radtest(1)

send packets to a RADIUS server, show reply

Section 1 freeradius-common bookworm source

Summary

radtest is a simple front-end to radclient that sends a test authentication request to a RADIUS server and shows the reply. It builds the attribute/value pairs from your command-line arguments, so it's a fast way to confirm a RADIUS server accepts a given username and password. Use it to verify FreeRADIUS configuration and client/shared-secret setup.

Tip: The nas-port-number argument is arbitrary for testing, so just use 10; the secret must match the shared secret configured for this client on the server.

Description

RADTEST

NAME

radtest - send packets to a RADIUS server, show reply

SYNOPSIS

radtest [-d raddb_directory] [-P tcp/udp] [-t pap/chap/mschap/eap-md5] [-x ] [-4 ] [-6 ] user password radius-server nas-port-number secret [ppphint] [nasname]

DESCRIPTION

radtest is a frontend to radclient(1). It generates a list of attribute/value pairs based on the command line arguments, and feeds these into radclient. It’s a fast and convenient way to test a radius server.

OPTIONS

-d raddb_directory

The directory that contains the RADIUS dictionary files. Defaults to /etc/freeradius/3.0.

-P proto

Use proto transport protocol ("tcp" or "udp"). Only available if FreeRADIUS is compiled with TCP transport support.

-t pap/chap/mschap/eap-md5

Choose the authentication method to use. e.g. "-t pap", "-t chap", "-t mschap", or "-t eap-md5",. Defaults to "pap". Using EAP-MD5 requires that the "radeapclient" program is installed.

-x

Enables debugging output for the RADIUS client.

-4

Use NAS-IP-Address for the NAS address (default)

-6

Use NAS-IPv6-Address for the NAS address (default)

user

Username to send.

password

Password of the user.

radius-server

Hostname or IP address of the radius server. Optionally, you may specify a port by appending :port

nas-port-number

The value of the NAS-Port attribute. Is an integer between 0 and 2ˆ31, and it really doesn’t matter what you put here. 10 will do fine.

secret

The shared secret for this client.

ppphint

If you put an integer > 0 here, radtest (or actually radclient) will add the attribute Framed-Protocol = PPP to the request packet.

nasname

If present, this will be resolved to an IP address and added to the request packet as the NAS-IP-Address attribute. If you don’t specify it, the local hostname of the system will be used.

SEE ALSO

radiusd(8), radclient(1).

AUTHOR

Miquel van Smoorenburg, miquels@cistron.nl.

Examples

radtest bob hello 127.0.0.1 10 testing123

Authenticate user bob with password hello against the local RADIUS server using shared secret testing123.

radtest -t chap bob hello 127.0.0.1 10 testing123

Use CHAP instead of the default PAP authentication method.

radtest -x bob hello radius.example.com 10 testing123

Enable debugging output to see the full request and reply packets.

radtest bob hello radius.example.com:1812 10 testing123

Specify a non-default server port by appending :port to the server address.

See Also