<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=DALORADIUS_-_Documentation</id>
	<title>DALORADIUS - Documentation - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=DALORADIUS_-_Documentation"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=DALORADIUS_-_Documentation&amp;action=history"/>
	<updated>2026-05-02T18:41:21Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=DALORADIUS_-_Documentation&amp;diff=918&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=DALORADIUS_-_Documentation&amp;diff=918&amp;oldid=prev"/>
		<updated>2026-01-17T07:09:54Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 07:09, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== System Architecture and Data Flow ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== System Architecture and Data Flow ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=DALORADIUS_-_Documentation&amp;diff=721&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;Category:Wiki  == System Architecture and Data Flow ==  daloradius operates as a management abstraction layer above FreeRADIUS, relying entirely on SQL-backed authorization and accounting.  === Request Lifecycle === # NAS sends Access-Request # FreeRADIUS preprocesses packet # SQL authorization module queries radcheck and radreply # Group resolution via radusergroup # radgroupcheck and radgroupreply merged by priority # Reply attributes returned to NAS # Accounting p...&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=DALORADIUS_-_Documentation&amp;diff=721&amp;oldid=prev"/>
		<updated>2025-12-20T16:54:05Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  == System Architecture and Data Flow ==  daloradius operates as a management abstraction layer above FreeRADIUS, relying entirely on SQL-backed authorization and accounting.  === Request Lifecycle === # NAS sends Access-Request # FreeRADIUS preprocesses packet # SQL authorization module queries radcheck and radreply # Group resolution via radusergroup # radgroupcheck and radgroupreply merged by priority # Reply attributes returned to NAS # Accounting p...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Wiki]]&lt;br /&gt;
&lt;br /&gt;
== System Architecture and Data Flow ==&lt;br /&gt;
&lt;br /&gt;
daloradius operates as a management abstraction layer above FreeRADIUS, relying entirely on SQL-backed authorization and accounting.&lt;br /&gt;
&lt;br /&gt;
=== Request Lifecycle ===&lt;br /&gt;
# NAS sends Access-Request&lt;br /&gt;
# FreeRADIUS preprocesses packet&lt;br /&gt;
# SQL authorization module queries radcheck and radreply&lt;br /&gt;
# Group resolution via radusergroup&lt;br /&gt;
# radgroupcheck and radgroupreply merged by priority&lt;br /&gt;
# Reply attributes returned to NAS&lt;br /&gt;
# Accounting packets written to radacct&lt;br /&gt;
&lt;br /&gt;
=== Accounting Lifecycle ===&lt;br /&gt;
* Start packet creates radacct row&lt;br /&gt;
* Interim-Update updates counters&lt;br /&gt;
* Stop packet closes session&lt;br /&gt;
&lt;br /&gt;
== Database Design and Integrity ==&lt;br /&gt;
&lt;br /&gt;
=== Attribute Evaluation Order ===&lt;br /&gt;
# radcheck&lt;br /&gt;
# radgroupcheck (ascending priority)&lt;br /&gt;
# radreply&lt;br /&gt;
# radgroupreply&lt;br /&gt;
&lt;br /&gt;
Incorrect priority configuration is a common cause of unexpected behavior.&lt;br /&gt;
&lt;br /&gt;
=== Mandatory Indexes ===&lt;br /&gt;
Large installations must ensure indexes exist:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CREATE INDEX idx_radacct_user ON radacct (username);&lt;br /&gt;
