Re: [PacketFence-users] PKI installation

2018-02-06 Thread Fabrice Durand via PacketFence-users
Hello Eugene, can you try that: sqlite3 db.sqlite3 UPDATE "auth_user" set password='pbkdf2_sha256$2$Z2Lhr1cW8QM0$mN9PtNhxneIDzApqFa4uG8V44IXqHe+r7yootSoSzJQ=' where username='admin'; the password is p@ck3tf3nc3 Regards Fabrice Le 2018-02-03 à 01:31, E.P. a écrit : > > Hi Fabrice, > >

Re: [PacketFence-users] Restarting swicthports errors

2018-02-06 Thread Fabrice Durand via PacketFence-users
Hello, the issue is open on github https://github.com/inverse-inc/packetfence/issues/2923 Regards Fabrice Le 2018-02-02 à 10:43, David Harvey via PacketFence-users a écrit : > Sorry for all the mailing list spam. I've been having a bit of a > packetfence tinkering week! > > Since upgrading t

Re: [PacketFence-users] users stay in registration VLAN after authentication success

2018-02-06 Thread Fabrice Durand via PacketFence-users
Hello Tom, sorry, this is a really busy period. What we can try to find the issue is to put the log in debug, since it looks that is on the portal that you have the issue we can try it first. So in conf/log.conf.d/httpd.portal.conf , replace INFO per TRACE (2nd line) and restart the portal. Onc

Re: [PacketFence-users] PFCMD Violation ADD & TRIGGER Clarification

2018-02-06 Thread Fabrice Durand via PacketFence-users
Hello Scott, it looks a bug in PacketFence, can you open an issue on github ? https://github.com/inverse-inc/packetfence Regards Fabrice Le 2018-02-01 à 15:05, Scott Bodeen via PacketFence-users a écrit : > Hello all, > > I've spent a good part of the day looking through the PF manuals and >

Re: [PacketFence-users] R: R: R: No client IP update in cluster

2018-01-31 Thread Fabrice Durand via PacketFence-users
Hello Luca, dhcp is udp traffic so it's not really easy to load balance. Btw there is a pull request on github for that: https://github.com/inverse-inc/packetfence/pull/2887 Regards Fabrice Le 2018-01-31 à 03:40, luca comes via PacketFence-users a écrit : > Hi Fabrice, > I checked and what

Re: [PacketFence-users] packetfence 7.4 + Authentication Sources

2018-01-31 Thread Fabrice Durand via PacketFence-users
Hello Will, yes i saw that on my setup and we will push a fix in the maintenance. Regards Fabrice Le 2018-01-31 à 08:00, Will Halsall via PacketFence-users a écrit : > > Hi Folks, > >   > > Adding an Associated Realms to any of my Authentication Sources causes > the test connection to fail wi

Re: [PacketFence-users] All authentication failed with error "No EAPsession matching state xxxx"

2018-01-31 Thread Fabrice Durand via PacketFence-users
Hello Yan, Le 2018-01-31 ?? 00:28, Yan a ??crit?0?2: > > Hi dear users, > > After a whole night??s analysis, we found it??s pf that takes too much > time processing authentication request if the QPS is too high and > hangs all radius requests later and then Aruba AC meets the radius > timeout set

Re: [PacketFence-users] Packetfence Authentication Issue.

2018-01-30 Thread Fabrice Durand via PacketFence-users
Hello Rana, In fact you need first to choose clear text ot mschap to store the local user password (it's bcrypt by default). Next if it still not working then run radius in debug mode and send me the debug. Regards Fabrice Le 2018-01-30 à 09:28, Rana, Vijaykumar via PacketFence-users a écrit

Re: [PacketFence-users] Packetfence 7.4

2018-01-30 Thread Fabrice Durand via PacketFence-users
Hello Will, this is a limitation of your OS, https://www.cyberciti.biz/faq/linux-increase-the-maximum-number-of-open-files/ Regards Fabrice Le 2018-01-30 à 09:19, Will Halsall via PacketFence-users a écrit : > > Hi Folks, > >   > >   > > I just noticed these errors reported in our logs. I am

Re: [PacketFence-users] Read Only Unregistered Nodes

2018-01-25 Thread Fabrice Durand via PacketFence-users
ns to a handful of roles. Hope > that makes more since. > >   > > Jeremy Plumley > > ITS Network Administrator > > Ext 50024 > >   > > *From:*Fabrice Durand via PacketFence-users > [mailto:packetfence-users@lists.sourceforge.net] > *Sent:* Thursday, Jan

Re: [PacketFence-users] Aruba Switch Network Configuration

2018-01-25 Thread Fabrice Durand via PacketFence-users
Hello Jeremy, it looks that the Aruba HPE 2930M support the CoA (http://www.arubanetworks.com/assets/ds/DS_2930MSwitchSeries.pdf) So it should be cool to add the support in Packetfence. Regards Fabrice Le 2018-01-25 à 09:25, Jeremy Plumley via PacketFence-users a écrit : > > Just wanted to s

Re: [PacketFence-users] Re: Image broken in PF status dashboard

2018-01-25 Thread Fabrice Durand via PacketFence-users
yum update libdrm is suppose to fix the issue. Le 2018-01-25 ?? 09:00, Yan a ??crit?0?2: > Hi Fabrice, > It seems to be the same issue you said. The error is as below. I run > "yum?0?2--exclude=collectd*?0?2update" but the image is still broken. Is > there any other way to fix it ? > > Python 2.

