Set up Free Radius on PfSense with two factor authentication for OpenVPN

Поділитися
Вставка
  • Опубліковано 30 лип 2024
  • In this video I'll go through how to setup FreeRadius on pfsense for the purposes of using two factor authentication on OpenVPN . Two factor authentication strengthens the security of your VPN connection because a successful connection requires, an SSL certificate, user name, pin code and one time password (Via Google Authenticator in this video)
    If you haven't already setup OpenVPN on your PfSense box, please take a look at my previous video here:
    • PfSense OpenVPN Config...
    In this video I go through the steps of:
    Installing FreeRadius 3
    Setting up the initial Free Radius parameters
    Creating a couple of test users
    Testing these users authenticate OK
    Setting up the two factor authentication in Free Radius
    Installing Google Authenticator on an Android phone
    Going through establishing a connection for the first time.
    AFFILIATE LINK DISCLOSURE
    Some of the links below are Amazon affiliate links. If you click on a link and make a purchase, I may receive a commission. Using this link won't cost you any more and any money earned helps to support this channel.
    Items used in this video:
    Samsung Galaxy S5 phone
    amzn.to/2UUHQpJNew
    MHL cable
    amzn.to/3io6nLK
    Used in conjunction with the above phone (Which I already owned) to output HDMI to record Google Authenticator setup as the security on the phone stops this being recorded via a screen recorder.
    HDMI to USB capture Card
    amzn.to/3imO3CR
    Used to record from an HDMI source, in this case via the MHL cable plugged into the Galaxy S5 phone
    Screen and HDMI capture was done using OBS Studio:
    obsproject.com/
    Intro and Outro video was filmed using a OnePlus 5 phone with software from Iriun to capture video into OBS Studio
    amzn.to/3zlrpBC
    iriun.com/
    Sound was recorded using a Boya BY-M1 lapel microphone with Audacity
    amzn.to/3Bs637F
    www.audacityteam.org/
    For lighting I used 3 x 70 LED photography lights:
    amzn.to/3rmhGbC
    Video production was done using Cyberlink Power Director 19 Ultimate
    amzn.to/3kxw4w1
    Hardware used for PfSense
    amzn.to/36SjxeF
  • Наука та технологія

КОМЕНТАРІ • 30

  • @dusanvuckovic9888
    @dusanvuckovic9888 2 роки тому +4

    Man you should continue doing this . Its been a while since I watched a tutorial and it worked first time out. Really! . Excellent .

  • @ethangender
    @ethangender 7 місяців тому

    after days and days searching i found you by accident! your explanation its very concrete with no circles and detailed! congratulations!

  • @djotade
    @djotade 4 місяці тому

    Excellent setup guide working first time. Thank you very much for sharing.

  • @heiaheiaheiahei
    @heiaheiaheiahei Рік тому

    easy to follow and setup , thanks.

  • @yogeshmishra5219
    @yogeshmishra5219 2 роки тому

    You gave the perfect explanation !!

  • @TradersTradingEdge
    @TradersTradingEdge 2 роки тому

    Excellent, thanks and continue your great explanation videos!

  • @TheIceturk
    @TheIceturk 2 роки тому +2

    hi,
    ldap + Free Radius on PfSense with two factor authentication for OpenVPN
    my question is ldap + PfSense with two factor authentication support and method help pls

  • @homeassistantiptv8068
    @homeassistantiptv8068 3 роки тому +4

    Excellent steps and perfect speed, thank you

  • @compthing5656
    @compthing5656 4 місяці тому

    better than any other out there. Really!

  • @slackmoon
    @slackmoon Місяць тому

    Awesome. Thanks a lot! It works well done

  • @nicolaszabala4303
    @nicolaszabala4303 Рік тому

    Thank you very much!

  • @TheCpufixer
    @TheCpufixer 23 дні тому

    Can the Microsoft Authenticator be used instead of Google? Will this work if my users don't want to use an authenticator App? What about the encryption provided by the user certificate? Does that go away since new users are being created without certs?

  • @BrianThomas
    @BrianThomas 2 роки тому

    Is there a way to configure MFA on the web configuration (GUI) to limit admin access?

  • @gigilari2376
    @gigilari2376 5 місяців тому

    good morning, Can you implement access via complex password and otp instead of pin+opt? the second solution seems unsafe to me.

  • @woolloomoolooable
    @woolloomoolooable 8 місяців тому

    Thank you!

  • @paulk9532
    @paulk9532 2 роки тому +2

    "a successful connection requires, an SSL certificate, user name, pin code and one time password"
    But at 6:50 you disabled the TLS certificate requirement, allowing users to connect without a unique cert, so isn't this just username, pin, and otp code?

  • @greatsystem1820
    @greatsystem1820 2 роки тому

    Hi, It's not working for me I have configured the same steps but it is giving me error of TLS handshake failed, could you please help me out to fix this. I need to configure OpenVPN with SAML authentication for my office.

  • @emre-durgut
    @emre-durgut 2 роки тому

    How we can disable PIN and login only by using username and Google Authenticator rolling code?

  • @andersnilsson601
    @andersnilsson601 11 місяців тому

    Anyone that knows how to keep the VPN connection up for longer than an hour or so? It seems to timeout if not used... I have tried to Custom option "reneg-sec 43200;" in the VPN server section

  • @charlykjoseph
    @charlykjoseph Рік тому

    Great Video

  • @escuderon
    @escuderon 2 роки тому +1

    Hey There, any way to do this same thing but using an Active Directory backend for users instead of freeraduis local DB?

    • @paulk9532
      @paulk9532 2 роки тому

      FreeRadius supports both LDAP or AD via LDAP if you set some extra options. But the OTP support in FreeRadius is internal can't be tied to another auth provider.

  • @bsem68
    @bsem68 Рік тому

    Works great, but is there a way for users to generate their own OTP code?

  • @akramazad5137
    @akramazad5137 3 роки тому +1

    You completely escaped the OpenVPN, I followed your tutorial step by step but doesn’t work it was great if you did it step-by-step

    • @RobertSloan
      @RobertSloan  3 роки тому +1

      Could you tell me at what point you had the issue. I mentioned in my intro that if you hadn't already setup OpenVPN to refer to my previous video on how to set this up.

  • @HafizWien
    @HafizWien 3 роки тому

    Same here doesn’t work the OpenVPN steps escaped