# FreeRADIUS INSTALLATION

**URL:** https://community.cambiumnetworks.com/t/freeradius-installation/53857
**Category:** PMP
**Tags:** knowledge-base
**Created:** [November 18, 2017, 3:56pm UTC](https://community.cambiumnetworks.com/t/freeradius-installation/53857 "2017-11-18T15:56:54Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![skumar](https://d10gw3vjmzyp8.cloudfront.net/letter_avatar_proxy/v4/letter/s/e9c0ed/32.png) [@skumar](https://community.cambiumnetworks.com/u/skumar)
#### Post date: [November 18, 2017, 3:56pm UTC](https://community.cambiumnetworks.com/t/freeradius-installation/53857/1 "2017-11-18T15:56:54Z")

</div>

**Systematic procedure for basic FreeRADIUS installation in LINUX:**

&nbsp;

**FreeRADIUS Version: 2.X** &nbsp;

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Install the server through the command “ **_sudo apt-get install freeradius_** ”

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Navigate to the path “ **/etc/freeradius/** ” through the command “ **_cd /etc/freeradius/_**

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To define a client or AP IP, edit **/etc/freeradius/clients.conf** and add its entity as below

Here AP’s IP address is 10.110.65.159 and its shared secret is “SECRET”

![1.png](https://d1okf4ta8xniw3.cloudfront.net/original/2X/4/4a8c397520a18b1d276bd1f36a9767a548197f7e.png "1.png")&nbsp;

&nbsp;

&nbsp;

-&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;For authenticating a SM ,edit " **/etc/freeradius/users"** file and add the username and password as below.

&nbsp;Here “SM\_AUTHENTICATION” is the username and “password” is the shared secret. ![2.jpg](https://d1okf4ta8xniw3.cloudfront.net/original/2X/b/b2a4f9cfd5426f31734dc29570fcf150be7b0e21.jpeg "2.jpg")

&nbsp;

&nbsp;

&nbsp;

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Edit **“/etc/freeradius/users”** file for user authentication through radius as below

Here “USERAUTHENTICATION” is the username and “password” is the shared Secret.

“Cambium-Canopy-UserLevel” and “Cambium-Canopy-Usermode” called Vendor specific attributes (VSA). ![3.png](https://d1okf4ta8xniw3.cloudfront.net/original/2X/6/6da64e42ce3c30099be31ab78d33d212d7d7e306.png "3.png")

&nbsp;

&nbsp;

&nbsp;

&nbsp;

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To add these VSA’s download the Cambium Dictionary files at&nbsp; [https://support.cambiumnetworks.com/files/pmp450/](https://support.cambiumnetworks.com/files/pmp450/)&nbsp;and copy the downloaded files at **/usr/share/freeradius/.**

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Add the name of the copied file(dictionary.canopy) by editing the file **“/usr/share/freeradius/dictionary”**

&nbsp;Here **“dictionary.canopy”** is the dictionary file added. ![4.png](https://d1okf4ta8xniw3.cloudfront.net/original/2X/4/4c251cadca41ed71689293d3be7cda1f34904245.png "4.png")

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Add Cambium certificates by downloading them at&nbsp;[https://support.cambiumnetworks.com/files/pmp450/](https://support.cambiumnetworks.com/files/pmp450/)&nbsp;. Unzip and copy the files at **“/etc/freeradius/certs/".**

The certs folder should contain files same as below

![5.png](https://d1okf4ta8xniw3.cloudfront.net/original/2X/6/635ff899c78bc8e2f4372fcc0a116bd5c5f7e78b.png "5.png")

&nbsp;

&nbsp;

&nbsp;

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Finally editing **“eap.conf”** file as below helps freeradius to look for certificates, dictionary files and other.

 ![6.png](https://d1okf4ta8xniw3.cloudfront.net/original/2X/e/e4847f7c09a3fc61bf4a47f79cbc3acc017b1a42.png "6.png") ![7.jpg](https://d1okf4ta8xniw3.cloudfront.net/original/2X/d/d74de9e4cca069b45dc3092e76a665f03107819a.jpeg "7.jpg") ![8.jpg](https://d1okf4ta8xniw3.cloudfront.net/original/2X/0/03ead0967e65221e30042a5f96c8811b46634a34.jpeg "8.jpg")

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To&nbsp; copy the inner tunnel request to outer tunnel make the changes in **eap.conf** &nbsp;as below:

 ![9.jpg](https://d1okf4ta8xniw3.cloudfront.net/original/2X/6/6732787ca399801a74380e9a25891faf8f57861d.jpeg "9.jpg")

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

&nbsp;

**ADDITONAL LINKS:**

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Guide for getting started&nbsp;&nbsp;[https://wiki.freeradius.org/guide/Getting-Started](https://wiki.freeradius.org/guide/Getting-Started)

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Guide to troubleshoot freeraidus&nbsp;[https://wiki.freeradius.org/guide/Troubleshooting](https://wiki.freeradius.org/guide/Troubleshooting)

**Commands:**

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To run the freeradius in debugging mode:&nbsp; **freeradius –XX**

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To stop the running freeradius: **service freeradius stop**

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To start the freeradius: **service freeradius start**

-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Always restart the freeradius after making any changes.To restart the freeradius: **service freeradius restart**

-&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Freeradius is intelligent enough to automatically determine outer tunnel type and inner tunnel type.

&nbsp;

---

<div class="post-metadata">

### Author: ![NorthCoast](https://d10gw3vjmzyp8.cloudfront.net/letter_avatar_proxy/v4/letter/n/90db22/32.png) [@NorthCoast](https://community.cambiumnetworks.com/u/NorthCoast)
#### Post date: [February 19, 2021, 6:44pm UTC](https://community.cambiumnetworks.com/t/freeradius-installation/53857/2 "2021-02-19T18:44:48Z")

</div>

Any chance an updated version of this howto exists? I’m hoping to use more up-to-date stuff. Like FreeRADIUS Version 3.0.20 on Ubuntu 20.04 or Centos 8.
