bvm-radius: add new roaming2.ja.net IPs

This commit is contained in:
Luke Granger-Brown 2022-01-07 11:49:24 +00:00
parent 5001971b87
commit 9e79ad0cfa
3 changed files with 27 additions and 1 deletions

View file

@ -39,9 +39,12 @@ in {
# roaming1.ja.net
iptables -A nixos-fw -p udp --dport 1812 --src 194.83.56.233 -j nixos-fw-accept
ip6tables -A nixos-fw -p udp --dport 1812 --src 2001:630:1:12a::233 -j nixos-fw-accept
# roaming2.ja.net
# roaming2.ja.net (old)
iptables -A nixos-fw -p udp --dport 1812 --src 194.83.56.249 -j nixos-fw-accept
ip6tables -A nixos-fw -p udp --dport 1812 --src 2001:630:1:129::249 -j nixos-fw-accept
# roaming2.ja.net (new)
iptables -A nixos-fw -p udp --dport 1812 --src 193.63.195.50 -j nixos-fw-accept
ip6tables -A nixos-fw -p udp --dport 1812 --src 2001:630:1:133::50 -j nixos-fw-accept
# Allow inbound RADIUS from authenticators.
ip6tables -A nixos-fw -p udp --dport 1812 --src 2a09:a443::/64 -j nixos-fw-accept

View file

@ -27,6 +27,18 @@ client eduroam_flr_server_2_v6 {
secret = {{JANET_ROAMING1_SECRET}}
nastype = 'eduroam_flr'
}
client eduroam_flr_server_3_v4 {
# roaming2.ja.net
ipaddr = 193.63.195.50
secret = {{JANET_ROAMING2_SECRET}}
nastype = 'eduroam_flr'
}
client eduroam_flr_server_2_v6 {
# roaming2.ja.net
ipv6addr = 2001:630:1:133::50
secret = {{JANET_ROAMING2_SECRET}}
nastype = 'eduroam_flr'
}
client wireless_access_points_mgmt {
ipaddr = 92.118.30.0/24

View file

@ -18,11 +18,22 @@ home_server eduroam_flr_server_2 {
check_timeout = 5
require_message_authenticator = yes
}
home_server eduroam_flr_server_3 {
# roaming2.ja.net
ipv6addr = 2001:630:1:133::50
secret = {{JANET_ROAMING2_SECRET}}
status_check = status-server
response_window = 5
check_interval = 10
check_timeout = 5
require_message_authenticator = yes
}
home_server_pool eduroam_flr_pool {
type = keyed-balance
home_server = eduroam_flr_server_1
home_server = eduroam_flr_server_2
home_server = eduroam_flr_server_3
}
realm eduroam_flr {
auth_pool = eduroam_flr_pool