<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Unifi on Sysadmin Tales</title>
    <link>https://blog.ssb-tech.net/tags/unifi/</link>
    <description>Recent content in Unifi on Sysadmin Tales</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:39:10 -0400</lastBuildDate>
    <atom:link href="https://blog.ssb-tech.net/tags/unifi/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Setting up FreeRADIUS with an Active Directory backend for use with Unifi WiFi</title>
      <link>https://blog.ssb-tech.net/posts/freeradius-unifi-certbot/</link>
      <pubDate>Tue, 31 Mar 2026 15:56:30 -0400</pubDate>
      <guid>https://blog.ssb-tech.net/posts/freeradius-unifi-certbot/</guid>
      <description>&lt;p&gt;Or in other words, how to configure 802.1x authentication with an Active Directory backend.&lt;/p&gt;&#xA;&lt;p&gt;I wrote this for work with a few tweaks, but I figured that it would work just as well as a blog post.&lt;/p&gt;&#xA;&lt;p&gt;Given that &lt;code&gt;$job&lt;/code&gt; has a lot of people who aren&amp;rsquo;t the most Linux-savvy I tried to keep it as simple as I could, but there are a lot of pieces to making this work.&lt;/p&gt;&#xA;&lt;p&gt;It was written with Ubuntu in mind but it should work in most Linux distributions.&lt;/p&gt;&#xA;&lt;p&gt;Debian would be a drop in replacement, something RHEL based like Rocky Linux would require more work because the path names and package names likely differ slightly.&lt;/p&gt;&#xA;&lt;h2 id=&#34;installing-free-letsencrypt-tls-certificates&#34;&gt;Installing free LetsEncrypt TLS certificates&lt;/h2&gt;&#xA;&lt;p&gt;We need to get valid TLS certificates for FreeRADIUS to use for its connection.&lt;/p&gt;&#xA;&lt;div class=&#34;callout callout-note&#34; role=&#34;note&#34;&gt;&lt;div class=&#34;callout-title&#34;&gt;Note&lt;/div&gt;&lt;div class=&#34;callout-content&#34;&gt;Note, if you&amp;rsquo;re in a fully corporate environment, you can bypass LetsEncrypt and use Active Directory self-signed certificates here. However, this did not fit my use case.&lt;/div&gt;&lt;/div&gt;&#xA;&lt;p&gt;Install &lt;a href=&#34;https://eff-certbot.readthedocs.io/en/stable/index.html&#34;&gt;certbot&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo su&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;apt install certbot&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This is how you get LE certs with an HTTP challenge - feel free to substitute it for a &lt;a href=&#34;https://letsencrypt.org/docs/challenge-types/#dns-01-challenge&#34;&gt;DNS-01 challenge&lt;/a&gt;. I normally always use a DNS challenge, but the client I wrote this guide for has their DNS hosted at Network Solutions, who do not have support with certbot.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Create an A record that points to our public IP that matches the name we&amp;rsquo;re issuing the certificate for.&lt;/li&gt;&#xA;&lt;li&gt;We need to port forward port 80 to the FreeRADIUS box so that certbot can complete the challenge.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;First, lets create our deploy hook script that will move our certs into the correct location and set ownership so that FreeRADIUS can access them.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo nano /opt/renewal-certs.sh&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#!/bin/bash&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;CERT_RENEW_LOCATION&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;/etc/letsencrypt/live/freeradius.domain.tld&amp;#39;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;CERT_INSTALL_LOCATION&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;/certs&amp;#39;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;PRIVATE_KEY_NAME&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;privkey.pem&amp;#39;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;PUBLIC_KEY_NAME&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;fullchain.pem&amp;#39;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;# Test to make sure that install location exists and if not, create it.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; ! &lt;span style=&#34;color:#f92672&#34;&gt;[[&lt;/span&gt; -d &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_INSTALL_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;]]&lt;/span&gt;; &lt;span style=&#34;color:#66d9ef&#34;&gt;then&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        echo &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Directory not found, creating.&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        mkdir /certs&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;fi&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;# Test to make sure source files exist.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; ! &lt;span style=&#34;color:#f92672&#34;&gt;[[&lt;/span&gt; -f &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_RENEW_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PUBLIC_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;]]&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;||&lt;/span&gt; ! &lt;span style=&#34;color:#f92672&#34;&gt;[[&lt;/span&gt; -f &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_RENEW_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PRIVATE_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;]]&lt;/span&gt;; &lt;span style=&#34;color:#66d9ef&#34;&gt;then&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        echo &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Keys missing from &lt;/span&gt;$CERT_RENEW_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;. Exit script.&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        exit &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;fi&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;# Rename existing certs for safety.