Dear All,
we on our side are confugrind the webauth with CIsco 9800 wireless
controller and PH version 15, all the flow is okay but at the end a device
says : Your network acces is currently being enabled,,,,, but at the end,
it says Your network should be enabled within a minute or two , if it is
not reboot your computer,,,, and the device does nt really connect to
internet . below some logs of the device

 sudo grep -Ri "1e:3e:ed:ef:69:17" /usr/local/pf/logs/
/usr/local/pf/logs/packetfence.log:2026-07-28T15:45:47.418433-05:00
unvmc-hq-nac pfqueue-backend[5313]: pfqueue(5313) INFO: [mac:unknown]
DHCPREQUEST from 1e:3e:ed:ef:69:17 (10.178.57.156)
(pf::dhcp::processor_v4::parse_dhcp_request)
/usr/local/pf/logs/packetfence.log:2026-07-28T15:45:47.463572-05:00
unvmc-hq-nac httpd.webservices-docker-wrapper[3414]:
httpd.webservices(11486) INFO: [mac:1e:3e:ed:ef:69:17] Instantiate profile
default (pf::Connection::ProfileFactory::_from_profile)
/usr/local/pf/logs/packetfence.log:2026-07-28T15:46:26.892401-05:00
unvmc-hq-nac httpd.portal-docker-wrapper[6343]: httpd.portal(184) INFO:
[mac:0] [1e:3e:ed:ef:69:17] Activation code sent to email [email protected]
from [email protected] successfully verified.  for activation type:
sponsor (pf::activation::validate_code)
/usr/local/pf/logs/packetfence.log:2026-07-28T15:46:27.058705-05:00
unvmc-hq-nac httpd.portal-docker-wrapper[6343]: httpd.portal(184) INFO:
[mac:0] security_event 1300003 force-closed for 1e:3e:ed:ef:69:17
(pf::security_event::security_event_force_close)
/usr/local/pf/logs/packetfence.log:2026-07-28T15:58:24.154557-05:00
unvmc-hq-nac pfqueue-backend[5352]: pfqueue(5352) INFO: [mac:unknown]
DHCPREQUEST from 1e:3e:ed:ef:69:17 (10.178.57.156)
(pf::dhcp::processor_v4::parse_dhcp_request)
/usr/local/pf/logs/packetfence.log:2026-07-28T15:58:24.199907-05:00
unvmc-hq-nac httpd.webservices-docker-wrapper[3414]:
httpd.webservices(11486) INFO: [mac:1e:3e:ed:ef:69:17] Instantiate profile
default (pf::Connection::ProfileFactory::_from_profile)  and on the
WIRELESS CONTROLLER

show wireless profile policy detailed UNVMC-WIFI-GUEST | include VLAN
VLAN                                : UNVMC-WIFI-GUEST
Multicast VLAN                      : 0
OSEN client VLAN                    :
  VLAN based Central Switching      : DISABLED
  VLAN_ID                           : DISABLED
  Client VLAN                       : DISABLED
UNVMC-WLAN-CNTL1#show wireless client mac-address 1e3e.edef.6917 detail

