{"id":748,"date":"2026-09-16T18:03:40","date_gmt":"2026-09-16T15:03:40","guid":{"rendered":"https:\/\/imaxis.ru\/?p=748"},"modified":"2026-09-16T18:03:40","modified_gmt":"2026-09-16T15:03:40","slug":"dvuhfaktornaya-autentifikatsiya-dlya-vpn-i-wi-fi-cherez-freeradius-otp-totp-hotp","status":"publish","type":"post","link":"https:\/\/imaxis.ru\/?p=748","title":{"rendered":"\u0414\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u0430\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f \u0434\u043b\u044f VPN \u0438 Wi-Fi \u0447\u0435\u0440\u0435\u0437 FreeRADIUS + OTP (TOTP\/HOTP)"},"content":{"rendered":"<h1>\u0414\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u0430\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f \u0434\u043b\u044f VPN \u0438 Wi-Fi \u0447\u0435\u0440\u0435\u0437 FreeRADIUS + OTP (TOTP\/HOTP)<\/h1>\n<p>FreeRADIUS \u2014 \u0441\u0430\u043c\u044b\u0439 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0439 RADIUS-\u0441\u0435\u0440\u0432\u0435\u0440. \u041d\u0430 \u0435\u0433\u043e \u0431\u0430\u0437\u0435 \u043c\u043e\u0436\u043d\u043e \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u0434\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u0443\u044e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e (\u043f\u0430\u0440\u043e\u043b\u044c + OTP) \u0434\u043b\u044f \u043b\u044e\u0431\u043e\u0433\u043e RADIUS-\u043a\u043b\u0438\u0435\u043d\u0442\u0430: Mikrotik VPN (L2TP\/IPsec, PPTP), \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0439 Wi-Fi \/ Hotspot, RD Gateway. \u0412 \u0441\u0442\u0430\u0442\u044c\u0435 \u2014 Ubuntu FreeRADIUS + RADIUS-\u043a\u043b\u0438\u0435\u043d\u0442 \u043d\u0430 Mikrotik \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 OTP \u0447\u0435\u0440\u0435\u0437 \u043c\u043e\u0434\u0443\u043b\u044c <code>rlm_otp<\/code> (\u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 \u0441\u043a\u0440\u0438\u043f\u0442 TOTP).<\/p>\n<hr \/>\n<h2>\u0410\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u0430<\/h2>\n<pre><code>[\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c] --[VPN\/Wi-Fi\/RDG]--&gt; [Mikrotik \/ RD Gateway : \u0440\u0430\u0434\u0438\u0443\u0441-\u043a\u043b\u0438\u0435\u043d\u0442]\n                                         |\n                                        (UDP 1812\/1813)\n                                         v\n                              [FreeRADIUS @ Ubuntu :1812]\n                                         |\n                              [OTP-\u043c\u043e\u0434\u0443\u043b\u044c: TOTP\/HOTP]\n<\/code><\/pre>\n<ul>\n<li><strong>RADIUS-\u043a\u043b\u0438\u0435\u043d\u0442<\/strong> (NAS) \u2014 Mikrotik (L2TP\/IPsec, hotspot), Windows NPS, RD Gateway<\/li>\n<li><strong>RADIUS-\u0441\u0435\u0440\u0432\u0435\u0440<\/strong> \u2014 FreeRADIUS \u043d\u0430 Ubuntu<\/li>\n<li><strong>OTP<\/strong> \u2014 TOTP (Google Authenticator\/FreeOTP) \u0438\u043b\u0438 HOTP<\/li>\n<\/ul>\n<hr \/>\n<h2>\u0428\u0430\u0433 1. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 FreeRADIUS<\/h2>\n<pre><code class=\"language-bash\">sudo apt update &amp;&amp; sudo apt install -y freeradius\n<\/code><\/pre>\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430:<\/p>\n<pre><code class=\"language-bash\">sudo freeradius -X\n<\/code><\/pre>\n<p>\u041e\u0448\u0438\u0431\u043a\u0438 \u043a\u043e\u043d\u0444\u0438\u0433\u0430 \u0432\u0438\u0434\u043d\u044b \u043f\u0440\u044f\u043c\u043e \u0432 \u0432\u044b\u0432\u043e\u0434\u0435.