Add RADIUS node pinning to enforce client connection to assigned OpenVPN node
This commit is contained in:
@@ -418,7 +418,20 @@ authorize {
|
|||||||
#
|
#
|
||||||
# See "Authorization Queries" in mods-available/sql
|
# See "Authorization Queries" in mods-available/sql
|
||||||
sql
|
sql
|
||||||
|
update control {
|
||||||
|
Tmp-String-0 := "%{sql:SELECT node_ip FROM node_assignments WHERE username='%{User-Name}'}"
|
||||||
|
}
|
||||||
|
|
||||||
|
if (&control:Tmp-String-0 == "") {
|
||||||
|
reject
|
||||||
|
}
|
||||||
|
|
||||||
|
if (&control:Tmp-String-0 != "%{NAS-IP-Address}") {
|
||||||
|
update reply {
|
||||||
|
Reply-Message := "Wrong node"
|
||||||
|
}
|
||||||
|
reject
|
||||||
|
}
|
||||||
# If you are using /etc/smbpasswd, and are also doing mschap authentication, the un-comment this line, and configure the 'smbpasswd' module.
|
# If you are using /etc/smbpasswd, and are also doing mschap authentication, the un-comment this line, and configure the 'smbpasswd' module.
|
||||||
# smbpasswd
|
# smbpasswd
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user