diff --git a/net/pfSense-pkg-freeradius2/files/usr/local/pkg/freeradius.inc b/net/pfSense-pkg-freeradius2/files/usr/local/pkg/freeradius.inc index 4a4f151696ad..e0957d34480c 100644 --- a/net/pfSense-pkg-freeradius2/files/usr/local/pkg/freeradius.inc +++ b/net/pfSense-pkg-freeradius2/files/usr/local/pkg/freeradius.inc @@ -1530,8 +1530,10 @@ function freeradius_serverdefault_resync() { // post-auth section DATABASE 1 if (($sqlconf['varsqlconfincludeenable'] == 'on') && ($sqlconf['varsqlconfenablepostauth'] == 'Enable')) { $varsqlconfpostauth = "$varsqlconf2failover {" . "\n\t\t\tsql" . "\n\t\t\t$varsqlconf2postauth" . "\n\t}"; + $varsqlconfpostauthtypereject = 'sql'; } else { $varsqlconfpostauth = '### sql DISABLED ###'; + $varsqlconfpostauthtypereject = '# sql'; } // Changing authorize section for plain mac auth @@ -2163,7 +2165,7 @@ post-auth { Post-Auth-Type REJECT { # log failed authentications in SQL, too. - # sql + $varsqlconfpostauthtypereject attr_filter.access_reject } }