotik and Freeradius

Sat May 18, 2013 8:08 pm

i have been successful (as I believe you have) in implementing PPTP VPN authentication using a FreeRadius. However, I have not been able to successfully use the response from FreeRadius to authenticate a WinBox login. For Winbox I needed to implement a Mikrotik User Manager, which was certainly not my preference. Have you been successful in authenticating Winbox Logins using FreeRadius?

I have not had reason yet to attempt SSTP or L2TP authentication.

thanks
 
tomaskir
Forum Guru
Forum Guru
Posts: 1004
Joined: Sat Sep 24, 2011 2:32 pm
Reputation: 26
Location: Slovakia

Re: Mikrotik and Freeradius

Sat May 18, 2013 9:52 pm

We authenticate users for WinBox login and L2TP from FreeRadius with MySQL.

For Winbox, you have to send back a group name as an attribute.
MikroTik deep-dives and tutorials (MPLS/VPLS, IPSec, Mange, etc.)
Click for the playlist
 
telepro
newbie
Posts: 44
Joined: Sun Apr 03, 2011 7:50 pm
Reputation: 0

Re: Mikrotik and Freeradius

Sat May 18, 2013 10:34 pm

Thanks much for the info that it can be made to work. We'll give it a try. Since there are about 90+ standard attributes, do you remember in which attribute you sent the group name? The only standard Attribute with 'group' in its name that I find is "Tunnel-Private-Group-ID", which does not seem appropriate. Perhaps it is a vendor specific type value? If so, did you find the attribute type number defined some place?
thanks again, and have a great day
 
tomaskir
Forum Guru
Forum Guru
Posts: 1004
Joined: Sat Sep 24, 2011 2:32 pm
Reputation: 26
Location: Slovakia

Re: Mikrotik and Freeradius

Sat May 18, 2013 11:03 pm

Include this as a dictionary in FreeRadius.
http://wiki.mikrotik.com/wiki/Manual:RADIUS_Client/vendor_dictionary

Send Mikrotik-Group back as an attribute with the name of the group you want the user to be in for winbox.
Also, winbox uses CHAP, but console, ssh, telnet, use PAP.
MikroTik deep-dives and tutorials (MPLS/VPLS, IPSec, Mange, etc.)
Click for the playlist

Who is online

Users browsing this forum: No registered users and 22 guests