Can Passbeam authenticate our VPN as well as the network?
Yes, with the same certificates. A client's VPN access tab is where you add a gateway — one per appliance that terminates a VPN, whether that is the firewall itself or a concentrator sitting behind it — and each gets its own shared secret and its own list of addresses it is allowed to send from. The person connecting from home uses the certificate that already gets their laptop onto the office network, so revoking it in one place takes away both.
Whatever terminates the tunnel has to be able to relay EAP-TLS to a RADIUS server. This is the thing to check before anything else, and it is a question about the appliance doing the VPN rather than about the brand on the rack. Plenty of gateways speak RADIUS perfectly well and only ever forward a username and password, and one of those cannot use Passbeam at all — there is no password to forward, and we would never accept one. Look in the VPN settings for EAP-TLS or certificate authentication against RADIUS rather than for a RADIUS option on its own.
The rest is ordinary. A VPN gateway talks standard RADIUS over UDP on port 1812, not RADSec — the two addresses to point it at are on the VPN access tab, and you enter both. Every attempt appears in the same authentication log as the switches and access points, saying which gateway it came through.
Everything else about the decision is unchanged, which is the point: the certificate is checked, the person's Microsoft 365 account is checked, and any group rules for the client apply. A leaver loses the VPN at the same moment they lose the Wi-Fi, without anybody editing the firewall.
Related questions
- RADIUS or RADSec — which should I use?
- Is standard RADIUS safe enough to use?
- What address and port do I point my equipment at?
- A printer keeps failing with a TLS error. Why would I let a site accept older TLS?
- A camera or printer is still refused after I allowed older TLS. What now?
- Our VPN concentrator serves several clients from one address. Will Passbeam tell them apart?
- Can I let only some people use the VPN, but everyone use the office network?
- Can I require a second factor on the VPN?
- Do you support PEAP, MSCHAPv2 or EAP-TTLS?
- Do you support RADIUS accounting?
- How do I disconnect a device that is already connected?
- What firewall rules does the connector need?
Still stuck? Ask us, or read the rest of the knowledge base.