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;mv &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_INSTALL_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PUBLIC_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_INSTALL_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PUBLIC_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;.bak&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;mv &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_INSTALL_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PRIVATE_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_INSTALL_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PRIVATE_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;.bak&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;# Copy the renewed certificates into place.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;cp &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_RENEW_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PUBLIC_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_INSTALL_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PUBLIC_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;cp &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_RENEW_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PRIVATE_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_INSTALL_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;/&lt;/span&gt;$PRIVATE_KEY_NAME&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;# Set the freerad user to be the owner of the certs.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;chown -R freerad:freerad &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;$CERT_INSTALL_LOCATION&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;# Restart freeradius so that it picks up the new cert.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;systemctl restart freeradius&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Quit out of nano with Ctrl+X and save the file.&lt;/p&gt;&#xA;&lt;p&gt;Next, we need to make that script executable:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;chmod +x /opt/renewal-certs.sh&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Run the following command to generate the certs &lt;strong&gt;(note that this assumes that you don&amp;rsquo;t already have a web server running on port 80 - if you do, you should use the &lt;a href=&#34;https://eff-certbot.readthedocs.io/en/stable/using.html#webroot&#34;&gt;&lt;code&gt;--webroot&lt;/code&gt;&lt;/a&gt; flag instead of &lt;code&gt;standalone&lt;/code&gt;.)&lt;/strong&gt;:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo certbot certonly --standalone &lt;span style=&#34;color:#ae81ff&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  -d radius.domain.tld &lt;span style=&#34;color:#ae81ff&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  --non-interactive &lt;span style=&#34;color:#ae81ff&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  --agree-tos &lt;span style=&#34;color:#ae81ff&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  -m your-email@example.com&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  --deploy-hook &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/opt/renewal-certs.sh&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If successful, you should have certificates installed at &lt;code&gt;/etc/letsencrypt/live/radius.domain.tld&lt;/code&gt;, and a copy of them in &lt;code&gt;/certs&lt;/code&gt; that FreeRADIUS can use.&lt;/p&gt;&#xA;&lt;h2 id=&#34;configuring-freeradius-samba-and-kerberos&#34;&gt;Configuring FreeRADIUS, Samba and Kerberos&lt;/h2&gt;&#xA;&lt;p&gt;On Ubuntu, we need to disable systemd-resolved as it causes issues with &lt;code&gt;.local&lt;/code&gt; addresses.&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;This is not required if you’re using a different top level domain for your Active Directory like &lt;code&gt;.com&lt;/code&gt; or &lt;code&gt;.org.&lt;/code&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;It&amp;rsquo;s also not needed on Debian because they do not use systemd-resolved.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo rm /etc/resolv.conf&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo systemctl disable systemd-resolved &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo systemctl stop systemd-resolved &#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo nano /etc/resolv.conf&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Then enter a &amp;ldquo;nameserver&amp;rdquo; stanza like so:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;nameserver 10.10.10.9&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Obviously the nameserver should be your AD controller.&lt;/p&gt;&#xA;&lt;p&gt;Quit out of nano with Ctrl+X and save the file.&lt;/p&gt;&#xA;&lt;p&gt;Run the following commands to install Kerberos, winbind and samba (dependencies for FreeRADIUS when you want it to auth against AD):&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo add-apt-repository universe&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo apt install winbind samba krb5-user freeradius -y&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo usermod -aG winbindd_priv freerad&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo mv /etc/krb5.conf /etc/krb5.conf.bak&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Create new krb5.conf file with the following contents:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo nano /etc/krb5.conf&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;# EXAMPLE.LOCAL should be replaced with your actual AD domain.