Hello Miradji,

WLC 9800 uses port 1700 for CoA.

Change it under the switch definition on PacketFence switch.

Thanks,



Ludovic Zammit
Product Support Engineer Principal Lead

Cell: +1.613.670.8432
Akamai Technologies - Inverse
145 Broadway
Cambridge, MA 02142
Connect with Us:         <https://community.akamai.com/>  
<http://blogs.akamai.com/>  <https://twitter.com/akamai>  
<http://www.facebook.com/AkamaiTechnologies>  
<http://www.linkedin.com/company/akamai-technologies>  
<http://www.youtube.com/user/akamaitechnologies?feature=results_main>

> On Jul 28, 2026, at 6:02 PM, Miradji AMIZERO via PacketFence-users 
> <[email protected]> wrote:
> 
> This Message Is From an External Sender
> This message came from outside your organization.
> Dear All,
> we on our side are confugrind the webauth with CIsco 9800 wireless controller 
> and PH version 15, all the flow is okay but at the end a device says : Your 
> network acces is currently being enabled,,,,, but at the end, it says Your 
> network should be enabled within a minute or two , if it is not reboot your 
> computer,,,, and the device does nt really connect to internet . below some 
> logs of the device
> 
>  sudo grep -Ri "1e:3e:ed:ef:69:17" /usr/local/pf/logs/
> /usr/local/pf/logs/packetfence.log:2026-07-28T15:45:47.418433-05:00 
> unvmc-hq-nac pfqueue-backend[5313]: pfqueue(5313) INFO: [mac:unknown] 
> DHCPREQUEST from 1e:3e:ed:ef:69:17 (10.178.57.156) 
> (pf::dhcp::processor_v4::parse_dhcp_request)
> /usr/local/pf/logs/packetfence.log:2026-07-28T15:45:47.463572-05:00 
> unvmc-hq-nac httpd.webservices-docker-wrapper[3414]: httpd.webservices(11486) 
> INFO: [mac:1e:3e:ed:ef:69:17] Instantiate profile default 
> (pf::Connection::ProfileFactory::_from_profile)
> /usr/local/pf/logs/packetfence.log:2026-07-28T15:46:26.892401-05:00 
> unvmc-hq-nac httpd.portal-docker-wrapper[6343]: httpd.portal(184) INFO: 
> [mac:0] [1e:3e:ed:ef:69:17] Activation code sent to email [email protected] 
> <mailto:[email protected]> from [email protected] 
> <mailto:[email protected]> successfully verified.  for activation type: 
> sponsor (pf::activation::validate_code)
> /usr/local/pf/logs/packetfence.log:2026-07-28T15:46:27.058705-05:00 
> unvmc-hq-nac httpd.portal-docker-wrapper[6343]: httpd.portal(184) INFO: 
> [mac:0] security_event 1300003 force-closed for 1e:3e:ed:ef:69:17 
> (pf::security_event::security_event_force_close)
> /usr/local/pf/logs/packetfence.log:2026-07-28T15:58:24.154557-05:00 
> unvmc-hq-nac pfqueue-backend[5352]: pfqueue(5352) INFO: [mac:unknown] 
> DHCPREQUEST from 1e:3e:ed:ef:69:17 (10.178.57.156) 
> (pf::dhcp::processor_v4::parse_dhcp_request)
> /usr/local/pf/logs/packetfence.log:2026-07-28T15:58:24.199907-05:00 
> unvmc-hq-nac httpd.webservices-docker-wrapper[3414]: httpd.webservices(11486) 
> INFO: [mac:1e:3e:ed:ef:69:17] Instantiate profile default 
> (pf::Connection::ProfileFactory::_from_profile)  and on the WIRELESS 
> CONTROLLER 
> 
> show wireless profile policy detailed UNVMC-WIFI-GUEST | include VLAN
> VLAN                                : UNVMC-WIFI-GUEST
> Multicast VLAN                      : 0
> OSEN client VLAN                    :
>   VLAN based Central Switching      : DISABLED
>   VLAN_ID                           : DISABLED
>   Client VLAN                       : DISABLED
> UNVMC-WLAN-CNTL1#show wireless client mac-address 1e3e.edef.6917 detail
> 
> Client MAC Address : 1e3e.edef.6917
> Client MAC Type : Locally Administered Address
