Hello all,

 

Having a problem getting my 2530's working properly with PacketFence 5.3.0
on CentOS 6.6. 

 

Currently the switches are sending the Mac Address violation traps and the
server is receiving them. The server states that it is authorizing the MAC
Address. (Doesn't Actually happen) It then successfully sets the VLAN of the
port to the registration VLAN.

 

So my problem is that because it doesn't overwrite the the Mac Address in
the security table, the connection doesn't progress. The log shows no errors
that I can find. 

 

Jul 22 11:27:04 pfsetvlan(2) INFO: nb of items in queue: 1; nb of threads
running: 0 (main::startTrapHandlers)

Jul 22 11:27:04 pfsetvlan(2) INFO: secureMacAddrViolation trap received on
10.10.10.8 ifIndex 9 for f0:de:f1:e1:d0:f9 (main::handleTrap)

Jul 22 11:27:04 pfsetvlan(2) INFO: Will try to check on this node's previous
switch if secured entry needs to be removed. Old Switch IP: 10.10.10.8
(main::do_port_security)

Jul 22 11:27:04 pfsetvlan(2) INFO: MAC not found on node's previous switch
secure table or switch inaccessible. (main::do_port_security)

Jul 22 11:27:06 pfsetvlan(2) INFO: [f0:de:f1:e1:d0:f9] is of status unreg;
belongs into registration VLAN (pf::vlan::getRegistrationVlan)

Jul 22 11:27:06 pfsetvlan(2) INFO: authorizing f0:de:f1:e1:d0:f9 (old entry
00:10:02:00:30:04) at new location 10.10.10.8 ifIndex 9 (main::handleTrap)

Jul 22 11:27:06 pfsetvlan(2) INFO: setting VLAN at 10.10.10.8 ifIndex 9 from
4000 to 50 (pf::Switch::setVlan)

Jul 22 11:27:06 pfsetvlan(2) INFO: finished (main::cleanupAfterThread)

 

 

I know from working with the switch CLI directly that you can't just specify
a new Mac Address. It generates the output below.

 

GREENRMSWT24(config)# port-security 7 mac-address f0def1e1d0f9

Too many addresses for port 7.

 

I suspect this is the issue with packetfence unless it is using a different
command to change the mac address. 

 

Any thoughts or suggestions?

Thanks

 

Paul Taylor

IT Support
Luther College High School



 

 

 

------------------------------------------------------------------------------
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to