Community discussions

MikroTik App
 
SkullKill
just joined
Topic Author
Posts: 7
Joined: Wed Apr 30, 2008 5:58 pm
Location: Perth, Australia

Using UserManager as RADIUS for other AP

Wed Apr 30, 2008 6:11 pm

hi,
i am running User-manager 3.7 with a license level 4

i have setup the user-manager and hotspot correctly and all that works fine,

now, i am trying to setup other AP to use the userManager for authentication of wireless clients using WPA,
setup the radius server ip as the ip of the mikrotik but once a user try to authenticate with the AP,
usermanager returns "unknown authentication algorithm"

tried with an D-link AP and a Cisco AP

this is the debug output from the user-manager

when trying to connect to the d-link AP
18:20:52 manager,debug,packet received Access-Request with id 2 from 192.168.5.253:1202
18:20:52 manager,debug,packet Signature = 0x84a49103cc815a8aeb3d9cb12b4137c4
18:20:52 manager,debug,packet User-Name = "blah"
18:20:52 manager,debug,packet NAS-IP-Address = 192.168.5.253
18:20:52 manager,debug,packet NAS-Port = 0
18:20:52 manager,debug,packet Called-Station-Id = "00-40-05-5E-FA-C7"
18:20:52 manager,debug,packet Calling-Station-Id = "00-19-D2-8F-0B-7A"
18:20:52 manager,debug,packet NAS-Identifier = "DI-624"
18:20:52 manager,debug,packet Framed-MTU = 1380
18:20:52 manager,debug,packet NAS-Port-Type = 19
18:20:52 manager,debug,packet EAP-Message = 0x0201000901626c6168
18:20:52 manager,debug,packet Message-Authenticator = 0x0a9f9dc298bf91b9dc6ff0910fb0d9c8
18:20:52 manager,debug received remote request 115 code=Access-Request from 192.168.5.253:1202
18:20:52 manager,debug sending Access-Reject to request 115
18:20:52 manager,debug,packet sending Access-Reject with id 2 to 192.168.5.253:1202
18:20:52 manager,debug,packet Signature = 0x7754294530c983190983071605ea0978
18:20:52 manager,debug,packet Reply-Message = "unknown authentication algorithm"
18:20:52 manager,debug unknown authentication algorithm for user <blah> in authentication request 115, rejecting

when trying to connect to the Cisco AP
21:21:06 manager,debug,packet received Access-Request with id 2 from 192.168.0.254:1645
21:21:06 manager,debug,packet Signature = 0x86f6743ef048f45b2d95ba18d826e2ce
21:21:06 manager,debug,packet User-Name = "blah"
21:21:06 manager,debug,packet Framed-MTU = 1400
21:21:06 manager,debug,packet Called-Station-Id = "001f.6cf4.d0e0"
21:21:06 manager,debug,packet Calling-Station-Id = "0019.d28f.0b7a"
21:21:06 manager,debug,packet Service-Type = 1
21:21:06 manager,debug,packet Message-Authenticator = 0x275e9d78d317bbcf4e150d9d0a3bfd2c
21:21:06 manager,debug,packet EAP-Message = 0x0202111e01536b756c6c4b696c6d
21:21:06 manager,debug,packet NAS-Port-Type = 19
21:21:06 manager,debug,packet NAS-Port = 259
21:21:06 manager,debug,packet NAS-Port-Id = "259"
21:21:06 manager,debug,packet NAS-IP-Address = 192.168.0.254
21:21:06 manager,debug,packet NAS-Identifier = "SkullKillR"
21:21:06 manager,debug received remote request 117 code=Access-Request from 192.168.0.254:1645
21:21:06 manager,debug sending Access-Reject to request 117
21:21:06 manager,debug,packet sending Access-Reject with id 2 to 192.168.0.254:1645
21:21:06 manager,debug,packet Signature = 0x8a04f8fffc18e107f6911c1acc0342df
21:21:06 manager,debug,packet Reply-Message = "unknown authentication algorithm"
21:21:06 manager,debug unknown authentication algorithm for user <SkullKill> in authentication request 117, rejecting



any idea why??? :(

note: try to connect to AP with windows vista / XP
trying to use PEAP
Last edited by SkullKill on Wed Apr 30, 2008 6:14 pm, edited 1 time in total.
 
User avatar
omega-00
Forum Guru
Forum Guru
Posts: 1167
Joined: Sat Jun 06, 2009 4:54 am
Location: Australia
Contact:

Re: Using UserManager as RADIUS for other AP

Wed Apr 30, 2008 6:14 pm

What authentication method are you trying to use on the wireless?
 