CREATE INDEX idx_radacct_stop ON radacct (acctstoptime);&lt;br /&gt;
CREATE INDEX idx_radcheck_user ON radcheck (username);&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Orphaned Sessions Detection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
SELECT radacctid, username&lt;br /&gt;
FROM radacct&lt;br /&gt;
WHERE acctstoptime IS NULL&lt;br /&gt;
AND acctstarttime &amp;lt; NOW() - INTERVAL 1 DAY;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Advanced User Policy Modeling ==&lt;br /&gt;
&lt;br /&gt;
=== Layered Policy Strategy ===&lt;br /&gt;
* User-level: credentials only&lt;br /&gt;
* Group-level: bandwidth, access rules&lt;br /&gt;
* NAS-level: vendor attributes&lt;br /&gt;
* Time-based: expiration and session limits&lt;br /&gt;
&lt;br /&gt;
=== Simultaneous-Use Enforcement ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
INSERT INTO radcheck (username, attribute, op, value)&lt;br /&gt;
VALUES (&amp;#039;user1&amp;#039;, &amp;#039;Simultaneous-Use&amp;#039;, &amp;#039;:=&amp;#039;, &amp;#039;1&amp;#039;);&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Session Timeout Control ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
INSERT INTO radgroupreply (groupname, attribute, op, value)&lt;br /&gt;
VALUES (&amp;#039;standard_users&amp;#039;, &amp;#039;Session-Timeout&amp;#039;, &amp;#039;:=&amp;#039;, &amp;#039;3600&amp;#039;);&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Vendor-Specific Attribute Management ==&lt;br /&gt;
&lt;br /&gt;
=== MikroTik Rate Limits ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
INSERT INTO radgroupreply (groupname, attribute, op, value)&lt;br /&gt;
VALUES (&amp;#039;gold&amp;#039;, &amp;#039;Mikrotik-Rate-Limit&amp;#039;, &amp;#039;:=&amp;#039;, &amp;#039;10M/10M&amp;#039;);&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cisco AVPairs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
INSERT INTO radreply (username, attribute, op, value)&lt;br /&gt;
VALUES (&amp;#039;user1&amp;#039;, &amp;#039;Cisco-AVPair&amp;#039;, &amp;#039;:=&amp;#039;, &amp;#039;ip:addr-pool=POOL1&amp;#039;);&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Dictionary Handling ===&lt;br /&gt;
Vendor dictionaries must be loaded in FreeRADIUS, not daloradius.&lt;br /&gt;
&lt;br /&gt;
== Authentication Security Models ==&lt;br /&gt;
&lt;br /&gt;
=== Password Storage ===&lt;br /&gt;
* Cleartext-Password: maximum compatibility&lt;br /&gt;
* NT-Password: MS-CHAPv2&lt;br /&gt;
* Avoid User-Password storage&lt;br /&gt;
&lt;br /&gt;
=== Enforcing Encrypted Authentication ===&lt;br /&gt;
Disable PAP where possible in FreeRADIUS configuration.&lt;br /&gt;
&lt;br /&gt;
=== Replay Protection ===&lt;br /&gt;
* Enable Message-Authenticator&lt;br /&gt;
* Reject malformed packets&lt;br /&gt;
* Use unique shared secrets per NAS&lt;br /&gt;
&lt;br /&gt;
== Web Interface Security and Role Separation ==&lt;br /&gt;
&lt;br /&gt;
=== Operator Roles ===&lt;br /&gt;
* Super Administrator&lt;br /&gt;
* Administrator&lt;br /&gt;
* Operator&lt;br /&gt;
* Read-only&lt;br /&gt;
&lt;br /&gt;
Never use the same operator account for automation and humans.&lt;br /&gt;
&lt;br /&gt;
=== Session Security ===&lt;br /&gt;
* Enforce HTTPS&lt;br /&gt;
* Disable PHP error display&lt;br /&gt;
* Secure cookies&lt;br /&gt;
&lt;br /&gt;
=== File Permissions ===&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
chown -R www-data:www-data daloradius/&lt;br /&gt;
chmod -R 750 daloradius/&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Database Security and Access Control ==&lt;br /&gt;