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;[&lt;/span&gt;libdefaults&lt;span style=&#34;color:#f92672&#34;&gt;]&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    default_realm &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; EXAMPLE.LOCAL&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    dns_lookup_realm &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    dns_lookup_kdc &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    permitted_enctypes &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    default_tgs_enctypes &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    default_tkt_enctypes &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;[&lt;/span&gt;realms&lt;span style=&#34;color:#f92672&#34;&gt;]&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    EXAMPLE.LOCAL &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        kdc &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; kdc.example.local&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        admin_server &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; kdc.example.local&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;[&lt;/span&gt;domain_realm&lt;span style=&#34;color:#f92672&#34;&gt;]&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    .example.local &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; EXAMPLE.LOCAL&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    example.local &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; EXAMPLE.LOCAL&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    kdc.example.local &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; EXAMPLE.LOCAL&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;[&lt;/span&gt;logging&lt;span style=&#34;color:#f92672&#34;&gt;]&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    default &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; FILE:/var/log/krb5.log&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Do the same for the samba configuration file: &lt;code&gt;/etc/samba/smb.conf&lt;/code&gt;&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo mv /etc/samba/smb.conf /etc/samba/smb.conf.bak&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;#&#xA;# /etc/samba/smb.conf&#xA;#&#xA;&#xA;# start of global variables&#xA;[global]&#xA;&#xA;# server information, this is the domain/workgroup&#xA;# Replace this with whatever would come before the backslash when logging into a domain, e.g. DOMAIN\username&#xA;workgroup = DOMAIN&#xA;&#xA;# Kerberos / authentication information&#xA;# Replace with the actual domain name&#xA;realm = DOMAIN.LOCAL&#xA;&#xA;# replace with the linux server&amp;#39;s hostname. You can find this info by running &amp;#34;hostname&amp;#34; in the command line.&#xA;netbios name = RADIUS1&#xA;&#xA;# security used (Active Directory)&#xA;security = ADS&#xA;&#xA;# EoF&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Edit the hosts file. It should have entries for the system&amp;rsquo;s FQDN, etc.&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code class=&#34;language-hosts&#34; data-lang=&#34;hosts&#34;&gt;127.0.1.1 freeradius.example.local freeradius localhost.localdomain localhost&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Restart the samba daemon.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo systemctl restart smbd&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Try to get a Kerberos ticket.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo kinit Administrator@EXAMPLE.LOCAL&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Make sure that the ticket was issued:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo klist&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Join the domain and make sure it&amp;rsquo;s joined successfully.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo net ads join -U Administrator&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo net ads testjoin&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If the join is &amp;ldquo;OK&amp;rdquo;, restart Winbind:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo systemctl restart winbind&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Test Winbind by listing domain users:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;wbinfo -u&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Should get output like this:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;root@freeradius:~# wbinfo -u&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;EXAMPLE&lt;span style=&#34;color:#ae81ff&#34;&gt;\a&lt;/span&gt;dministrator&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;EXAMPLE&lt;span style=&#34;color:#ae81ff&#34;&gt;\g&lt;/span&gt;uest&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;EXAMPLE&lt;span style=&#34;color:#ae81ff&#34;&gt;\k&lt;/span&gt;rbtgt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;EXAMPLE&lt;span style=&#34;color:#ae81ff&#34;&gt;\t&lt;/span&gt;estuser&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In the file &lt;code&gt;/etc/freeradius/3.0/radiusd.conf&lt;/code&gt;, change this line to &lt;code&gt;auth = yes&lt;/code&gt;:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;auth = no&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Change or delete the password from this line in &lt;code&gt;/etc/freeradius/3.0/mods-available/eap&lt;/code&gt;:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;private_key_password =&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Change these lines to point to your keys:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;private_key_file = /your_private_key_location.key&#xA;# For the &amp;#34;cert&amp;#34; file - use the LetsEncrypt &amp;#34;fullchain.pem&amp;#34;&#xA;certificate_file = /your_certificate_file.cert&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Delete or comment-out this line:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;# ca_file = /etc/ssl/certs/ca-certificates.crt&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;If you allow all users to connect to WiFi, then edit &lt;code&gt;/etc/freeradius/3.0/mods-available/mschap&lt;/code&gt; and uncomment out these two lines:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;winbind_username = &amp;#34;%{mschap:User-Name}&amp;#34;&#xA;winbind_domain = &amp;#34;%{mschap:NT-Domain}&amp;#34;&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;And finally configure the RADIUS client (will be the Unifi APs) in &lt;code&gt;/etc/freeradius/3.0/sites-available/wifi&lt;/code&gt;:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;#&#xA;# /etc/freeradius/3.0/sites-available/wifi&#xA;#&#xA;&#xA;client UniFi-APs {&#xA;&#x9;shortname&#x9;= WiFi&#xA;&#x9;virtual_server&#x9;= wifi&#xA;&#x9;# RADIUS secret - should match what you have in the Unifi Controller.