Re: [PacketFence-users] Using remote MySQL host

2015-04-21 Thread Louis Munro
On Apr 21, 2015, at 14:25 , Andy A andthereitg...@hotmail.com wrote: Change the first line in conf/log.conf.d/pfdhcplistener.conf from : log4perl.rootLogger = INFO, PFDHCPLISTENER to : log4perl.rootLogger = INFO, PFDHCPLISTENER You meant this right? Change the first line in

Re: [PacketFence-users] Using remote MySQL host

2015-04-21 Thread Louis Munro
On Apr 21, 2015, at 12:53 , Andy A andthereitg...@hotmail.com wrote: I am using a remote MySQL host (MySQL on a different box from PF installation) I have changed the database host address in pf.conf, pfconfig.conf and pf.conf.defaults. I have also used pf-schema.sql to populate the remote

[PacketFence-users] Google authentication error cannot get token

2015-04-21 Thread Steve Spence
Has anyone been getting google authentication errors . My implementation has been running fine form September 2014. But last week all the users that authenticate using google accounts start getting fail to get token errors. The initial password seem to go through find then when they accept

Re: [PacketFence-users] Using remote MySQL host

2015-04-21 Thread Louis Munro
On Apr 21, 2015, at 14:11 , Andy A andthereitg...@hotmail.com wrote: Hi Louis. PF version is 5.0 Here's the output that you requested. That seems valid. Try running pfdhcplistener with logging set to TRACE for two minutes. It should give some output that will let us know what it is

Re: [PacketFence-users] Using remote MySQL host

2015-04-21 Thread Andy A
Change the first line in conf/log.conf.d/pfdhcplistener.conffrom :log4perl.rootLogger = INFO, PFDHCPLISTENERto : log4perl.rootLogger = INFO, PFDHCPLISTENER You meant this right? Change the first line in conf/log.conf.d/pfdhcplistener.conffrom :log4perl.rootLogger = INFO, PFDHCPLISTENERto :

[PacketFence-users] pf on an older 3com 4400

2015-04-21 Thread heupink
Hi all, Configuring inline enforcement went great, but... VLAN enforcement not so much... I'm having difficulties getting VLAN enforcement to work on an (old) 3com 4400 (3C17205) 24 ports switch. Unfortunately these are the only test devices around here, until the HP ProCurve 5400 arrives.

Re: [PacketFence-users] Using remote MySQL host

2015-04-21 Thread Louis Munro
Actually, This does look like a bug. Give us a few hours, we are testing a fix. In the meantime if you want to you could try this patch: https://github.com/inverse-inc/packetfence/commit/be04b7ca372497e1e3e5d9f829e10b6e63cb8346.diff I.e. run curl -o node.patch

Re: [PacketFence-users] perform checkup | captiveportal_modperl_require.pl doesn't compile

2015-04-21 Thread heupink
Haha, ok. So it's not something to worry about :-) Thanks, MJ On 4/21/2015 14:35, Fabrice DURAND wrote: Hi, yes i have seen that too. I have to ask the dev why. Regards Fabrice Le 2015-04-21 08:23, heupink a écrit : Hi, Packetfence 5.0, clicking the perform checkup in the web admin

[PacketFence-users] Upgrade from 4.7.0 to 5.0.0 sql problem

2015-04-21 Thread luca comes
Hi all, I'm running PF version 4.7.0 on CentOS 6.6. Today I tried to update to the new release but I had some problems with the SQL procedure. My database schema is shown underneath: mysql show tables; +---+ | Tables_in_test_pf_upg | +---+ | action

Re: [PacketFence-users] Upgrade from 4.7.0 to 5.0.0 sql problem

2015-04-21 Thread Fabrice DURAND
Hello Lucas, iplog_history come from upgrade 4.3 to 4.4 ( upgrade-4.3.0-4.4.0.sql) 4.7.0 was the original release version installed ? Regards Fabrice Le 2015-04-21 08:48, luca comes a écrit : Hi all, I'm running PF version 4.7.0 on CentOS 6.6. Today I tried to update to the new release but I

