Re: [PacketFence-users] IP Change

2017-10-25 Thread Fabrice Durand via PacketFence-users
Hello Alessandro, you also need to have a vlan interface on the system. So in /etc/sysconfig/network-script you need to have a file ifcfg-eth0.50 Regards Fabrice Le 2017-10-24 à 08:29, Alessandro Canella via PacketFence-users a écrit : > > Hello, > >   > > I’ve changed IP at my PF ZEN. From

Re: [PacketFence-users] SMS gateway configuration

2017-10-23 Thread Fabrice Durand via PacketFence-users
ice, > > Thank you for your advice. I am not really familiar with database > configuration. > I am network engineer. > Could you be more specific about how and where to do that? > > > Regards, > Nicolay > > > 2017-10-23 15:30 GMT+02:00 Fabrice Durand via

Re: [PacketFence-users] R: Radiusd don't start after upgarde

2017-10-23 Thread Fabrice Durand via PacketFence-users
mit. > >     # > >     msg_denied = "You are already logged in - access denied" > > } > >   > >   > >   > > */Luca Messori/* > > _ > >   > >       Descrizione: mead > >   > >   > &

Re: [PacketFence-users] SMS gateway configuration

2017-10-23 Thread Fabrice Durand via PacketFence-users
Hello Nicolay, if it's a new SMS gateway then you will need to import it in the database. So connect to the database and: INSERT INTO sms_carrier     (id, name, email_pattern, created) VALUES     (100122, 'MyGateway', '%s@mygateway.gateway', now()); Regards Fabrice Le 2017-10-20 à 09:50,

Re: [PacketFence-users] Logo change problem

2017-10-23 Thread Fabrice Durand via PacketFence-users
Hello Nicolay, something like that should work: /common/IPGL.png Regards Fabrice Le 2017-10-20 à 03:37, Nicolay Rytchev via PacketFence-users a écrit : > Hello All, > > I try to change logo on portal web page but without success. > May be special path for the file should be specified ? > > > >

Re: [PacketFence-users] Can't download and update fingerbank DB

2017-10-19 Thread Fabrice Durand via PacketFence-users
Hello Yan, it mean that it worked, the importation can be long, there is 5M combinations in the database. Regards Fabrice Le 2017-10-18 ?? 22:17, Yan via PacketFence-users a ??crit?0?2: > Oh 2 more tables, "dhcp_vendor" and "user_agent" appeared lately. And > there is corresponding data in

Re: [PacketFence-users] Username format for portal and automatically registered devices

2017-10-19 Thread Fabrice Durand via PacketFence-users
IOS switches but I agree this should be handled by PF. > > Il 18/10/2017 17:22, Fabrice Durand via PacketFence-users ha scritto: >> Hello Cristian, >> >> It is but because the supplicant send DOMAIN\Username and the portal use >> the sAMAccountName. >> >>

Re: [PacketFence-users] Bandwidth statistics make no sense (Cisco 2960x)

2017-10-19 Thread Fabrice Durand via PacketFence-users
Hello Cristian, which version are you running ? Regards Fabrice Le 2017-10-19 à 09:48, Cristian Mammoli via PacketFence-users a écrit : > Hi, I received an alert from packetfence with the following content: > > Detect  : No Antivirus software installed > > Last Session   : >     Session

Re: [PacketFence-users] Radiusd don't start after upgarde

2017-10-19 Thread Fabrice Durand via PacketFence-users
Hello Luca, Can you paste /usr/local/pf/raddb/auth.conf ? Regards Fabrice Le 2017-10-19 à 10:28, Luca Messori via PacketFence-users a écrit : > >   > > Hi, > > after upgrading to PF 7.3, the Radius daemon don’t start > >   > > Running it in debug mode, I have this error: > > Thu Oct 19 14:25:27