Re: [PacketFence-users] Read Only Unregistered Nodes

2018-01-25 Thread Fabrice Durand via PacketFence-users
Hello Jeremy, i am not sure to understand , you mix device role and administration access that is completely different. Regards Fabrice Le 2018-01-25 à 08:48, Jeremy Plumley via PacketFence-users a écrit : > > Wanted to follow up on this and see if there is a way to add “no role” > access so I c

Re: [PacketFence-users] Problem with Certificates

2018-01-25 Thread Fabrice Durand via PacketFence-users
Hello Hubert, it will be cat server.crt intermediate1.cert intermediate2.crt server.key > server.pem Regards Fabrice Le 2018-01-25 à 08:40, Hubert Kupper via PacketFence-users a écrit : > Hello Fabrice, > > thanks. I did: cat server.crt server.key > server.pem. Now packetfence > starts and the r

Re: [PacketFence-users] Problem getting Radius MacAuth to work.

2018-01-25 Thread Fabrice Durand via PacketFence-users
Le 2018-01-25 à 05:41, Schenkelberg, Martin via PacketFence-users a écrit : > > Hello all, i hope you can give me a hint of what im doing wrong. > >   > > We are evaluating to use PacketFence 7.3.0 Zen to authenticate users > connecting to our lan and wifi infrastructure and to assign them the >

Re: [PacketFence-users] Number of devices to connect to the network

2018-01-25 Thread Fabrice Durand via PacketFence-users
or this role. > > Then, the end-user just connects to SSID, authenticates and gets > on the network. How would I assign the user to the “staff” role? > > Is this where provisioners come to help ? > >   > > Eugene > >   > >

Re: [PacketFence-users] NULL realm

2018-01-25 Thread Fabrice Durand via PacketFence-users
Hello Eugene, in fact the REALM is used in 2 cases, if you add the option STRIP in the realm config and restart radius then you will see that radius will strip it. When you assign a REALM to a domain then if the realm match then it will use the domain you define (options.bc.ca -> use AD OPTIONS)

Re: [PacketFence-users] 回复: Image broken in PF status dashboard

2018-01-25 Thread Fabrice Durand via PacketFence-users
Hello Yan, try that: fdurand@oeufdure:~$ python Python 2.7.12 (default, Nov 20 2017, 18:23:56) [GCC 5.4.0 20160609] on linux2 Type "help", "copyright", "credits" or "license" for more information. >>> import cairo And give me the error. Also it can be this bug: https://github.com/inverse-inc/p

Re: [PacketFence-users] Number of devices to connect to the network

2018-01-25 Thread Fabrice Durand via PacketFence-users
  > > Le 2018-01-17 à 01:07, E.P. a écrit : > > Great! > > That confirms my train of thought. But it is still not > clear to me how will it affect the user that authenticates > against AD. > > Yes, I h

Re: [PacketFence-users] users stay in registration VLAN after authentication success

2018-01-22 Thread Fabrice Durand via PacketFence-users
Hello Tom, there : https://pf_mgmt:1443/admin/configuration#configuration/main/advanced Regards Fabrice Le 2018-01-20 à 19:03, tom lo a écrit : > Hi Durand, > > What change should I make on PF to "disable update locationlog on accounting"? > > > Regards, > Tom > > On Sun, Jan 21, 2018 at 4:31 AM

Re: [PacketFence-users] Successfully passed 802.1x auth but nonetwork access

2018-01-18 Thread Fabrice Durand via PacketFence-users
Hello Yan, in Freeradius if you want to authenticate a user with 802.1x peap/mschapv2 then you need to use ntlm_auth and you need to join the domain to the active directory. (http://deployingradius.com/documents/protocols/compatibility.html) I don't know exactly how they do with acs but i remembe

Re: [PacketFence-users] Successfully passed 802.1x auth but no network access

2018-01-18 Thread Fabrice Durand via PacketFence-users
Hello Yan, sorry for the delay. So why don't you joined pf2 to ad2 , i think it will be simpler and probably fix your issue. Regards Fabrice ?0?2 Le 2018-01-15 ?? 11:17, Yan a ??crit?0?2: > > Yes. They have the same domain/users but on different servers. Both of > them can authenticate our a

Re: [PacketFence-users] pf with ruckus smartzone not working for me

2018-01-16 Thread Fabrice Durand via PacketFence-users
Hello Barry, when the error happen , is it when you try to do web-auth or out of band ? (if you have the httpd.portal.access lines when you hit the portal) Because it looks that packetfence is not able to fetch your ip address. Also to reevaluate an access on Ruckus SmartZone packetfence use the

Re: [PacketFence-users] Number of devices to connect to the network

2018-01-16 Thread Fabrice Durand via PacketFence-users
Hello Eugene, this is exactly where you have to control that. So just set a limit on the roles where you want to limit the number of devices per users. Regards Fabrice Le 2018-01-16 à 02:01, E.P. via PacketFence-users a écrit : > > It sounds close to the number of devices/nodes a user can re

Re: [PacketFence-users] PKI provisioning configuration for Apple OS/iOS

2018-01-16 Thread Fabrice Durand via PacketFence-users
  > >   > > *From:*Fabrice Durand via PacketFence-users > [mailto:packetfence-users@lists.sourceforge.net] > *Sent:* Monday, January 15, 2018 6:01 AM > *To:* packetfence-users@lists.sourceforge.net > *Cc:* Fabrice Durand > *Subject:* Re: [PacketFence-users] PKI provisi