User avatar
sergejs
MikroTik Support
MikroTik Support
Posts: 6694
Joined: Thu Mar 31, 2005 3:33 pm
Location: Riga, Latvia
Contact:

Re: Using UserManager as RADIUS for other AP

Fri May 02, 2008 2:15 pm

I believe that User-Manager is not able to provide with PEAP or similar authentication.
Currently you need to use Free RADIUS or similar product to get PEAP or other kind of authentication.
 
SkullKill
just joined
Topic Author
Posts: 7
Joined: Wed Apr 30, 2008 5:58 pm
Location: Perth, Australia

Re: Using UserManager as RADIUS for other AP

Fri May 02, 2008 4:47 pm

ok then, snif snif, would be a GOOD option to have in the userManager though.... :(
 
lagosta
just joined
Posts: 21
Joined: Sun May 11, 2008 10:02 pm

Re: Using UserManager as RADIUS for other AP

Sat Jun 07, 2008 7:37 pm

+1 vote :D
 
aizukanne
just joined
Posts: 3
Joined: Sun Jul 04, 2004 5:57 pm
Contact:

Re: Using UserManager as RADIUS for other AP

Thu Sep 24, 2009 12:46 pm

Very interesting. I have same issue here as well. using Open Radius means a new server right? Or is there a way to integrate that to Mikrotik perhaps running a Linux distro with Open Radius in xen.
 
Chilene
just joined
Posts: 11
Joined: Wed Dec 16, 2009 1:05 pm

Re: Using UserManager as RADIUS for other AP

Sun Jan 17, 2010 1:54 am

Are there currently any plans to integrate EAP into User Manager or do we still have to use Freeradius in the Future?
 
User avatar
sergejs
MikroTik Support
MikroTik Support
Posts: 6694
Joined: Thu Mar 31, 2005 3:33 pm
Location: Riga, Latvia
Contact:

Re: Using UserManager as RADIUS for other AP

Mon Jan 18, 2010 12:02 pm

As far as I know there is no plans for near future, but it could be possible in future.
 
Chilene
just joined
Posts: 11
Joined: Wed Dec 16, 2009 1:05 pm

Re: Using UserManager as RADIUS for other AP

Mon Jan 18, 2010 1:11 pm

Ok, thank you for the answer. Would be really a great option for the future! ;)

+1 vote for EAP in UM! 8)
 
jandafields
Forum Guru
Forum Guru
Posts: 1515
Joined: Mon Sep 19, 2005 6:12 pm

Re: Using UserManager as RADIUS for other AP

Tue Apr 06, 2010 3:42 am

This would definitely be a nice feature. I assumed it could do that already until I read this. Please include in v4!
 
alex_rhys-hurn
Member
Member
Posts: 348
Joined: Mon Jun 05, 2006 8:26 pm
Location: Kenya
Contact:

Re: Using UserManager as RADIUS for other AP

Mon Apr 26, 2010 7:24 pm

I Agree that this would be a very good addition:

+1 Vote
 
User avatar
zervan
Member
Member
Posts: 329
Joined: Fri Aug 20, 2010 10:43 pm
Location: Slovakia
Contact:

Re: Using UserManager as RADIUS for other AP

Fri Dec 17, 2010 11:14 pm

Do I understand well that I can't use the Mikrotik with User Manager as central RADIUS server for users connecting to AP? Is anything new in this area?
 
SurferTim
Forum Guru
Forum Guru
Posts: 4636
Joined: Mon Jan 07, 2008 10:31 pm
Location: Miramar Beach, Florida

Re: Using UserManager as RADIUS for other AP

Sat Dec 18, 2010 12:47 pm

@zervan: This thread is about PEAP authentication. If you use the default http-chap, it does fine.
 
User avatar
THG
Member
Member
Posts: 472
Joined: Thu Oct 15, 2009 1:05 am

Re: Using UserManager as RADIUS for other AP

Thu Jan 20, 2011 6:56 am

As far as I know there is no plans for near future, but it could be possible in future.
I need it for IEEE 802.1X port-based authentication on my switches. :)
 
User avatar
peterd
newbie
Posts: 46
Joined: Mon Nov 05, 2007 1:23 pm

Re: Using UserManager as RADIUS for other AP

Mon Sep 12, 2011 4:08 pm

+1 here
 
User avatar
SunnyNL
just joined
Posts: 9
Joined: Sat Feb 25, 2012 4:26 pm
Location: Netherlands

Re: Using UserManager as RADIUS for other AP

Sun Mar 04, 2012 3:27 am

+1

Missing EAP-TLS authentication with (user manager) RADIUS!
Last edited by SunnyNL on Wed Mar 21, 2012 11:10 pm, edited 1 time in total.
 