<\/p>\n<hr \/>\n<h2>\u0428\u0430\u0433 2. \u0411\u0430\u0437\u043e\u0432\u044b\u0435 \u043f\u0430\u0440\u043e\u043b\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439<\/h2>\n<p>\u041f\u0435\u0440\u0432\u0438\u0447\u043d\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 (\u043f\u0430\u0440\u043e\u043b\u044c \u0438\u0437 <code>users<\/code>):<\/p>\n<p><code>\/etc\/freeradius\/3.0\/users<\/code>:<\/p>\n<pre><code># \u0444\u043e\u0440\u043c\u0430\u0442:  User-Name  Cleartext-Password := &quot;\u043f\u0430\u0440\u043e\u043b\u044c&quot;\nvpnuser01  Cleartext-Password := &quot;Passw0rd!&quot;\n<\/code><\/pre>\n<p>\u0421\u043f\u0438\u0441\u043e\u043a \u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430:<\/p>\n<pre><code class=\"language-bash\"># \u0438\u0437 Ubuntu\necho &quot;User-Name=vpnuser01, User-Password=Passw0rd!&quot; | radclient localhost auth testing123\n<\/code><\/pre>\n<p>\u041e\u0442\u0432\u0435\u0442 <code>Access-Accept<\/code> \u043e\u0437\u043d\u0430\u0447\u0430\u0435\u0442 \u0443\u0441\u043f\u0435\u0445.<\/p>\n<blockquote>\n<p>\u041f\u0430\u0440\u043e\u043b\u0438 \u043b\u0443\u0447\u0448\u0435 \u0445\u0440\u0430\u043d\u0438\u0442\u044c \u0432 <code>hash<\/code>: <code>vpnuser01  Cleartext-Password := \"...\"<\/code> \u041d\u0415 \u0440\u0430\u0448\u043b\u0438\u0442\u0435 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u0432\u0438\u0434\u0435 \u2014 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 NTHash\/MD5\/SSHA.<\/p>\n<\/blockquote>\n<hr \/>\n<h2>\u0428\u0430\u0433 3. \u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u043c\u043e\u0434\u0443\u043b\u044c rlm_otp (TOTP)<\/h2>\n<p>\u0412 FreeRADIUS \u043d\u0435\u0442 \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u043e\u0433\u043e TOTP, \u043d\u043e \u0435\u0441\u0442\u044c <code>rlm_otp<\/code> (HOTP) \u043b\u0438\u0431\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u043c python\/exec \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0443 \u0434\u043b\u044f TOTP. \u041f\u0440\u043e\u0441\u0442\u043e\u0439 \u0440\u0430\u0431\u043e\u0447\u0438\u0439 \u043f\u0443\u0442\u044c \u2014 \u0447\u0435\u0440\u0435\u0437 <code>exec<\/code> \u0438 \u0441\u043a\u0440\u0438\u043f\u0442 <code>oathtool<\/code>.<\/p>\n<h3>3.1. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 oathtool<\/h3>\n<pre><code class=\"language-bash\">sudo apt install -y oathtool\n<\/code><\/pre>\n<h3>3.2. \u0413\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u044f \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439<\/h3>\n<pre><code class=\"language-bash\"># \u0413\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u044f \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e\u0433\u043e \u0441\u0435\u043a\u0440\u0435\u0442\u0430 (base32 \u0434\u043b\u044f Google Authenticator)\nSECRET=$(head -c 20 \/dev\/urandom | base32 | tr -d '=')\necho &quot;\u0421\u0435\u043a\u0440\u0435\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f: $SECRET&quot;\n# \u0412 Google Authenticator \u0432\u0432\u043e\u0434\u0438\u0442\u0435 \u044d\u0442\u043e\u0442 \u0441\u0435\u043a\u0440\u0435\u0442\n<\/code><\/pre>\n<h3>3.3. \u0421\u043a\u0440\u0438\u043f\u0442 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 OTP<\/h3>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 <code>\/usr\/local\/bin\/check_totp.sh<\/code>:<\/p>\n<pre><code class=\"language-bash\">#!