FreeRADIUS 3.0.15与NodeJS API集成:动态客户端权限判定技术问询
Great question—dynamic clients are perfect for scenarios where you need on-the-fly client authorization instead of rigid static configs. I’ve helped multiple developers set up this exact integration, so here’s a practical, step-by-step plan tailored to your needs:
1. Enable & Configure the Dynamic Clients Module
First, make sure the dynamic_clients module is active in your FreeRADIUS setup:
- Open your
radiusd.conffile and ensure this line is uncommented:$INCLUDE mods-available/dynamic_clients - Enable the module (Linux systems):
ln -s /etc/raddb/mods-available/dynamic_clients /etc/raddb/mods-enabled/
Next, edit mods-available/dynamic_clients to tie it to your NodeJS API. We’ll use the rest module for HTTP communication:
dynamic_clients { # Tell FreeRADIUS to use the rest module to fetch client data authorize rest # Optional: Cache client data to reduce API calls (adjust timeout as needed) cache_timeout = 3600 # Define mandatory attributes your API must return required_attributes { Client-Secret } }
2. Set Up the REST Module to Communicate with Your NodeJS API
The rest module handles the HTTP handshake between FreeRADIUS and your NodeJS service. Configure it in mods-available/rest:
rest { # Replace with your NodeJS API endpoint uri = "http://your-node-api-host:3000/api/radius/dynamic-client" method = post headers { Content-Type = "application/json" # Add API authentication (e.g., Bearer token) to prevent misuse Authorization = "Bearer your-secure-api-key" } # Map FreeRADIUS request attributes to your API's payload structure request_attributes { Client-IP-Address = "client_ip" } # Map your API's response back to FreeRADIUS attributes response_attributes { "client_secret" = Client-Secret "client_shortname" = Client-Shortname } }
Don’t forget to enable the rest module too:
ln -s /etc/raddb/mods-available/rest /etc/raddb/mods-enabled/
3. Build the NodeJS API Endpoint
Your API needs to receive the client IP from FreeRADIUS, validate if the client should be allowed, and return the required client attributes. Here’s a minimal Express example:
const express = require('express'); const app = express(); app.use(express.json()); // Replace this with your actual business logic (DB lookup, auth checks, etc.) const validateClientAccess = (clientIp) => { // Example: Allow IP 192.168.1.100 with secret "radius-client-123" if (clientIp === "192.168.1.100") { return { client_secret: "radius-client-123", client_shortname: "office-wifi-ap" }; } return null; // Return null to deny the client }; app.post('/api/radius/dynamic-client', (req, res) => { const { client_ip } = req.body; const clientData = validateClientAccess(client_ip); if (clientData) { res.status(200).json(clientData); } else { // Return 404 or empty response to reject the client res.status(404).send(); } }); app.listen(3000, () => { console.log('NodeJS Radius API running on port 3000'); });
4. Test & Debug
- Start FreeRADIUS in debug mode to monitor API calls in real time:
radiusd -X - Use
radtestto simulate a client request from an allowed IP:
Check the debug logs to confirm FreeRADIUS calls your API and processes the response correctly.radtest testuser testpass your-radius-server-ip 0 radius-client-123
Key Considerations
- Security: Always authenticate API requests (like the Bearer token example) to prevent bad actors from feeding fake client data to FreeRADIUS.
- Fallback: If your API goes down, add a fallback in
dynamic_clients(e.g.,authorize files) to use static client configs as a backup. - Caching: Adjust
cache_timeoutbased on how often your client access rules change—shorter timeouts mean more real-time checks but higher API load.
内容的提问来源于stack exchange,提问作者TomSCW

