Hello Cristian,

When you say "the pc gets the correct ip address", is it given by PacketFence? Make sure the DNS and gateway are the interface registration of PacketFence.

Make sure you do not have any ACL on the switch or network that could conflict with it.

Try to reach the portal and see if the IP of the test device is hitting the portal look into logs/httpd.portal.access

Thanks


On 07/28/2017 08:00 AM, Cristian Mammoli via PacketFence-users wrote:
Hi, installed the latest pf on CentOS 7 following the official documentation, I configured a mangement, registration, isolation and portal interfaces. I joined the server to a AD domain, configured an authentication source and a connection profile and configured a switch (Cisco 2960x) with 8021.x+MAB.


Then I tried plugging a win7 notebook not yet joined to the domain in the switch port and packetfence correctly puts it in the registration vlan:

Jul 28 13:56:33 srvpf packetfence_httpd.aaa: httpd.aaa(12173) INFO: [mac:20:cf:30:36:7c:bb] handling radius autz request: from switch_ip => (192.168.16.44), connection_type => WIRED_MAC_AUTH,switch_mac => (2c:86:d2:5d:47:81), mac => [20:cf:30:36:7c:bb], port => 10101, username => "20cf30367cbb" (pf::radius::authorize) Jul 28 13:56:33 srvpf packetfence_httpd.aaa: httpd.aaa(12173) INFO: [mac:20:cf:30:36:7c:bb] Instantiate profile gruppoapra (pf::Connection::ProfileFactory::_from_profile) Jul 28 13:56:33 srvpf packetfence_httpd.aaa: httpd.aaa(12173) INFO: [mac:20:cf:30:36:7c:bb] is of status unreg; belongs into registration VLAN (pf::role::getRegistrationRole) Jul 28 13:56:33 srvpf packetfence_httpd.aaa: httpd.aaa(12173) INFO: [mac:20:cf:30:36:7c:bb] (192.168.16.44) Added VLAN 112 to the returned RADIUS Access-Accept (pf::Switch::returnRadiusAccessAccept)


The pc gets the correct ip address but from there there is no redirection to the captive portal, I can ping the packefence ip address on the registration vlan but nothing else. If I try to open a browser I get connection refused to every url


I'm new to packetfence so I'm probably missing somethin obviuos but any help would be greatly appreciated

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

--
Antoine Amacher
[email protected]  ::  www.inverse.ca
+1.514.447.4918 x130  :: +1 (866) 353-6153 x130
Inverse inc. :: Leaders behind SOGo (www.sogo.nu) and PacketFence 
(www.packetfence.org)


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to