Add RADIUS node pinning to enforce client connection to assigned OpenVPN node

This commit is contained in:
2026-04-14 16:24:35 +02:00
parent 8c1289f92e
commit fca66dfa52
+13
View File
@@ -418,7 +418,20 @@ authorize {
# #
# See "Authorization Queries" in mods-available/sql # See "Authorization Queries" in mods-available/sql
sql sql
update control {
Tmp-String-0 := "%{sql:SELECT node_ip FROM node_assignments WHERE username='%{User-Name}'}"
}
if (&control:Tmp-String-0 == "") {
reject
}
if (&control:Tmp-String-0 != "%{NAS-IP-Address}") {
update reply {
Reply-Message := "Wrong node"
}
reject
}
# If you are using /etc/smbpasswd, and are also doing mschap authentication, the un-comment this line, and configure the 'smbpasswd' module. # If you are using /etc/smbpasswd, and are also doing mschap authentication, the un-comment this line, and configure the 'smbpasswd' module.
# smbpasswd # smbpasswd