thorization not working if proxying to anoither radius

Peter Hudec peter at home.hudecof.net
Tue Jan 28 11:30:35 UTC 2025


Hello,
I would like to ask  you to help me solve my issue.
Forst, the freeradius is aliite bit older - Alma 9, freeradius-3.0.21-43.el9_5.x86_64

The packages froem the https://networkradius.com/packages/ do not wolr on Alma 9 ;( tehre is SSL ISSUE.

My problemis as follows.

I have users, with realms, there based on the relam I need to send request to another radius for 2FA.

My radius should do the first FA, means the password authorization, the realm radius should do the 2fa In my case Cisco Duo for onretype of realm and some 3rd party radius for another realm.

Based on the documentation, the PAPIf one is found, and no Auth-Type or Proxy-To-Realm attribute is set, the module will set Auth-Type := pap.

So if I run the suffix module, to get the realm and pass the request to another radius, the PAP is omitted.

I gva tried various solution as setting the Proxy-To-Realm after PAP in authorize section
or
set Auth-Type ;= PAP manually

but neither solution is working, the PAP is not working and I have just the 2FA ;(

Anyone got such a solution, wgere the freeradius is doing the fisrt facror and the 3rd party radius second ?

	regards
		Peter






More information about the Freeradius-Users mailing list