Hello Yan,

my answer bellow.


Le 2017-07-21 à 06:13, Yan Kimiko via PacketFence-users a écrit :
Hi all,

Our company has the intent to use PF in our office environment later this year. 
Since there are over 7000 people in our company(which means devices’ number is 
over 1.5w),we have to do sufficient previous confirmation before we deploy PF 
in our production environment.

I’ve checked PF website and there is a list of PF supported material but not so 
detail.

I’ve listed the switches used in our company, can anyone help to confirm us if 
our switches can integrate well with PF to fulfill our requirement ?

Our Switch list:
Cisco: C3850、C3650、C2960XR、C2960X、C4500E、C6500E
Let's say ios version starting from 12.2 then you will be good.
H3C:H3C S5120S S5120 S5130 S3600 S7500
Check if you are able to apply this configuration on each h3c switches (https://packetfence.org/doc/PacketFence_Network_Devices_Configuration_Guide.html#_h3c).
I am not enough aware of h3c switches config.



Our requirement:
1.Identification
—802.1x based on user info from AD source or based on device’s MAC address.
802.1x and mac auth bypass seems to be ok for both.

2.Compliance and health check when registering to office network.
—When a device logs in, checking if the device has installed our official 
antivirus software before giving the device normal network’s access.Isolated 
the device from normal inner network but gives it restricted network access so 
that they can have a way to install the required software.
wmi scan

3.Isolation dangerous device from normal network
—When our antivirus agent find some threat exists in the device, update the 
device’s VLAN to an isolation VLAN so that the threat won’t spread to other 
inner network.
you need to find a way to trigger a webservice api call from the antivirus management console or send the syslog to packetfence.
4.Device management
—Offer a place to check all the devices’ status and have the ability to control 
their network access manually.
PacketFence admin gui

Appreciate your reply gratefully.
You can probably ask inverse for consulting since your setup look a little bit advance.

Regards
Fabrice


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to