Hi Fabrice,

Once again great advice and thank you so much for your help!  I have
imported all the roles, and added the Dynamic VLAN definition to
radius_filters.conf and it sort of works, but not exactly as intended.
If I create a new user 'test' and assign it to the role 'room906' it
will fail to do the dynamic vlan assignment.  If I create a user with
username 'room906' and assign it to the role 'room906', then the
dynamic vlan assignment does work!  I believe that in your code it
looks at the username instead of the rolename?  Is there a way to use
the role name instead?
I'm guessing something like:
BuildFromMatch($node_info.role,"^room(\d+)$","$1")
But i'm not sure about the correct syntax, etc.

Also there is a WARN "No parameter room906Vlan found in
conf/switches.conf" even when the dynamic vlan does work, i'm not sure
if this is important or can just be ignored.

Thanks!

Logs:
# username test example
[mac:5c:e0:c5:c1:d6:fd] Instantiate profile RookHotelGuest
(pf::Connection::ProfileFactory::_from_profile)
[mac:5c:e0:c5:c1:d6:fd] Found authentication source(s) : 'local' for
realm 'null' (pf::config::util::filter_authentication_sources)
[mac:5c:e0:c5:c1:d6:fd] Connection type is MAC-AUTH. Getting role from
node_info (pf::role::getRegisteredRole)
[mac:5c:e0:c5:c1:d6:fd] Username was defined "5c:e0:c5:c1:d6:fd" -
returning role 'room906' (pf::role::getRegisteredRole)
[mac:5c:e0:c5:c1:d6:fd] PID: "test", Status: reg Returned VLAN:
(undefined), Role: room906 (pf::role::fetchRoleForNode)
[mac:5c:e0:c5:c1:d6:fd] No parameter room906Vlan found in
conf/switches.conf for the switch 10.2.2.59
(pf::Switch::getVlanByName)

# username room906 example
INFO: [mac:5c:e0:c5:c1:d6:fd] handling radius autz request: from
switch_ip => (10.2.2.59), connection_type =>
Wireless-802.11-NoEAP,switch_mac => (74:83:c2:25:e2:d4), mac =>
[5c:e0:c5:c1:d6:fd], port => 0, username => "5c:e0:c5:c1:d6:fd", ssid
=> Rook Hotel Unifi (pf::radius::authorize)
INFO: [mac:5c:e0:c5:c1:d6:fd] Instantiate profile RookHotelGuest
(pf::Connection::ProfileFactory::_from_profile)
INFO: [mac:5c:e0:c5:c1:d6:fd] Found authentication source(s) : 'local'
for realm 'null' (pf::config::util::filter_authentication_sources)
INFO: [mac:5c:e0:c5:c1:d6:fd] Connection type is MAC-AUTH. Getting
role from node_info (pf::role::getRegisteredRole)
INFO: [mac:5c:e0:c5:c1:d6:fd] Username was defined "5c:e0:c5:c1:d6:fd"
- returning role 'room906' (pf::role::getRegisteredRole)
INFO: [mac:5c:e0:c5:c1:d6:fd] PID: "room906", Status: reg Returned
VLAN: (undefined), Role: room906 (pf::role::fetchRoleForNode)
WARN: [mac:5c:e0:c5:c1:d6:fd] No parameter room906Vlan found in
conf/switches.conf for the switch 10.2.2.59
(pf::Switch::getVlanByName)
INFO: [mac:5c:e0:c5:c1:d6:fd] Match rule DynamicVLAN
(pf::access_filter::radius::test)

