I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.

I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.

I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-06-23 07:07:15 - last edited 2025-06-27 08:24:57
Tags: #WPA2-Enterprise EAP-TLS Wifi
Model: ER605 (TL-R605)   EAP245   TL-SG2008  
Hardware Version: V3
Firmware Version: Various ** see Content below for details

To start .... I am running Omada Software Controller (Currently on Windows 10) as a service.  It is currently version 5.15.20.21 (Stable build).

 

My network consists of the following devices (in addition to the SDC):

 

1x ER605 - 5 port VPN / Internet Gateway    ---  ER605 v2.0   firmware 2.3.0

 

1x SG2008 - 8 port Layer 2 Switch (non-PoE)  ---  SG2008 v4.20   firmware 4.20.9

 

1x EAP245 - Wireless Access Point --- EAP245(US) v3.0     firmware 5.2.0

 

1x Linux Mint Server v22.1 Xia   -  FreeRADIUS v3.2.5 (no proxies ... single realm ... wifi device x509 cert authentication only, no accounting)

 

There is SCANT documentation on setting up a network with this configuration (Most of which is so deprecated that it almost qualifies as dis-information) so please, excuse my fumbling about ... it is the best I could do given no experience, no support, and limited access to useful technical documentation or relevant information (outside of the RFCs themselves which are virtually indecipherable as they are written in elite nerd code. A language that sadly I have yet to fully comprehend, despite many years of diligent effort made toward that score). I digress ...

 

What I am trying to accomplish, as stated in the Subject line for this thread, is to simply create a secure wireless environment where I can exist beyond the clutches of the innumerable hacker-type mac-address spoofing identity-thieving "criminals" that cannot or will not leave my information, devices, nor my internet connection alone. This is the final step ... beyond this, I'm going to have to resort to other more drastic measures which I will not discuss here.

 

I have connected, configured, and documented my network topology both physically and logically with this sole exception. I cannot get any wireless devices to successfully complete the authentication process of joining my secure wireless network. There aren't any errors or warnings ... nothing in Radius debugging etc .... in fact I can see in the rather verbose output FreeRadius provides during attempted connections that there isn't a problem .... it's all green lights up until the process stalls. It just stops processing and everything server side goes back into a waiting type state, while the device just hangs in a connecting state until eventually it too gives up and then stubbornly tries again... and the cycle repeats ad-nauseum into perpetuity.

 

It might be Radius, but if it is I couldn't say where or why ... there is nothing pointing to a misconfiguration or what to look for if your devices simply hang in a "Connecting" state until eventually something or everything simply times out ... I guess, I'm completely out of ideas at this point and nowhere to turn for guidance. The freerradius forums and community resources have proven to be of little actual help, either no replies at all or unhelpful snarky comments from elitist knowledge hoarding trolls that exist solely to cause people like me to think very dark and evil thoughts.

 

As for the SDC as I said, there aren't any errors that I'm seeing in the logs aside from the ARP cache poisoning, constant and non-ceasing mac address spoofing and of course the evil-twin / deauthorization combo attacks (those are my personal favorites... inspired me to actually go to a sporting goods store where I purchased a nice aluminum bat. I'm practicing my swing, and getting better too). Once again, I digress...

 

So, I have all the fun icky verbose logs and the verbose radius output all of which Im more than happy to share. 

 

What information specifically would you like to see first? Or should I post it all (it's a LOT)?

 

Really, thank you ... if you've read this far you deserve a medal just for that. But any ideas would be most appreciated. For anyone willing to take this on with me to try and run it to ground and find root cause .... I'll gladly buy you a pizza and a 2 litre of soda... send me an address and what you want on the bad boy and BAM!, I'll get one sent over easy as pie! (not joking). 

It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
  0      
  0      
#1
Options
2 Accepted Solutions
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.-Solution
2025-06-24 07:46:30 - last edited 2025-06-27 08:24:57

Hi  @Net-Moose 

 

Here are some guides for your reference:

Configuration Guide on Dynamic VLAN with the VLAN Assignment function of RADIUS


Troubleshooting for RADIUS Authentication Failure

 

If you need further help, such as analyzing logs, you may contact TP-Link support to investigate the issue further. 

Recommended Solution
  0  
  0  
#2
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.-Solution
2025-07-13 18:45:13 - last edited 2025-07-13 18:47:51

  @Net-Moose 

 

Still no response to my request for support .... I am beginning to see why the support certificates I naively purchased with each of my Omada devices were so affordable; the old adage "you get what you pay for" was not lost on this network implementation's devices. I'll attest to that...

 

I'm considering boxing the whole thing up and throwing it in a dumpster ... my life has never been this frazzled trying to implement standard technologies on a simple flat network. Who needs it? I don't.

 

I just need to find something capable of replacing it all with first, which incidentally comes with actual support but also won't force me to take out a second mortgage on the house to pay for it.

 

Buyer beware! It's better than Linksys / Netgear / etc .... but then again, what isn't? Avoid the headache and the endless stress ... just buy Cisco and be done with it ... it'll cost you but you'll see the value, and probably save yourself an additional 15 years worth of gray hair overnight ... and as an added bonus, you could then skip having to attend any of those pointless anger management courses. Value add!

 

-Just another happy "EX"-customer

It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
Recommended Solution
  0  
  0  
#13
Options
13 Reply
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.-Solution
2025-06-24 07:46:30 - last edited 2025-06-27 08:24:57

Hi  @Net-Moose 

 

Here are some guides for your reference:

Configuration Guide on Dynamic VLAN with the VLAN Assignment function of RADIUS


Troubleshooting for RADIUS Authentication Failure

 

If you need further help, such as analyzing logs, you may contact TP-Link support to investigate the issue further. 

