Page 1 of 1

RADIUS with MSCHAPv2 or Limit AD users by group?

Posted: Tue Nov 11, 2014 6:25 am
by BitingChaos
We have an AD server and RADIUS server.

When SoftEther uses the AD server directly, I do not see any way to limit or restrict which users can connect via VPN. For example, I would like to limit it so that only users of a "VPN Users" group can connect.

I tried setting SoftEther to use our RADIUS server. It is Linux-based, and its configuration allows it to query AD/LDAP looking for a "VPN Users" group before allowing a connection. I figured this would be a decent work-around for the above issue.
It seems SoftEther uses PAP to connect to RADIUS, not MSCHAPv2. It seems that using PAP fills the logs with *plain text* passwords.

How do we limit AD users by specific group?
How can I make it not use PAP with RADIUS?

Re: RADIUS with MSCHAPv2 or Limit AD users by group?

Posted: Tue Nov 18, 2014 9:26 am
by thisjun
BitingChaos wrote:
> How do we limit AD users by specific group?
There is no such function.

> How can I make it not use PAP with RADIUS?
CHAP is for only PPP protocol.

Re: RADIUS with MSCHAPv2 or Limit AD users by group?

Posted: Sat Nov 21, 2015 2:40 pm
by PaulC
Hi,

This is an old post, but I have a bit of a solution if you're interested.

Re: RADIUS with MSCHAPv2 or Limit AD users by group?

Posted: Fri Aug 09, 2019 12:18 pm
by Antiokh
This is a very old post, but I'm interested