Re: [PacketFence-users] Dot1.x Computer authentication

2015-04-21 Thread Calugaru Adrian
Hi Fabrice, Yes, could I send them to your email directly ? Thank youAdrian -- BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT Develop your own process in accordance with the BPMN 2 standard Learn Process

Re: [PacketFence-users] Dot1.x Computer authentication

2015-04-21 Thread Fabrice DURAND
yep Le 2015-04-21 08:57, Calugaru Adrian a écrit : Hi Fabrice, Yes, could I send them to your email directly ? Thank you Adrian -- BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT Develop your own

Re: [PacketFence-users] Upgrade to 5.0.0 still show version 4.7.0

2015-04-21 Thread Fabrice DURAND
Hello Cheslin, you are not doing something wrong, but it look that there a cache between the server and packetfence repo. Can you try to do : http://inverse.ca/downloads/PacketFence/CentOS6/x86_64/RPMS/packetfence-5.0.0-1.el6.noarch.rpm ? Regards Fabrice Le 2015-04-21 08:55, Bagley, Cheslin

Re: [PacketFence-users] PacketFence 5

2015-04-21 Thread Nicolas Gailly
If you need additional informations, do not hesitate. Or should I report this as a bug ? If I'm the only one, it may have been a misconfiguration from my part... Anyway I switched to 802.1x + MAC auth, and it works flawlessly =) Thanks. 2015-04-21 0:05 GMT+02:00 Nicolas Gailly

Re: [PacketFence-users] Upgrade from 4.7.0 to 5.0.0 sql problem

2015-04-21 Thread luca comes
Hi Fabrice, no original version installed was 4.3.0. From that point I upgraded to the versions without problems befor today. Do you think that if I try to patch it with the sql upgrade from 4.3 to 4.4 it fix the problem? thank you Luca Date: Tue, 21 Apr 2015 08:55:00 -0400 From:

[PacketFence-users] Snom 821 (v. 8.7.3.25), Cisco 2960X, LLDP

2015-04-21 Thread Steve Miller
Hello list! I'm having some issues getting a Snom 821 VoIP phone set up with packetfence and my Cisco 2960X switch. First, I was having issues having packetfence realize it was a phone, and it kept putting the phone into the registration VLAN but I started up a really basic LLDP (lldp run,

Re: [PacketFence-users] PacketFence 5

2015-04-21 Thread Fabrice DURAND
It look like you are trying 802.1x and portsec Just configure 802.1x on the switch port. Regards Fabrice Le 2015-04-21 09:29, Nicolas Gailly a écrit : Change : In fact 802.1x DOES NOT work. Client with 802.1x try to authenticate, radius respond with ACCEPT, PF set it in the registration VLAN

Re: [PacketFence-users] PacketFence 5

2015-04-21 Thread Nicolas Gailly
Change : In fact 802.1x DOES NOT work. Client with 802.1x try to authenticate, radius respond with ACCEPT, PF set it in the registration VLAN (that's OK), and that's all. The DHCP does not work it, there is no knowledge of the connectivity accepted from the client. The log is here. But NOTE that

Re: [PacketFence-users] Upgrade to 5.0.0 still show version 4.7.0

2015-04-21 Thread Bagley, Cheslin (Mr) (Summerstrand Campus North)
I assume I must do a yum install http://inverse.ca/downloads/PacketFence/CentOS6/x86_64/RPMS/packetfence-5.0.0-1.el6.noarch.rpm; . If that is the case, I did and it complains of the following: Requires: packetfence-pfcmd-suid = 5.0.0 Requires: fingerbank = 1.0.0 Requires: packetfence-config =

Re: [PacketFence-users] Upgrade to 5.0.0 still show version 4.7.0

2015-04-21 Thread Fabrice DURAND
Yes: yum cleanall yum cleanall --enablerepo=packetfence yum makecache --enablerepo=packetfence yum update packetfence --enablerepo=packetfence Regards Fabrice Le 2015-04-21 09:25, Bagley, Cheslin (Mr) (Summerstrand Campus North) a écrit : I assume I must do a yum install

Re: [PacketFence-users] perform checkup | captiveportal_modperl_require.pl doesn't compile

