Jump to content

RADIUS Server Certificate Issue

Ok so I recently set up a RADIUS server on my pfSense router based on the FreeRADIUS 3 package and it worked fine until I created a new radius server certificate and deleted the old default one. Now, all my Unix based clients prompted me to check the new cert when I tried to connect but all of my Windows clients simply said "Unable to connect to network" after authentication. I wonder if I have to delete the old certificate but I didn't need to download the certificate at the very start. Help? Anyone?

Link to comment
Share on other sites

Link to post
Share on other sites

Are all your devices on the same network? and do all of them point back to the PfSense router?

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Yes. My network is set up such that the Wireless AP is connected to a switch which is then connected to the pfSense router. All clients mentioned are connected to the Wireless AP. No VLANs are set up. I believe this is a certificate issue.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, TheRealOranges said:

Yes. My network is set up such that the Wireless AP is connected to a switch which is then connected to the pfSense router. All clients mentioned are connected to the Wireless AP. No VLANs are set up. I believe this is a certificate issue.

Can you ping the router and the radius server from your client PCs?

 

Also, please quote so I I know you've replied. 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Abdul201588 said:

Can you ping the router and the radius server from your client PCs?

 

Also, please quote so I I know you've replied. 

Sorry, ok I am using the pfSense router as my RADIUS server and yes i can ping my router. Just to clarify, the Unix based clients can connect.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, TheRealOranges said:

Sorry, ok I am using the pfSense router as my RADIUS server and yes i can ping my router. Just to clarify, the Unix based clients can connect.

So you're having issues with your Windows based clients? Are you entering the correct password and username for the radius server?

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, Abdul201588 said:

So you're having issues with your Windows based clients? Are you entering the correct password and username for the radius server?

Yes I believe so

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, GrayFox1991 said:

Is the root CA of the new cert on your clients?

No I changed the CA

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, TheRealOranges said:

No I changed the CA

So isn't the issue that the Clients don't trust the new cert as they do not recognise the CA.
What happens when you install the CA's cert under the "Trusted Root Certification Authorities"?

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, GrayFox1991 said:

Is the root CA of the new cert on your clients?

i added this to my windows PC and it still refused to connect

Link to comment
Share on other sites

Link to post
Share on other sites

Do you get any log entries from the Windows PC or RADIUS server when you initiate a connection?

Link to comment
Share on other sites

Link to post
Share on other sites

The radius server doesn't show a failed authentication nor a successful one

15 minutes ago, GrayFox1991 said:

Do you get any log entries from the Windows PC or RADIUS server when you initiate a connection?

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×