Hi Everyone,

We patched the system using pf-maint.pl, and it did not resolve any of the
issues that we are having.
A user successfully authenticates but none of the profiles we have
configured are selected not even the default profile is selected.
Because of that the user never connects to the network because Radius does
not return a valid Vlan.
The owner in the nodes table is set to default even though the user
successfully authenticated and the user information is not registered in
the system either.

At what stage does PF determine the connection profile that needs to be
used based on the configured filters?

I will be more than happy to share the debug file from Radius regarding
this issue.

Best,

Nadim

On Wed, Feb 5, 2020 at 2:19 AM Nadim El-Khoury <nel-kho...@springfield.edu>
wrote:

> Hi Everyone,
>
> It does not look like that PF 9.3.0 is able to assign the right connection
> profile once a user is authenticated.
>
> Question 1) Why is the right connection profile not being picked up based
> on the created filter?
> Question 2) Can the default connection profile be disabled?
> Question 3) Why is the system not entering the right owner for the
> registered device after successful authentication?
> Question 4) Why is the connection profile is set to N/A when it does not
> properly match a profile?
>
> When running the /usr/local/pf/bin/pftest authentication username ""
> The command returns the right AD group the user is part of.
>
> Recomputing of roles does not seem to be working if a device is
> successfully registered with another user or owner. So, if a new user uses
> the same device the role is not recomputed and the new user using the same
> old registered device ends up with the same previous role as the previous
> user.
>
> Question 1) How can we change the above behavior?
>
> Your help is very much appreciated.
>
> Best,
>
> Nadim
>
>
_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to