\/bin\/bash\n# $1 - \u043b\u043e\u0433\u0438\u043d, $2 - \u0432\u0432\u0435\u0434\u0451\u043d\u043d\u044b\u0439 OTP\nUSER=&quot;$1&quot;\nTOKEN=&quot;$2&quot;\nBASE32_SECRET=$(grep &quot;^$USER:&quot; \/etc\/freeradius\/totp_secrets | awk -F: '{print $2}')\nif [ -z &quot;$BASE32_SECRET&quot; ]; then\n  echo &quot;Auth-Type reject&quot;\n  exit 1\nfi\n# \u0414\u043e\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u043e\u043a\u043d\u043e -1,0,+1 (\u0434\u0435\u0440\u0436\u0438\u0442 \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0440\u0430\u0441\u0441\u0438\u043d\u0445\u0440\u043e\u043d)\nfor ((off=-1; off&lt;=1; off++)); do\n  EXPECTED=$(oathtool --totp --base32 --time-step-size=30 --window=$off &quot;$BASE32_SECRET&quot; 2&gt;\/dev\/null)\n  if [ &quot;$EXPECTED&quot; = &quot;$TOKEN&quot; ]; then\n    echo &quot;Auth-Type accept&quot;\n    exit 0\n  fi\ndone\necho &quot;Auth-Type reject&quot;\nexit 1\n<\/code><\/pre>\n<p>\u0424\u0430\u0439\u043b \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 <code>\/etc\/freeradius\/totp_secrets<\/code>:<\/p>\n<pre><code>vpnuser01:BASE32SECRET123456\nvpnuser02:ANOTHERBASE32SECRET\n<\/code><\/pre>\n<p>\u0417\u0430\u0441\u0435\u043a\u0440\u0435\u0447\u044c\u0442\u0435 \u0444\u0430\u0439\u043b:<\/p>\n<pre><code class=\"language-bash\">sudo chmod 600 \/etc\/freeradius\/totp_secrets\n<\/code><\/pre>\n<h3>3.4. \u041f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u043a FreeRADIUS<\/h3>\n<p><code>\/etc\/freeradius\/3.0\/sites-enabled\/otp<\/code>:<\/p>\n<pre><code>authorize {\n    if (User-Password =~ \/^[0-9]{6}$\/) {\n        update {\n            control:Packet-Type := Access-Accept\n        }\n    }\n    else {\n        update {\n            control:Auth-Type := Reject\n        }\n    }\n}\n<\/code><\/pre>\n<p>\u0418\u043b\u0438 \u043f\u043e\u043b\u043d\u0435\u0435 \u0447\u0435\u0440\u0435\u0437 <code>exec<\/code> \u0432 <code>authenticate<\/code>:<\/p>\n<p>\u0412 <code>\/etc\/freeradius\/3.0\/modules\/exec<\/code> \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c:<\/p>\n<pre><code>exec totp_check {\n    wait = yes\n    input = &quot;dummy&quot;\n    program = &quot;\/usr\/local\/bin\/check_totp.sh %{User-Name} %{User-Password}&quot;\n    output = none\n}\n<\/code><\/pre>\n<p>\u0412 <code>sites-enabled\/otp<\/code>:<\/p>\n<pre><code>authenticate {\n    Auth-Type OTP {\n        exec totp_check\n    }\n}\n<\/code><\/pre>\n<hr \/>\n<h2>\u0428\u0430\u0433 4. RADIUS-\u043a\u043b\u0438\u0435\u043d\u0442 \u043d\u0430 Mikrotik (L2TP\/IPsec)<\/h2>\n<p>\u041d\u0430\u0441\u0442\u0440\u043e\u0438\u043c Mikrotik \u043a\u0430\u043a RADIUS-\u043a\u043b\u0438\u0435\u043d\u0442 \u2014 \u0442\u043e\u0433\u0434\u0430 \u043f\u0440\u0438 L2TP\/IPsec VPN \u0441\u0435\u0440\u0432\u0435\u0440 \u0441\u043f\u0440\u0430\u0448\u0438\u0432\u0430\u0435\u0442 <code>Username + Password<\/code> \u0443 FreeRADIUS, \u0433\u0434\u0435 \u00abPassword\u00bb \u2014 OTP.