Hi Francis,

   this is also what happen when change the Node Status from "Grace" to
"Registered"

May 23 11:56:57 httpd.admin(0) INFO: loading Net::MAC::Vendor cache from
/usr/local/pf/conf/oui.txt (pf::util::load_oui)
May 23 11:57:13 httpd.admin(0) INFO: grace expired on violation 1200001
for node 00:0b:5d:23:02:4d (pf::violation::violation_add)
May 23 11:57:13 httpd.admin(0) WARN: database query failed with: Cannot
add or update a child row: a foreign key constraint fails
(`pf`.`violation`, CONSTRAINT `0_61` FOREIGN KEY (`vid`) REFERENCES
`class` (`vid`) ON DELETE CASCADE ON UPDATE CASCADE). (errno: 1452), will
try again (pf::db::db_query_execute)
May 23 11:57:13 httpd.admin(0) WARN: database query failed with: Cannot
add or update a child row: a foreign key constraint fails
(`pf`.`violation`, CONSTRAINT `0_61` FOREIGN KEY (`vid`) REFERENCES
`class` (`vid`) ON DELETE CASCADE ON UPDATE CASCADE). (errno: 1452), will
try again (pf::db::db_query_execute)
May 23 11:57:13 httpd.admin(0) WARN: database query failed with: Cannot
add or update a child row: a foreign key constraint fails
(`pf`.`violation`, CONSTRAINT `0_61` FOREIGN KEY (`vid`) REFERENCES
`class` (`vid`) ON DELETE CASCADE ON UPDATE CASCADE). (errno: 1452), will
try again (pf::db::db_query_execute)
May 23 11:57:13 httpd.admin(0) ERROR: Database issue: We tried 3 times to
serve query violation_add_sql called from pf::violation::violation_add and
we failed. Is the database running? (pf::db::db_query_execute)
May 23 11:57:13 httpd.admin(0) INFO: re-evaluating access for node
00:0b:5d:23:02:4d (manage_register called)
(pf::enforcement::reevaluate_access)
May 23 11:57:13 httpd.admin(0) INFO: 00:0b:5d:23:02:4d is currentlog
connected at 10.2.253.2 ifIndex 10115 in VLAN 333
(pf::enforcement::_should_we_reassign_vlan)
May 23 11:57:13 httpd.admin(0) INFO: MAC: 00:0b:5d:23:02:4d, PID: admin,
Status: reg. Returned VLAN: 223 (pf::vlan::fetchVlanForNode)
May 23 11:57:13 httpd.admin(0) INFO: VLAN reassignment required for
00:0b:5d:23:02:4d (current VLAN = 333 but should be in VLAN 223)
(pf::enforcement::_should_we_reassign_vlan)
May 23 11:57:13 httpd.admin(0) INFO: switch port for 00:0b:5d:23:02:4d is
10.2.253.2 ifIndex 10115 connection type: Wired MAC Auth
(pf::enforcement::_vlan_reevaluation)
May 23 11:57:17 pfsetvlan(21) INFO: local (127.0.0.1) trap for switch
10.2.253.2 (main::parseTrap)
May 23 11:57:17 pfsetvlan(1) INFO: nb of items in queue: 1; nb of threads
running: 0 (main::startTrapHandlers)
May 23 11:57:17 pfsetvlan(1) INFO: reAssignVlan trap received on
10.2.253.2 ifIndex 10115 (main::handleTrap)
May 23 11:57:17 pfsetvlan(1) WARN: Until CoA is implemented we will bounce
the port on VLAN re-assignment traps for MAC-Auth
(pf::SNMP::handleReAssignVlanTrapForWiredMacAuth)
May 23 11:57:21 pfsetvlan(1) INFO: finished (main::cleanupAfterThread)
May 23 11:57:39 pf::WebAPI(3916) INFO: handling radius autz request: from
switch_ip => 10.2.253.2, connection_type => Ethernet-NoEAP mac =>
00:0b:5d:23:02:4d, port => 50015, username => 000b5d23024d
(pf::radius::authorize)
May 23 11:57:39 pf::WebAPI(3916) INFO: MAC: 00:0b:5d:23:02:4d, PID: admin,
Status: reg. Returned VLAN: 223 (pf::vlan::fetchVlanForNode)
May 23 11:57:39 pf::WebAPI(3916) WARN: Role-based Network Access Control
is not supported on network device type pf::SNMP::Cisco::Catalyst_3560G.
 (pf::SNMP::supportsRoleBasedEnforcement)

   Cheers
   LT

Citando Francis Lachapelle <[email protected]>: > Hi Luis

  On 2013-05-20, at 7:03 AM, luis torres <[email protected]> wrote:
trought the browser , in nodes section, I can only enforce vlans on
a specific node , between Register or Unregiste, Grace and Pending
doesnt do nothing..., however if I give the cmd
(/usr/local/pf/bin/pfcmd node edit 00:0b:5d:23:02:4d
pid=admin,status="grace")  on the linux with root user, it works
perfectly.
  I committed a fix yesterday :

https://github.com/inverse-inc/packetfence/commit/27ca8615999265099dc5e00b4fe5cd4c33991ddd

  It will be integrated to 4.0.2.

  Thanks,

  Francis

  --
[email protected] :: +1.514.755.3640 :: http://www.inverse.ca
  Inverse :: Leaders behind SOGo (http://sogo.nu) and PacketFence
(http://packetfence.org)



------------------------------------------------------------------------------
  Try New Relic Now & We'll Send You this Cool Shirt
  New Relic is the only SaaS-based application performance monitoring service
  that delivers powerful full stack analytics. Optimize and monitor your
  browser, app, & servers with just a few lines of code. Try New Relic
  and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_may
  _______________________________________________
  PacketFence-users mailing list
[email protected]https://lists.sourceforge.net/lists/listinfo/packetfence-users
------------------------------------------------------------------------------
Try New Relic Now & We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, & servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_may
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to