Community discussions

MikroTik App
 
kimdobranski
newbie
Topic Author
Posts: 43
Joined: Mon Aug 03, 2015 9:39 pm

Feature Request: URL as an option for radius IP

Sun Aug 07, 2016 9:42 pm

Hi,

It would be nice if we could put a domain or URL in place of an IP. There are times when the IP could change and having to put an actual IP makes it difficult to chance every device we have deployed. (ie radius1.mydomain.com)

[img]
radius.png
[/img]
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10223
Joined: Mon Jun 08, 2015 12:09 pm

Re: Feature Request: URL as an option for radius IP

Sun Aug 07, 2016 11:58 pm

Sure it could be convenient. However, I would advise to deploy a VPN for management and authentication.
The bonus for cases like this is that you can have a fixed IP for your RADIUS server within the VPN.
But it also simplifies the correct firewalling against break-in attempts.
 
paulct
Member
Member
Posts: 336
Joined: Fri Jul 12, 2013 5:38 pm

Re: Feature Request: URL as an option for radius IP

Mon Aug 08, 2016 9:55 am

Use e.g openvpn with CA certs. We push out routes on a private IP range from openvpn. We then use an amazon ec2 instance with an elastic IP for freeradius.
 
kimdobranski
newbie
Topic Author
Posts: 43
Joined: Mon Aug 03, 2015 9:39 pm

Re: Feature Request: URL as an option for radius IP

Mon Aug 08, 2016 9:36 pm

Sure it could be convenient. However, I would advise to deploy a VPN for management and authentication.
The bonus for cases like this is that you can have a fixed IP for your RADIUS server within the VPN.
But it also simplifies the correct firewalling against break-in attempts.

That's a great suggestion. As long as the router traffic is not routed through this VPN connection.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10223
Joined: Mon Jun 08, 2015 12:09 pm

Re: Feature Request: URL as an option for radius IP

Mon Aug 08, 2016 9:53 pm

Of course. The VPN is used only for management and things like RADIUS. Keep it all in a local subnet e.g. under 10.x.x.x.
The actual user and internet traffic is routed directly.
 
kimdobranski
newbie
Topic Author
Posts: 43
Joined: Mon Aug 03, 2015 9:39 pm

Re: Feature Request: URL as an option for radius IP

Mon Aug 08, 2016 11:42 pm

Of course. The VPN is used only for management and things like RADIUS. Keep it all in a local subnet e.g. under 10.x.x.x.
The actual user and internet traffic is routed directly.
Awesome! I have a Windows 2008 R2 Server that hosts my radius server. Will the build in windows VPN server work? Or do you recommend another that is free? I always seem to have issues with the windows VPN server connecting.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10223
Joined: Mon Jun 08, 2015 12:09 pm

Re: Feature Request: URL as an option for radius IP

Tue Aug 09, 2016 10:21 am

Put a MikroTik router on the network that includes the WIndows server and you can do all the VPN stuff
on the router. Just assign the Windows server an extra address in the VPN on a second LAN card or a VLAN.
(you can even do it on the normal LAN)

Who is online

Users browsing this forum: Bing [Bot], dazzaling69, erlinden, grayfoxbsd, Question, tarfox and 134 guests