Actions
Bug #13140
closed
MM
Cisco-AVPair - anchor entries incomplete / GUI and command line show different results
Bug #13140:
Cisco-AVPair - anchor entries incomplete / GUI and command line show different results
Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
OpenVPN
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
Affected Architecture:
Description
pfSense+ version 22.01 on Netgate 7100 1u
I have run into an issue where users connecting to OpenVPN using a RADIUS backend for authentication/authorization are not having the correct rules installed in pf when the RADIUS server responds using Cisco-AVPair(s).
As an example, I have the following Cisco-AVPair response configured in Freeradius
Cisco-AVPair += "ip:inacl#1=permit udp host {clientip} host 10.100.0.1 eq 53"
Cisco-AVPair += "ip:inacl#2=permit ip host {clientip} host 10.100.0.1"
Cisco-AVPair += "ip:inacl#5=permit tcp host {clientip} host 10.120.0.1 eq 22"
Cisco-AVPair += "ip:inacl#230=permit ip host {clientip} host 10.121.0.0 0.0.0.255"
Cisco-AVPair += "ip:inacl#100=permit ip host {clientip} host 10.122.0.0 0.0.0.255"
Cisco-AVPair += "ip:inacl#1000=permit ip host {clientip} host 10.123.0.0 0.0.0.255"
Cisco-AVPair += "route=10.0.0.0 255.0.0.0",
Cisco-AVPair += "route=172.16.0.0 255.240.0.0",
Cisco-AVPair += "route=192.168.0.0 255.255.0.0"
NOTE: The above is dynamically generated based on LDAP group membership.
When the user (user100) connects to OpenVPN, I see the following:
- Status -> OpenVPN -> Click the i for user100
All the above rules are listed correctly - [22.01-RELEASE][root@host] more /tmp/ovps_ovpns1_user100_1194.rules
All the above rules are listed correctly - [22.01-RELEASE][root@host] pfSsh.php plyaback pfanchordrill
Only some of the rules from above are listed - [22.01-RELEASE][root@host]/tmp: pfctl -a openvpn/ovpns1_user100_1194 -s rules
The output is the same as the pfSsh.php plyaback pfanchordrill for the specific user
This could possibly be related to:
https://redmine.pfsense.org/issues/12982
Actions