Hello everyone,

What we're trying to accomplish:
Migrate to 802.1x and still support our current captive portal.

With that said, how can we add a Login VLAN? This VLAN's purpose would be to 
place users in a captive portal before accessing the network.  They'd have to 
put in their username/password before getting placed in the Production VLAN, 
kind of like how registering works, but this would be to check credentials 
against a db every time they connect before getting placed in the Production 
VLAN.

I see PF acting as the DNS and DHCP server in that VLAN and with an 
Access-Accept from the RADIUS server, PF would disassociate them and push a new 
VLAN to the controller for that client.  Eventually the lease would time out 
(8hrs) and then they would need to hit that captive portal once again.  I know 
802.1x solves this, which is why we're pushing it but as much as I'd like to 
drop what we currently have and do 802.1x across the board, the powers above me 
pay the bills.

Any thoughts on this?


[cid:image002.jpg@01CBCC3C.68AEA090]

<<inline: image002.jpg>>

------------------------------------------------------------------------------
The ultimate all-in-one performance toolkit: Intel(R) Parallel Studio XE:
Pinpoint memory and threading errors before they happen.
Find and fix more than 250 security defects in the development cycle.
Locate bottlenecks in serial and parallel code that limit performance.
http://p.sf.net/sfu/intel-dev2devfeb
_______________________________________________
Packetfence-devel mailing list
Packetfence-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-devel

Reply via email to