[PacketFence-users] Question PacketFence is able to read others SQL dataBase as a Authentication Source ?

2018-01-18 Thread Rafael Rocha via PacketFence-users
Hello Friends, as my subject says, is possible to make packetfence read a SQL data base to look at user and passwords information ? I know that packetfence have its own freeradius, but I far I can say its only read the local database, and using the authentication source options I did not see

Re: [PacketFence-users] Error trying to install on Centos 7

2018-01-18 Thread Truax, Peter via PacketFence-users
Everyone, Update: We got the install to complete by using a workaround. We added -nogpgcheck to the install command. This disabled the GPG check and allowed install to continue. Just FYI, the error still exists and will stop a normal install. Regards, Peter From: Truax, Peter via

[PacketFence-users] Can't synchronize new cluster databases

2018-01-18 Thread Trinklein, Jason R via PacketFence-users
I’m setting up a new cluster with three total members. Server1 is running with /usr/local/pf/sbin/pf-mariadb --force-new-cluster Server2 runs systemctl restart packetfence-mariadb But fails with: Job for packetfence-mariadb.service failed because a timeout was exceeded. See "systemctl status

Re: [PacketFence-users] Successfully passed 802.1x auth but nonetwork access

2018-01-18 Thread Fabrice Durand via PacketFence-users
Hello Yan, in Freeradius if you want to authenticate a user with 802.1x peap/mschapv2 then you need to use ntlm_auth and you need to join the domain to the active directory. (http://deployingradius.com/documents/protocols/compatibility.html) I don't know exactly how they do with acs but i

[PacketFence-users] RES: Packetfence not passing traffic

2018-01-18 Thread Rafael Rocha via PacketFence-users
Hey James, I did have some similar happened to me, did you confirm that the PF has the correct MAC address associate if the IPs that are having this issue ? In my case for some reason the packetfence was associenting the mac address of the users with wrong IPs, I did corret that by saying that

Re: [PacketFence-users] Successfully passed 802.1x auth but nonetwork access

2018-01-18 Thread Yan via PacketFence-users
I... AD2 was just in preparation after I deployed pf2. Several days later, ad2 was ready but I thought joining domain was just one time action since there were also a featrue named authentication source. So I nearly forget it until I reviewed the configuration after the network issue. We are

[PacketFence-users] No client IP update in cluster

2018-01-18 Thread luca comes via PacketFence-users
Hi all, I've migrated my single node infrastructure to a 3 node cluster. At the moment I'm testing 802.1x with a Cisco catalyst 2950 and the authentication is working fine. I also have in production a wireless guest access with sponsor on Cisco WLC taht is working really well. Unfortunately I

Re: [PacketFence-users] Successfully passed 802.1x auth but no network access

2018-01-18 Thread Fabrice Durand via PacketFence-users
Hello Yan, sorry for the delay. So why don't you joined pf2 to ad2 , i think it will be simpler and probably fix your issue. Regards Fabrice ?0?2 Le 2018-01-15 ?? 11:17, Yan a ??crit?0?2: > > Yes. They have the same domain/users but on different servers. Both of > them can authenticate our

Re: [PacketFence-users] firewalling for inline on the packetfence server

2018-01-18 Thread mj via PacketFence-users
Hi Fabrice, list, On 16-1-2018 14:54, Fabrice Durand via PacketFence-users wrote: Hello, you can play with iptables.conf in the conf directory in order to add your custom rules. So, in the case of limiting outgoing traffic for inline nat clients to http/https/dns, do you mean adding lines

[PacketFence-users] Error trying to install on Centos 7

2018-01-18 Thread Truax, Peter via PacketFence-users
We are getting an error when installing PacketFence on Centos 7. Retrieving key from file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PACKETFENCE-CENTOS Importing GPG key 0xA0030E2C: Userid : "Inverse Support (RPM package signing) >" Fingerprint