Re: [PacketFence-users] Can't download and update fingerbank DB

2017-10-18 Thread Fabrice Durand via PacketFence-users
Hi Yan, once you have the file, go in the admin gui,?0?2 Configuration -> Compliance -> General settings, verify that the mysql credentials and database name is correct then "Action -> Initialize MySQL database" If the access to the db is ok then you should be able to see a process "python"

Re: [PacketFence-users] Username format for portal and automatically registered devices

2017-10-18 Thread Fabrice Durand via PacketFence-users
Hello Cristian, It is but because the supplicant send DOMAIN\Username and the portal use the sAMAccountName. The solution could be to use another attribute that contain the DOMAIN\Username but i am not sure it exist on the active directory and i am not sure that user will be happy to fill

Re: [PacketFence-users] Can't download and update fingerbank DB

2017-10-18 Thread Fabrice Durand via PacketFence-users
Hi Yan, there is a database who is coming with the fingerbank package, so you can probably found it in /usr/local/fingerbank/db. (yum reinstall fingerbank if needed) If you have it (fingerbank_Upstream.db) then you can integrate it into mysql then the futur update will be just some interim

Re: [PacketFence-users] R: R: R: AD authentication issue

2017-10-18 Thread Fabrice Durand via PacketFence-users
> >   > > Questo messaggio puo' contenere informazioni di carattere > riservato e confidenziale. Qualora non foste i destinatari, vi > preghiamo di notificarcelo > e di provvedere ad eliminare il messaggio, con gli eventual

Re: [PacketFence-users] Can't download and update fingerbank DB

2017-10-18 Thread Fabrice Durand via PacketFence-users
Hello Yan, do you have a proxy between PacketFence and internet ? When i see your wget command, i can see that :?0?2 "Issued certificate has expired" and the fingerbank.inverse.ca certificate is not yet expired so there is probably something that block/filter the request. Regards Fabrice Le

Re: [PacketFence-users] R: R: AD authentication issue

2017-10-18 Thread Fabrice Durand via PacketFence-users
civili > e penali. > >   > > This message may contain information which is confidential or > privileged. if you are not the intended recipient, please > immediately notify us > and destroy this message and any attachments without retaining a > copy. Any u

Re: [PacketFence-users] R: AD authentication issue

2017-10-17 Thread Fabrice Durand via PacketFence-users
a copy. > Any unauthorized use of this message can expose the responsabile party > to civil and/or criminal penalties. > >   > > Descrizione: Descrizione: cid:696372015@22072008-1A64 > >   > >   > > *Da:*Fabrice Durand via PacketFence-users > [mailt

Re: [PacketFence-users] R: AD authentication issue

2017-10-17 Thread Fabrice Durand via PacketFence-users
ged. if you are not the intended recipient, please immediately > notify us > and destroy this message and any attachments without retaining a copy. > Any unauthorized use of this message can expose the responsabile party > to civil and/or criminal penalties. > >   > > Descrizione: Descriz

Re: [PacketFence-users] AD authentication issue

2017-10-17 Thread Fabrice Durand via PacketFence-users
Hello Luca, pftest will use ldap bind to authenticate but freeradius will use ntlm_auth. Can you do this on your server: raddebug -f /usr/local/pf/var/run/radiusd.sock -t 3000 And try to authenticate, you will be able to see why it failed to authenticate. (you can paste the result). Regards

Re: [PacketFence-users] Captive Portal customization

2017-10-17 Thread Fabrice Durand via PacketFence-users
> Встроенное изображение 3Встроенное изображение 2Встроенное изображение 1 > > 2017-10-17 15:56 GMT+02:00 Fabrice Durand via PacketFence-users > <packetfence-users@lists.sourceforge.net > <mailto:packetfence-users@lists.sourceforge.net>>: > > Hello Nicolay,

Re: [PacketFence-users] Packetfence working with WLC 8.3.122

2017-10-17 Thread Fabrice Durand via PacketFence-users
Hello Brian, did you try to use the same acl that we have in the documentation ? https://packetfence.org/doc/PacketFence_Network_Devices_Configuration_Guide.html#_wireless_lan_controller_wlc_web_auth This acl is more a trigger than a real acl. Also can you paste a radius answer when you try to

