Hello Zammit,
Kindly look into this.
Any help will be appreciated.
Thanks,
*Vincent Oliver*
System Support Engineer | Linux Enthusiast | Transitioning into DevOps
[email protected]
On 7/28/2026 1:12 PM, Vincent wrote:
Hi All,
Greetings!
We recently stood up a PacketFence NAC pilot (v15.0.0 on Rocky Linux)
covering wired 802.1X/PEAP, MAC Authentication Bypass, and a captive
portal flow, integrated with Active Directory for role-based VLAN
assignment on a Cisco Catalyst 2960S. The core flow is working, but we
ran into several recurring issues during setup that I'd appreciate the
community's input on, in case others have hit the same things.
1) Authentication rule matching is strictly first-match, not best-match
Within a single authentication source (AD, in our case), we have rules
like "memberOf Finance group -> role FINDEPT" and "memberOf IT group
-> role ITDEPT". We found that when a user matched more than one
rule's condition, PacketFence always applied whichever rule appears
first (by position), not the most specific match, with no visible
warning that multiple rules matched. This caused a real mix-up during
testing where a Finance-group user was silently assigned the IT role
because the IT rule happened to be listed first. Is this
expected/documented behavior, and is there a recommended way to make
rule matching more deterministic (e.g. mutually exclusive rule
conditions, or a way to flag when a user matches more than one rule)?
We'd also like confirmation that reordering rules must be done via the
admin UI drag-and-drop (to correctly persist priority), since editing
authentication.conf by hand didn't reliably reflect the same order the
UI would have produced.
2) iptables rules disappearing on "Other" type interfaces
We created a management-only VLAN interface (not
Registration/Isolation type) so PacketFence could reach our switch for
RADIUS/CoA. We found that PacketFence never auto-generates iptables
ACCEPT rules for RADIUS (1812/1813) or CoA (3799) on "Other" type
interfaces the way it does for Registration/Isolation. We had to add
these manually, and they kept getting wiped whenever config reloaded
or certain services restarted. Is there a supported way to have
PacketFence persist/manage firewall rules for RADIUS traffic on a
non-Registration/Isolation interface, rather than us maintaining them
outside PacketFence's control?
3) httpd.portal container being killed unexpectedly
Mid-session, our httpd.portal Docker container was killed (log showed
an explicit SIGKILL and "No such container" message from a wrapper
script), causing captive portal 503s, while other containers
(httpd.webservices, etc.) stayed healthy. We didn't find a clear
trigger in our own actions. Has anyone seen this pattern, and is there
a known cause (Docker cleanup routine, resource limit, watchdog) we
should be looking at?
4) Consumer-grade wireless AP and dynamic VLAN assignment
We attempted WPA2-Enterprise (PEAP) authentication via a consumer
TP-Link router configured as an AP. RADIUS authentication itself
worked correctly, but the AP does not appear to support RADIUS
CoA/Disconnect-Message (RFC 3576), so PacketFence's dynamic VLAN
reassignment after role evaluation never applied - we saw repeated
"Unable to perform RADIUS Disconnect-Request: Timeout" in the logs. We
ended up designing around this with a fixed VLAN per SSID instead. Is
there a known list of consumer/prosumer AP hardware that reliably
supports CoA for anyone considering a similar low-cost wireless pilot?
5) Guest VLAN with a Registration-type interface never getting real
internet access
We set up a guest VLAN as a "Registration" type interface in
PacketFence, and predictably it stayed walled-garden (DNS hijack to
the portal) even after guest role/auth succeeded. We understand this
is by design for Registration/Isolation interfaces. For a guest VLAN
that should get real internet after authenticating, is the recommended
pattern to always use an "Other" type interface with a separate
router/firewall as the gateway (similar to a production VLAN), rather
than trying to get PacketFence itself to route/NAT that traffic?
6) Role file (roles.conf) losing entries after renaming roles via the
admin UI
We renamed a couple of roles via the GUI mid-project and later found
that roles.conf only contained the renamed roles - two other roles we
still actively use in switches.conf and authentication rules (guest,
isolation) had disappeared from roles.conf entirely. Is this expected
behavior when renaming roles through the UI, and is there a safer
workflow to rename roles without orphaning others?
Any pointers, known issues, or links to relevant tickets/docs would be
much appreciated. Happy to share more logs/configs if useful for
troubleshooting.
Thanks in advance,
--
*Vincent Oliver*
System Support Engineer | Linux Enthusiast | Transitioning into DevOps
[email protected]
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users