On Wed, Nov 25, 2020 at 6:09 PM Durand fabrice <[email protected]> wrote:
>
> Hello Adrian,
>
> there is multiples way.
>
> First one, fill the roles.conf file:
>
> [room1]
> max_nodes_per_pid=0
> notes=Room1 devices
>
> [room2]
> max_nodes_per_pid=0
> notes=Room2 devices
>
> [room3]
> max_nodes_per_pid=0
> notes=Room3 devices
>
>
> ...
>
> Then run addons/upgrade/to-7.0-roles-conf.pl (it will insert them in the
> db).
>
> Next you can check how a user is created from the admin gui (enable dev
> mode in chrome and check the network tab to see what is the request and
> what is the payload)
>
>
> Second one (a little bit more advanced)
>
> You need to have the users in packetfence , then add this in
> radius_filters.conf
>
> [DynamicVLAN]
> answer.1=reply:Tunnel-Type = VLAN
> status=enabled
> answer.0=reply:Tunnel-Medium-Type = IEEE-802
> description=Return VLAN id based on the room number
> scopes=returnRadiusAccessAccept
> radius_status=RLM_MODULE_OK
> merge_answer=no
> answer.2=reply:Tunnel-Private-Group-Id =
> ${BuildFromMatch($node_info.pid,"^room(\d+)$","$1")}
> condition=node_info.pid =~ "room(\\d+)" && node_info.status == "reg"
>
>
> So it mean if the device is reg and the pid is room(digit) then return
> the vlan id (digit).
>
> So per example the device have the pid room101 then packetfence will
> return the vlan id 101.
>
> room102 -> vlan 102
>
> ...
>
> I hope it will help.
>
> Regards
>
> Fabrice
>
>
> Le 20-11-25 à 17 h 47, Adrian D'Atri-Guiran a écrit :
> > Hi Fabrice,
> >
> > This was helpful.  I have some small problems with this approach
> > though.  For my building I have 120 rooms.
> > As I understand, I should add 120 roles -- one for each room.
> > For each of my access points I should define VLAN ID for each of those
> > 120 roles.
> > While this is a bit tedious but not impossible.
> >
> > Questions:
> > 1) I looked at the API to see if there is some way to programatically
> > create these 120 roles, but there is no method for POST
> > /api/v1/config/roles. So for bulk role creation this must be done
> > manually?
> >
> > 2) At guest check in, I wish to programmatically generate a new user
> > and assign them to this role using the API.  I looked at endpoint:
> > POST /api/v1/users and this does allow me to create a user, but the
> > user has no username, and more importantly, there is no way to assign
> > a role to this user with the API?
> >
> > 3) Is there some way I could use a script or code block to define the
> > VLAN ID assignment from role? I'm worried that someone will make a
> > mistake when entering in these VLAN IDs for each of the 120 roles on
> > each new AP that is installed.
> >
> > Thank you,
> > Adrian
> >
> > On Tue, Nov 24, 2020 at 5:57 PM Durand fabrice <[email protected]> wrote:
> >> Hello Adrian,
> >>
> >> create a role for each room (like room101 room102 ...) then in the
> >> switch config define the vlan id for each roles.
> >>
> >> Btw you need to set the correct role for each users.
> >>
> >> Regards
> >>
> >> Fabrice
> >>
> >>
> >> Le 20-11-22 à 19 h 00, Adrian D'Atri-Guiran a écrit :
> >>> Hello Fabrice,
> >>>
> >>> Thank you, this was immensely helpful.  I now have my users
> >>> authenticating and getting past the captive portal.  But I can't
> >>> figure out how I should assign them a VLAN? where is this setting?
> >>> My goal is 1 vlan per hotel room, i.e. 1 vlan per login.  For example:
> >>> Room 101 - username 101 - password (set via API at check in) - vlan 101
> >>> Room 102 - username 102 - password (set via API at check in) - vlan 102
> >>> Room 103 - username 103 - password (set via API at check in) - vlan 103
> >>>
> >>> Please point me in the right direction to accomplish this.
> >>> Thank you,
> >>> Adrian
> >>>
> >>> On Fri, Nov 20, 2020 at 7:00 PM Durand fabrice via PacketFence-users
> >>> <[email protected]> wrote:
> >>>> Hello Adrian,
> >>>>
> >>>> this is not the correct approach and it's not really a good idea to use
> >>>> the local freeradius server as a source.
> >>>>
> >>>> What you can do instead is to use the local accounts to authenticate the
> >>>> users.
> >>>>
> >>>> Like create a new user in packetfence, assign a role and an access 
> >>>> duration.
> >>>>
> >>>> On a connection profile with let's say a filter based on the SSID name
> >>>> add the "local" source.
> >>>>
> >>>> So when you will hit the portal, packetfence will instanciate the