&lt;br /&gt;
=== SQL User Separation ===&lt;br /&gt;
* radius_rw: operational access&lt;br /&gt;
* radius_ro: reporting&lt;br /&gt;
* radius_backup: dump only&lt;br /&gt;
&lt;br /&gt;
=== Credential Rotation ===&lt;br /&gt;
Automate credential rotation every 90 days.&lt;br /&gt;
&lt;br /&gt;
== Performance Optimization and Scaling ==&lt;br /&gt;
&lt;br /&gt;
=== High-Load Patterns ===&lt;br /&gt;
* Accounting-heavy workloads&lt;br /&gt;
* PPPoE reconnect storms&lt;br /&gt;
* Interim-Update flooding&lt;br /&gt;
&lt;br /&gt;
=== Recommended Mitigations ===&lt;br /&gt;
* Increase SQL connection pool&lt;br /&gt;
* Enable query caching&lt;br /&gt;
* Partition radacct table&lt;br /&gt;
&lt;br /&gt;
=== radacct Partitioning Example ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
PARTITION BY RANGE (YEAR(acctstarttime));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Automation and External Integration ==&lt;br /&gt;
&lt;br /&gt;
=== API-less Automation ===&lt;br /&gt;
daloradius relies on direct SQL manipulation.&lt;br /&gt;
&lt;br /&gt;
=== Example: Bulk User Creation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
INSERT INTO radcheck (username, attribute, op, value)&lt;br /&gt;
SELECT username, &amp;#039;Cleartext-Password&amp;#039;, &amp;#039;:=&amp;#039;, password&lt;br /&gt;
FROM import_users;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Monitoring Integration ===&lt;br /&gt;
Monitor:&lt;br /&gt;
* radacct growth&lt;br /&gt;
* authentication failures&lt;br /&gt;
* response latency&lt;br /&gt;
&lt;br /&gt;
== Backup, Recovery, and Data Consistency ==&lt;br /&gt;
&lt;br /&gt;
=== Consistent Backup ===&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
mysqldump --single-transaction -u radius -p radius &amp;gt; radius.sql&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Restore Validation ===&lt;br /&gt;
Verify radcheck, radreply, radusergroup integrity post-restore.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
=== Authentication Rejected ===&lt;br /&gt;
* Shared secret mismatch&lt;br /&gt;
* Missing Cleartext-Password&lt;br /&gt;
* Group priority override&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
freeradius -X&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Accounting Sessions Stuck ===&lt;br /&gt;
* NAS reboot without Stop packet&lt;br /&gt;
* Interim-Update disabled&lt;br /&gt;
* Clock drift between NAS and server&lt;br /&gt;
&lt;br /&gt;
=== daloradius UI Errors ===&lt;br /&gt;
* PHP version mismatch&lt;br /&gt;
* Missing SQL privileges&lt;br /&gt;
* Incorrect config.inc.php&lt;br /&gt;
&lt;br /&gt;
=== Performance Degradation ===&lt;br /&gt;
* radacct table too large&lt;br /&gt;
* No indexes&lt;br /&gt;
* Excessive logging&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
&lt;br /&gt;
* daloradius GitHub  &lt;br /&gt;
  https://github.com/lirantal/daloradius&lt;br /&gt;
&lt;br /&gt;
* daloradius Wiki  &lt;br /&gt;
  https://github.com/lirantal/daloradius/wiki&lt;br /&gt;
&lt;br /&gt;
* FreeRADIUS Official Documentation  &lt;br /&gt;
  https://wiki.freeradius.org&lt;br /&gt;
&lt;br /&gt;
* FreeRADIUS SQL Module  &lt;br /&gt;
  https://wiki.freeradius.org/guide/SQL-HOWTO&lt;br /&gt;
&lt;br /&gt;
* RFC 2865 – RADIUS  &lt;br /&gt;
  https://datatracker.ietf.org/doc/html/rfc2865&lt;br /&gt;
&lt;br /&gt;
* RFC 2866 – RADIUS Accounting  &lt;br /&gt;
  https://datatracker.ietf.org/doc/html/rfc2866&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>