Re: [PacketFence-users] Number of registered devices notification

2018-01-16 Thread Fabrice Durand via PacketFence-users
Hello Raphael, can you try that: in /usr/local/pf/ patch -p1 --dry-run < status.diff and if there is no error: patch -p1 < status.diff and restart packetfence. Let me know if it works, i will push it in the main code. Regards Fabrice Le 2018-01-15 à 18:01, Raphael Dias via PacketFence-u

Re: [PacketFence-users] firewalling for inline on the packetfence server

2018-01-16 Thread Fabrice Durand via PacketFence-users
Hello, you can play with iptables.conf in the conf directory in order to add your custom rules. Regards Fabrice Le 2018-01-15 à 11:18, lists via PacketFence-users a écrit : > Hi, > > We're using packetfence in inline modus for our wifi (10.10.10.0/24) > segment. The external packetfence inter

Re: [PacketFence-users] R: R: no httpd portal in a Cluster

2018-01-15 Thread Fabrice Durand via PacketFence-users
e?  > > Luca > > > > *Da:* Fabrice Durand > *Inviato:* lunedì 15 gennaio 2018 15:10 > *A:* luca comes; Fabrice Durand via PacketFence-users > *Oggetto:* Re: R: [PacketFence-users] no httpd portal in a Cluster >   > > Hello Luca, > >

Re: [PacketFence-users] Re: Successfully passed 802.1x auth but no network access

2018-01-15 Thread Fabrice Durand via PacketFence-users
Hello Yan, does AD1 and AD2 are the same ? (same domain/users ...) Regards Fabrice Le 2018-01-15 ?? 00:41, Yan a ??crit?0?2: > Hi Durand, > > I installed a netdata in my pf server and not found any network issue > yet(I'm learning to use it). But there is another case I'm not sure if > it is

Re: [PacketFence-users] R: no httpd portal in a Cluster

2018-01-15 Thread Fabrice Durand via PacketFence-users
t; ip=172.27.17.3 > type=management,high-availability > mask=255.255.255.0 > > [pfnac03 interface ens192.2445] > enforcement=vlan > ip=10.255.20.10 > type=internal > mask=255.255.255.0 > > [pfnac03 interface ens192.2446] > enforcement=vlan > ip=10.255.

Re: [PacketFence-users] PKI provisioning configuration for Apple OS/iOS

2018-01-15 Thread Fabrice Durand via PacketFence-users
Hello Eugene, Le 2018-01-13 à 02:59, E.P. via PacketFence-users a écrit : > > Folks, > > Our two big shots in the organization live their lives with Apple > macbooks and we need to get them on the secure WiFi. > > Can someone explain me where and how to get the content of > certificates that are

Re: [PacketFence-users] no httpd portal in a Cluster

2018-01-15 Thread Fabrice Durand via PacketFence-users
Hello Lucas, can i have the cluster.conf file ? Regards Fabrice Le 2018-01-15 à 05:10, luca comes via PacketFence-users a écrit : > > Hi all, > > I've successfully migrated a single node infrastructure to a full 3 > node cluster, all things has gone well but I have only one problem. > After t

Re: [PacketFence-users] Assistance with nessus

2018-01-11 Thread Fabrice Durand via PacketFence-users
t; André > > > > 2018-01-10 20:50 GMT-03:00 Durand fabrice <mailto:fdur...@inverse.ca>>: > > Hello André, > > so you have to choose nessus6 and not nessus. > > Restart > > Fabrice > > > > Le 2018-01-10 à 17:53, André Scriven

Re: [PacketFence-users] Assistance with nessus

2018-01-10 Thread Fabrice Durand via PacketFence-users
Hello André, what is the version of nessus ? Regards Fabrice Le 2018-01-10 à 15:59, André Scrivener via PacketFence-users a écrit : > Hey guys! > > > I'm enabling nessus to scan hosts, but I'm trying out these logs below: > > > Jan 10 18:33:25 packetfence pfqueue: pfqueue(12693) INFO: > [mac:

Re: [PacketFence-users] Device authentication with client TLS certificate issued by PKI

2018-01-10 Thread Fabrice Durand via PacketFence-users
without validating server certificate, same results, > reason - eap_tls: SSL says error 20 : unable to get local issuer > certificate > >   > > Eugene > >   > > *From:*Fabrice Durand via PacketFence-users > [mailto:packetfence-users@lists.sourceforge.net] > *Se

Re: [PacketFence-users] Re: Successfully passed 802.1x auth but nonetworkaccess

2018-01-10 Thread Fabrice Durand via PacketFence-users
Hello Yan, i checked the logs and all looks to be ok, 802.1x authentication works correctly. What i can imagine that you maybe lost the connection between PacketFence and the AP/Controller or maybe a cache on the AP/Controller. What you can do to check that is to install netdata on the PacketFen

Re: [PacketFence-users] Successfully passed 802.1x auth but no networkaccess

2018-01-10 Thread Fabrice Durand via PacketFence-users
Hello Yan, you need to check on the PacketFence side what happen: run that (raddebug -f /usr/local/pf/var/run/radiusd.sock -t 3000) , try to connect and paste the result Also take a look in audit in packetfence gui and check for a mac address where you have the issue. Regards Fabrice Le 2018-

Re: [PacketFence-users] Device authentication with client TLS certificate issued by PKI