> >>>> correct connection profile and use the local source to authenticate.
> >>>>
> >>>> Regards
> >>>>
> >>>> Fabrice
> >>>>
> >>>>
> >>>> Le 20-11-20 à 15 h 23, Adrian D'Atri-Guiran via PacketFence-users a 
> >>>> écrit :
> >>>>> Hello,
> >>>>>
> >>>>> I am attempting to set up packetfence 10.2 on Debian 9. My goal is to
> >>>>> have users authenticate via a captive portal, and have each user
> >>>>> mapped to a unique and specific VLAN.  As far I am aware, the only way
> >>>>> to accomplish this is via authentication with RADIUS.  I would like to
> >>>>> know if this would be possible using only packetfence as the
> >>>>> authentication / user manager, if so which authentication source do I
> >>>>> use? otherwise, if radius is required, please review my problem below.
> >>>>>
> >>>>> On /admin/alt#/configuration/sources
> >>>>> I have added an internal source, RADIUS, in the config for this source
> >>>>> I have defined the host as 127.0.0.1 and port 18120 and secret.
> >>>>> (I have also tried 10.2.2.254 as the host, and a wide variety of
> >>>>> different ports.)
> >>>>> https://i.imgur.com/SBFPctS.png
> >>>>>
> >>>>> In /admin/alt#/configuration/realms
> >>>>> I have added RADIUS with the following config: 
> >>>>> https://i.imgur.com/0yektXa.png
> >>>>>
> >>>>> In /admin/alt#/configuration/interfaces
> >>>>> I have one interface defined, with daemons `portal` and `radius`
> >>>>> https://i.imgur.com/Sc1S7V6.png
> >>>>>
> >>>>> I have added a user to the top of:
> >>>>> $ head -n 1 /usr/local/pf/raddb/users
> >>>>> test Cleartext-Password := "qwerty"
> >>>>>
> >>>>> When I direct my computer to 10.2.2.254/captive-portal I receive a
> >>>>> captive portal, and after checking the box I get the login prompt.
> >>>>> When I enter in 'test' and 'qwerty' i receive this error in
> >>>>> /usr/local/pf/logs/packetfence.log:
> >>>>> ERROR: [mac:68:f7:28:e1:a6:26] Unable to perform RADIUS authentication
> >>>>> on any server: ERECVFAIL
> >>>>> (pf::Authentication::Source::RADIUSSource::_handle_radius_request)
> >>>>> and at the same time I receive no new messages in 
> >>>>> /usr/local/pf/logs/radius.log
> >>>>>
> >>>>> I have tried to test using radtest, and at first I was unsuccessful,
> >>>>> until I changed the radius config
> >>>>> in:/usr/local/pf/conf/radiusd/auth.conf
> >>>>> To enable it to bind to a port other than port 0. Note: this feels
> >>>>> really wrong, should I really have to be changing these configs to get
> >>>>> Radius working with packetfence?
> >>>>> listen {
> >>>>>            ipaddr = [% ip %]
> >>>>>            port = 0
> >>>>>            type = auth
> >>>>>            virtual_server = [% virtual_server %]
> >>>>> }
> >>>>> to:
> >>>>> listen {
> >>>>>            ipaddr = [% ip %]
> >>>>>            port = 18120
> >>>>>            type = auth
> >>>>>            virtual_server = [% virtual_server %]
> >>>>> }
> >>>>>
> >>>>> After this change I was able to confirm radius was sort of working with:
> >>>>> radtest test qwerty2 10.2.2.254:18120 12 redacted_shared_secret
> >>>>> I receive:
> >>>>> Sent Access-Request Id 221 from 0.0.0.0:43344 to 10.2.2.254:18120 
> >>>>> length 75
> >>>>>            User-Name = "test2"
> >>>>>            User-Password = "qwerty2"
> >>>>>            NAS-IP-Address = 10.2.2.254
> >>>>>            NAS-Port = 12
> >>>>>            Message-Authenticator = 0x00
> >>>>>            Cleartext-Password = "qwerty2"
> >>>>> Received Access-Accept Id 221 from 10.2.2.254:18120 to
> >>>>> 10.2.2.254:43344 length 20
> >>>>>
> >>>>> But the strangest part about this is that I can actually send any
> >>>>> username/password and get Access-Accept.
> >>>>>
> >>>>> Despite the above changes, when I attempt to login via the captive
> >>>>> portal I receive:
> >>>>> ERROR: [mac:68:f7:28:e1:a6:26] Unable to perform RADIUS authentication
> >>>>> on any server: ERECVFAIL
> >>>>> (pf::Authentication::Source::RADIUSSource::_handle_radius_request)
> >>>>>
> >>>>> Thank you for your time, I appreciate it immensely.
> >>>>> -Adrian
> >>>>>
> >>>>>
> >>>>> _______________________________________________
> >>>>> PacketFence-users mailing list
> >>>>> [email protected]
> >>>>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
> >>>> _______________________________________________
> >>>> PacketFence-users mailing list
> >>>> [email protected]
> >>>> https://lists.sourceforge.net/lists/listinfo/packetfence-users


_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to