Skip to content

Commit

Permalink
[chores] Added basic inner-tunnel
Browse files Browse the repository at this point in the history
  • Loading branch information
nemesifier authored and atb00ker committed Apr 27, 2021
1 parent 6680a18 commit ef14796
Show file tree
Hide file tree
Showing 2 changed files with 90 additions and 1 deletion.
10 changes: 9 additions & 1 deletion tasks/freeradius.yml
Original file line number Diff line number Diff line change
Expand Up @@ -142,7 +142,6 @@
state: absent
with_items:
- "{{ freeradius_sites_enabled_dir }}/default"
- "{{ freeradius_sites_enabled_dir }}/inner-tunnel"

- name: Site configuration
template:
Expand All @@ -152,3 +151,12 @@
owner: freerad
group: freerad
notify: restart freeradius

- name: Inner tunnel
template:
src: freeradius/openwisp_site.j2
dest: "{{ freeradius_sites_enabled_dir }}/inner-tunnel"
mode: 0640
owner: freerad
group: freerad
notify: restart freeradius
81 changes: 81 additions & 0 deletions templates/freeradius/inner-tunnel.j2
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
server inner-tunnel {
listen {
ipaddr = 127.0.0.1
port = 18120
type = auth
}

authorize {
filter_username
rest

chap
mschap
suffix

update control {
&Proxy-To-Realm := LOCAL
}

eap {
ok = return
}

-ldap

pap

dailycounter
dailybandwidthcounter
noresetcounter
expiration
logintime
}

authenticate {
Auth-Type PAP {
pap
}

Auth-Type CHAP {
chap
}

Auth-Type MS-CHAP {
mschap
}
eap
}

session {}

post-auth {
if (0) {
update reply {
User-Name !* ANY
Message-Authenticator !* ANY
EAP-Message !* ANY
Proxy-State !* ANY
MS-MPPE-Encryption-Types !* ANY
MS-MPPE-Encryption-Policy !* ANY
MS-MPPE-Send-Key !* ANY
MS-MPPE-Recv-Key !* ANY
}
update {
&outer.session-state: += &reply:
}
}

Post-Auth-Type REJECT {
attr_filter.access_reject
update outer.session-state {
&Module-Failure-Message := &request:Module-Failure-Message
}
}
}

pre-proxy {}
post-proxy {
eap
}
}

0 comments on commit ef14796

Please sign in to comment.