> Client DUID: NA
> Client IPv4 Address : 10.178.57.156
> Client IPv6 Addresses : fe80::1c3e:edff:feef:6917
> Client Username: N/A
> AP MAC Address : 002c.c8cd.3840
> AP Name: FLR2-UNVMC-Security
> AP slot : 1
> Client State : Associated
> Policy Profile : UNVMC-WIFI-GUEST
> Flex Profile : N/A
> Wireless LAN Id: 5
> WLAN Profile Name: UNVMC-WIFI-GUEST
> Wireless LAN Network Name (SSID): UNVMC-WIFI-GUEST
> BSSID : 002c.c8cd.3849
> Connected For : 20 seconds
> Protocol : 802.11ac
> Channel : 100
> Client IIF-ID : 0xa0000149
> Association Id : 4
> Authentication Algorithm : Open System
> Idle state timeout : N/A
> Session Timeout : 28800 sec (Timer not running)
> Session Warning Time : Timer not running
> Input Policy Name  : None
> Input Policy State : None
> Input Policy Source : None
> Output Policy Name  : None
> Output Policy State : None
> Output Policy Source : None
> WMM Support : Enabled
> U-APSD Support : Disabled
> Fastlane Support : Disabled
> Client Active State : In-Active
> Power Save : OFF
> Supported Rates : 6.0,9.0,12.0,18.0,24.0,36.0,48.0,54.0
> AAA QoS Rate Limit Parameters:
>   QoS Average Data Rate Upstream             : 0 (kbps)
>   QoS Realtime Average Data Rate Upstream    : 0 (kbps)
>   QoS Burst Data Rate Upstream               : 0 (kbps)
>   QoS Realtime Burst Data Rate Upstream      : 0 (kbps)
>   QoS Average Data Rate Downstream           : 0 (kbps)
>   QoS Realtime Average Data Rate Downstream  : 0 (kbps)
>   QoS Burst Data Rate Downstream             : 0 (kbps)
>   QoS Realtime Burst Data Rate Downstream    : 0 (kbps)
> Mobility:
>   Move Count                  : 0
>   Mobility Role               : Local
>   Mobility Roam Type          : None
>   Mobility Complete Timestamp : 07/28/2026 16:19:32 COL
> Client Join Time:
>   Join Time Of Client : 07/28/2026 16:19:32 COL
> Client State Servers : None
> Client ACLs : None
> Policy Manager State: Webauth Pending
> Last Policy Manager State : IP Learn Complete
> Client Entry Create Time : 20 seconds
> Policy Type : N/A
> Encryption Cipher : None
> Transition Disable Bitmap : 0x00
> User Defined (Private) Network : Disabled
> User Defined (Private) Network Drop Unicast : Disabled
> Encrypted Traffic Analytics : No
> Protected Management Frame - 802.11w : No
> EAP Type : Not Applicable
> VLAN Override after Webauth : No
> VLAN : UNVMC-WIFI-GUEST
> Multicast VLAN : 0
> VRF Name : N/A
> WiFi Direct Capabilities:
>   WiFi Direct Capable           : No
> Central NAT : DISABLED
> Session Manager:
>   Point of Attachment : capwap_90000009
>   IIF ID             : 0x90000009
>   Authorized         : FALSE
>   Session timeout    : 28800
>   Common Session ID: 4206B20A0013DAE2AA98C624
>   Acct Session ID  : 0x00000000
>   Auth Method Status List
>         Method : Web Auth
>                 Webauth State    : Login
>                 Webauth Method   : Webauth
>   Local Policies:
>         Service Template : IP-Adm-V6-Int-ACL-global (priority 100)
>                 URL Redirect ACL : IP-Adm-V6-Int-ACL-global
>                 Preauth ACL      : preauth_v6
>         Service Template : WA-v4-int-10.178.10.147-5 (priority 100)
>                 URL Redirect ACL : WA-v4-int-10.178.10.147
>                 Preauth ACL      : PREAUTH-GUEST
>         Service Template : wlan_svc_UNVMC-WIFI-GUEST_local (priority 254)
>                 VLAN             : UNVMC-WIFI-GUEST
>                 Absolute-Timer   : 28800
