Community discussions

MikroTik App
 
mankomal
Member Candidate
Member Candidate
Topic Author
Posts: 106
Joined: Fri Nov 24, 2006 8:56 am

EAP on virtual AP on two separate RADIUS

Wed Jun 28, 2017 12:39 pm

Hello

Is it possible to create two or more Virtual APs and point each of their respective security profiles(using EAP) to two separate RADIUS??
 
User avatar
pukkita
Trainer
Trainer
Posts: 3051
Joined: Wed Dec 04, 2013 11:09 am
Location: Spain

Re: EAP on virtual AP on two separate RADIUS

Wed Jun 28, 2017 1:20 pm

No. On ROS AFAIK you can define more than one radius, but 2nd, 3d only will get used if previous one doesn't respond.

You can however setup proxying on your radius and "route" from there.
 
mankomal
Member Candidate
Member Candidate
Topic Author
Posts: 106
Joined: Fri Nov 24, 2006 8:56 am

Re: EAP on virtual AP on two separate RADIUS

Wed Jun 28, 2017 2:03 pm

No. On ROS you can define more than one radius, but 2nd, 3d only will get used if previous one doesn't respond.

You can however setup proxying on your radius and "route" from there.
in that case username or realm or something have to be known. right?
So like @abc.com go to one server and @def.com go to other server
 
User avatar
pukkita
Trainer
Trainer
Posts: 3051
Joined: Wed Dec 04, 2013 11:09 am
Location: Spain

Re: EAP on virtual AP on two separate RADIUS

Wed Jun 28, 2017 4:45 pm

That's it, that could be a way.
 
mankomal
Member Candidate
Member Candidate
Topic Author
Posts: 106
Joined: Fri Nov 24, 2006 8:56 am

Re: EAP on virtual AP on two separate RADIUS

Wed Jun 28, 2017 4:48 pm

That's it, that could be a way.
thanks for your help pukkita
But the problem is I dont have a known distinguisher for the users
 
petterg
Member Candidate
Member Candidate
Posts: 230
Joined: Wed Sep 16, 2009 2:55 pm

Re: EAP on virtual AP on two separate RADIUS

Wed Jun 28, 2017 5:37 pm

A customer has a setup where sstp uses two different radius servers depending on the domain-part of the username. I would think that wlan would give similar behavior in respect to domain name.

The only thing I did to make it work was to enter domainname for each radius server. I'll post config here, in case you want to test.
/radius
add address=10.60.255.220 domain=SALES secret=Radiuspass service=ppp
add address=10.61.6.212 domain=ADM secret=Radiuspass service=ppp
the windows full domain names are sales.company.local and adm.company.local. The IP's is the ip of a domain controller in each domain.

Who is online

Users browsing this forum: infabo, neki and 11 guests