Hello Adrian,

this is not the correct approach and it's not really a good idea to use the local freeradius server as a source.

What you can do instead is to use the local accounts to authenticate the users.

Like create a new user in packetfence, assign a role and an access duration.

On a connection profile with let's say a filter based on the SSID name add the "local" source.

So when you will hit the portal, packetfence will instanciate the correct connection profile and use the local source to authenticate.

Regards

Fabrice


Le 20-11-20 à 15 h 23, Adrian D'Atri-Guiran via PacketFence-users a écrit :
Hello,

I am attempting to set up packetfence 10.2 on Debian 9. My goal is to
have users authenticate via a captive portal, and have each user
mapped to a unique and specific VLAN.  As far I am aware, the only way
to accomplish this is via authentication with RADIUS.  I would like to
know if this would be possible using only packetfence as the
authentication / user manager, if so which authentication source do I
use? otherwise, if radius is required, please review my problem below.

On /admin/alt#/configuration/sources
I have added an internal source, RADIUS, in the config for this source
I have defined the host as 127.0.0.1 and port 18120 and secret.
(I have also tried 10.2.2.254 as the host, and a wide variety of
different ports.)
https://i.imgur.com/SBFPctS.png

In /admin/alt#/configuration/realms
I have added RADIUS with the following config: https://i.imgur.com/0yektXa.png

In /admin/alt#/configuration/interfaces
I have one interface defined, with daemons `portal` and `radius`
https://i.imgur.com/Sc1S7V6.png

I have added a user to the top of:
$ head -n 1 /usr/local/pf/raddb/users
test Cleartext-Password := "qwerty"

When I direct my computer to 10.2.2.254/captive-portal I receive a
captive portal, and after checking the box I get the login prompt.
When I enter in 'test' and 'qwerty' i receive this error in
/usr/local/pf/logs/packetfence.log:
ERROR: [mac:68:f7:28:e1:a6:26] Unable to perform RADIUS authentication
on any server: ERECVFAIL
(pf::Authentication::Source::RADIUSSource::_handle_radius_request)
and at the same time I receive no new messages in /usr/local/pf/logs/radius.log

I have tried to test using radtest, and at first I was unsuccessful,
until I changed the radius config
in:/usr/local/pf/conf/radiusd/auth.conf
To enable it to bind to a port other than port 0. Note: this feels
really wrong, should I really have to be changing these configs to get
Radius working with packetfence?
listen {
         ipaddr = [% ip %]
         port = 0
         type = auth
         virtual_server = [% virtual_server %]
}
to:
listen {
         ipaddr = [% ip %]
         port = 18120
         type = auth
         virtual_server = [% virtual_server %]
}

After this change I was able to confirm radius was sort of working with:
radtest test qwerty2 10.2.2.254:18120 12 redacted_shared_secret
I receive:
Sent Access-Request Id 221 from 0.0.0.0:43344 to 10.2.2.254:18120 length 75
         User-Name = "test2"
         User-Password = "qwerty2"
         NAS-IP-Address = 10.2.2.254
         NAS-Port = 12
         Message-Authenticator = 0x00
         Cleartext-Password = "qwerty2"
Received Access-Accept Id 221 from 10.2.2.254:18120 to
10.2.2.254:43344 length 20

But the strangest part about this is that I can actually send any
username/password and get Access-Accept.

Despite the above changes, when I attempt to login via the captive
portal I receive:
ERROR: [mac:68:f7:28:e1:a6:26] Unable to perform RADIUS authentication
on any server: ERECVFAIL
(pf::Authentication::Source::RADIUSSource::_handle_radius_request)

Thank you for your time, I appreciate it immensely.
-Adrian


_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users


_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to