Re: [PacketFence-users] Aruba AP and VLAN Mapping

2020-03-10 Thread Zacharry Williams via PacketFence-users
Are you using the correct distinguished name of the group? On Tue, Mar 10, 2020 at 2:04 PM Christian Sudec via PacketFence-users < packetfence-users@lists.sourceforge.net> wrote: > Hi, here the logs: > > Mar 10 12:10:21 ippf packetfence_httpd.aaa: httpd.aaa(848) INFO: > [mac:02:de:ad:04:be:ef] ha

Re: [PacketFence-users] Captive Portal Issues

2020-03-10 Thread Durand fabrice via PacketFence-users
Hello, can you provide the packetfence.log file and the profiles.conf file ? Regards Fabrice Le 20-03-10 à 15 h 19, Zacharry Williams via PacketFence-users a écrit : Hey all, Randomly it matched the correct connection profile, one time. Is this like a 9.3 bug where connection profiles aren

Re: [PacketFence-users] Aruba AP and VLAN Mapping - Addition

2020-03-10 Thread Gregor Fajdiga via PacketFence-users
Hello, Try assigning the vlan to the node and see if it works. Try installing 9.2 version. I have been stuck on similar one for 3 weeks. My nodes couldn't get the vlan I set in authenication source. With or without filter. With PF 9.2, it works flawlessly. Regards, Gregor Fajdiga Sistemski

Re: [PacketFence-users] Captive Portal Issues

2020-03-10 Thread Zacharry Williams via PacketFence-users
Hey all, Randomly it matched the correct connection profile, one time. Is this like a 9.3 bug where connection profiles aren't being match? On Mon, Mar 9, 2020 at 3:06 PM Zacharry Williams wrote: > Hey all, > > I've been working on setting up a guest LAN and a byod LAN for a few days > now. Whe

Re: [PacketFence-users] Aruba AP and VLAN Mapping - Addition

2020-03-10 Thread Fetakungen Virtual Adventurer via PacketFence-users
Ive got the same problem (previously posted) without solving it yet.. pftest works as expected but real world only gets auth but no role.. Get Outlook for iOS From: Christian Sudec via PacketFence-users Sent: Tuesday, March 10, 2020 5:19:2

Re: [PacketFence-users] Aruba AP and VLAN Mapping

2020-03-10 Thread Christian Sudec via PacketFence-users
Hi, here the logs: Mar 10 12:10:21 ippf packetfence_httpd.aaa: httpd.aaa(848) INFO: [mac:02:de:ad:04:be:ef] handling radius autz request: from switch_ip => (10.71.100.63), connection_type => Wireless-802.11-EAP,switch_mac => (b8:3a:5a:c1:8d:aa), mac => [02:de:ad:04:be:ef], port => 0, username

Re: [PacketFence-users] Aruba AP and VLAN Mapping - Addition

2020-03-10 Thread Ludovic Zammit via PacketFence-users
Post the result of that command: cat /usr/local/pf/conf/realm.conf Thanks, Ludovic Zammit lzam...@inverse.ca :: +1.514.447.4918 (x145) :: www.inverse.ca Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu ) and Pac

Re: [PacketFence-users] [External] Re: Assign the default VLAN based on a mac address

2020-03-10 Thread Gregor Fajdiga via PacketFence-users
I have now installed an older version of packetfence (9.2) and guess what. It works. It seems just like 9.3 is ignoring my authentication rules and filters. Regards, Gregor Fajdiga Sistemski administrator, Informatika System administrator, IT Delo, d.o.o. Dunajska 5, SI-1509 Ljubljana T: +3

Re: [PacketFence-users] Aruba AP and VLAN Mapping - Addition

2020-03-10 Thread Christian Sudec via PacketFence-users
Hi again! I ran 'pftest authentication Testy Testpwd' and these are the results: Authenticating against 'HTL_AD' in context 'admin'   Authentication SUCCEEDED against HTL_AD (Authentication successful.)   Matched against HTL_AD for 'authentication' rule Teachers     set_role : Teacher     set_ac

Re: [PacketFence-users] Aruba AP and VLAN Mapping

2020-03-10 Thread Christian Sudec via PacketFence-users
Hello Ludovic! On 10.03.2020 14:42, Ludovic Zammit wrote: Hello Christian, Are you doing VLAN enforcement or Role enforcement ? We're doing only 'RADIUS Enforcement' as this is the requirement for 802.1x (both wireless and wired). On Aruba you have to do one of them, not both at the same t

Re: [PacketFence-users] Aruba AP and VLAN Mapping

2020-03-10 Thread Ludovic Zammit via PacketFence-users
Ok, so if you are doing 802.1x then most of the time you do auto-registration where you don’t display the captive portal. In that case, your access would be computed on the fly. Do that and remove device info: grep MAC_ADDRESS /usr/local/pf/logs/packetfence.log My guess is that you don’t match

Re: [PacketFence-users] Aruba AP and VLAN Mapping

2020-03-10 Thread Ludovic Zammit via PacketFence-users
Hello Christian, Are you doing VLAN enforcement or Role enforcement ? On Aruba you have to do one of them, not both at the same time. How are you redirected on the captive portal ? By a radius request ? Once you get authenticated PF sends a radius disconnect message to the AP to kick your Mac

[PacketFence-users] Aruba AP and VLAN Mapping

2020-03-10 Thread Christian Sudec via PacketFence-users
Hi everybody! First the current situation so far: We installed a test-network, where the packetfence-server is reachable with an ip 10.5.1.4 (type management) and set 'RADIUS enforcement' as chosen method. Next we installed a Mikrotik-Switch (POE) with 4 VLANS (771-774) and attached an Aruba

Re: [PacketFence-users] Mikrotik routerboard cli/winbox access via Packetfence

2020-03-10 Thread Ludovic Zammit via PacketFence-users
Hello, The error is pretty obvious. It looks like your LDAP bind is failing, fix you AD-source and you would be good. Thanks, Ludovic Zammit lzam...@inverse.ca :: +1.514.447.4918 (x145) :: www.inverse.ca Inverse inc. :: Leaders behind SOG

[PacketFence-users] Mikrotik routerboard cli/winbox access via Packetfence

2020-03-10 Thread evren korkmaz via PacketFence-users
Hi, I try to use packetfence for mikrotik device cli access. I want to access with my MS Active Directory users. First i try with freeradius via ldap connection. It's working but when i try with packetfence, it doesn't work. To my understanding, mikrotik try to ldap connection but packetfence con