Hello Daniele,

VLAN filter because the security event are triggered by DHCP so much slower 
reaction than the VLAN filter that operate on the radius request.

Thanks,

Ludovic Zammit
Product Support Engineer Principal

Cell: +1.613.670.8432
Akamai Technologies - Inverse
145 Broadway
Cambridge, MA 02142
Connect with Us:         <https://community.akamai.com/>  
<http://blogs.akamai.com/>  <https://twitter.com/akamai>  
<http://www.facebook.com/AkamaiTechnologies>  
<http://www.linkedin.com/company/akamai-technologies>  
<http://www.youtube.com/user/akamaitechnologies?feature=results_main>

> On Jul 15, 2022, at 2:24 PM, Daniele via PacketFence-users 
> <packetfence-users@lists.sourceforge.net> wrote:
> 
> Thanks, it works!
> But I have some doubts. I tried to do the same thing using the security event 
> "Connection transport change" with action "Unregister" and target role 
> "Registration"
> What is the main difference in using filters or security events? which one is 
> recommended to use?
> 
> Thanks,
> Daniele
> 
> Il giorno ven 15 lug 2022 alle ore 14:16 Zammit, Ludovic <luza...@akamai.com 
> <mailto:luza...@akamai.com>> ha scritto:
> Hello Daniele,
> 
> Depending on the PF version that you are using, PF has a VLAN filter rules 
> that automatically unregister device seen doing Mac authentication while 
> their previous authentication known was 802.1x.
> 
> That rule is by default enabled on the wireless but not on the wired.
> 
> Thanks,
> 
> Ludovic Zammit
> Product Support Engineer Principal
> 
> Cell: +1.613.670.8432
> Akamai Technologies - Inverse
> 145 Broadway
> Cambridge, MA 02142
> Connect with Us:       <https://community.akamai.com/>  
> <http://blogs.akamai.com/>  
> <https://urldefense.com/v3/__https://twitter.com/akamai__;!!GjvTz_vk!QpZfjf_6veWYtJeHwD3DvakpRDclz4QHtYfrwDY1CUe7cJf9AcfLd2mSdZHJR--oVaITqqOOKmHhk_fyCJMur7WsqgbXsm8nlIdgcg$>
>   
> <https://urldefense.com/v3/__http://www.facebook.com/AkamaiTechnologies__;!!GjvTz_vk!QpZfjf_6veWYtJeHwD3DvakpRDclz4QHtYfrwDY1CUe7cJf9AcfLd2mSdZHJR--oVaITqqOOKmHhk_fyCJMur7WsqgbXsm-uAITL5Q$>
>   
> <https://urldefense.com/v3/__http://www.linkedin.com/company/akamai-technologies__;!!GjvTz_vk!QpZfjf_6veWYtJeHwD3DvakpRDclz4QHtYfrwDY1CUe7cJf9AcfLd2mSdZHJR--oVaITqqOOKmHhk_fyCJMur7WsqgbXsm_8_dw_gw$>
>   
> <https://urldefense.com/v3/__http://www.youtube.com/user/akamaitechnologies?feature=results_main__;!!GjvTz_vk!QpZfjf_6veWYtJeHwD3DvakpRDclz4QHtYfrwDY1CUe7cJf9AcfLd2mSdZHJR--oVaITqqOOKmHhk_fyCJMur7WsqgbXsm9dWYLpBw$>
> 
>> On Jul 14, 2022, at 7:02 PM, Daniele via PacketFence-users 
>> <packetfence-users@lists.sourceforge.net 
>> <mailto:packetfence-users@lists.sourceforge.net>> wrote:
>> 
>> Hello, everybody.
>> I am using packetfence 10.1 in dot1x + mab mode.
>> Everything works correctly, business users authenticate with domain 
>> credentials and guests through the portal. However, I have a problem. When a 
>> user is already authenticated with dot1x, if I use the same mac address on 
>> another network device on any other network port, the new device is 
>> authenticated in mab even without entering credentials. Is there any way to 
>> prevent mab from inheriting authentication from dot1x? in other words, how 
>> to force the re-authentication of a device if the mac address is already 
>> registered with dot1x somewhere else?
>> 
>> Thanks,
>> Daniele
>> _______________________________________________
>> PacketFence-users mailing list
>> PacketFence-users@lists.sourceforge.net 
>> <mailto:PacketFence-users@lists.sourceforge.net>
>> https://urldefense.com/v3/__https://lists.sourceforge.net/lists/listinfo/packetfence-users__;!!GjvTz_vk!V2aSBtnSYfHgZufxrG_MFLKGDLfb5Rrp1qTszoImP1zuZ1QaKjqFzX9yNxHMwkJyroD9iRqV0YMGTIpzst5eEX-li5NhX-XBKL-0FA$
>>  
>> <https://urldefense.com/v3/__https://lists.sourceforge.net/lists/listinfo/packetfence-users__;!!GjvTz_vk!V2aSBtnSYfHgZufxrG_MFLKGDLfb5Rrp1qTszoImP1zuZ1QaKjqFzX9yNxHMwkJyroD9iRqV0YMGTIpzst5eEX-li5NhX-XBKL-0FA$>
>>  
> 
> _______________________________________________
> PacketFence-users mailing list
> PacketFence-users@lists.sourceforge.net
> https://urldefense.com/v3/__https://lists.sourceforge.net/lists/listinfo/packetfence-users__;!!GjvTz_vk!QpZfjf_6veWYtJeHwD3DvakpRDclz4QHtYfrwDY1CUe7cJf9AcfLd2mSdZHJR--oVaITqqOOKmHhk_fyCJMur7WsqgbXsm-xTZPaWQ$
>  

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to