Hello Scott,

what i can notice is when you register on the portal then packetfence deauth your device on 10.20.21.22 but you reconnect on 10.20.21.51 but after that packetfence is not able to deauth your device:

RADIUS Disconnect-Request: No answer from 10.20.21.51 on port 3799

It looks that you have 2 networks equipment, one is correctly configured and the other one no.

Regards

Fabrice


Le 19-06-12 à 15 h 35, Lu, Scott a écrit :
Hi Fabrice, here is the packetfence.log thank you,

Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) WARN: [mac:unknown] locale from the URL  is not supported (pf::Portal::Session::getLanguages) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:unknown] External captive portal detected ! (captiveportal::PacketFence::Model::Portal::Session::_build_dispatcherSession) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:unknown] Detected external portal client. Using the IP 10.20.224.217 address in it's session. (captiveportal::PacketFence::Model::Portal::Session::_build_clientIP) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) WARN: [mac:b8:c1:11:37:68:40] locale from the URL  is not supported (pf::Portal::Session::getLanguages) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:b8:c1:11:37:68:40] External captive portal detected ! (captiveportal::PacketFence::Model::Portal::Session::_build_dispatcherSession) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:b8:c1:11:37:68:40] Detected external portal client. Using the IP 10.20.224.217 address in it's session. (captiveportal::PacketFence::Model::Portal::Session::_build_clientIP) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:b8:c1:11:37:68:40] Instantiate profile WiFi_onBoard (pf::Connection::ProfileFactory::_from_profile) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) WARN: [mac:b8:c1:11:37:68:40] locale from the URL  is not supported (captiveportal::PacketFence::Controller::Root::getLanguages) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:b8:c1:11:37:68:40] Releasing device (captiveportal::PacketFence::DynamicRouting::Module::Root::release) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:b8:c1:11:37:68:40] User default has authenticated on the portal. (Class::MOP::Class:::after) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) WARN: [mac:b8:c1:11:37:68:40] locale from the URL  is not supported (pf::Portal::Session::getLanguages) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:b8:c1:11:37:68:40] re-evaluating access (manage_register called) (pf::enforcement::reevaluate_access) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:b8:c1:11:37:68:40] VLAN reassignment is forced. (pf::enforcement::_should_we_reassign_vlan) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2646) INFO: [mac:b8:c1:11:37:68:40] switch port is (10.20.21.22) ifIndex unknown connection type: Wifi Web Auth (pf::enforcement::_vlan_reevaluation) Jun 12 11:40:27 pfz9 packetfence_httpd.portal: httpd.portal(2647) INFO: [mac:[undef]] URI '/RuckusSmartZone' is detected as an external captive portal URI (pf::web::externalportal::handle) Jun 12 11:40:28 pfz9 pfqueue: pfqueue(3978) INFO: [mac:b8:c1:11:37:68:40] [b8:c1:11:37:68:40] DesAssociating mac on switch (10.20.21.22) (pf::api::desAssociate) Jun 12 11:40:28 pfz9 packetfence_httpd.aaa: httpd.aaa(1754) INFO: [mac:b8:c1:11:37:68:40] handling radius autz request: from switch_ip => (10.20.21.51), connection_type => Wireless-802.11-NoEAP,switch_mac => (54:3d:37:2c:a7:9c), mac => [b8:c1:11:37:68:40], port => 0, username => "B8:C1:11:37:68:40", ssid => VUSD-Guest (pf::radius::authorize) Jun 12 11:40:28 pfz9 packetfence_httpd.aaa: httpd.aaa(1754) INFO: [mac:b8:c1:11:37:68:40] Instantiate profile WiFi_onBoard (pf::Connection::ProfileFactory::_from_profile) Jun 12 11:40:28 pfz9 packetfence_httpd.aaa: httpd.aaa(1754) INFO: [mac:b8:c1:11:37:68:40] Connection type is Wireless-802.11-NoEAP. Getting role from node_info (pf::role::getRegisteredRole) Jun 12 11:40:28 pfz9 packetfence_httpd.aaa: httpd.aaa(1754) INFO: [mac:b8:c1:11:37:68:40] Username was defined "B8:C1:11:37:68:40" - returning role 'pf_onBoard' (pf::role::getRegisteredRole) Jun 12 11:40:28 pfz9 packetfence_httpd.aaa: httpd.aaa(1754) INFO: [mac:b8:c1:11:37:68:40] PID: "s...@hhh.aaa", Status: reg Returned VLAN: (undefined), Role: pf_onBoard (pf::role::fetchRoleForNode) Jun 12 11:40:28 pfz9 packetfence_httpd.aaa: httpd.aaa(1754) WARN: [mac:b8:c1:11:37:68:40] No parameter pf_onBoardVlan found in conf/switches.conf for the switch 10.20.21.51 (pf::Switch::getVlanByName) Jun 12 11:40:28 pfz9 packetfence_httpd.aaa: httpd.aaa(1754) INFO: [mac:[undef]] Updating locationlog from accounting request (pf::api::handle_accounting_metadata) Jun 12 11:40:28 pfz9 pfqueue: pfqueue(3978) INFO: [mac:b8:c1:11:37:68:40] Contacted Ruckus to perform deauthentication (pf::Switch::Ruckus::SmartZone::deauthenticateMacWebservices) Jun 12 11:41:25 pfz9 packetfence_httpd.aaa: httpd.aaa(1754) INFO: [mac:b8:c1:11:37:68:40] Instantiate profile WiFi_onBoard (pf::Connection::ProfileFactory::_from_profile) Jun 12 11:45:08 pfz9 pfipset[2432]: t=2019-06-12T11:45:08-0700 lvl=info msg="No Inline Network bypass ipsets reload" pid=2432 Jun 12 11:46:00 pfz9 pfqueue: pfqueue(4227) INFO: [mac:b8:c1:11:37:68:40] [b8:c1:11:37:68:40] DesAssociating mac on switch (10.20.21.51) (pf::api::desAssociate) Jun 12 11:46:00 pfz9 pfqueue: pfqueue(4227) INFO: [mac:b8:c1:11:37:68:40] deauthenticating (pf::Switch::Ruckus::SmartZone::radiusDisconnect) Jun 12 11:46:00 pfz9 pfqueue: pfqueue(4227) WARN: [mac:b8:c1:11:37:68:40] Unable to perform RADIUS Disconnect-Request: No answer from 10.20.21.51 on port 3799 at /usr/local/pf/lib/pf/util/radius.pm <http://radius.pm> line 147. (pf::Switch::Ruckus::SmartZone::catch {...} )

