Hello Jona,

you need to run pf-maint.pl on you system first.

Regards

Fabrice


Le 19-07-22 à 05 h 58, Stegmaier, Jona via PacketFence-users a écrit :

Hello,

thanks for your reply!

I tried the authentication with the help of roles, but nothing changed. Packetfence sends the role update, but the access points can’t enforce the VLAN change.

The only error message, that Packetfence creates, you can find in the last line:

Jul 22 11:04:31 packetfence packetfence_httpd.portal: httpd.portal(24693) INFO: [mac:ac:7b:a1:55:25:9e] User default has authenticated on the portal. (Class::MOP::Class:::after)

Jul 22 11:04:31 packetfence packetfence_httpd.portal: httpd.portal(24693) WARN: [mac:ac:7b:a1:55:25:9e] Unknown network type for network 10.82.51.0 (pf::config::get_network_type)

Jul 22 11:04:31 packetfence packetfence_httpd.portal: httpd.portal(24693) INFO: [mac:ac:7b:a1:55:25:9e] re-evaluating access (manage_register called) (pf::enforcement::reevaluate_access)

Jul 22 11:04:31 packetfence packetfence_httpd.portal: httpd.portal(24693) INFO: [mac:ac:7b:a1:55:25:9e] VLAN reassignment is forced. (pf::enforcement::_should_we_reassign_vlan)

Jul 22 11:04:31 packetfence packetfence_httpd.portal: httpd.portal(24693) INFO: [mac:ac:7b:a1:55:25:9e] switch port is (10.82.50.167) ifIndex unknown connection type: WiFi MAC Auth (pf::enforcement::_vlan_reevaluation)

Jul 22 11:04:32 packetfence pfqueue: pfqueue(28927) INFO: [mac:ac:7b:a1:55:25:9e] [ac:7b:a1:55:25:9e] DesAssociating mac on switch (10.82.50.167) (pf::api::desAssociate)

Jul 22 11:04:32 packetfence pfqueue: pfqueue(28927) INFO: [mac:ac:7b:a1:55:25:9e] [10.82.50.167] Returning ACCEPT with role: -test- (pf::Switch::Aruba::Instant_Access::radiusDisconnect)

Jul 22 11:04:32 packetfence pfqueue: pfqueue(28927) ERROR: [mac:ac:7b:a1:55:25:9e] Error handling desAssociate : Undefined subroutine &pf::Switch::Aruba::Instant_Access::perform_coa called at /usr/local/pf/lib/pf/Switch/Aruba/Instant_Access.pm line 81.

Best regards,

Jona

*Von:*G PL via PacketFence-users <[email protected]>
*Gesendet:* Samstag, 20. Juli 2019 23:29
*An:* [email protected]
*Cc:* G PL <[email protected]>
*Betreff:* Re: [PacketFence-users] Configuration help for Aruba Instant controller needed (guest access)

Hello,

In my setup, I'm sending role to the iap and not using coa. The iap translate role to vlan.

You need the register and guest role.

Regards

Le vendredi 19 juillet 2019, Stegmaier, Jona via PacketFence-users <[email protected] <mailto:[email protected]>> a écrit :

    Hi all,

    I try to configure a guest access (WLAN) with our Packetfence v9
    system and our Aruba Instant Virtual Controller (Version 6.5.4) /
    305 Access Points.

    The steps of the official support document refer to an older
    version of Aruba Instant, so I want to ask, if anybody uses the
    Aruba Version 6 and can tell me, how to configure the Aruba
    controller.

    I tried an configuration, but the process fails, when Packetfence
    tries to enforce the guest VLAN. (no VLAN change is made).

    On the packetfence side, CoA is enabled (and all the necessary
    VLAN roles).

    Thanks and best regards,
    Jona

--
    Jona Stegmaier

    Fraunhofer-Institut für Physikalische Messtechnik IPM; ITK

    Heidenhofstr. 8, 79110 Freiburg, Germany
    
<https://www.google.com/maps/search/Heidenhofstr.+8,+79110+Freiburg,+Germany?entry=gmail&source=g>


    Phone +49 761 8857-132, [email protected]
    <mailto:[email protected]>

    https://www.ipm.fraunhofer.de



_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

--
Fabrice Durand
[email protected] ::  +1.514.447.4918 (x135) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org)

_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to