2018-01-10 Thread Fabrice Durand via PacketFence-users
Hello Eugene, you probably need to import the CA certificate or uncheck verify server certificate in your supplicant config. Regards Fabrice Le 2018-01-10 à 03:57, E.P. via PacketFence-users a écrit : > > And here comes the culmination of my saga with PKI ;) > > Actually, I was slowly going t

Re: [PacketFence-users] PKI installation

2018-01-09 Thread Fabrice Durand via PacketFence-users
Hello Eugene, Le 2018-01-09 à 03:01, E.P. a écrit : > > Couple of questions on PKI, Fabfice > >   > > 1.   How would I change the password for admin user in PKI. The > “User Management” section gives me the option of editing the admin > user but I can’t see the password change option > >   >

Re: [PacketFence-users] Assistance with AD dot1x

2018-01-08 Thread Fabrice Durand via PacketFence-users
Hello All, just to clarify some points. First realmd can't be used because we have to use ntlm_auth in Freeradius to authenticate user for eap/peap mschap v2. Next, Configuration → Policies and Access Control → Domains → Active Directory Domains – Add Domain is only to join the machine to a wind

Re: [PacketFence-users] packetfence 7.3 configuration wizard - radius?

2018-01-04 Thread Fabrice Durand via PacketFence-users
secret = <<< secret >>> > >     nas_type = "other" > >     proto = "*" > >   limit { > >     max_connections = 16 > >     lifetime = 0 > >     idle_timeout = 30 > >   } > > } > >

Re: [PacketFence-users] PKI installation

2018-01-03 Thread Fabrice Durand via PacketFence-users
Just for information, i uploaded a new version of the packetfence-pki for centos7 who fix all the install issues. Regards Fabrice Le 2017-12-12 à 23:58, E.P. a écrit : > > Well, I’m taking my hat off in front of you, no kidding and pun > intended ;) > > Do you need traceback from the error pag

Re: [PacketFence-users] Need help solving a problem with vlan enforcement

2018-01-03 Thread Fabrice Durand via PacketFence-users
name "Registration" >> exit >> vlan 3 >> name "Isolation" >> exit >> vlan 4 >> name "Mac detection" >> exit >> vlan 5 >> name "G

Re: [PacketFence-users] Aruba Switch Network Configuration

2018-01-03 Thread Fabrice Durand via PacketFence-users
Hello Jeremy, do you have any documentation related to the support of the VoIP on the Aruba switch ? There is probably a vsa attribute to return when PacketFence detect that a phone is plugged on a switch port. If the vsa exist then it will be easy to add the VoIP support for the Aruba switches.

Re: [PacketFence-users] Packetfence-pki restore/ovewrite admin password

2018-01-03 Thread Fabrice Durand via PacketFence-users
Hello, what you can do is to connect in the sqlite db and update the password. sqlite3 db.sqlite3 UPDATE "auth_user" set password='pbkdf2_sha256$2$Z2Lhr1cW8QM0$mN9PtNhxneIDzApqFa4uG8V44IXqHe+r7yootSoSzJQ=' where username='admin'; the password is p@ck3tf3nc3 Regards Fabrice Le 2018-01-

Re: [PacketFence-users] packetfence 7.3 configuration wizard - radius?

2018-01-03 Thread Fabrice Durand via PacketFence-users
Hello Ivan, what you can do is the following: /usr/local/pf/bin/pfcmd service radiusd generateconfig /usr/sbin/radiusd -d /usr/local/pf/raddb  -n auth -fxx -l stdout And paste the debug if the service is not able to start. Regards Fabrice Le 2018-01-03 à 09:31, Auger, Ivan (ITS) via Packet

Re: [PacketFence-users] Need an advice and maybe assistance with FreeRADIUS

2018-01-03 Thread Fabrice Durand via PacketFence-users
https://i.imgsafe.org/05/05bbd86ab4.png > >   > > Also please make sure you have the latest UniFi AP and controller > firmware as they were just updated a few days ago.  > >   > > See my earlier post on the PacketFence-Users forum if you

Re: [PacketFence-users] Need help solving a problem with vlan enforcement

2018-01-03 Thread Fabrice Durand via PacketFence-users
> aaa server radius dynamic-author > client 172.16.0.2 server-key "useStrongerSecret" > exit               > radius-server host auth 172.16.0.2 > name "PacketFence" > usage 802.1x       > key "useStrongerSecret" &

Re: [PacketFence-users] Need an advice and maybe assistance with FreeRADIUS

2018-01-03 Thread Fabrice Durand via PacketFence-users
nge the deauthentication method to >>>> HTTPS and specify the UniFi controller IP? See my setup below: >>>> >>>>   >>>> >>>> https://i.imgsafe.org/0c/0cff2c7f19.png >>>> >>>> https://i.imgsafe.org/0c/0cff2dfd99.png >>>> >>

Re: [PacketFence-users] Need help solving a problem with vlan enforcement

2017-12-29 Thread Fabrice Durand via PacketFence-users
Hello André, First you need to check on the switch side if the mac address of the device is in the vlan 300. Next a registration vlan is a vlan managed by PacketFence, so you need to enable dhcp on the vlan 300 and 600. Another thing i can see is that the interface enp0s8.300 (vlan 300) use the