>   Server Policies:
>   Resultant Policies:
>                 URL Redirect ACL : IP-Adm-V6-Int-ACL-global
>                 Preauth ACL      : preauth_v6
>                 URL Redirect ACL : WA-v4-int-10.178.10.147
>                 Preauth ACL      : PREAUTH-GUEST
>                 VLAN Name        : UNVMC-WIFI-GUEST
>                 VLAN             : 555
>                 Absolute-Timer   : 28800
> DNS Snooped IPv4 Addresses : None
> DNS Snooped IPv6 Addresses : None
> Client Capabilities
>   CF Pollable : Not implemented
>   CF Poll Request : Not implemented
>   Short Preamble : Not implemented
>   PBCC : Not implemented
>   Channel Agility : Not implemented
>   Listen Interval : 0
> Fast BSS Transition Details :
>   Reassociation Timeout : 0
> 11v BSS Transition : Implemented
> 11v DMS Capable : No
> QoS Map Capable : Yes
> FlexConnect Data Switching : Central
> FlexConnect Dhcp Status : Central
> FlexConnect Authentication : Central
> Client Statistics:
>   Number of Bytes Received from Client : 0
>   Number of Bytes Sent to Client : 0
>   Number of Packets Received from Client : 0
>   Number of Packets Sent to Client : 0
>   Number of Data Retries : 0
>   Number of RTS Retries : 0
>   Number of Tx Total Dropped Packets : 10
>   Number of Duplicate Received Packets : 0
>   Number of Decrypt Failed Packets : 0
>   Number of Mic Failured Packets : 0
>   Number of Mic Missing Packets : 0
>   Number of Policy Errors : 0
>   Radio Signal Strength Indicator : -64 dBm
>   Signal to Noise Ratio : 32 dB
> Fabric status : Disabled
> Radio Measurement Enabled Capabilities
>   Capabilities: Link Measurement, Neighbor Report, Repeated Measurements, 
> Passive Beacon Measurement, Active Beacon Measurement, Table Beacon 
> Measurement, RM MIB
> Client Scan Report Time : Timer not running
> Client Scan Reports
> Assisted Roaming Neighbor List
> Nearby AP Statistics:
> EoGRE : Pending Classification
> Device Classification Information:
>   Device Type      : Unknown (Phone)
>   Device Name      : Unknown
>   Protocol Map     : 0x000401  (OUI, DOT11)
>   Device OS        : Android 16
>   Software Version        : ZE9
>   Software Version(Carrier Code)     : ZE9(COM)
>   Device Vendor        : Samsung
>   Country        : Unknown
>   Device Protocol  : DOT11
>     Type             : 0    11
>     Data             : 0b
>     00000000  00 00 00 07 55 6e 6b 6e  6f 77 6e                  |....Unknown 
>     |
>     Type             : 1    7
>     Data             : 07
>     00000000  00 01 00 03 5a 45 39                              |....ZE9      
>    |
>     Type             : 2    7
>     Data             : 07
>     00000000  00 02 00 03 43 4f 4d                              |....COM      
>    |
>     Type             : 3    5
>     Data             : 05
>     00000000  00 03 00 01 31                                    |....1        
>    |
>     Type             : 4    14
>     Data             : 0e
>     00000000  00 04 00 0a 41 6e 64 72  6f 69 64 20 31 36         |....Android 
> 16  |
>     Type             : 5    11
>     Data             : 0b
>     00000000  00 05 00 07 55 6e 6b 6e  6f 77 6e                  |....Unknown 
>     |
>     Type             : 10   5
>     Data             : 05
>     00000000  00 0a 00 01 32                                    |....2        
>    |
> Max Client Protocol Capability: 802.11ac Wave 2
> WiFi to Cellular Steering : Not implemented
> Cellular Capability : N/A
