net/freeradius: Fallback VLAN interferes with other authentication methods
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 92/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Domain
- authentication
Research direction
Open net/freeradius/src/opnsense/service/templates/OPNsense/Freeradius/users and inspect the generated fallback rule alongside the related issues. Verify the behavior with fallback VLAN enabled for unknown and known MAC authentication, EAP-TLS, and captive portal authentication; done means MAC authentication still gets the intended VLAN while the other methods complete normally.
Written by the indexing model from the issue text.
Description
Important notices
- I have read the contributing guide lines at https://github.com/opnsense/plugins/blob/master/CONTRIBUTING.md
- I have searched the existing issues, open and closed, and I'm convinced that mine is new.
- The title contains the plugin to which this issue belongs
Related to #2722 and #5051. The underlying issue remains present in the current FreeRADIUS plugin.
Describe the bug
Enabling Fallback VLAN generates:
DEFAULT Auth-Type := Accept
This rule is unconditional and can intercept authentication methods other than MAC authentication. In my case, EAP-TLS was accepted after the ClientHello with the fallback VLAN instead of completing the TLS handshake.
To Reproduce
- Configure FreeRADIUS for EAP-TLS and MAC authentication.
- Enable Fallback VLAN.
- Attempt EAP-TLS authentication.
- The fallback rule can return Access-Accept before EAP-TLS completes.
Expected behavior
Fallback VLAN should apply only to MAC authentication and should not affect other authentication methods.
Restricting the rule to the RADIUS service type used for MAC authentication resolves the issue.
The rule is generated by:
net/freeradius/src/opnsense/service/templates/OPNsense/Freeradius/users
The following one-line change resolves the issue:
-DEFAULT Auth-Type := Accept
+DEFAULT Service-Type == Call-Check, Auth-Type := Accept
Service-Type = Call-Check is the RADIUS semantic used for MAC address checking.
Tested successfully with Fallback VLAN enabled:
- Unknown MAC authentication → fallback VLAN
- Known MAC authentication → configured VLAN
- EAP-TLS → authenticates normally
- Captive portal authentication → authenticates normally
Screenshots
N/A
Relevant log files
Packet capture confirmed EAP-TLS was prematurely intercepted and accepted by the fallback rule preventing EAP-TLS normal exchange. With the proposed change, the complete EAP-TLS exchange occurs normally.
Additional context
RFC 5080 recommends Service-Type = Call-Check for MAC address checking:
https://www.rfc-editor.org/rfc/rfc5080.html
Related: #2722, #5051
Environment
OPNsense 26.7.4_1 (amd64)
os-freeradius 1.10.2
- Dominant language
- PHP
- Stars
- 1.2k
- Forks
- 874
- Avg merge
- 2d 8h
- Merged PRs (30d)
- 15
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from opnsense/plugins
-
incomplete
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
opnsense/plugins#5763 · 1 comment ·
Maintainers usually reply within 1 day
-
security/tor: Advanced mode / help toggles are brokenPossibly taken @txr13 claimed this 15 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
os-opnproxy 1.0.5_5Openincomplete
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
opnsense/plugins#5710 · 1 comment ·
Maintainers usually reply within 1 day
-
net/vnstat: use OPNsense interface names in dashboard widgetPossibly taken @joeroback claimed this 79 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
All issues in opnsense/plugins
Similar issues
-
Talk Review
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
socallinuxexpo/scale-drupal#351 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
code4romania/cpc#47 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
mautic/api-library#351 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
nunomaduro/collision#371 ·
-
Lead create/update: a product row without a "product_id" key passes LeadForm validation and fails in the database (500)Possibly taken @Arslan-TR claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
krayin/laravel-crm#2681 ·
Maintainers usually reply within 2 days