We have much the same situation and we have solved it by assigning the category to the user according to what module they use to authenticate.
For example, we have 3 types of users: Admin, Student, and Guest. We have 3 authentication modules named .. can you guess : ) Admin, Student, and Guest. When you hit the captive portal you are presented with a drop own menu and you select the option the you need and then authenticate. There is some logic (which is essentially what has already been suggested) that updates the request and sets the users' category accordingly. Then once the category is set we return a custom vlan based on that category. Works very well for us. One could easily adapt this to just about any scenario that requires different users to receive different network access. If you are interested, I can post my settings here for you to see. Come to think of it, I did just that not too long ago ... try a quick search of the list using my address and it should come up, if not I'll re-post it. Jake Sallee Godfather of Bandwidth System Engineer University of Mary Hardin-Baylor 900 College St. Belton TX. 76513 Fone: 254-295-4658 Phax: 254-295-4221 HTTP://WWW.UMHB.EDU -----Original Message----- From: Dan Nelson [mailto:[email protected]] Sent: Monday, October 22, 2012 4:54 PM To: [email protected] Subject: Re: [PacketFence-users] captive Portal radius login add to Guest Vlan Dan Nelson <DNelson@...> writes: > > > I have combed through the forum to try and find a solution to this but > haven't found exactly what I am looking for. Right now the captive portal is working fine with Radius authentication. Upon successful authentication the node will go to the normalVlan but with no category assigned. > I have setup the guest category and have the /usr/local/pf/lib/pf/vlan/custom.pm working for that guest category. > > I would like on a successful authentication to not go to the > normalVlan but rather to the guest. It should work fine if I can just categorize the successful user to the guest category. > > If I missed it in the forums then I apologize. Can someone help me > out assigning a captive portal user to a category? Maybe I didn't explain it good enough. I need the normalVlan to stay the way it is. This is only on registering a new device. A user brings a new laptop into the network, It is caught by pf and is brought to a captive portal. If he has a valid username and password he is able to get that device on the guest vlan which is setup as internet only. I have the captive portal wording that if the device needs corporate access to contact the helpdesk and we will manally get it on the vlan. This would be done by moving it to the right category in PF. Can pf assign a category during the registration? I am pretty sure it can be done so need to know if it is done in the radius.pm or somewhere else? ------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_sfd2d_oct _______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users ------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_sfd2d_oct _______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users