Re: [PacketFence-users] Need an advice and maybe assistance with FreeRADIUS

2017-12-29 Thread Fabrice Durand via PacketFence-users
For me it looks that 172.19.254.2 is define twice. Can you do in /usr/local/pf/raddb: grep 172.19.254.2 * -r  Also can you try to run radiusd in debug mode and see if you can see 172.19.254.2 (radiusd -d /usr/local/pf/raddb -n auth -X) Regards Fabrice Le 2017-12-29 à 01:26, E.P. a écrit : >

Re: [PacketFence-users] OMAPI.pm errors

2017-12-20 Thread Fabrice Durand via PacketFence-users
Hum if it's a cluster then omapi will not work on one of them (dhcpd only run on 2 of the 3 servers). What you can do is just to disable omapi. Regards Fabrice Le 2017-12-20 à 05:12, Luís Torres via PacketFence-users a écrit : > > I didnt..., and yes its a cluster. > > Should I use in all the

Re: [PacketFence-users] Packetfence doesn't change VLAN after registration

2017-12-15 Thread Fabrice Durand via PacketFence-users
sent, is there any > other thing I can check? > > > Thanks > > > Luca > > > > ---- > *Da:* Fabrice Durand via PacketFence-users > > *Inviato:* venerdì 15 dicembre 2017 14:46 > *A:* packetfence-users@lists.sourceforge.net > *Cc:* Fabrice Durand > *Oggetto:*

Re: [PacketFence-users] Cisco Catalyst 9300 and 9400 support

2017-12-15 Thread Fabrice Durand via PacketFence-users
Hello, yes if the ios is not something completely exotic it should be ok. Regards Fabrice Le 2017-12-15 à 06:25, Tomasz Karczewski via PacketFence-users a écrit : > > Does it have different cisco ios? > >   > > Tomasz Karczewski > > Administrator Sieci > >   > > olman > >   > > tkarczew...@man

Re: [PacketFence-users] Packetfence doesn't change VLAN after registration

2017-12-15 Thread Fabrice Durand via PacketFence-users
Hello Luca, if you want faster answer you can buy a support contract with Inverse. I answer on the mailing list when i have time to do it and most of the time i am busy. So the packetfence.log is not enough complete because what is interesting is just a after and we should suppose to see "Deaut

Re: [PacketFence-users] Cluster - Portal opening

2017-12-15 Thread Fabrice Durand via PacketFence-users
Hello Luís, the only solution i can see is to raise the server resources Regards Fabrice Le 2017-12-14 à 10:05, Luís Torres via PacketFence-users a écrit : > > Hi mates, > >   > > is there a way to speed up the opening of the portal webpage? in the > cluster it takes a few seconds to open it...

Re: [PacketFence-users] Ubiquiti UniFi AP Captive Portal

2017-12-13 Thread Fabrice Durand via PacketFence-users
ption only shows up as an > option in the UniFi controller when you choose WPA Enterprise. You > can see screenshots of my setup below: > > https://i.imgsafe.org/05/ 05bb81f5b4.png > <https://i.imgsafe.org/05/05bb81f5b4.png> > https://i.imgsafe.org/05/ 05bbd86

Re: [PacketFence-users] Cluster - no dhcp

2017-12-12 Thread Fabrice Durand via PacketFence-users
Just on one of them, right ? If it's the case then it's normal. Le 2017-12-12 à 14:22, Luís Torres via PacketFence-users a écrit : > > Hi mates, > >   > > manage to recover the cluster but now the dhcp wont start. Gives me > the error: > >   > > /usr/local/pf/bin/pfcmd service dhcpd restart > se

Re: [PacketFence-users] Ubiquiti UniFi AP Captive Portal

2017-12-12 Thread Fabrice Durand via PacketFence-users
n assignment on open SSIDs? For open networks it only lets me > specify a static VLAN to use.  > > Thanks! > > Sent from mobile phone > > On Dec 12, 2017, at 07:41, Fabrice Durand via PacketFence-users > <mailto:packetfence-users@lists.sourceforge.net>> wrote: &

Re: [PacketFence-users] Can PF return multiple VLANs in one time ?

2017-12-12 Thread Fabrice Durand via PacketFence-users
Hello Yan, you need to patch packetfence: cd /usr/local/pf curl https://patch-diff.githubusercontent.com/raw/inverse-inc/packetfence/pull/2530.diff | patch -p1 Then restart all the services. On the Ruckus side i don't know, i have no documentation. Btw if you have screenshot of how to set the

Re: [PacketFence-users] Ubiquiti UniFi AP Captive Portal

2017-12-12 Thread Fabrice Durand via PacketFence-users
Hello Timothy, you must enable that: https://raw.githubusercontent.com/inverse-inc/packetfence/ae18f50b4879cc2d4132490fcee33f2fbe53b36f/docs/images/unifi-radius.png Regards Fabrice Le 2017-12-12 à 01:37, Timothy Mullican via PacketFence-users a écrit : > Hello all, > I am trying to setup a pr

Re: [PacketFence-users] Wireless hotspot creation - help

2017-12-12 Thread Fabrice Durand via PacketFence-users
Ok so it should work with coovachilli on openwrt. There is a module in PacketFence for that. Regards Fabrice Le 2017-12-12 à 07:36, Luca Fois via PacketFence-users a écrit : > Hi; > > Thanks for your quick reply > I will use a ubiquiti picostation m2 with openwrt. > > I think its better than

Re: [PacketFence-users] PKI installation

2017-12-12 Thread Fabrice Durand via PacketFence-users
Just change the owner of the sqlite file to pf and it should be ok. Btw all these steps are made in the packaging, so it probably failled or never finish correctly. I will do a test on my side. Regards Fabrice Le 2017-12-12 à 03:47, E.P. a écrit : > > Well, we are getting closer ;) > > Ran t