2015-04-21 Thread Fabrice DURAND
We use pfconfig now to keep a valid configuration for all the process of packetfence. This pfconfig try to connect to the database but it need the mysql password. So the first start will produce this warning but at the end of the configuration the password will be set and akk theses messages will

Re: [PacketFence-users] perform checkup | captiveportal_modperl_require.pl doesn't compile

2015-04-21 Thread heupink
Ok, something else I noticed during my upgrade from 4.7 - 5.0, but now I'm seeing it again installing 5.0 from scratch on a fresh system: Messages like: Could not write namespace interfaces::vlan_enforcement_nets to L2 cache ! This is bad. Could not write namespace interfaces::monitor_int to L2

Re: [PacketFence-users] Problem configuring inline mode

2015-04-21 Thread Fabrice DURAND
Hi Peter, at the end of the registration, the device try to fetch a gif at by defaut : http://192.95.20.194/ common/network-access-detection.gif . So if you change the ip address to 192.168.0.1 and common/network-access-detection.gif doesn't exist then the network detection will not work.

[PacketFence-users] perform checkup | captiveportal_modperl_require.pl doesn't compile

2015-04-21 Thread heupink
Hi, Packetfence 5.0, clicking the perform checkup in the web admin gives this error: FATAL: Apache will fail to start! /usr/local/pf/lib/pf/web/captiveportal_modperl_require.pl doesn't compile Installed on debian wheezy, everything up-to-date. I ran pf-maint.pl in addons directory, to make

[PacketFence-users] Captive portal inactive timeout

2015-04-21 Thread Dima Ermakov
Good day! I use PacketFence 4.7.0 (PF ZEN), inline enforcement I configure Captive Portal with RADIUS authentication (Windows Server 2008 R2 as RADIUS server). Can i use inactive session timeout? So, that if client PC don't uses INTERNET for example 30 minutes it will be unregistered; but if it

Re: [PacketFence-users] Dot1.x Computer authentication

2015-04-21 Thread Calugaru Adrian
Hi Fabrice I just had the time to try and still no luck. I've added under the vlan_filter.conf: [machineauth] filter = username operator = match value = host\/ [EthernetEAP] filter = connection_type operator = match value = Ethernet-EAP [1:EthernetEAPmachineauth] scope = AutoRegister role =

Re: [PacketFence-users] perform checkup | captiveportal_modperl_require.pl doesn't compile

2015-04-21 Thread Fabrice DURAND
Hi, yes i have seen that too. I have to ask the dev why. Regards Fabrice Le 2015-04-21 08:23, heupink a écrit : Hi, Packetfence 5.0, clicking the perform checkup in the web admin gives this error: FATAL: Apache will fail to start!

Re: [PacketFence-users] Dot1.x Computer authentication

2015-04-21 Thread Fabrice DURAND
Hi Adrian, do you have the packetfence.log and the radius debug ? Regards Fabrice Le 2015-04-21 08:29, Calugaru Adrian a écrit : Hi Fabrice I just had the time to try and still no luck. I've added under the vlan_filter.conf: [machineauth] filter = username operator = match value =

[PacketFence-users] Ubuntu 14

2015-04-21 Thread Steven Jones
just made an oopsie, installed ubuntu 14 and now find there is no packet fence for it Is this coming out on 14 very shortly? or is it best to install 12? regards Steven -- BPM Camp - Free Virtual Workshop May

Re: [PacketFence-users] Ubuntu 14

2015-04-21 Thread Fabrice DURAND
Hi Steven, it's on the way, i just have to find the time to do Trusty, Centos 7 and the incoming Jessy. Maybe on summer. Regards Fabrice Le 2015-04-20 23:31, Steven Jones a écrit : just made an oopsie, installed ubuntu 14 and now find there is no packet fence for it Is this coming out

Re: [PacketFence-users] Captive portal inactive timeout

2015-04-21 Thread Fabrice DURAND
Hello Dima, no it is not possible yet. The thing is that we have to detect the last traffic of the device and keep the timestamp and there is no code for that yet. Regards Fabrice Le 2015-04-21 08:01, Dima Ermakov a écrit : Good day! I use PacketFence 4.7.0 (PF ZEN), inline enforcement I

