Re: [PacketFence-users] Many problems; Trying Inline Layer 3

2015-06-15 Thread Louis Munro
On Jun 15, 2015, at 16:59 , Stanley Bammel wrote: > I have have been working a few weeks to get PacketFence up, and have run into > a multitude of problems: > Installed PacketFence on Debian 7 (because it is the only approved Linux > which comes with functioning l2tp tunneling), and setup som

[PacketFence-users] Many problems; Trying Inline Layer 3

2015-06-15 Thread Stanley Bammel
I have have been working a few weeks to get PacketFence up, and have run into a multitude of problems: 1.. Installed PacketFence on Debian 7 (because it is the only approved Linux which comes with functioning l2tp tunneling), and setup some l2tp tunnels, but found that PacketFence will only w

Re: [PacketFence-users] pfsetvlan ERROR

2015-06-15 Thread Hugo Rodenburg
Hi, > Hi James, > > Thanks for your reply. It resolves the errors when starting pfsetvlan, but the > initial error remains: > > Jun 15 20:03:34 pfsetvlan(6) ERROR: Thread 6 terminated abnormally: Deep > recursion on subroutine > "CHI::Driver::File__WITH__CHI::Driver::Role::Universal__AND__pf::Ro

Re: [PacketFence-users] pfsetvlan ERROR

2015-06-15 Thread Hugo Rodenburg
Hi James, Thanks for your reply. It resolves the errors when starting pfsetvlan, but the initial error remains: Jun 15 20:03:34 pfsetvlan(6) ERROR: Thread 6 terminated abnormally: Deep recursion on subroutine "CHI::Driver::File__WITH__CHI::Driver::Role::Universal__AND__pf::Role::CHI::Driver::F

[PacketFence-users] Invalid accounting trigger id for violations

2015-06-15 Thread Bill Roemhild
Taking a look at the admin guide the example given is: Accounting::TOT200GB1W I added this to my violations.conf: [501] priority=1 trigger=accounting::TOT200GB1W actions=email,trap,log max_enable=2 desc=Used 200GB of data in 1 week enabled=Y template=sample auto_enable=Y vlan=isolation grace

Re: [PacketFence-users] User Authentication using 802.1X and MAB

2015-06-15 Thread Fabrice DURAND
Hi Abdelghafour, you have to define your switch in packetfence. So in configuration -> Switches -> add a new switch with the ip address : 192.168.0.254 It should be something like that in switches.conf: [192.168.0.254] description=Cisco 2960 type=Cisco::Catalyst_2960 mode=production deauth

Re: [PacketFence-users] User Authentication using 802.1X and MAB

2015-06-15 Thread Abdelghafour Rakhma
Here are what the logs look like, there is interesting happening there! which is weird! => Packetfence.log: Jun 15 10:54:48 pfcmd.pl(2238) INFO: Hard expiring resource : resource::Profile_Filters (pfconfig::manager::expire) Jun 15 10:54:48 pfcmd.pl(2238) INFO: Hard expiring resource::cluster_serv

Re: [PacketFence-users] User Authentication using 802.1X and MAB

2015-06-15 Thread Abdelghafour Rakhma
Thank you for your quick response! I'm using the latest version of PF (5.1.0), I'll provide here the configuration files: And That's what I thought Too: there is radius no communication between the server and the switch, but still i don't know how to fix that! Switch configuration (cisco 2960): !

Re: [PacketFence-users] User Authentication using 802.1X and MAB

2015-06-15 Thread Sallee, Jake
Abdelghafour: Did you add the switch in the admin GUI on PF? You can also tail the packetfence.log file when you are doing your test and you should see why PF is rejecting the authentication. This is just a shot in the dark, but my feeling is that the switch for some reason did not make it in

Re: [PacketFence-users] User Authentication using 802.1X and MAB

2015-06-15 Thread Fabrice DURAND
Hello Abdelghafour, please provide your switches.conf, pf.conf and the configuration of you cisco switch. Also can you post the radius.log (/usr/local/pf/logs/) Regards Fabrice Le 2015-06-15 11:30, Abdelghafour Rakhma a écrit : > Hello everyone! > We're deploying packefence in our university, we

[PacketFence-users] User Authentication using 802.1X and MAB

2015-06-15 Thread Abdelghafour Rakhma
Hello everyone! We're deploying packefence in our university, we've choosed the OUT-OF-BAND mode, as a basic configuration I've made a test on my Cisco catalyst 2960 switch and PF on my VMware! Overview: -

Re: [PacketFence-users] pfsetvlan ERROR

2015-06-15 Thread James Rouzier
Apply the following patch on top of the previous one. https://github.com/inverse-inc/packetfence/commit/10edc098f9f9c6360ca322c9a17571b24dbe5a11.diff James Rouzier jrouz...@inverse.ca :: +1.514.755.3630 :: http://www.inverse.ca Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and Packet

Re: [PacketFence-users] PERL modules requirements

2015-06-15 Thread James Rouzier
Good catch Fabrice James Rouzier jrouz...@inverse.ca :: +1.514.755.3630 :: http://www.inverse.ca Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence (http://www.packetfence.org) On 2015-06-12 10:00 PM, Durand fabrice wrote: Maybe just a detail but before do a: rpm -Uvh

Re: [PacketFence-users] Kerberos Authentication

2015-06-15 Thread Louis Munro
On Jun 12, 2015, at 5:14 , Nicolas Gailly wrote: > "The windows supplicant tries PEAP by default iirc. PEAP is not compatible > with kerberos." > ==> We do not use windows in our office for regular users anyway so it's fine > on this side. > > " radius server is not configured to authorize 8

Re: [PacketFence-users] pfsetvlan ERROR

2015-06-15 Thread Hugo Rodenburg
Hi Fabrice, Thanks for the quick response! > > let's try that: > > https://github.com/inverse-inc/packetfence/commit/8830ddb52225d85d1ee36d30e466c764e47bfd17.diff > #/usr/local/pf$ sudo patch -p1 < ~/8830ddb52225d85d1ee36d30e466c764e47bfd17.diff patching file addons/accounting.pl patching f