<\/p>\n<h3>4.1. \u0414\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c RADIUS-\u0441\u0435\u0440\u0432\u0435\u0440<\/h3>\n<pre><code class=\"language-routeros\">\/radius add service=pppoe,l2tp address=192.168.10.55 \n    secret=radsecret ports=1812 timeout=3s comment=&quot;FreeRADIUS&quot;\n<\/code><\/pre>\n<h3>4.2. \u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c RADIUS \u0434\u043b\u044f L2TP (VPN)<\/h3>\n<pre><code class=\"language-routeros\">\/ppp l2tp-server set enabled=yes authentication=mschap2 \n    use-ipsec=yes ips-pool=vpn-pool\n\n\/ppp profile add name=vpn-radius change-address=none \n    bridge-mode=none use-radius=yes\n<\/code><\/pre>\n<h3>4.3. \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0438\u0437 WinBox<\/h3>\n<p>\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0432\u0432\u043e\u0434\u0438\u0442 \u0432 VPN-\u043a\u043b\u0438\u0435\u043d\u0442\u0435: \u043b\u043e\u0433\u0438\u043d <code>vpnuser01<\/code>, \u043f\u0430\u0440\u043e\u043b\u044c <code>&lt;\u0435\u0433\u043e OTP&gt;<\/code>. \u0415\u0441\u043b\u0438 \u0432\u0441\u0451 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d\u043e \u2014 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u0442 \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438 \u0432\u0435\u0440\u043d\u043e\u043c OTP.<\/p>\n<hr \/>\n<h2>\u0428\u0430\u0433 5. RD Gateway \/ Windows NPS \u0447\u0435\u0440\u0435\u0437 RADIUS<\/h2>\n<p>\u0421\u0432\u044f\u0437\u043a\u0430 \u0441\u043e \u0441\u0442\u0430\u0442\u044c\u0451\u0439 \u043f\u0440\u043e RD Gateway:<\/p>\n<ol>\n<li>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u0435 \u0440\u043e\u043b\u044c <strong>Network Policy and Access Services<\/strong> (NPS).<\/li>\n<li>\u0412 NPS: RADIUS Clients \u2192 \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c FreeRADIUS.<\/li>\n<li>\u0414\u043b\u044f RD Gateway: \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u0442\u0435 CAP \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435 \u043a RADIUS.<\/li>\n<li>\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0432\u0432\u043e\u0434\u0438\u0442 \u0434\u043e\u043c\u0435\u043d\u043d\u0443\u044e \u0443\u0447\u0451\u0442\u043a\u0443, \u0430 NPS \u043f\u0435\u0440\u0435\u0434\u0430\u0451\u0442 \u043f\u0430\u0440\u043e\u043b\u044c \u043a\u0430\u043a \u00abpassword + OTP\u00bb (\u043f\u0430\u0440\u043e\u043b\u044c8021x&#8230;). \u0421\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u0430\u044f \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0430: <code>\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439-\u043f\u0430\u0440\u043e\u043b\u044c<\/code> \u0432 \u043f\u043e\u043b\u0435 User-Password, \u043d\u043e \u0441 FreeRADIUS \u0433\u0438\u0431\u0447\u0435 OTP-\u043c\u043e\u0434\u0443\u043b\u044c.<\/li>\n<\/ol>\n<p>\u0423\u043f\u0440\u043e\u0449\u0451\u043d\u043d\u043e: RD Gateway \u2192 NPS (Windows) \u2192 FreeRADIUS (OTP). \u0412 RNPS <code>connection request policy<\/code> \u0443\u043a\u0430\u0436\u0438\u0442\u0435 forwarded to FreeRADIUS.