Files
notes/projects/gg/freeradius/20250725_init.md
Petar Cubela 584265c22c 20250907
2025-09-07 13:07:01 +02:00

1.7 KiB

Now

  • Probably MS Radius Server. -> Network Policy Server on gg-srv-pd-app-01

!Pasted image 20250727185114.png

  • eap type: secured peap (proprietary?)
  • mschapv2 as second next

TODO

  • ruckus network config
  • network config
  • Ruckus filter via username (identity + group). If user already connected with one device do not allow other device. Measure time -> next 8 hours device is connected and can not connect with other device
  • test authentication with user not being in ldap group
  • Restrict user login to only one device at a time
  • Auto logout after 8h

Notes

  • MS AD makes things complicated
  • RADIUS does not get 'good password' from AD which it needs

Questions

  • Which authorization and authentication methods do the iPads use?
  • How should the system behave when the same user connects with different devices?
  • Do we track the used devices?
  • Are rules applied depending on the user or/and on the device?

Resources