[PacketFence-users] Fingerbank accuracy

2018-08-23 Thread Max McGrath via PacketFence-users
Hi all -

I have a student trying to register a device via the /device-registration
page, but is unable to.

The device is showing up as 'Hardware Manufacturer' for its class and
'Private' for its type:

[image: image.png]

This is clearly not very accurate.  For the time being I have allowed
'Hardware Manufacturer' to be registered on the /device-registration page
by adding it to the *Device Registration* config section.

What can I do to help the accuracy of Fingerbank in the future?  I'm being
told that this is a Bluray player -- and am currently waiting to be told
the make/model of it.

Mid-email the student got back to me...she is telling me it is a RCA
BRC11072E - Blu-ray disc player.  I am taking her word on it as I have not
physically seen the device!

Thanks!

Max
--
Max McGrath  
Infrastructure and Security Manager
Carthage College
262-551-
mmcgr...@carthage.edu
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] VLAN Filter

2018-08-23 Thread Nicolas Quiniou-Briand via PacketFence-users

Hello Jason,

Try to rename your second action [autoreg:aruba_aps] to 
[autoreg_aruba_aps:aruba_aps]. Action names need to be unique and you 
define two actions with same name "autoreg".

--
Nicolas Quiniou-Briand
n...@inverse.ca  ::  +1.514.447.4918 *140  ::  https://inverse.ca
Inverse inc. :: Leaders behind SOGo (https://sogo.nu), PacketFence 
(https://packetfence.org) and Fingerbank (http://fingerbank.org)


--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Warnings after upgrade to 8.1.0

2018-08-23 Thread Christian Gfeller via PacketFence-users
Hello Fabrice
Tank you for your response.
I found the solution:
 in/usr/local/pf/conf/pf.conf.defaults
 variable "unifiedapi" was missing.


# ports.unified_api## port to use for accessing the Unified APIunifiedapi=
after adding this config, it works fine.
RegardsChristian


   Am Donnerstag, 23. August 2018, 03:54:47 MESZ hat Durand fabrice via 
PacketFence-users  Folgendes 
geschrieben:  
 
  
Hello Christian,
 
can you try that:
 
iptables-restore < /usr/local/pf/var/conf/iptables.conf
 
and see if you have any errors.
 
Regards
 
Fabrice
 

 
 
 Le 2018-08-21 à 11:52, Christian Gfeller via PacketFence-users a écrit :
  
 
 Hello  
  I have upgraded Packetfence from 8.0.1 to 8.1.0 on Debian 8. 
  Now i see the following warnings in packetfence.log: 
  Aug 21 16:50:04 nac-test packetfence: WARN -e(604): Problem trying to run 
command: LANG=C sudo /sbin/iptables -S | grep input-management-if called from 
manager::iptables::isAlive. Child exited with non-zero value 1 
(pf::util::pf_run) Aug 21 16:50:04 nac-test packetfence: WARN -e(604): Problem 
trying to run command: LANG=C sudo /sbin/iptables -S | grep input-management-if 
called from manager::iptables::isAlive. Child exited with non-zero value 1 
(pf::util::pf_run) Aug 21 16:50:04 nac-test packetfence: WARN -e(604): Problem 
trying to run command: LANG=C sudo /sbin/iptables -S | grep input-management-if 
called from manager::iptables::isAlive. Child exited with non-zero value 1 
(pf::util::pf_run) Aug 21 16:50:04 nac-test packetfence: INFO -e(604): saving 
existing iptables to /usr/local/pf/var/iptables.bak 
(pf::iptables::iptables_save) Aug 21 16:50:04 nac-test packetfence: WARN 
-e(604): We are using IPSET (pf::ipset::iptables_generate) Aug 21 16:50:04 
nac-test packetfence: INFO -e(604): flushing iptables 
(pf::ipset::iptables_flush_mangle) Aug 21 16:50:04 nac-test packetfence: INFO 
-e(604): Adding Forward rules to allow connections to the OAuth2 Providers and 
passthrough. (pf::iptables::generate_passthrough_rules) Aug 21 16:50:04 
nac-test packetfence: INFO -e(604): Adding NAT Masquerade statement. 
(pf::iptables::generate_passthrough_rules) Aug 21 16:50:04 nac-test 
packetfence: WARN -e(604): Use of uninitialized value in substitution iterator 
at /usr/local/pf/lib/pf/util.pm line 531, <$template_fh> line 27. 
(pf::util::parse_template) Aug 21 16:50:05 nac-test packetfence: INFO -e(604): 
restoring iptables from /usr/local/pf/var/conf/iptables.conf 
(pf::iptables::iptables_restore) Aug 21 16:50:05 nac-test packetfence: WARN 
-e(604): Problem trying to run command: LANG=C /sbin/iptables-restore < 
/usr/local/pf/var/conf/iptables.conf called from iptables_restore. Child exited 
with non-zero value 2 (pf::util::pf_run) 
  
  What to do now? 
  Thank you Christian 
  
   
  
 --
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot 
  
 ___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users
 
 --
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! 
http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users
  --
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Packetfence 8 Log duration

2018-08-23 Thread Hubert Kupper via PacketFence-users

Ok that helps me. Many thanks.

Regards
Hubert

Am 23.08.2018 um 03:51 schrieb Durand fabrice via PacketFence-users:

Hello Hubert,

by default it's based on that file: 
https://github.com/inverse-inc/packetfence/blob/devel/packetfence.logrotate


So you can adapt it as you want.

Regards

Fabrice



Le 2018-08-21 à 08:28, Hubert Kupper via PacketFence-users a écrit :

Hi all,

how long is the standard duration for the packetfence logging?

Regards,
Hubert

-- 


Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users



-- 


Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users



--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


[PacketFence-users] VLAN Filter

2018-08-23 Thread HALL, Jason (CITY HEALTH CARE PARTNERSHIP CIC - NNF) via PacketFence-users
I am trying to setup a couple of VLAN Filters to autoregister devices and put 
them in the correct roles and VLANs

I have the below which works perfectly. It registered the phones and drops then 
in the correct role and vlan

[yealink_phones]
filter = node_info.mac
operator = regex
value = ^(00:15:65).*

[autoreg:yealink_phones]
scope = IsPhone
role = voice

But when I try the same for another device it registers them but it doesn't put 
them in the correct role or vlan

[aruba_aps]
filter = node_info.dhcp_vendor
operator = is
value = ArubaAP

[autoreg:aruba_aps]
scope = AutoRegister
role = CHCP_LAN
action = modify_node
action_param = mac = $mac, catergory = CHCP_LAN

Regards

Jason Hall





This message may contain confidential information. If you are not the intended 
recipient please inform the
sender that you have received the message in error before deleting it.
Please do not disclose, copy or distribute information in this e-mail or take 
any action in relation to its contents. To do so is strictly prohibited and may 
be unlawful. Thank you for your co-operation.

NHSmail is the secure email and directory service available for all NHS staff 
in England and Scotland. NHSmail is approved for exchanging patient data and 
other sensitive information with NHSmail and other accredited email services.

For more information and to find out how you can switch, 
https://portal.nhs.net/help/joiningnhsmail

--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users