<\/p>\n<hr \/>\n<h2>\u0428\u0430\u0433 6. Hotspot\/Wi-Fi \u0447\u0435\u0440\u0435\u0437 RADIUS (\u0441\u0432\u044f\u0437\u043a\u0430 \u0441\u043e \u0441\u0442\u0430\u0442\u044c\u0451\u0439 \u043f\u0440\u043e captive portal)<\/h2>\n<p>\u041d\u0430 Mikrotik-\u0440\u043e\u0443\u0442\u0435\u0440\u0435 \u0434\u043b\u044f \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0433\u043e Wi-Fi:<\/p>\n<pre><code class=\"language-routeros\">\/radius set service=hotspot address=192.168.10.55 secret=radsecret \n    timeout=3s\n\/ip hotspot profile set guest use-radius=yes\n\/ip hotspot user profile set default radius-accounting=yes\n<\/code><\/pre>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0438 \u0432\u0445\u043e\u0434\u0435 \u043d\u0430 wiki-\u043f\u043e\u0440\u0442\u0430\u043b \u0433\u043e\u0441\u0442\u044c \u0432\u0432\u043e\u0434\u0438\u0442 \u043b\u043e\u0433\u0438\u043d + OTP \u2014 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 \u0434\u0435\u043b\u0430\u0435\u0442 FreeRADIUS.<\/p>\n<hr \/>\n<h2>\u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0432\u0441\u0435\u0439 \u0446\u0435\u043f\u043e\u0447\u043a\u0438<\/h2>\n<pre><code class=\"language-bash\"># 1. FreeRADIUS \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b\nsudo tail -f \/var\/log\/freeradius\/radius.log\n\n# 2. \u041a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u044b\u0439 e2e \u0447\u0435\u0440\u0435\u0437 radclient (\u0431\u0435\u0437 NAS):\n#    - \u0435\u0441\u043b\u0438 OTP \u0432\u0435\u0440\u043d\u044b\u0439:\necho &quot;User-Name=vpnuser01, User-Password=123456&quot; | \n  radclient -x 127.0.0.1:1812 auth testing123\n#    \u0432\u044b\u0432\u043e\u0434: Access-Accept\n\n# 3. \u041e\u0442 Mikrotik \u0432 \u043b\u043e\u0433\u0430\u0445 FreeRADIUS \u043f\u043e\u044f\u0432\u0438\u0442\u0441\u044f NAS-\u0430\u0434\u0440\u0435\u0441 \u0438 User-Name\n<\/code><\/pre>\n<hr \/>\n<h2>\u0422\u043e\u043d\u043a\u043e\u0441\u0442\u0438 \u0438 \u043f\u043e\u0434\u0432\u043e\u0434\u043d\u044b\u0435 \u043a\u0430\u043c\u043d\u0438<\/h2>\n<ul>\n<li><strong>OTP \u0431\u044b\u0432\u0430\u0435\u0442 \u0440\u0430\u0441\u0441\u0438\u043d\u0445\u0440\u043e\u043d\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d<\/strong> \u2014 \u043e\u043a\u043d\u043e \u00b11 \u0448\u0430\u0433 (30c) \u0440\u0435\u0448\u0430\u0435\u0442; \u0435\u0441\u043b\u0438 \u043a\u043b\u0438\u0435\u043d\u0442 \u0432\u0432\u043e\u0434\u0438\u0442 \u043a\u043e\u0434 \u043f\u043e\u0441\u043b\u0435 long-\u0442\u0438\u043a\u0438 \u2014 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u0442\u0435 <code>--window=2<\/code>.<\/li>\n<li><strong>\u041d\u0435 \u043f\u0443\u0442\u0430\u0439\u0442\u0435 \u043f\u0430\u0440\u043e\u043b\u044c \u0438 OTP<\/strong> \u2014 \u0432 RADIUS <code>User-Password<\/code> \u043e\u0434\u0438\u043d. \u0412\u0430\u0440\u0438\u0430\u043d\u0442\u044b: \u00ab\u043f\u0430\u0440\u043e\u043b\u044c+OTP\u00bb \u0447\u0435\u0440\u0435\u0437 <code>%{User-Password}<\/code> \u0441\u043a\u043b\u0435\u0438\u0432\u0430\u043d\u0438\u0435, \u043b\u0438\u0431\u043e TOTP-only (\u043a\u0430\u043a \u0437\u0434\u0435\u0441\u044c). \u0414\u043b\u044f \u0434\u043e\u043c\u0430\u0448\u043d\u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f TOTP-only \u2014 \u043d\u043e\u0440\u043c\u0430.