Community discussions

MUM Europe 2020
 
kirua
just joined
Topic Author
Posts: 9
Joined: Fri Jun 10, 2016 2:45 pm
Contact:

openvpn server + radius client (solved)

Mon Jun 27, 2016 4:57 pm

Hello,
I try to use an authentication to my openvpn server (under mikrotikOS) via a radius server (under debian) but I'm still confuse on the way to do it on the mikrotik side.
the configuration of the radius server is ok and i had try to login on ssh via radius and it work (radius add service=login).

I understood that i have to create a new radius service (radius add service=ppp) but after that i don't understand how to use it with openvpn ?
I assume that i have something to do in ppp but what exactly ?
I had try to do this:
ppp aaa set use-radius=yes
but apparently it didn't change anything.

if someone know how it work or have some idea it would really help me.
Last edited by kirua on Mon Jun 27, 2016 6:13 pm, edited 1 time in total.
some interest in 3d printing ? take a tour on pantadora.com
 
rufee
newbie
Posts: 27
Joined: Mon Dec 10, 2012 2:41 pm

Re: openvpn server + radius client

Mon Jun 27, 2016 5:10 pm

Enable OpenVPN server and test it without Radius just for now to see if it works and suits your needs, Mikrotik implementation does not support all features of ovpn.
Then make sure the Radius service is configured correctly, enable "Use radius" in the PPP Secrets tab, create a profile for ovpn connections.

Try to connect while observing RouterOS logs and Radius server logs.
MTCNA
 
kirua
just joined
Topic Author
Posts: 9
Joined: Fri Jun 10, 2016 2:45 pm
Contact:

Re: openvpn server + radius client

Mon Jun 27, 2016 5:21 pm

I forget to say it but openvpn work fine without radius, and i have anything into the log (mikrotik and linux) that why I think that there is some option to activate it but i can't find it.
I have "use radius" enabled in the "ppp secret Authentication&Accounting" on the web interface but i can't find it on the console.

also i assume that radius service is configured correctly since i can connect to it for the ssh authentication.
some interest in 3d printing ? take a tour on pantadora.com
 
kirua
just joined
Topic Author
Posts: 9
Joined: Fri Jun 10, 2016 2:45 pm
Contact:

Re: openvpn server + radius client

Mon Jun 27, 2016 6:13 pm

I finally found the solution.
if someone is looking for it you have to note that radius user database is consulted only if the required username is not found in local user database. That means that you have to use a username who don't exist on the local database but only on the radius server.

thanks you rufee for the attempt to help me.
some interest in 3d printing ? take a tour on pantadora.com
 
vlangelov
just joined
Posts: 3
Joined: Mon Jan 04, 2016 10:27 am

Re: openvpn server + radius client (solved)

Fri Jul 15, 2016 4:40 pm

Hello Kirua,

I followed your advise but for some reason I am still unable to make it run. Could you please let me know if you can provide more details on your setup?

Thanks!
 
kirua
just joined
Topic Author
Posts: 9
Joined: Fri Jun 10, 2016 2:45 pm
Contact:

Re: openvpn server + radius client (solved)

Mon Jul 25, 2016 10:55 am

Hello vlangelov,

I don't know if you've resolved your problem but here some more info: I use a freeradius server under debian who use a database to authenticate the user, my mikrotik server is on V.6.35.2 and here is my configuration of the ovpn-server :
enabled: yes
                        port: 1194
                        mode: ip
                     netmask: 24
                 mac-address: FE:03:33:69:A3:B7
                     max-mtu: 1500
           keepalive-timeout: 20
             default-profile: ovpn-mikrotik
                 certificate: server
  require-client-certificate: no
                        auth: sha1,md5
                      cipher: blowfish128,aes128,aes192,aes256
have you try to use your radius server in local to be sure that it working right ? (under freeradius you launch it with
freeradius ­-X
and then you type
: radtest myuser mypassword 127.0.0.1 0 mysecret
some interest in 3d printing ? take a tour on pantadora.com

Who is online

Users browsing this forum: No registered users and 86 guests