Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

net/freeradius: Fallback VLAN interferes with other authentication methods

Open Beginner friendly
#5,734 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

@claudioguareschi is already working on this.

Since Oct 2, 2026.

  • #5759 by @claudioguareschi — open

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
92/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active

Research direction

Open net/freeradius/src/opnsense/service/templates/OPNsense/Freeradius/users and inspect the generated fallback rule alongside the related issues. Verify the behavior with fallback VLAN enabled for unknown and known MAC authentication, EAP-TLS, and captive portal authentication; done means MAC authentication still gets the intended VLAN while the other methods complete normally.

Written by the indexing model from the issue text.

Description

Important notices

Related to #2722 and #5051. The underlying issue remains present in the current FreeRADIUS plugin.

Describe the bug

Enabling Fallback VLAN generates:

DEFAULT Auth-Type := Accept

This rule is unconditional and can intercept authentication methods other than MAC authentication. In my case, EAP-TLS was accepted after the ClientHello with the fallback VLAN instead of completing the TLS handshake.

To Reproduce

  1. Configure FreeRADIUS for EAP-TLS and MAC authentication.
  2. Enable Fallback VLAN.
  3. Attempt EAP-TLS authentication.
  4. The fallback rule can return Access-Accept before EAP-TLS completes.

Expected behavior

Fallback VLAN should apply only to MAC authentication and should not affect other authentication methods.

Restricting the rule to the RADIUS service type used for MAC authentication resolves the issue.

The rule is generated by:

net/freeradius/src/opnsense/service/templates/OPNsense/Freeradius/users

The following one-line change resolves the issue:

-DEFAULT Auth-Type := Accept

+DEFAULT Service-Type == Call-Check, Auth-Type := Accept

Service-Type = Call-Check is the RADIUS semantic used for MAC address checking.

Tested successfully with Fallback VLAN enabled:

  • Unknown MAC authentication → fallback VLAN
  • Known MAC authentication → configured VLAN
  • EAP-TLS → authenticates normally
  • Captive portal authentication → authenticates normally

Screenshots

N/A

Relevant log files

Packet capture confirmed EAP-TLS was prematurely intercepted and accepted by the fallback rule preventing EAP-TLS normal exchange. With the proposed change, the complete EAP-TLS exchange occurs normally.

Additional context

RFC 5080 recommends Service-Type = Call-Check for MAC address checking:
https://www.rfc-editor.org/rfc/rfc5080.html

Related: #2722, #5051

Environment

OPNsense 26.7.4_1 (amd64)
os-freeradius 1.10.2

Dominant language
PHP
Stars
1.2k
Forks
874
Avg merge
2d 8h
Merged PRs (30d)
15

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from opnsense/plugins

All issues in opnsense/plugins

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.