Re: [PacketFence-users] Packetfence working with WLC 8.3.122

2017-10-17 Thread Fabrice Durand via PacketFence-users
Hello Brian, the dns must be a production one. The wlc is suppose to intercept the http/https traffic and forward you to the captive portal. So it can be an issue with the ACL (i am not sure since you are able to hit it), or a maybe you didn't enabled Radius NAC in the ssid config. Regards

Re: [PacketFence-users] Customize captive portal profile

2017-10-17 Thread Fabrice Durand via PacketFence-users
Hello Hubert, you have a tab "Files" in Connection Profiles and Pages. Feel freer to edit the html pages. Also there is locales in  conf/locale/en/LC_MESSAGES you probably have to edit too. Do that after you edited the locales: for TRANSLATION in de en es fr he_IL it nl pl_PL pt_BR; do    

Re: [PacketFence-users] Can't download and update fingerbank DB

2017-10-17 Thread Fabrice Durand via PacketFence-users
Hello Yan, it looks that you didn't imported fingerbank into mysql. Go in Configuration -> Compliance -> Fingerbank Profiling -> General settings then in Action "Initialize MySQL database". Regards Fabrice Le 2017-10-17 ?? 03:19, Yan via PacketFence-users a ??crit?0?2: > Hi dear users, > >

Re: [PacketFence-users] VERY Slow Database

2017-10-17 Thread Fabrice Durand via PacketFence-users
Hello Joshua, it's probably the radacct/radacct_log/locationlog table. Do a: select count(*) from radacct; (on each tables) you probably have a huge table. So just do a truncate radacct/radacct_log/locationlog and it should be ok. Btw in the new packetfence version we limit that. Regards

Re: [PacketFence-users] Packetfence working with WLC 8.3.122

2017-10-12 Thread Fabrice Durand via PacketFence-users
Hello Brian, are you able to resolve a fqdn from your laptop ? What is your acl , can you show me how it look ? Regards Fabrice Le 2017-10-11 à 09:23, Brian Ott a écrit : > > Thanks for the reply Fabrice! > > > Changing to HTTP doesn't alter the results, it still doesn't forward.  > > > Brian

Re: [PacketFence-users] Cheap AP

2017-10-10 Thread Fabrice Durand via PacketFence-users
Hello Spencer, you can try with AP that support openwrt, also there is a Ubiquity controller that can manage Ubiquity AP and we are close to support MAC-AUTH and 802.1x with this setup. Regards Fabrice Le 2017-10-10 à 05:12, Spencer Hazell via PacketFence-users a écrit : > > Hi > >   > > Can

Re: [PacketFence-users] Captive Portal allow only selected usernames

2017-10-10 Thread Fabrice Durand via PacketFence-users
ined in users field? > > If this field not match don’t allow? > >   > > Tomasz Karczewski > > Administrator Sieci > >   > > olman > >   > > tkarczew...@man.olsztyn.pl <mailto:tkarczew...@man.olsztyn.p

Re: [PacketFence-users] Captive Portal allow only selected usernames

2017-10-10 Thread Fabrice Durand via PacketFence-users
//www.uwm.edu.pl > > tel. (89) 523 45 55  fax. (89) 523 43 47 > >   > > Ośrodek Eksploatacji i Zarządzania > > Miejską Siecią Komputerową OLMAN w Olsztynie > > Uniwersytet Warmińsko-Mazurski w Olsztynie > >   > > *From:*Fabrice Du

Re: [PacketFence-users] Captive Portal allow only selected usernames

2017-10-05 Thread Fabrice Durand via PacketFence-users
Hello Tomasz, create a rule for each users and at the end add a catch_all with the reject role. Regards Fabrice Le 2017-10-05 à 07:42, Tomasz Karczewski via PacketFence-users a écrit : > Hi, > > I'm trying to allow only selected users to wifi with specific ssid and > connection-type. > For