Client MAC Address : 1e3e.edef.6917
Client MAC Type : Locally Administered Address
Client DUID: NA
Client IPv4 Address : 10.178.57.156
Client IPv6 Addresses : fe80::1c3e:edff:feef:6917
Client Username: N/A
AP MAC Address : 002c.c8cd.3840
AP Name: FLR2-UNVMC-Security
AP slot : 1
Client State : Associated
Policy Profile : UNVMC-WIFI-GUEST
Flex Profile : N/A
Wireless LAN Id: 5
WLAN Profile Name: UNVMC-WIFI-GUEST
Wireless LAN Network Name (SSID): UNVMC-WIFI-GUEST
BSSID : 002c.c8cd.3849
Connected For : 20 seconds
Protocol : 802.11ac
Channel : 100
Client IIF-ID : 0xa0000149
Association Id : 4
Authentication Algorithm : Open System
Idle state timeout : N/A
Session Timeout : 28800 sec (Timer not running)
Session Warning Time : Timer not running
Input Policy Name  : None
Input Policy State : None
Input Policy Source : None
Output Policy Name  : None
Output Policy State : None
Output Policy Source : None
WMM Support : Enabled
U-APSD Support : Disabled
Fastlane Support : Disabled
Client Active State : In-Active
Power Save : OFF
Supported Rates : 6.0,9.0,12.0,18.0,24.0,36.0,48.0,54.0
AAA QoS Rate Limit Parameters:
  QoS Average Data Rate Upstream             : 0 (kbps)
  QoS Realtime Average Data Rate Upstream    : 0 (kbps)
  QoS Burst Data Rate Upstream               : 0 (kbps)
  QoS Realtime Burst Data Rate Upstream      : 0 (kbps)
  QoS Average Data Rate Downstream           : 0 (kbps)
  QoS Realtime Average Data Rate Downstream  : 0 (kbps)
  QoS Burst Data Rate Downstream             : 0 (kbps)
  QoS Realtime Burst Data Rate Downstream    : 0 (kbps)
Mobility:
  Move Count                  : 0
  Mobility Role               : Local
  Mobility Roam Type          : None
  Mobility Complete Timestamp : 07/28/2026 16:19:32 COL
Client Join Time:
  Join Time Of Client : 07/28/2026 16:19:32 COL
Client State Servers : None
Client ACLs : None
Policy Manager State: Webauth Pending
Last Policy Manager State : IP Learn Complete
Client Entry Create Time : 20 seconds
Policy Type : N/A
Encryption Cipher : None
Transition Disable Bitmap : 0x00
User Defined (Private) Network : Disabled
User Defined (Private) Network Drop Unicast : Disabled
Encrypted Traffic Analytics : No
Protected Management Frame - 802.11w : No
EAP Type : Not Applicable
VLAN Override after Webauth : No
VLAN : UNVMC-WIFI-GUEST
Multicast VLAN : 0
VRF Name : N/A
WiFi Direct Capabilities:
  WiFi Direct Capable           : No
Central NAT : DISABLED
Session Manager:
  Point of Attachment : capwap_90000009
  IIF ID             : 0x90000009
  Authorized         : FALSE
  Session timeout    : 28800
  Common Session ID: 4206B20A0013DAE2AA98C624
  Acct Session ID  : 0x00000000
  Auth Method Status List
        Method : Web Auth
                Webauth State    : Login
                Webauth Method   : Webauth
  Local Policies:
        Service Template : IP-Adm-V6-Int-ACL-global (priority 100)
                URL Redirect ACL : IP-Adm-V6-Int-ACL-global
                Preauth ACL      : preauth_v6
        Service Template : WA-v4-int-10.178.10.147-5 (priority 100)
                URL Redirect ACL : WA-v4-int-10.178.10.147
                Preauth ACL      : PREAUTH-GUEST
        Service Template : wlan_svc_UNVMC-WIFI-GUEST_local (priority 254)
                VLAN             : UNVMC-WIFI-GUEST
                Absolute-Timer   : 28800
  Server Policies:
  Resultant Policies:
                URL Redirect ACL : IP-Adm-V6-Int-ACL-global
                Preauth ACL      : preauth_v6
                URL Redirect ACL : WA-v4-int-10.178.10.147
                Preauth ACL      : PREAUTH-GUEST
                VLAN Name        : UNVMC-WIFI-GUEST
                VLAN             : 555
                Absolute-Timer   : 28800
DNS Snooped IPv4 Addresses : None
DNS Snooped IPv6 Addresses : None
Client Capabilities
  CF Pollable : Not implemented
  CF Poll Request : Not implemented
  Short Preamble : Not implemented
  PBCC : Not implemented
  Channel Agility : Not implemented
  Listen Interval : 0
Fast BSS Transition Details :
  Reassociation Timeout : 0
11v BSS Transition : Implemented
11v DMS Capable : No
QoS Map Capable : Yes
FlexConnect Data Switching : Central
FlexConnect Dhcp Status : Central
FlexConnect Authentication : Central
Client Statistics:
  Number of Bytes Received from Client : 0
  Number of Bytes Sent to Client : 0
  Number of Packets Received from Client : 0
  Number of Packets Sent to Client : 0
  Number of Data Retries : 0
  Number of RTS Retries : 0
  Number of Tx Total Dropped Packets : 10
  Number of Duplicate Received Packets : 0
  Number of Decrypt Failed Packets : 0
  Number of Mic Failured Packets : 0
  Number of Mic Missing Packets : 0
  Number of Policy Errors : 0
  Radio Signal Strength Indicator : -64 dBm
  Signal to Noise Ratio : 32 dB
Fabric status : Disabled
Radio Measurement Enabled Capabilities
  Capabilities: Link Measurement, Neighbor Report, Repeated Measurements,
Passive Beacon Measurement, Active Beacon Measurement, Table Beacon
Measurement, RM MIB
Client Scan Report Time : Timer not running
Client Scan Reports
Assisted Roaming Neighbor List
Nearby AP Statistics:
EoGRE : Pending Classification
Device Classification Information:
  Device Type      : Unknown (Phone)
  Device Name      : Unknown
  Protocol Map     : 0x000401  (OUI, DOT11)
  Device OS        : Android 16
  Software Version        : ZE9
  Software Version(Carrier Code)     : ZE9(COM)
  Device Vendor        : Samsung
  Country        : Unknown
  Device Protocol  : DOT11
    Type             : 0    11
    Data             : 0b
    00000000  00 00 00 07 55 6e 6b 6e  6f 77 6e
 |....Unknown     |
    Type             : 1    7
    Data             : 07
    00000000  00 01 00 03 5a 45 39                              |....ZE9
      |
    Type             : 2    7
    Data             : 07
    00000000  00 02 00 03 43 4f 4d                              |....COM
      |
    Type             : 3    5
    Data             : 05
    00000000  00 03 00 01 31                                    |....1
      |
    Type             : 4    14
    Data             : 0e
    00000000  00 04 00 0a 41 6e 64 72  6f 69 64 20 31 36
|....Android 16  |
    Type             : 5    11
    Data             : 0b
    00000000  00 05 00 07 55 6e 6b 6e  6f 77 6e
 |....Unknown     |
    Type             : 10   5
    Data             : 05
    00000000  00 0a 00 01 32                                    |....2
      |
Max Client Protocol Capability: 802.11ac Wave 2
WiFi to Cellular Steering : Not implemented
Cellular Capability : N/A
Advanced Scheduling Requests Details:
  Apple Specific Requests(ASR) Capabilities/Statistics:
    Regular ASR support: DISABLED

