MikroTik VPN + HotSpot
Adnan RIHAN
axel50397 at gmail.com
Tue Feb 11 00:20:41 UTC 2025
New to Radius in general, I’m currently using it to connect our users on L2TP on MikroTik (RouterOS 7.16.2), with Freeradius (3.0.21) using Samba AD (4.17.12-Debian) as the backend.
It works great, users and computers are members of the AD, so it’s using mschapv2 and ntlm_auth.
Now, I would like to setup a hotspot on mikrotik to authenticate the users to the same Samba AD, the thing is, Mikrotik only supports CHAP and PAP. As far as I understand, Samba AD only supports mschapv2 so it seems I’m stuck with PAP as the common mechanism. Am I right ?
If so, as I’m still using the default site, is there a guide to use ntlm_auth with PAP as a fallback mechanism if mschap and eventually chap (keeping it just in case I can use it for something else later) fail? Or do you guys have a better idea for my needs please?
--
Cordialement, Adnan RIHAN
GPG: D433-5C63 (https://keybase.io/max13/key.asc)
⇒ Si vous n’utilisez pas GPG/PGP mais voulez m’envoyer un e-mail chiffré: https://encrypt.to/0xD4335C63.
More information about the Freeradius-Users
mailing list