Re: [PacketFence-users] PKI installation

2017-12-11 Thread Fabrice Durand via PacketFence-users
hed Dependency Resolution > > Error: Package: packetfence-pki-1.1.1-1.el7.centos.noarch > (packetfence-extra) > >    Requires: python-django-rest-framework > > Error: Package: packetfence-pki-1.1.1-1.el7.centos.noarch > (packetfence-extra) > >    Requir

Re: [PacketFence-users] PKI installation

2017-12-11 Thread Fabrice Durand via PacketFence-users
Hello Eugene, can you try: yum makecache --enablerepo=packetfence,packetfence-extra yum install packetfence-pki --enablerepo=packetfence-extra, packetfence Regards Fabrice Le 2017-12-11 à 16:03, E.P. via PacketFence-users a écrit : > > Hi guys, > > I’m trying to follow the guide published h

Re: [PacketFence-users] PoC: Social Login from Captive Portal and Firewall (Checkpoint) Enforcement

2017-12-08 Thread Fabrice Durand via PacketFence-users
Le 2017-12-08 à 09:45, Benoît Dubé via PacketFence-users a écrit : > > Merci beaucoup Fabrice, > > > When external users are redirected to the PacketFence portal, IP > packets contain the user's IP.  I can install the DHCP remote sensor > on the server, but question is why to do that if the IP in

Re: [PacketFence-users] Aruba Switch Network Configuration

2017-12-06 Thread Fabrice Durand via PacketFence-users
Hello Jeremy, does the Aruba Switch run Arubas OS or is it something like HP Os ? Regards Fabrice Le 2017-12-06 à 09:07, Jeremy Plumley via PacketFence-users a écrit : > > I’m looking into possibly replacing some of our access layer switch > needs with Aruba Networks switches. I notice in 7.2

Re: [PacketFence-users] VLAN filter rule to temporarily allow specific switch

2017-11-29 Thread Fabrice Durand via PacketFence-users
Hello Yan, you also need to register the device. so something like that: [pf_ssid] filter = ssid operator = is value = PF-Wireless [SG1_switch] filter = switch._ip operator = is value = 172.11.5.121 [reg_by_switch:pf_ssid&SG1_switch] scope = RegistrationRole action = modify_node action_param =

Re: [PacketFence-users] Violation 1300003 force-closed after successful Captive Portal Authentication

2017-11-28 Thread Fabrice Durand via PacketFence-users
500] "192.168.2.223" "GET > /captive-portal?destination_url=https://www.domain.com/&sip=192.168.2.100&mac=58b63311d5e0&client_mac=60f81dc3e758&uip=192.168.2.126&lid=&dn=ZoneDirector218.domain.com&url=https%3a%2f%2fwww.domain.com%2f&ssid=domain

Re: [PacketFence-users] Violation 1300003 force-closed after successful Captive Portal Authentication

2017-11-28 Thread Fabrice Durand via PacketFence-users
Hello Ricardo, i am not seeing what is wrong but it's not suppose to have that in the log: Can't re-evaluate access because no open locationlog entry was found Can you put the portal in debug mode ? conf/log.conf.d/httpd.portal.conf: ### httpd.portal logger ### log4perl.rootLogger = INFO, HTTPD

Re: [PacketFence-users] Supported standalone AP

2017-11-24 Thread Fabrice Durand via PacketFence-users
https://github.com/inverse-inc/packetfence/pull/2735 Le 2017-11-24 à 08:48, Gonzague Dambricourt a écrit : > Yeah for now . .UniFi doesn’t support CoA :(  > >> Le 24 nov. 2017 à 14:46, Fabrice Durand via PacketFence-users >> > <mailto:packetfence-users@lists.s

Re: [PacketFence-users] Supported standalone AP

2017-11-24 Thread Fabrice Durand via PacketFence-users
Hello Spencer, you can use something like that: https://www.ubnt.com/unifi/unifi-ap-ac-lite/ There is only a limitation with 802.1x (i hope Ubiquiti will fix it) but mac auth should be ok. Regards Fabrice Le 2017-11-24 à 06:11, Spencer Hazell via PacketFence-users a écrit : > > Hi > >   > >

Re: [PacketFence-users] Failed to connect to config service for namespace resource::URI_Filters, retrying

2017-11-23 Thread Fabrice Durand via PacketFence-users
Hello, try first to restart packetfence-config systemctl restart packetfence-config and do a pfcmd configreload hard Regards Fabrice Le 2017-11-23 à 07:07, Samuel Chege via PacketFence-users a écrit : > You can also try to remove the package called kf5-kio-widgets FIRST > before re-installi

Re: [PacketFence-users] [WISPr redirection]Can't direct user todownload specific files in registration VLAN

2017-11-23 Thread Fabrice Durand via PacketFence-users
Hello Yan, use proxy_passthroughs=123.23.1.2 instead of passthroughs=123.23.1.2 and retry. Regards Fabrice Le 2017-11-22 ?? 10:26, Yan via PacketFence-users a ??crit?0?2: > In short, I want to know if it is possible to use PF's Captive Portal > detection mechanism to pop out the captive porta

