Setup of Synology RADIUS server for EAP Authentication
This is the eighth and final of a series that documents the Tier 3 / Co-Managed IT work we did to setup a wireless test bed for a Linux based scientific device. The testing environment included two different wireless network hardware types (Ubiquiti and Cisco). There was also a Synology device used for various purposes including hosting the Ubiquiti controller inside a Kubernetes container, providing certificate services, providing LDAP authentication, and providing RADIUS authentication. Each article has detailed a separate piece of the project. This article shows the setup of Synology RADIUS server for EAP authentication via EAP-PEAP, EAP-TLS, and EAP-TTLS.
Setup Synology Radius for EAP-PEAP
Login to Synology IP via SSH
Use admin login credentials
Go to the Radius certificate directory cd /var/packages/RadiusServer/target/etc/raddb/certs/
Radius must be configured on our certificates: sudo vi ../mods-enabled/eap
2 thoughts on “Setup of Synology RADIUS server for EAP Authentication”
KatBl
Thank you for your step by step tutorial. It’s very helpful.
1. Is the simplified GUI of Synology Radius insufficient to properly set up EAP?
2. Which certificate(s) need to be installed in the Synology Radius Server?
3. Which certificate(s) need to be installed in the UniFi Network Controller?
4. And which certificate(s) need to be installed in the end user/supplicant?
1. Is the simplified GUI of Synology Radius insufficient to properly set up EAP?
This is a basic setup, if you need more security then you need to import certificates from your AD Certificate Service or Certificate provider.
2. Which certificate(s) need to be installed in the Synology Radius Server?
See above
3. Which certificate(s) need to be installed in the UniFi Network Controller?
None, unless you want the web portal to be more secure then you would need to add a certificate from a Certificate provider
4. And which certificate(s) need to be installed in the end user/supplicant?
It depends on the method for connection, but generally the server certificate is added to a wireless profile.
And God will generously provide all you need. Then you will always have everything you need and plenty left over to share with others. As the Scriptures say,
“They share freely and give generously to the poor. Their good deeds will be remembered forever.”
For God is the one who provides seed for the farmer and then bread to eat. In the same way, he will provide and increase your resources and then produce a great harvest of generosity in you. - 2 Corinthians 9:8-10
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
Thank you for your step by step tutorial. It’s very helpful.
1. Is the simplified GUI of Synology Radius insufficient to properly set up EAP?
2. Which certificate(s) need to be installed in the Synology Radius Server?
3. Which certificate(s) need to be installed in the UniFi Network Controller?
4. And which certificate(s) need to be installed in the end user/supplicant?
Thank you again!
1. Is the simplified GUI of Synology Radius insufficient to properly set up EAP?
This is a basic setup, if you need more security then you need to import certificates from your AD Certificate Service or Certificate provider.
2. Which certificate(s) need to be installed in the Synology Radius Server?
See above
3. Which certificate(s) need to be installed in the UniFi Network Controller?
None, unless you want the web portal to be more secure then you would need to add a certificate from a Certificate provider
4. And which certificate(s) need to be installed in the end user/supplicant?
It depends on the method for connection, but generally the server certificate is added to a wireless profile.