> Advanced Scheduling Requests Details:
>   Apple Specific Requests(ASR) Capabilities/Statistics:
>     Regular ASR support: DISABLED
> 
> UNVMC-WLAN-CNTL1# show wireless client summary | include 1e3e
> 1e3e.edef.6917 FLR2-UNVMC-Security                            WLAN 5    
> Webauth Pending   11ac     Web Auth   Local
> UNVMC-WLAN-CNTL1#
> UNVMC-WLAN-CNTL1#show run | section radius-server attribute
> radius-server attribute 6 on-for-login-auth
> 
> 
> any help is the most welcome 
> 
> 
> 
> Le jeu. 7 mai 2026 à 07:56, Christos Ntokos via PacketFence-users 
> <[email protected] 
> <mailto:[email protected]>> a écrit :
>> Hello,
>> 
>>  
>> 
>> We are using Packetfence to implement a captive portal for authenticating 
>> guest users connecting via WiFi and being authenticated via Web auth 
>> (external portal). The guest user can register using email and SMS. The WiFi 
>> equipment is a Huawei Wireless LAN Controller. We have completed the 
>> implementation and it works fine.
>> 
>> Now we want to apply a daily time limit, different for each type of user. 
>> So, on our two authentication sources I applied the attributes:
>> 
>> Email source: access-duration: 1 day, time-balance: 3 hours
>> SMS source: access-duration: 1 day, time-balance: 12 hours
>> But the behavior is as follows: after the time-balance has been consumed, a 
>> time-expiration security event is created but it has no release date. Now 
>> the guest user is stuck in quarantine. The only remediation is for the 
>> portal administrator to manually release the security event and the user can 
>> connect again. We obviously cannot do that for our (hundreds of expected) 
>> daily users.
>> 
>> I tried to edit the time-expiration security event and enable the ‘dynamic 
>> window’ but it has no effect.
>> 
>> The only thing that kinda works it to set a time value in the ‘window’ 
>> property of the time-expiration security event, but that is not desirable 
>> since:
>> 
>> we cannot distinguish between email/SMS-registered users,
>> window time starts counting after the user has exhausted time time-balance 
>> which can be anytime during the day.
>>  
>> 
>> So, is there another way to implement daily time limits for my guest users. 
>> It should be straightforward and I don’t see why such a feature-rich and 
>> powerful NAC suite as Packetfence is would not be able to do it.
>> 
>>  
>> 
>> Thanks
>> 
>>  
>> 
>> Christos Ntokos
>> 
>> -----------------------------------------------------------------
>> 
>> Network Services and Infrastructure Department
>> 
>> Digital Governance Unit, University of Ioannina, GR
>> 
>>  
>> 
>>  
>> 
>> _______________________________________________
>> PacketFence-users mailing list
>> [email protected] 
>> <mailto:[email protected]>
>> https://lists.sourceforge.net/lists/listinfo/packetfence-users 
>> <https://urldefense.com/v3/__https://lists.sourceforge.net/lists/listinfo/packetfence-users__;!!GjvTz_vk!XfE0QY5b-EzA6n-k0KfIshXeT0lS8crnJ_p5TYF6NbGPU3luoVihIed0w8UsD0Jh4UkxlU5ufBAGX7D0ZTxX_iDbCQpd7UsMmHD8TQ$>
> _______________________________________________
> PacketFence-users mailing list
> [email protected] 
> <mailto:[email protected]>
> https://urldefense.com/v3/__https://lists.sourceforge.net/lists/listinfo/packetfence-users__;!!GjvTz_vk!XfE0QY5b-EzA6n-k0KfIshXeT0lS8crnJ_p5TYF6NbGPU3luoVihIed0w8UsD0Jh4UkxlU5ufBAGX7D0ZTxX_iDbCQpd7UsMmHD8TQ$

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to