Тёмный

Installing and configuring FreeRADIUS for 802.1x, MAC Auth/iPSK- Integrated with Meraki Dashboard 

Meraki Matt
Подписаться 75
Просмотров 624
50% 1

In this video, we will be installing FreeRADIUS on Rocky Linux and have it in operation in approx. 15 minutes. We will integrate into Meraki wireless via dashboard with 802.1x, MAC Auth and MAC auth with iPSK support. We will also test authentication for MAC auth and 802.1x. The FreeRADIUS server will be integrated into an Active Directory Environment with Group membership checking for auth.
GitHub REPO for FreeRADIUS Install:
github.com/fum...
FreeRADIUS Install Document:
Please download if you want to view the embedded objects
docs.google.co...
The Installer will deploy/implement the following:
• Update the system and add REPOS it may need for deployment
• Join the server to the domain
• Synchronize time
• Check that RPC calls are successful to AD
• Validate that it can see the Users
• Validate that it can see Groups
• Use wbinfo to validate that the test user you provided earlier can login
• Modify the ntlm_auth paths and binary as needed
• Change permissions for winbind
• Add ntlm/MSCHAP configuration
• Add the rewrite for MAC Auth
• Add the NAS client entries to allow connectivity
• Create the default certs (you can modify this after install)
• Enable the radiusd service for boot time
• Validate MSCHAP configuration via radtest with the test user provided
• Add MAC Auth examples to the /etc/raddb/users file for Mac Auth and MAC Auth with IPSK
• Will remove all installers files

Опубликовано:

 

15 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 4   
@darligoncalvesborges3992
@darligoncalvesborges3992 9 часов назад
Good morning, I'm getting this error when I try to authenticate users via radius. Ready to process requests Ignoring request for authentication address * port 1812 bound to unknown client default server 10.0.1.49 port 61533 proto udp. Can you help me?
@MerakiMatt
@MerakiMatt 8 часов назад
Good morning, a quick google search shows that maybe your NAS endpoint (AP, WLC, VPN, whatever you are using, is not in the allowed NAS list that you setup when installing FreeRADIUS. You can manually edit this in the clients.conf file of the FR server. This is located in /etc/raddb/clients.conf. If you look towards the bottom of the file, (apronx line 250). You'll see an entry called " #Added by FR-Installer" This is the subnet and password you provided when setting up the server to allow devices to talk to the RADIUS server. I would start there, and validate that the IP address of the device (network device) is in the range of the clients.conf file. If it is not, you can always add another network if you need. Please review line 237 in the file, as that's important. Hope this helps. I should probably add an option in the menu to allow you to edit this file.. I will add this later this week when I get a chance.
@choate85
@choate85 2 месяца назад
If you close the server freeradius management - is there an easy way to reopen it?
@MerakiMatt
@MerakiMatt 2 месяца назад
@@choate85 Hi! If you type server-manager from the cli it will come back up
Далее
ITZY "GOLD" M/V
03:20
Просмотров 4,9 млн
Это было очень близко...
00:10
Просмотров 2,3 млн
Setup FreeRADIUS on Kali Linux for 802.1X Authentication
1:06:34
2 PKI and 802 1X Certificate Based Authentication
8:52
Modernizing Grant Management
39:42
Просмотров 84
Meraki WiFi Network Access   Part 1
14:35
Просмотров 4 тыс.
How to configure and start Non Meraki VPN Video
7:15
FreeRADIUS Server
21:39
Просмотров 17 тыс.
ITZY "GOLD" M/V
03:20
Просмотров 4,9 млн