bweyrick
just joined
Posts: 3
Joined: Sat Mar 22, 2008 7:54 pm

Re: Using UserManager as RADIUS for other AP

Wed Mar 07, 2012 9:29 pm

+ 1 looking to drop pppoe from network
 
miooodek
just joined
Posts: 5
Joined: Thu Apr 05, 2012 11:41 pm

Re: Using UserManager as RADIUS for other AP

Tue Apr 10, 2012 1:09 am

+1 here
 
Seanny
just joined
Posts: 7
Joined: Sat Jun 02, 2012 11:22 pm

Re: Using UserManager as RADIUS for other AP

Thu Aug 02, 2012 3:28 am

+1 here
 
User avatar
bax
Member Candidate
Member Candidate
Posts: 268
Joined: Mon Dec 20, 2004 8:45 pm
Location: Croatia

Re: Using UserManager as RADIUS for other AP

Tue Jan 08, 2013 2:50 pm

Im also have Userman on x86 Ros v5.22 and I want to give some other network usage to same users which is already in userman base ...
Is it possible to the existing RADIUS server access to some external method?
For now, I'm trying to make a connection with NTRadPing ... but no luck ...
If anyone knows the settings with which you can connect, please help.
I always have errors like in this picture :
You do not have the required permissions to view the files attached to this post.
 
minjun
just joined
Posts: 3
Joined: Tue Jul 07, 2015 9:17 am

Re: Using UserManager as RADIUS for other AP

Tue Jul 07, 2015 10:47 am

+1

Missing EAP-TLS authentication with (user manager) RADIUS!
+1 for EAP-TLS authentication with user manager!!!!!!
 
User avatar
kiler129
Member
Member
Posts: 352
Joined: Tue Mar 31, 2015 4:32 pm
Location: IL, USA
Contact:

Re: Using UserManager as RADIUS for other AP

Sun Sep 27, 2015 6:28 am

+1s are little annoying but in this case I have to add my one - user manager should be able to act as RADIUS server for other APs.
Mikrotik, consider this feature requested for 7 years, please ;)
 
JanezFord
Member Candidate
Member Candidate
Posts: 269
Joined: Wed May 23, 2012 10:58 am

Re: Using UserManager as RADIUS for other AP

Fri Oct 23, 2015 9:19 pm

I agree ... this feature is needed for corporate environments, CCR series as capsman works great but having to use external radius for this is just silly.

JF.
 
aryjrbnu
just joined
Posts: 1
Joined: Mon Jul 17, 2017 8:38 pm

Re: Using UserManager as RADIUS for other AP

Wed Aug 15, 2018 2:53 am

Any news on the subject userman as radius server?
 
RandomBlue
just joined
Posts: 2
Joined: Fri Oct 26, 2018 1:30 pm

Re: Using UserManager as RADIUS for other AP

Fri Sep 20, 2019 12:13 pm

Hi - I have just tried it and I believe the issue persist. Any news / hopes ? ( It has been 11 years since the original post :D )
 
shivansps
Frequent Visitor
Frequent Visitor
Posts: 54
Joined: Fri Sep 22, 2017 1:18 am

Re: Using UserManager as RADIUS for other AP

Fri Nov 01, 2019 6:22 pm

Yup, just tried is not possible to use userman to as a radius server for wireless clients. No EAP-TLS, EAP-SIM, EAP-AKA, PEAP, LEAP or EAP-TTLS support.
 
krisjanisj
Member Candidate
Member Candidate
Posts: 101
Joined: Wed Feb 20, 2019 2:53 pm
Contact:

Re: Using UserManager as RADIUS for other AP

Mon Nov 04, 2019 9:17 am

We are planning to add RADIUS Server features to our User-Manager in v7.
 
AlexPr0
just joined
Posts: 1
Joined: Tue Mar 10, 2020 7:01 pm

Re: Using UserManager as RADIUS for other AP

Tue Mar 10, 2020 7:11 pm

Hello there,

I can't remotely access RADIUS server however it perfectly works for internal services. For example NTRadPing says me "no response from server".
Is this somehow related to discussed issue with authentication?
 
sangope
just joined
Posts: 1
Joined: Thu Jun 24, 2021 11:16 am

Re: Using UserManager as RADIUS for other AP

Thu Jun 24, 2021 11:23 am

Hi again

I'm really interested on this feature. I was trying to install 7.0 version in a hap lite but I couldn't. Do you know when the official 7 versión Will be released for all devices? I'd like to use usermanager to autenticate the wifi conection with radius without a freeradius server

Regards

Who is online

Users browsing this forum: No registered users and 8 guests