- 以yum install方式安裝FreeRadius(有些Linux版本尚未提供FreeRadius 2以上的版本,請下載未編譯之安裝檔進行編譯、安裝),為了以radtest指令進行簡單基本測試,則請一併安裝freeradius2-utils。
- 設定proxy.conf(yum安裝之FreeRadius之預設目錄為『/etc/raddb')。
- 若本機器並非是貴單位進行認證之主機,並且是以FreeRadius服務進行認證動作,則需在proxy.conf設定時將貴單位之realm轉至認證之機器上。
- 設定clients.conf。
- 若有其他連線至本機器的FreeRadius服務,則請在clients.conf加入其他連線資訊。
- 設定防火牆政策,開放FreeRadius預設使用通訊埠UDP 1812、1813、1814通行。
- 進行FreeRadius初始化設定,後續也可以radiusd -X進行FreeRadius偵錯。
- 啟動FreeRadius服務,並以漫遊中心提供之測試帳號、密碼進行radtest簡單測試(radtest指令僅提供認證之測試步驟,需後續再以radclient指令或是以筆電實際測試無線網路漫遊才算是完成測試動作,建議是以筆電進行實際測試)。
- 設定開機自動啟動FreeRadius服務。
- 以筆電實際進行測試,測試後請聯繫漫遊中心以確認Accounting資訊是否成功紀錄。
| [root@SSLVPN openvpn]# yum install freeradius2 freeradius2-utils<--安裝詳細過程省略--> Installed: freeradius2.i386 0:2.1.7-7.el5 Complete! |
| [root@SSLVPN openvpn]# vim /etc/raddb/proxy.conf<--於檔案最後處加入下列內容--> realm NULL { #當遇到帳號並沒有realm時的預設動作為以本機進行認證動作 authhost = LOCAL accthost = LOCAL secret = niucltcc } realm DEFAULT { #當遇到帳號帶有realm時的預設動作為送至漫遊中心進行proxy動作 authhost = 10.1.0.7:1812 accthost = 10.1.0.7:1813 secret = niucltcc nostrip } |
| [root@SSLVPN openvpn]# vim /etc/raddb/proxy.conf<--於檔案最後處加入下列內容--> realm niu.edu.tw { #假設貴單位之realm為niu.edu.tw authhost = 123.123.123.123 #假設貴單位認證主機位址為123.123.123.123 accthost = 123.123.123.123 #假設貴單位認證主機位址為123.123.123.123 secret = niucltcc #假設貴單位於認證主機上clients.conf 之secret為niucltcc nostrip } |
| [root@SSLVPN openvpn]# vim /etc/raddb/clients.conf<--於檔案最後處加入下列內容--> client 10.1.0.7 { secret = niucltcc shortname = niu } |
| [root@SSLVPN openvpn]# vim /etc/raddb/clients.conf<--於檔案最後處加入下列內容--> client 123.123.123.123 { #假設需與貴單位認證主機進行連線位址為123.123.123.123 secret = niucltcc #假設secret設定為niucltcc,需與proxy.conf設定相同 shortname = niu } |
| [root@SSLVPN openvpn]# radiusd -X正在啟動 RADIUS 伺服器: [ 確定 ] <--詳細過程略--> Listening on authentication address * port 1812 Listening on accounting address * port 1813 Listening on command file /var/run/radiusd/radiusd.sock Listening on proxy address * port 1814 Ready to process requests. ←FreeRadius初始化完成,以ctrl+c結束執行 |
| [root@SSLVPN openvpn]# service radiusd start正在啟動 RADIUS 伺服器: [ 確定 ] [root@SSLVPN openvpn]# radtest testuser@niu testpass 10.1.0.7 0 niucltcc <radtest 帳號 密碼 測試伺服器 測試伺服器之通訊埠 Secret> Sending Access-Request of id 234 to 10.1.0.7 port 1812 User-Name = "testuser@niu" User-Password = "testpass" NAS-IP-Address = 127.0.0.1 NAS-Port = 0 rad_recv: Access-Accept packet from host 10.1.0.7 port 1812,, length=20 ↑FreeRadius基本簡單測試成功 |
| [root@SSLVPN openvpn]# chkconfig radiusd on |
0 意見:
張貼留言