Re: [PacketFence-users] Problem configuring inline mode

2015-04-21 Thread Peter Trifonov
Dear Fabrice, at the end of the registration, the device try to fetch a gif at by defaut : http://192.95.20.194/ common/network-access-detection.gif . So if you change the ip address to 192.168.0.1 and common/network-access- detection.gif doesn't exist then the network detection will not

Re: [PacketFence-users] Captive portal inactive timeout

2015-04-21 Thread Dima Ermakov
Thank you, Fabrice! On 21 April 2015 at 15:32, Fabrice DURAND fdur...@inverse.ca wrote: Hello Dima, no it is not possible yet. The thing is that we have to detect the last traffic of the device and keep the timestamp and there is no code for that yet. Regards Fabrice Le 2015-04-21

Re: [PacketFence-users] perform checkup | captiveportal_modperl_require.pl doesn't compile

2015-04-21 Thread heupink
Hi fabrice, Thank you for your super-quick support and presence here. I have one more thing, and then i will shut up... I installed pf on a test machine this morning, no problems. Now I'm doing the same on a real server, with the packetfence/backports apt repos, and I'm getting: The following

Re: [PacketFence-users] perform checkup | captiveportal_modperl_require.pl doesn't compile

2015-04-21 Thread heupink
Hi fabrice, list, I forgot to enble the non-free repository... :-( My bad, I really have to go home. MJ On 4/21/2015 15:49, Fabrice DURAND wrote: We use pfconfig now to keep a valid configuration for all the process of packetfence. This pfconfig try to connect to the database but it need

[PacketFence-users] loop redirection

2015-04-21 Thread Dima Ermakov
Good day! I use packetfence zen 4.7, inline mode. I use default captive portal with RADIUS authentication. My client machine is windows XP pro with mozilla firefox, IE browsers. I have valid wildcart web server certificate for my domain. Date and time on client and server are correct. Now i try

Re: [PacketFence-users] Google authentication error cannot get token

2015-04-21 Thread Steve Spence
Has anyone been getting google authentication errors . My implementation has been running fine form September 2014. But last week all the users that authenticate using google accounts start getting fail to get token errors. The initial password seem to go through find then when they accept

Re: [PacketFence-users] Problem configuring inline mode

2015-04-21 Thread Peter Trifonov
Hi Fabrice, let's run pf-maint.pl in addons directory. Thanks a lot! After application of the patches, the exception does not appear anymore, and the users are able to access the network. However, they still see for a few seconds message Cannot detect network connectivity before being

[PacketFence-users] Using remote MySQL host

2015-04-21 Thread Andy A
Hello. I am using a remote MySQL host (MySQL on a different box from PF installation)I have changed the database host address in pf.conf, pfconfig.conf and pf.conf.defaults. I have also used pf-schema.sql to populate the remote DB host. I am unable to get an IP address via DHCP because when a

[PacketFence-users] Packetfence v5.0.0: iptables error

2015-04-21 Thread Allan Amores Sorensen
Hello, I recently upgraded out packetfence test server from v4.7.0 to v5.0.0. I am currently trying to configure Inline enforcement, but I'm getting errors when starting the iptables services. Those errors are the following ones: Use of uninitialized value $protocol in concatenation (.) Or

Re: [PacketFence-users] Help , Looking for Vlan isolation with some scenarios?

2015-04-21 Thread Tal Bar-Or
Thanks ALL for the answer , Sorry to bother again with this topic , but i need to understand the concept :-) I have on my LAN 3 users VLAN'S 17 18 19 , should i set in pfence Nic for each vlan? On the switch side how specific config set for Procuve 2910,20 toward Pfence 801.x and MAC Auth ?

[PacketFence-users] Missing packages during packet fence upgrade

2015-04-21 Thread Leja, Maciej
Curious if you guys have seen any of these two issues during packet fence upgrade/ install in Red Hat (running 6.5) Get it on a clean install of packet fence and am getting it when upgrading to 5 now. Installing some of these through CPAN still generates the same missing packages. Probably