[Packetfence-users] PacketFence and routed networks

2011-06-30 Thread Mark Duling
Hello all, I'm new to PF and planning a test setup. I've read as much as I can of the docs and mailing lists, but I still have a few questions about how I need to setup PF. My planned setup is for all registration and isolation vlans to be routed --none will be local--since our campus uses route

Re: [Packetfence-users] LDAP auth for webui issue in PF 2.2.1

2011-06-30 Thread Ritter, Nicholas
[root@pfence01 authentication]# ldapsearch -x -b "OU=IS,OU=Users,OU=American OUs,dc=ds,dc=atv" -h 10.10.0.26 -W -D "redacted" "sAMAccountName=nritter" dn Enter LDAP Password: # extended LDIF # # LDAPv3 # base with scope subtree # filter: sAMAccountName=nritter # requesting: dn # # Ri

Re: [Packetfence-users] Solitary confinement in the isolation and registration VLANs

2011-06-30 Thread Francois Gaudreault
Hi Brent, Glad everything is working, it may be also a good idea to restrict the registration VLAN the same way. I created a FAQ entry on our website with that information. I am sure a lot of people will be interested about that "feature". Also I am wandering if this is available with othe

Re: [Packetfence-users] LDAP auth for webui issue in PF 2.2.1

2011-06-30 Thread Ritter, Nicholas
Anonymous binds are not permitted. See below: [root@pfence01 conf]# ldapsearch -h 10.10.0.26 -p 389 -x -b "OU=IS,OU=Users,OU=American OUs,dc=ds,dc=atv" # extended LDIF # # LDAPv3 # base with scope subtree # filter: (objectclass=*) # requesting: ALL # # search result search: 2 r

Re: [Packetfence-users] LDAP auth for webui issue in PF 2.2.1

2011-06-30 Thread Francois Gaudreault
HI Nicholas, I updated to PF 2.2.1 last night, everything is working great with the exception that the PF admin WebUI login is requiring a valid username from the context I have specified in admin_ldap.conf, but ignoring the password entered, and a password does not even need to be entered. A

[Packetfence-users] LDAP auth for webui issue in PF 2.2.1

2011-06-30 Thread Ritter, Nicholas
I updated to PF 2.2.1 last night, everything is working great with the exception that the PF admin WebUI login is requiring a valid username from the context I have specified in admin_ldap.conf, but ignoring the password entered, and a password does not even need to be entered. A tcpdump on the PF

Re: [Packetfence-users] Solitary confinement in the isolation and registration VLANs

2011-06-30 Thread Brent Knotts
I missed something really important (initial DHCP broadcast) and added another out of preference (being able to ping the PacketFence server for troubleshooting): ip access-list extended pf_isolation 10 permit ip host pf_host any 15 permit icmp any host pf_host 20 permit tcp any host pf_host eq w

Re: [Packetfence-users] possible bug in PF 2.2.2

2011-06-30 Thread Sallee, Stephen (Jake)
> We already released that version? I thought we were at 2.2.1 ;) Oops! : ) I have submitted bug# 0001229 ... but I accidentally set the severity to block I realized it just as I submitted it, sorry! I still haven't fully recovered from pulling an all-nighter last night, my apologies. Again (a

Re: [Packetfence-users] possible bug in PF 2.2.2

2011-06-30 Thread Olivier Bilodeau
> possible bug in PF 2.2.2 We already released that version? I thought we were at 2.2.1 ;) > I don’t know if this is a bug or not but it is interesting: > > My wifi equipment (Xirrus) does not send the radius value for NAS-Port > when using RADIUS MAC (read NOT 802.1x but still RADIUS) This c

[Packetfence-users] possible bug in PF 2.2.2

2011-06-30 Thread Sallee, Stephen (Jake)
I don't know if this is a bug or not but it is interesting: My wifi equipment (Xirrus) does not send the radius value for NAS-Port when using RADIUS MAC (read NOT 802.1x but still RADIUS) This causes an entry not to be made in the locationlog table in the DB since the port field is not allowed