authorize with other variable

Florian Traxler (mieX GmbH) traxler at miex.co
Mon Nov 20 11:04:39 UTC 2023


Hello!

I would like to authenticate with Agent Remote ID instead of using MAC as the user name.
Can this be solved with "Based on PIN Code" when creating a new user in FreeRadius.
In which file can the variable be adjusted to check the agent remote ID instead of the user name and send access-accept.

(0) Received Access-Request Id 42 from xxx.xxx.xxx.xxx:57848 to xxx.xxx.xxx.xxx:1812 length 202
(0)   NAS-Port-Type = Ethernet
(0)   NAS-Port = 2207262241
(0)   Calling-Station-Id = "cisco-8c94.8s77.dd97-Et0.34"
(0)   Called-Station-Id = "dhcp1"
(0)   User-Name = "8C:94:1F:34:EE:89"
(0)   User-Password = ""
(0)   Agent-Remote-Id = 0x393734302d31323434313932357c31344d7c35303530343938347c7c
(0)   Agent-Circuit-Id = 0x4c493732383730322d5045494c5354454930312065746820312f312f31372f31313a3334
(0)   NAS-Identifier = "xxx"
(0)   NAS-IP-Address = xxx.xxx.xxx.xxx
(0) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(0)   authorize {


Thank you for your help


More information about the Freeradius-Users mailing list