Re: [PacketFence-users] RADIUS 802.1x EAP-TLS + Machine Auth

2017-11-22 Thread Fabrice Durand via PacketFence-users
Hello Jason, Le 2017-11-21 à 23:40, Jason Sloan a écrit : > Fabrice, > > Totally understand being busy. Thanks for the reply. I was actually > able to get this working a few hours ago, and hadn't had time to post > a reply. I'm not sure what did it, perhaps adding "strip" to the realm > options b

Re: [PacketFence-users] DHCP service not listed

2017-11-17 Thread Fabrice Durand via PacketFence-users
Hello, this is normal, the dhcp can run only on 2 off them. Regards Fabrice Le 2017-11-17 à 14:35, Tobias Friede via PacketFence-users a écrit : > Hi, > > I have the same problem, maybe that behavior is normal? > > My Cluster is a PF 7.2 Cluster.  > > Greetings > Tobias > > 2017-11-17 16:34 G

Re: [PacketFence-users] Captive portal not redirecting after registration

2017-11-17 Thread Fabrice Durand via PacketFence-users
Hello Pedro, it looks that it's a reevaluation issue, can you provide the packetfence.log ? What controler/AP are you using in your POC ? Regards Fabrice Le 2017-11-17 à 13:03, Pedro Trindade via PacketFence-users a écrit : > Hello all, I've been trying to make a Packetfence 7.3.0 POC on a >

Re: [PacketFence-users] R: R: R: R: Switch Compatibility

2017-11-17 Thread Fabrice Durand via PacketFence-users
ll:priv-lvl=3'; >     $radius_reply_ref->{'Reply-Message'} = "Switch read access > granted by PacketFence"; >     $logger->info("User $args->{'user_name'} logged in > $args->{'switch'}{'_id'} wi

Re: [PacketFence-users] auth request from wrong switch

2017-11-17 Thread Fabrice Durand via PacketFence-users
Hum ok, really weird. It looks that first when the device connect on the port 2/43 802.1x failed so it start mac auth but just after that the port goes down and a new request is coming from the port 5/3. When this happen, can you check in the mac-address-table where is the mac address (before and

Re: [PacketFence-users] Mysql query error -"Database query failed with non retryable error"

2017-11-16 Thread Fabrice Durand via PacketFence-users
Hello Yan, it looks that the pid ( the person ) doesn't exist on your setup. So check in the person tab if you can find it (the person id appear just before the error in the log). Regards Fabrice Le 2017-11-16 ?? 05:21, Yan via PacketFence-users a ??crit?0?2: > Hi dear users, > > We use PF V

Re: [PacketFence-users] Bandwidth statistics make no sense (Cisco 2960x)

2017-11-16 Thread Fabrice Durand via PacketFence-users
. > > Maybe the bug is related to this: > https://quickview.cloudapps.cisco.com/quickview/bug/CSCve85309 ? > > Il 15/11/2017 22:50, Fabrice Durand via PacketFence-users ha scritto: >> Hello Cristian, >> >> so i am able to replicate it and it looks to be a bug wi

Re: [PacketFence-users] Bandwidth statistics make no sense (Cisco 2960x)

2017-11-15 Thread Fabrice Durand via PacketFence-users
Hello Cristian, so i am able to replicate it and it looks to be a bug with the ios version. Let's say i have a nothing connected on the port Gi1/0/8, if i do that: Switch#sh interfaces gigabitEthernet 1/0/8 GigabitEthernet1/0/8 is administratively down, line protocol is down (disabled)   Hardwar

Re: [PacketFence-users] Packetfence-PKI / Setup Wizard Error

2017-11-15 Thread Fabrice Durand via PacketFence-users
Ok so here the patch https://github.com/inverse-inc/packetfence-pki/commit/c66ef2ab34964caecda3d2cdff1c956656227ffc.diff Regards Fabrice Le 2017-11-15 à 08:56, Fabrice Durand via PacketFence-users a écrit : > > Ok i am able to replicate it, let me fix it and i will give you a

Re: [PacketFence-users] Packetfence-PKI / Setup Wizard Error

2017-11-15 Thread Fabrice Durand via PacketFence-users
Ok i am able to replicate it, let me fix it and i will give you a patch. Regards Fabrice Le 2017-11-14 à 22:41, Jason Sloan a écrit : > Sorry, I should have included the values. > I wasn't sure if the values should be comma delimited or not. I tried > both comma and space delimited. > > KU: >

Re: [PacketFence-users] Bandwidth statistics make no sense (Cisco 2960x)

2017-11-14 Thread Fabrice Durand via PacketFence-users
nce-users ha scritto: >> If you mean PacketFence is 7.3.0 >> If you mean IOS: Cisco IOS Software, C2960X Software >> (C2960X-UNIVERSALK9-M), Version 15.2(2)E6, RELEASE SOFTWARE (fc1) >> >> >> Il 19/10/2017 16:41, Fabrice Durand via PacketFence-users ha

Re: [PacketFence-users] Recommended Distribution / Version

2017-11-14 Thread Fabrice Durand via PacketFence-users
Ok let me fix that. Btw you can remove the file initial_data.json and do a python manage.py syncdb. Le 2017-11-14 à 04:12, Jason Sloan a écrit : > Looks like there's 2 more dependencies > python-ipaddress > python-idna > > Then it looks like I'm bombing out on an initial data load of some >

Re: [PacketFence-users] Question about device-registration page

2017-11-13 Thread Fabrice Durand via PacketFence-users
Hello Marcus, in the device registration page there is no way to allow the end user to choose the role. You define it or PacketFence use the same one of the user. Also Julien did this sort of thing you want to use on the device registration page but for the captive portal. (https://github.com/in

