Score:0

pfSense RADIUS challenge

gp flag

I'm trying to configure my pfSense box (running 2.5.2-RELEASE) to use my RADIUS server for admin login authentication.

My RADIUS server challenges for a TOTP code after getting the correct password, and this is working correctly (I have a number of other systems here using it for login).

I've configured my pfSense box with a RADIUS server (User Manager->Authentication Server) and I've set pfSense to try to authenticate via the RADIUS server (User Manager->Settings, select the RADIUS server).

If I watch the activity on the RADIUS server, I can see pfSense asking for authentication, and then the RADIUS server replying with a challenge for the TOTP code. pfSense doesn't appear to be able to deal with the challenge.

Is there anyway to get pfSense to do the right thing here? Or do I have to add support for entering the TOTP code with the password to my RADIUS server?

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.