Recommended Solution
  0  
  0  
#2
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-06 01:01:04

  @Vincent-TP 

 

Thank you Vincent for taking the time to reply and for providing the links. Though, I followed the configuration suggestions within the documents, they didn't match my device's configuration options exactly ... and in the end I still am unable to join any devices to my WPA2-Enterprise EAP-TLS FreeRADIUS wlan .... but after following the examples provided I now have actual errors appearing in my FreeRADIUS server's debugging output that I did not have previously ....

 

 

The VLAN configuration for the WLAN is as follows:

 

 

The WLAN configuration screen is as follows:

 

 

 

Here is the RADIUS Profile configuration:

 

 

And my FreeRADIUS servers Clients.conf and EAP.conf files were all reconfigured to reflect the information provided in the first linked document. It is these configuration changes in particular which caused the failures to appear in the debugging output, of that I am 100% certain. However, rather than revert the settings I am wondering if it might be prudent to combine the two such that my Access Point remains a client listed in Clients.conf as I believe it should be...

 

After looking over my posted settings do you have any additional concerns or pebbles of enlightenment to toss my way? Thank you for both your time and consideration.

 

 

 
It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
  0  
  0  
#3
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-06 04:32:27 - last edited 2025-07-06 04:33:02

  

 @Vincent-TP

 

After going back to my original Clients.conf file and adding the documents recommended client data (vs. replacing any existing configured client data) this is the complete debugging output of FreeRADIUS after attempting to join a device to the WAP2-Enterprise wlan network:

 

 

Once the output goes back to "Ready to process requests" I look at my device and it is still waiting to connect. No error, no connection, just connecting f o r e v e r .... until eventually the battery dies or I lose interest ... tantamount to watching paint dry .... with full battery its even worse. And I've tried it with different devices of different platforms each with the exact same result (except the devices without battery power don't ever quit trying, but other than that ... same).

It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
  0  
  0  
#4
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-06 04:43:56

 

 @Vincent-TP

 

Oh, and unsure if this is of any actual relevance .... but ..... my OCSP instance which I have configured to run on same system as FreeRADIUS server but on a different IP address (also hard coded into each device's certificate) does not ever get so much as a blip during any of the attempted device authentications ... I have radius configured to check OCSP to validate the certs used by the devices .... but from the perspective of OCSP .... * crickets chirping * .... and nothing. Hmmmmm

 

It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
  0  
  0  
#5
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-06 05:04:41

 

@Vincent-TP 

 

Sorry for the continuous rapid-fire updates, I'm just posting em as I find em, or as in this case as I remember em .... 

 

Interesting to note ... in the first linked document there is a comment detailing what to expect and how to react when connecting a device to the WLAN ... the information provided does not mirror my experience whatsoever:

 

"When connecting your client to the SSID, you will be asked to choose the authentication type of WPA-Enterprise, and enter the account username and password. After successfully authenticating with account “test10”, the client will obtain an IP address from VLAN10, while with account “test20”, it will get that from VLAN20."

 

Instead my devices receive / display absolutely no prompts for anything .... at all .... as stated previously .... connecting f o r e v e r .... 

 

 

It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
  0  
  0  
#6
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-07 07:41:18 - last edited 2025-07-07 07:42:51

  @Net-Moose 

 

Thanks for those info.

 

May we know what kind of controller you are using?

 

We recommend submitting a support ticket via email for efficient assistance.


Please include the following information in the email:
1. this Forum ID 827580;
2. your community nickname;
3. The type of controller you are using;

4. The config file of the controller.

  0  
  0  
#7
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-08 06:48:16

  @Vincent-TP 

 

Excellent, I will get that information together and submitted via email.

 

Thanks!

It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
  0  
  0  
#8
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-08 08:12:34

  @Vincent-TP \

 

I have done as instructed and submitted an email ticket with the requested information .

 

I am unsure whether or not the config export made it in with the ticket. Attempts to upload after renaming the .cfg file to .doc appeared to do nothing at all. No notification of success or failure was given and I could divine no indicator or other flag like iconography which might have indicated the status of any attempted upload.

 

If it did not make it through with the ticket I can provide the file via any number of alternate means, your choice.

It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
  0  
  0  
#9
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-09 02:23:53

  @Net-Moose 

 

If they don't receive the configuration file, they will request a new copy from you. No need to worry.

Please continue troubleshooting with the support team, and once a solution is found, kindly share it here to help others as well.

  0  
  0  
#10
Options
Re:I need help tracking down why my WPA2-Enterprise EAP-TLS FreeRADIUS Wifi network won't function.
2025-07-09 21:53:29 - last edited 2025-07-09 21:54:21

  @Vincent-TP 

 

Well, I've been monitoring my email and have gone through all of my received email including my junk folder ... and I have not received any email from anyone at TP-Link nor from anyone else regarding any of the ongoing Omada network issues.

 

Can you possibly verify that they have my correct email address information?

 

 

These are my public email addresses, either is fine ... I check both multiple times throughout the day 

 

 

CraigsLV69@gmail.com

 

Craigs_LV@outlook.com

 

 

Thanks!

It doesn't really matter whether you think that you can or whether you think that you can't .... either way .... you're always going to be correct.
  0  
  0  
#11
Options