&#xA;&#x9;secret          = RAD1USp4ssw0rd&#xA;  require_message_authenticator = true&#xA;&#x9;# allowed clients (the clients will be the APs, not the end user devices. Make sure you enter the right subnet here)&#xA;&#x9;ipaddr&#x9;&#x9;= 10.0.0.0/24&#xA;}&#xA;server wifi {&#xA;&#x9;authorize {&#xA;&#x9;&#x9;# cleans up attributes, required&#xA;&#x9;&#x9;preprocess&#xA;&#x9;&#x9;# we use eap authentication, required&#xA;&#x9;&#x9;eap &#xA;    mschap&#xA;&#x9;}&#xA;&#x9;authenticate {&#xA;&#x9;&#x9;# mschap authentication&#xA;&#x9;&#x9;Auth-Type mschap {&#xA;&#x9;&#x9;&#x9;mschap&#xA;&#x9;&#x9;}&#xA;&#x9;&#x9;# eap, this is required&#xA;&#x9;&#x9;eap&#xA;&#x9;}&#xA;}&#xA;&#xA;# EoF&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Create a symlink of our RADIUS site configuration in the &lt;code&gt;sites-enabled&lt;/code&gt; directory:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo ln -s /etc/freeradius/3.0/sites-available/wifi /etc/freeradius/3.0/sites-enabled/wifi&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You can test your configuration by running:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;freeradius -X&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Make sure that you can connect to the WiFi network, then proceed to the next step.&lt;/p&gt;&#xA;&lt;p&gt;Enable and start the FreeRADIUS service (this will make it run in the background and also start on boot):&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo systemctl enable freeradius.service &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo systemctl restart freeradius.service&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;configuring-the-radius-server-in-unifi&#34;&gt;Configuring the RADIUS server in Unifi&lt;/h2&gt;&#xA;&lt;p&gt;Log into your Unifi network controller and go to Settings &amp;gt; Networks.&lt;/p&gt;&#xA;&lt;div class=&#34;callout callout-note&#34; role=&#34;note&#34;&gt;&lt;div class=&#34;callout-title&#34;&gt;Note&lt;/div&gt;&lt;div class=&#34;callout-content&#34;&gt;For some reason Ubiquiti keeps moving this setting around. This is the current location of this setting as of 2026-03-31.&lt;/div&gt;&lt;/div&gt;&#xA;&lt;p&gt;Add a new RADIUS server.&lt;/p&gt;&#xA;&lt;p&gt;It should look like the below:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Picture of how to configure RADIUS in the Unifi control plane&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/freeradius-unifi-certbot/images/unificlients.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The &amp;ldquo;Shared Secret&amp;rdquo; should be the same as the &amp;ldquo;secret&amp;rdquo; field in your FreeRADIUS site configuration.&lt;/p&gt;&#xA;&lt;h2 id=&#34;connecting-wireless-clients&#34;&gt;Connecting wireless clients&lt;/h2&gt;&#xA;&lt;p&gt;Should use &amp;ldquo;EAP-TTLS&amp;rdquo; (might be called just TTLS or Tunneled TLS, at least it is on Android).&lt;/p&gt;&#xA;&lt;p&gt;Phase 2 auth should be MSCHAPv2.&lt;/p&gt;&#xA;&lt;p&gt;You&amp;rsquo;ll need to enter the fully qualified domain name of the RADIUS server. (radius.domain.tld, etc)&lt;/p&gt;&#xA;&lt;p&gt;On iOS you may need to trust the certificate the first time you connect.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Showing how to configure a WiFi network with TTLS and MSChapv2 on Android&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/freeradius-unifi-certbot/images/AndroidTTLS.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;credits&#34;&gt;Credits&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://xenomorph.net/linux/ubuntu/misc/radius-unifi/&#34;&gt;https://xenomorph.net/linux/ubuntu/misc/radius-unifi/&lt;/a&gt;&lt;/p&gt;&#xA;</description>
    </item>
    <item>
      <title>PSA: Unifi IPSec site-to-site tunnels and DHCP</title>
      <link>https://blog.ssb-tech.net/posts/unifi-ipsec-and-dhcp/</link>
      <pubDate>Tue, 01 Apr 2025 13:09:28 -0400</pubDate>
      <guid>https://blog.ssb-tech.net/posts/unifi-ipsec-and-dhcp/</guid>
      <description>&lt;p&gt;Bit of a PSA of sorts, as this is the second time that I have run into this particular issue.&lt;/p&gt;&#xA;&lt;p&gt;Scenario: You had a Unifi gateway such as a UDM Pro with a static IP address. You switched your WAN IP from static to dynamic, for whatever reason. (In my case it was a different ISP that doesn&amp;rsquo;t hand out actual static IPs, only DHCP reservations.)&lt;/p&gt;&#xA;&lt;p&gt;You may find that the router holds onto that old IP, and if you&amp;rsquo;re like me, you&amp;rsquo;ll be confused as hell.&lt;/p&gt;&#xA;&lt;p&gt;The cause is your IPSec site-to-site tunnel.&lt;/p&gt;&#xA;&lt;p&gt;You&amp;rsquo;ll need to make note of any settings it had (Pre-shared keys, remote endpoints, remote subnets, etc), delete the tunnel completely, and then once you&amp;rsquo;ve successfully gotten your new IP from DHCP, recreate the tunnel from scratch.&lt;/p&gt;&#xA;&lt;p&gt;Once you remove the tunnel, you should get an IP from DHCP almost immediately.&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>