UNVMC-WLAN-CNTL1# show wireless client summary | include 1e3e
1e3e.edef.6917 FLR2-UNVMC-Security                            WLAN 5
 Webauth Pending   11ac     Web Auth   Local
UNVMC-WLAN-CNTL1#
UNVMC-WLAN-CNTL1#show run | section radius-server attribute
radius-server attribute 6 on-for-login-auth


any help is the most welcome



Le jeu. 7 mai 2026 à 07:56, Christos Ntokos via PacketFence-users <
[email protected]> a écrit :

> Hello,
>
>
>
> We are using Packetfence to implement a captive portal for authenticating
> guest users connecting via WiFi and being authenticated via Web auth
> (external portal). The guest user can register using email and SMS. The
> WiFi equipment is a Huawei Wireless LAN Controller. We have completed the
> implementation and it works fine.
>
> Now we want to apply a daily time limit, different for each type of user.
> So, on our two authentication sources I applied the attributes:
>
>    - Email source: access-duration: 1 day, time-balance: 3 hours
>    - SMS source: access-duration: 1 day, time-balance: 12 hours
>
> But the behavior is as follows: after the time-balance has been consumed,
> a time-expiration security event is created but it has no release date. Now
> the guest user is stuck in quarantine. The only remediation is for the
> portal administrator to manually release the security event and the user
> can connect again. We obviously cannot do that for our (hundreds of
> expected) daily users.
>
> I tried to edit the time-expiration security event and enable the ‘dynamic
> window’ but it has no effect.
>
> The only thing that kinda works it to set a time value in the ‘window’
> property of the time-expiration security event, but that is not desirable
> since:
>
>    - we cannot distinguish between email/SMS-registered users,
>    - window time starts counting after the user has exhausted time
>    time-balance which can be anytime during the day.
>
>
>
> So, is there another way to implement daily time limits for my guest
> users. It should be straightforward and I don’t see why such a feature-rich
> and powerful NAC suite as Packetfence is would not be able to do it.
>
>
>
> Thanks
>
>
>
> Christos Ntokos
>
> -----------------------------------------------------------------
>
> Network Services and Infrastructure Department
>
> Digital Governance Unit, University of Ioannina, GR
>
>
>
>
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to