Re: [PacketFence-users] R: R: R: Switch Compatibility

2017-11-13 Thread Fabrice Durand via PacketFence-users
by PacketFence"; >     $logger->info("User $args->{'user_name'} logged in > $args->{'switch'}{'_id'} with read access"); >     my $filter = pf::access_filter::radius->new; >     my $rule = $filter->test('returnAuthorize

Re: [PacketFence-users] Switch Compatibility

2017-11-10 Thread Fabrice Durand via PacketFence-users
Hello Alessandro, what is the type of the switch ? Regards Fabrice Le 2017-11-10 à 09:44, Alessandro Canella via PacketFence-users a écrit : > > Hello all, > >   > > I solved everything (thanks to all..) ando now I0m investigating about > this: > >   > >   > >   > > Nov 10 13:37:03 PacketFenc

Re: [PacketFence-users] progress bar missing

2017-11-09 Thread Fabrice Durand via PacketFence-users
Hello Tobias, did you changed the html template files ? Because the progress bar is there by default. Regards Fabrice Le 2017-11-09 à 04:32, Schimanski Tobias via PacketFence-users a écrit : > > Hey guys > >   > > my packetfence didn’t show the progress bar after login. It shows an > error that

Re: [PacketFence-users] user management on web portal

2017-11-09 Thread Fabrice Durand via PacketFence-users
ese accounts have only user management rights. > > Regards, > Nicolay > > > 2017-11-07 22:17 GMT+01:00 Fabrice Durand via PacketFence-users > <mailto:packetfence-users@lists.sourceforge.net>>: > > Hello Nicolay, > > not sure to understand , you mean i

Re: [PacketFence-users] PF 7.3 - Problem with Device Registration - caught exception

2017-11-09 Thread Fabrice Durand via PacketFence-users
Hello Michel, did you define a device registration profile and did you assign it to your connection profile ? In 7.3 you can create multiples connection profile and assign one of them to a connection profile. Regards Fabrice Le 2017-11-09 à 01:20, Pedersen Michel via PacketFence-users a écrit

Re: [PacketFence-users] Problem with Reports in PF 7.3.0

2017-11-08 Thread Fabrice Durand via PacketFence-users
re shown only if I click "today" but "Operating >> Systems" or "Bandwidth Consumers" show the "What's going on..." >> message. When I click "7 days" or older, "Node States" is empty but >> the other options show graphs

Re: [PacketFence-users] Email-guest_sponsor_activation.html

2017-11-07 Thread Fabrice Durand via PacketFence-users
Hello Luís, in html/captive-portal/lib/captiveportal/PacketFence/DynamicRouting/Module/Authentication/Sponsor.pm line 177 add cell_phone in the list 177 foreach my $key (qw(firstname lastname telephone company cell_phone)) { regards Fabrice Le 2017-11-07 à 05:10, Luís Torres via PacketF

Re: [PacketFence-users] user management on web portal

2017-11-07 Thread Fabrice Durand via PacketFence-users
Hello Nicolay, not sure to understand , you mean in the admin gui ? Regards Fabrice Le 2017-11-07 à 08:23, Nicolay Rytchev via PacketFence-users a écrit : > Hello all, > > Is it possible to hide from the user or forbid to him see or change > user's account in local database that is not create

Re: [PacketFence-users] R: R: R: R: R: Radius Project Reloaded

2017-11-07 Thread Fabrice Durand via PacketFence-users
rse.ca] > *Inviato:* martedì 31 ottobre 2017 17.32 > *A:* Alessandro Canella > <mailto:alessandro.cane...@itcare.it>; > packetfence-users@lists.sourceforge.net > <mailto:packetfence-users@lists.sourceforge.net> > *Oggetto:* Re: R: [P

Re: [PacketFence-users] Wireless WPA2-PSK Devices

2017-11-06 Thread Fabrice Durand via PacketFence-users
Hello Paul, What i would do is to use the device registration page in this case. When user want to register there IOT devices, they use there already registered device to hit the device registration page and register the IOT by his mac address. At the end of the registration you will just have t

Re: [PacketFence-users] R: R: R: R: Radius Project Reloaded

2017-11-06 Thread Fabrice Durand via PacketFence-users
la > <mailto:alessandro.cane...@itcare.it>; > packetfence-users@lists.sourceforge.net > <mailto:packetfence-users@lists.sourceforge.net> > *Oggetto:* Re: R: [PacketFence-users] Radius Project Reloaded > >   > > Once you have the file do > &

Re: [PacketFence-users] R: R: R: Radius Project Reloaded

2017-11-02 Thread Fabrice Durand via PacketFence-users
[PacketFence-users] Radius Project Reloaded > >   > > Once you have the file do > > cd /usr/local/pf > > patch -p1 < the_patch.diff > >   > > Regards > > Fabrice > >   > >   > > Le 2017-10-

Re: [PacketFence-users] Entarasys/Extreme B5 Switch

2017-11-02 Thread Fabrice Durand via PacketFence-users
Hello Stephen, it looks that there an issue to connect to the OMAPI socket. Does the dhcp server is running ? Also try to disable OMAPI in the admin gui and restart pfqueue. Regards Fabrice Le 2017-11-02 à 10:20, Stephen Appleby via PacketFence-users a écrit : > > I've setup radius and MAC

<    1   2   3   4   5   6   7   8   >