Add RADIUS node pinning to enforce client connection to assigned OpenVPN node
This commit is contained in:
@@ -418,7 +418,20 @@ authorize {
|
||||
#
|
||||
# See "Authorization Queries" in mods-available/sql
|
||||
sql
|
||||
update control {
|
||||
Tmp-String-0 := "%{sql:SELECT node_ip FROM node_assignments WHERE username='%{User-Name}'}"
|
||||
}
|
||||
|
||||
if (&control:Tmp-String-0 == "") {
|
||||
reject
|
||||
}
|
||||
|
||||
if (&control:Tmp-String-0 != "%{NAS-IP-Address}") {
|
||||
update reply {
|
||||
Reply-Message := "Wrong node"
|
||||
}
|
||||
reject
|
||||
}
|
||||
# If you are using /etc/smbpasswd, and are also doing mschap authentication, the un-comment this line, and configure the 'smbpasswd' module.
|
||||
# smbpasswd
|
||||
|
||||
|
||||
Reference in New Issue
Block a user