Re: [PacketFence-users] Packetfence missing snort config

2017-10-04 Thread Fabrice Durand via PacketFence-users
Hello Kam, PacketFence doesn't support local snort/suricata but just remote. What you can do is to install security onion on another server and configure it to send the alert to the packetfence server. (see doc). I am also agree that there is still references in the documentation on the local

Re: [PacketFence-users] PF 7.3 fresh install on Debian Jessie

2017-10-04 Thread Fabrice Durand via PacketFence-users
Hello Draffin, it happen when your server is not able to download the database. What you can do is to answer no when it ask you for your fingerbank key and it will not download the database. Regards Fabrice Le 2017-10-03 à 22:21, Draffin, Walt via PacketFence-users a écrit : > I'm trying to

Re: [PacketFence-users] Captive Portal certificate

2017-10-03 Thread Fabrice Durand via PacketFence-users
t; ERROR pfcmd.pl(50729): > pf::services::manager::haproxy=HASH(0xade6b0)->name died or has failed > to start (pf::services::manager::postStartCleanup) > >   > > the service HAproxy wont start > >   > > regards > > LT > >   > > Em 2017-10-03 14:13, Fabr

Re: [PacketFence-users] Captive Portal certificate

2017-10-03 Thread Fabrice Durand via PacketFence-users
In fact haproxy terminate the ssl tunnel so you don't have to change the ssl-certificates.conf file. This file is just use for the admin interface now and not the portal anymore. So just do that: (MyCERT.crt and MyPRIVKEY.key are your certificate files) cat conf/ssl/MyCERT.crt

Re: [PacketFence-users] radius | node remains unreg

2017-10-03 Thread Fabrice Durand via PacketFence-users
Hello Mj, you can create a connection profile based on the connection type Ethernet-EAP and activate autoregistration on it. Regards Fabrice Le 2017-10-03 à 05:37, lists via PacketFence-users a écrit : > Hi, > > We have an pf-inline wifi-segment with a captive portal, and also a >

Re: [PacketFence-users] IP Revolution

2017-10-02 Thread Fabrice Durand via PacketFence-users
Hello Alessandro, what you probably have to do is to change the default route to use OUT and define in PacketFence configuration Interface SNAT to OUT. With that the OUT interface will be natted for the inline network and the default route will permit to pass through this interface. Regards

Re: [PacketFence-users] upgrade to 7.3.0

2017-10-02 Thread Fabrice Durand via PacketFence-users
Hello Kylián, anything in packetfence.log ? Can you see something in journalctl ? Regards Fabrice Le 2017-09-29 à 09:21, Kylián Martin via PacketFence-users a écrit : > Hi all, > > having strange behavior after upgrade to 7.3.0: > > > /var/log/messages > > Sep 29 15:02:04 NAC1 perl:

Re: [PacketFence-users] Service Disappeared

2017-09-26 Thread Fabrice Durand via PacketFence-users
<http://bfacademy.de/> > > > > > > On Tue, Sep 26, 2017 at 2:15 PM, Fabrice Durand via PacketFence-users > <packetfence-users@lists.sourceforge.net > <mailto:packetfence-users@lists.sourceforge.net>> wrote: > > Hello Nathan, > &g

Re: [PacketFence-users] Captive Portal fiels translation

2017-09-26 Thread Fabrice Durand via PacketFence-users
Hello Luís, there https://www.transifex.com/inverse/packetfence/ Regards Fabrice Le 2017-09-25 à 05:57, Luís Torres via PacketFence-users a écrit : > > Hello mates, > >   > > how can I translate the captive portal to other language? any guides? > >   > > thanks > >   > > >

Re: [PacketFence-users] Service Disappeared

2017-09-26 Thread Fabrice Durand via PacketFence-users
Hello Nathan, there is no systemd script to restart the whole packetfence's services. What you can do is the following: /usr/local/pf/bin/pfcmd service pf start Regard Fabrice Le 2017-09-26 à 04:43, Nathan, Josh via PacketFence-users a écrit : > Sorry, to be a little more specific... it

