Hello Ghani,

The simplest way to do it is to set -1 in the registration role.

Regards

Fabrice


Le 19-11-18 à 07 h 11, Sajawal Ghani via PacketFence-users a écrit :

Hello,

I am posting here for the first time, pardon me if this isn't the correct place to ask a question about PacketFence functionality.

I am using MAC authentication for the Phone and other devices that do not support dot1x supplicant. I have observed and understood that PacketFence will always send an access-accept response to the device with MAC authentication with the registration VLAN for the sake of Portal registration if needed. I wouldn't be using Portal authentication for the phones. Therefore, I need that PacketFence doesn't send an access-accept response for the devices that register with MAC-Auth. Is there any way I can achieve this i.e. PacketFence doesn't send an access-accept response until I have manually registered on the web front-end. I have checked the radius filters but I couldn't find the available scope* returnradiusAccessReject* at least in radius_filters.conf, which I believe I could use in the case of Ethernet-NoEAP.

I am looking forward to your response and would really appreciate it.
Thank you.




_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

--
Fabrice Durand
[email protected] ::  +1.514.447.4918 (x135) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org)

_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to