FreeRADIUS MPSK On Raspberry Pi

Поделиться
HTML-код
  • Опубликовано: 3 апр 2023
  • Setting up MPSK on an Aruba AP to authenticate with FreeRADIUS running on a Raspberry Pi.
    MPSK lets you use a single SSID Wi-Fi network with a client pre-shared key, but with the ability to assign variables like VLAN and passphrase per user.
  • НаукаНаука

Комментарии • 23

  • @johnkristiansen3390
    @johnkristiansen3390 День назад +1

    This video solved my problem configure a Aruba 305 AP, I used a lot of time today until I watched the video, many thanks 🙂.

  • @oxxysaurus
    @oxxysaurus Год назад +1

    Thanks for the effort mate, really good videos.

  • @nh--66
    @nh--66 Год назад +2

    Very informative sir 🙌🙌🙌🙌🙌🙌

  • @kokikocky4319
    @kokikocky4319 Год назад +1

    Great video ...

  • @mihumono
    @mihumono Год назад

    I did spin up freeradius in lxc container and openwrt vm with usb wifi card an it works great so far.

  • @auzzierocks
    @auzzierocks Год назад

    Yeah, my unifi gear does radius assigned vlan, it's a neat system

  • @alexscarbro796
    @alexscarbro796 Год назад +3

    Another fantastic video. Perhaps worth emphasising how useful this would be for pushing untrusted IoT devices in to their own VLAN without requiring the clients to be Radius capable.

    • @davidsomething4867
      @davidsomething4867 Год назад

      Yep I like the idea of only having one SSID. In process of moving over about 30 devices to the new SSID, some painful as need to reset them then of course if you are using a per device PSK you can't jus select the WiFi network on your mobile or device your running the setup app on.

  • @davidsomething4867
    @davidsomething4867 Год назад

    Finally got a few FreeRadius servers set up on Docker, it was bit of a mission as I'm jus getting into docker but it works and I've secured it 🙂, just need to now move the IoT devices over 😞 as some will require setting to default I should imagine and that includes the WiFi smart plugs which are configured in Home Assistant too.

  • @paulmacgiollacaoine8619
    @paulmacgiollacaoine8619 Год назад +1

    On what device had you the wireshark and where was it placed on the network to see packets to/ from Radius server? Thanks for the video

  • @sergeyvas123
    @sergeyvas123 Год назад +2

    How many RPIs do you have? 😮

  • @_Jonny_
    @_Jonny_ Год назад +2

    Is it possible to do the assignment based on the psk alone or do you need to specify the clients MAC?
    Idea being, you can just type different passwords on one device and join different VLANs as needed.

    • @excession1293
      @excession1293 Год назад

      Wanted to ask this exact question as well. On Ruckus it’s referred to as DPSK and is essentially dropping a client on a particular VLAN depending on what PsK they use, without having to pre register each MAC address.

    • @davidsomething4867
      @davidsomething4867 Год назад

      @@excession1293 That would be handy option especially when you use a iOS device which seems to force Private Addresses (mac address randomization) by default.

  • @yiyanzhang2695
    @yiyanzhang2695 4 месяца назад

    Does freeradius support IPSK (Cisco Identity PSK) ?

  • @FredrikRambris
    @FredrikRambris Год назад +1

    A bit tedious to add each device that isn't default. Is there a more convenient way of managing users in freeradius? Like flatfiles or databases with a webui or something to that nature?

  • @stevekemble8911
    @stevekemble8911 Год назад +1

    This is new to me. I had not seen FreeRADIUS before. I get the idea it could be used both for wired and wireless networks (.1x and .11i)?

    • @TallPaulTech
      @TallPaulTech  Год назад +1

      Of course. That X in 802.1X is a capital by the way ;)
      Here you go ruclips.net/video/ZPKKI0t5uH8/видео.html

    • @stevekemble8911
      @stevekemble8911 Год назад

      @@TallPaulTech That is a great video. I have been out of IT for a while now, but I have equipment at home I like to "Play" with. I think with a Pi I should be able to get it to work with my lab: Ubiquiti EdgeRouter 4 > NETGEAR Smart Switch (GS716Tv3) > Ubiquiti UAP-AC-LITE. The only question is about FreeRADIUS as I didn't see a dictionary for Ubiquiti - I will cross that bridge when I get there. (I had seen 802.1X with both upper and lower case. I should have checked official sites about it first).

    • @TallPaulTech
      @TallPaulTech  Год назад +1

      You might only need the generic RADIUS responses instead of anything special.

  • @lucianbuzatu4602
    @lucianbuzatu4602 Год назад

    Hello,
    great project, thanks.
    How can I get the dictionary for TP-link Omada controller?

  • @mindshelfpro
    @mindshelfpro Год назад

    Really interesting. I have 10 wifi networks for 10 vlans... terrible. Pfsense is the router/firewall and 4 OpenWRT APs to configure Wifi + VLANs individually (yikes). The only good thing is the OpenWRT APs are same model Netgear router so I can copy configuration and just change IPs for the APs.. but still terrible. I never setup FreeRadius before...but I see there is a pfsense FreeRadius package, but I don't see an OpenWRT dictionary for FreeRadius so lots of research ahead of me