Hello Matt,

with mac auth packetfence return by default Accept but the
vlan_id/Acl/Role is different based on the status of the device.

Let say if a device is unreg then you probably want to return Accept
with an acl name that will deny the access to the network and when you
set the device reg with a role then you probably want to Accept too by
with an acl name that will allow the device on the network.

On the opposite when you do 802.1x then if the username and password is
correct then PacketFence will return Accept but if you use a wrong
username and password the return will be Deny.

Also to debug when freeradius run, go in /usr/local/pf and do raddebug
-f var/run/radius.sock -t 3000


Regards
Fabrice

Le 2017-10-12 à 10:47, Matt Fogleman via PacketFence-users a écrit :
> I'm really new to both FreeRADIUS and PacketFence, what I am trying to
> do is just get a simple Mac auth configuration up for our wireless
> network.  I installed PacketFence with the new RADIUS only option on
> RHEL7, I added our wireless controller in the Configuration > Switches
> section and gave it the RADIUS key, and also configured the same thing
> on our wireless controller.
>
> It seems to be accepting connections, but it is just accepting
> everything.  I added the Mac address of a laptop in the "Nodes"
> section, and saw in Auditing that it sent back an Accept message.  But
> then I deleted the Mac address out of "Nodes" and tried again and it
> sent the Accept message again.  So I tried a different device that I
> hadn't added before, and it got accepted as well.
>
> Is there somewhere I have to configure the conditions for it to send
> back a Reject message?
>
> I'm also getting an error when trying to start debugging.
>
>     /Refusing to start with libssl version OpenSSL 1.0.1e-fips 11 Feb
>     2013 0x1000105f (1.0.1e release) (in range 1.0.1 release - 1.0.1t
>     rele)/
>
> Has anyone else encountered this?
>
> -- 
> *Matt Fogleman*
> Network Technician
> Unionville-Chadds Ford School District
> *(o)** (610) 347-0970*
>
>
> ------------------------------------------------------------------------------
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>
>
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users

-- 
Fabrice Durand
[email protected] ::  +1.514.447.4918 (x135) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org) 

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to