5 Commits
Author SHA1 Message Date
gitea_admin a1da7648b1 test Session-Timeout 2026-09-22 12:32:22 +02:00
gitea_admin da15f6ee51 fix(radius): allow OpenVPN TLS re-authentication for existing sessions
- exclude the current Acct-Session-Id from simultaneous-use checks
- prevent TLS renegotiation from being rejected as a second login
- keep Simultaneous-Use limited to fresh concurrent OpenVPN connections
- preserve the existing RADIUS accounting session during TLS re-authentication
2026-09-21 20:04:27 +02:00
gitea_admin b7034c733d feat(freeradius): set client-specific accounting intervals
- Set 60s interim updates for engineers
- Set 300s interim updates for devices
2026-09-16 18:17:55 +02:00
gitea_admin 728b99e138 fix(radius): prevent devices from using sqlippool during accounting 2026-09-16 17:04:06 +02:00
gitea_admin 8434a13338 fix(freeradius): check IP after pool allocation 2026-09-10 13:47:55 +02:00
2 changed files with 40 additions and 15 deletions
+2
View File
@@ -237,6 +237,7 @@ simul_count_query = "\
LEFT OUTER JOIN nasreload n USING (NASIPAddress) \
WHERE UserName='%{SQL-User-Name}' \
AND AcctStopTime IS NULL \
AND AcctSessionId != '%{Acct-Session-Id}' \
AND (a.AcctStartTime > n.ReloadTime OR n.ReloadTime IS NULL)"
simul_verify_query = "\
@@ -246,6 +247,7 @@ simul_verify_query = "\
LEFT OUTER JOIN nasreload n USING (nasipaddress) \
WHERE UserName='%{SQL-User-Name}' \
AND AcctStopTime IS NULL \
AND AcctSessionId != '%{Acct-Session-Id}' \
AND (a.AcctStartTime > n.reloadtime OR n.reloadtime IS NULL)"
#######################################################################
+36 -13
View File
@@ -446,15 +446,6 @@ authorize {
Pool-Name := "engineers-%{sql:SELECT split_part('%{User-Name}', '@', 2)}"
}
}
#
# HARD CHECK: must have IP
#
if (!&reply:Framed-IP-Address) {
update reply {
Reply-Message := "No IP assigned - access denied"
}
reject
}
# If you are using /etc/smbpasswd, and are also doing mschap authentication, the un-comment this line, and configure the 'smbpasswd' module.
# smbpasswd
@@ -657,13 +648,24 @@ accounting {
# Ensure that &control:Pool-Name is set to determine which pool of IPs are used.
# sqlippool
### rebuild Pool-Name
#
# Determine the client type.
# Devices use a fixed IP from radreply.
# Engineers use an IP from sqlippool/radippool.
#
update control {
Tmp-String-1 := "%{sql:SELECT client_type FROM node_assignments WHERE username='%{User-Name}'}"
}
#
# Return the IP to the pool only for engineers.
#
if (&control:Tmp-String-1 == "engineer") {
update control {
Pool-Name := "engineers-%{sql:SELECT split_part('%{User-Name}', '@', 2)}"
}
### apply only for engineers
if (&control:Pool-Name =~ /^engineers-/) {
sqlippool
}
# Log traffic to an SQL database.
@@ -804,12 +806,33 @@ post-auth {
if (&control:Pool-Name =~ /^engineers-/) {
update reply {
Session-Timeout := 3600
Session-Timeout := 1200
Acct-Interim-Interval := 60
}
sqlippool
}
#
# Devices → fixed IP
# authorize --> post-auth: reuse Tmp-String-1
elsif (&control:Tmp-String-1 == "device") {
update reply {
Acct-Interim-Interval := 300
}
}
#
# HARD CHECK: must have IP
#
if (!&reply:Framed-IP-Address) {
update reply {
Reply-Message := "No IP assigned - access denied"
}
reject
}
# Query VLAN ID from your DB
# VLAN assignment is no longer used
#vlan_test