Greetings,

I don't think these questions are new, but I can't seem to find anything via 
Google, so my apologies if you've seen these before.

We have a fairly large MPLS based network with a significant number of edge 
VLANs.  I have 802.1x and MAB working already, so my next step is captive 
portal.  First, does the captive portal have to run on the packetfence box, or 
can it run on a separate system?  Presumably there would need to be 
communication between the captive portal and packetfence.

Next, how do I redirect users to the captive portal?  I can see two options 
here.  First, I can configure the captive portal to have the gateway address 
for every registration vlan (100+).  This seems somewhat excessive and means I 
have to update the server every time we add/remove a registration VLAN.  This 
doesn't happen often, but it is an extra step.

The alternative, I think, is to use a route-map.  I can use "set-next-hop" and 
push all traffic on the registration VLANs to the captive portal.  This is 
pretty straighforward, I think, and I've had this working for other captive 
portal systems.  It's also a standard config I can put on all registration 
VLANs and will not require server changes to implement.

I will, eventually, be using the captive portal for AUP/TOS acceptance as well, 
but I don't think that changes any of the above.

Any insight into this would be helpful.  And if there are documents describing 
this in more detail, I would appreciate a pointer to them.  The only formal 
documentation I've seen is the admin guide which isn't much help with this.

Thanks,

--
Jason Frisvold
xenoph...@godshell.com
------------------------------------------------------------------------------
Learn Graph Databases - Download FREE O'Reilly Book
"Graph Databases" is the definitive new guide to graph databases and 
their applications. This 200-page book is written by three acclaimed 
leaders in the field. The early access version is available now. 
Download your free book today! http://p.sf.net/sfu/neotech_d2d_may
_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to