On Wed, Jun 12, 2019 at 11:20 AM Fabrice Durand via PacketFence-users <packetfence-users@lists.sourceforge.net <mailto:packetfence-users@lists.sourceforge.net>> wrote:

    Hello Scott,

    i will need to see the content of packetfence.log to see what happen.

    Regards

    Fabrice


    Le 19-06-12 à 12 h 59, Lu, Scott via PacketFence-users a écrit :
    Hi,

    I have configured PF9 captive-portal for Guest registration and
    send email for "Network access activation",

    1. Guest click "Activate Access" then network access is good.
    2. Guest not click Activate Access" then network access is good too.
    3. If guest send email to "a...@xyz.com <mailto:a...@xyz.com>,
    a@b.c <mailto:a@b.c>, any fake/makeup email account", guest still
    have network access too.
    No termination at all after fail to register, Could you help me
    on this issue?

    We are using Ruckus Smartzone with version 3.6.2.0.78 &
    PacketFence 9.0.1

    Much appreciated!

    Scott Lu


    _______________________________________________
    PacketFence-users mailing list
    PacketFence-users@lists.sourceforge.net  
<mailto:PacketFence-users@lists.sourceforge.net>
    https://lists.sourceforge.net/lists/listinfo/packetfence-users

-- Fabrice Durand
    fdur...@inverse.ca  <mailto:fdur...@inverse.ca>  ::  +1.514.447.4918 (x135) 
::www.inverse.ca  <http://www.inverse.ca>
    Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org)

    _______________________________________________
    PacketFence-users mailing list
    PacketFence-users@lists.sourceforge.net
    <mailto:PacketFence-users@lists.sourceforge.net>
    https://lists.sourceforge.net/lists/listinfo/packetfence-users



--
Scott Lu

--
Fabrice Durand
fdur...@inverse.ca ::  +1.514.447.4918 (x135) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org)

_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to