feat(radius): enable dynamic client support via SQL nas table

- Activated `dynamic_clients` module to allow loading RADIUS clients dynamically from the database
- Configured SQL query to fetch client secret, shortname, and type based on Packet-Src-IP-Address
- Integrated `dynamic_clients` into the `authorize` section for real-time NAS resolution
- Eliminated need to restart FreeRADIUS when adding new NAS entries
This commit is contained in:
2025-07-01 12:13:43 +02:00
parent aad17e7b3f
commit a08dcf6983
6 changed files with 49 additions and 3 deletions
+41
View File
@@ -0,0 +1,41 @@
# -*- text -*-
#
# $Id: cc2bd5fd22aa473b98af5dde3fac7a66e39a9e9d $
# This module loads RADIUS clients as needed, rather than when the server
# starts.
#
# There are no configuration entries for this module. Instead, it
# relies on the "client" configuration. You must:
#
# 1) link raddb/sites-enabled/dynamic_clients to
# raddb/sites-available/dynamic_clients
#
# 2) Define a client network/mask (see top of the above file)
#
# 3) uncomment the "directory" entry in that client definition
#
# 4) list "dynamic_clients" in the "authorize" section of the
# "dynamic_clients' virtual server. The default example already
# does this.
#
# 5) put files into the above directory, one per IP.
# e.g. file "192.0.2.1" should contain a normal client definition
# for a client with IP address 192.0.2.1.
#
# For more documentation, see the file:
#
# raddb/sites-available/dynamic-clients
#
dynamic_clients {
sql = "SELECT secret, shortname, type FROM nas WHERE nasname = '%{Packet-Src-IP-Address}'"
key = "%{Packet-Src-IP-Address}"
client {
ipaddr = "%{Packet-Src-IP-Address}"
secret = "%{reply:secret}"
shortname = "%{reply:shortname}"
nastype = "%{reply:type}"
}
}
+1
View File
@@ -282,6 +282,7 @@ listen {
# Make *sure* that 'preprocess' comes before any realm if you
# need to setup hints for the remote radius server
authorize {
dynamic_clients
#
# Take a User-Name, and perform some checks on it, for spaces and other
# invalid characters. If the User-Name appears invalid, reject the