<\/li>\n<li><strong>\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432<\/strong> \u2014 \u0444\u0430\u0439\u043b <code>totp_secrets<\/code> \u044d\u0442\u043e root-only. \u041d\u0435 \u0434\u0435\u043b\u0430\u0439\u0442\u0435 readable \u0434\u043b\u044f freeradius-\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f.<\/li>\n<li><strong>FreeRADIUS \u043f\u043e\u0440\u0442 1812\/1813<\/strong> \u2014 \u043e\u0442\u043a\u0440\u043e\u0439\u0442\u0435 \u0432 firewall:<br \/>\n<code>bash<br \/>\n  sudo ufw allow 1812\/udp &amp;&amp; sudo ufw allow 1813\/udp<\/code><\/li>\n<li><strong>Mikrotik mschap2 \u043f\u043e\u0434\u0441\u0435\u043a\u0430\u0435\u0442 OTP<\/strong> \u2014 \u0441 L2TP\/IPsec \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 <code>mschap-v2<\/code> \u0441 \u0440\u0430\u0441\u0448\u0438\u0440\u0435\u043d\u0438\u0435\u043c: FreeRADIUS \u0434\u043e\u043b\u0436\u0435\u043d \u0432\u0435\u0440\u043d\u0443\u0442\u044c <code>MS-CHAP2-Success<\/code>. \u0414\u043b\u044f TOTP-only \u043f\u0440\u043e\u0449\u0435 <code>chap\/mschap<\/code> \u043e\u0431\u044b\u0447\u043d\u044b\u0439 \u2014 \u043f\u0440\u043e\u0432\u0435\u0440\u044c\u0442\u0435.<\/li>\n<li><strong>NAS-\u043a\u043b\u044e\u0447 (secret)<\/strong> \u2014 \u043e\u0434\u0438\u043d\u0430\u043a\u043e\u0432\u044b\u0439 \u0432 <code>\/radius add<\/code> \u0438 \u0432 <code>clients.conf<\/code>: <code>secret = radsecret<\/code>. \u0418\u043d\u0430\u0447\u0435 Access-Reject.<\/li>\n<\/ul>\n<hr \/>\n<h2>\u0428\u043f\u0430\u0440\u0433\u0430\u043b\u043a\u0430<\/h2>\n<pre><code class=\"language-bash\">sudo apt install freeradius oathtool\n\n# \u0441\u0435\u043a\u0440\u0435\u0442 \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\nSECRET=$(head -c 20 \/dev\/urandom | base32 | tr -d '=')\necho &quot;user:$SECRET&quot; &gt;&gt; \/etc\/freeradius\/totp_secrets\n\n# \u043a\u043b\u0438\u0435\u043d\u0442\u044b (NAS) \u0432 \/etc\/freeradius\/3.0\/clients.conf\n# client mikrotik { ipaddr = 192.168.10.1 secret = radsecret }\n\n# Mikrotik:\n# \/radius add service=l2tp address=192.168.10.55 secret=radsecret\n# \/ppp profile set default use-radius=yes\n<\/code><\/pre>\n<p><em>\u041f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043e \u043d\u0430: Ubuntu 22.04 + FreeRADIUS 3.x + RouterOS 7.<\/em><br \/>\n<em>\u0414\u0430\u0442\u0430: \u0421\u0435\u043d\u0442\u044f\u0431\u0440\u044c 2026.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u0414\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u0430\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f \u0434\u043b\u044f VPN \u0438 Wi-Fi \u0447\u0435\u0440\u0435\u0437 FreeRADIUS + OTP<\/p>\n","protected":false},"author":0,"featured_media":749,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,7],"tags":[],"class_list":["post-748","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","category-mikrotik"],"aioseo_notices":[],"views":3,"_links":{"self":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=748"}],"version-history":[{"count":2,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/748\/revisions"}],"predecessor-version":[{"id":751,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/748\/revisions\/751"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/media\/749"}],"wp:attachment":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}