Re: [PacketFence-users] Packetfence works with core switch but not with attached AP

2017-09-05 Thread Fabrice Durand via PacketFence-users
Hello Spencer, it looks that your AP can do 802.1x but mac auth i am not sure. Also the switch must support multi auth in order to authenticate all the mac address. Lat thing you can do is to enable floating device in packetfence and return an inline vlan in order to authenticate each devices

Re: [PacketFence-users] Restricting users to specific interfaces In-Line setup

2017-08-31 Thread Fabrice Durand via PacketFence-users
Hello Michael, you will have to play with the iptables rules. check in conf/iptables.conf and the current rules in var/conf/iptables.conf, you will see what to do. Also have a look at ipset -L , there is some ipset session for each different network / roles. Regards Fabrice Le 2017-08-31 à

Re: [PacketFence-users] Unifi IP Accounting

2017-08-30 Thread Fabrice Durand via PacketFence-users
Hello Ian, it's an option to enable in PacketFence where you update the iplog information based on the radius accounting. Regards Fabrice Le 2017-08-28 à 23:10, Ian Halliday via PacketFence-users a écrit : > Hello Listmates, > > We just completed a PF install in a routed environment using

Re: [PacketFence-users] domain trouble shooting commands fail

2017-08-30 Thread Fabrice Durand via PacketFence-users
Hello Jon, does winbind run ? Regards Fabrice Le 2017-08-28 à 23:19, Jon Falconer via PacketFence-users a écrit : > Greetings all, > > I have done a fresh install of Packet Fence 7.2.0, and in configuring it, > have setup an Active Directory domain join. Packet Fence seems to think that >

Re: [PacketFence-users] radiusd service not starting on PF 7.2

2017-08-28 Thread Fabrice Durand via PacketFence-users
Hello Rokkhan, try this: cp /usr/local/pf/conf/radiusd/auth.conf.example /usr/local/pf/conf/radiusd/auth.conf then restart radiusd. Regards Fabrice Le 2017-08-28 à 16:52, Rokkhan via PacketFence-users a écrit : > i can not start radiusd service on PF 7.2 but packetfence logs show > like

Re: [PacketFence-users] Code fetched from PF gitub leads to HTTP 503 error, httpd.dispatcher service refusing to start.. Urgent please!!

2017-08-28 Thread Fabrice Durand via PacketFence-users
Hello Akala, it looks that it's an issue with proxypassthrough configuration. Check if this command return the correct config for fencing.proxy_passthroughs Regards Fabrice Le 2017-08-28 à 16:36, Akala Kehinde via PacketFence-users a écrit : > > > On 28 Aug 2017 8:10 PM, "Akala Kehinde"

Re: [PacketFence-users] Proper VLAN config

2017-08-25 Thread Fabrice Durand via PacketFence-users
Hello Moritz, just keep in mind that the registration and isolation vlan is managed by packetfence (dhcp/dns/gateway), after that the production vlan can be what you want. Regards Fabrice Le 2017-08-25 à 10:39, Moritz Schmid via PacketFence-users a écrit : > Hey guys, > > I’m new to pf and a

Re: [PacketFence-users] PF just refuses to join AD domain??

2017-08-23 Thread Fabrice Durand via PacketFence-users
out; trying next origin > ;; connection timed out; no servers could be reached > > [root@pfence sysctl.d]# > > > Regards, > Kehinde > > On Wed, Aug 23, 2017 at 6:45 PM, Fabrice Durand via PacketFence-users > <packetfence-users@lists.sourceforge.net > <mailto:p

Re: [PacketFence-users] PF just refuses to join AD domain??

2017-08-23 Thread Fabrice Durand via PacketFence-users
orward = 1 > > Checked timing already on both servers, it"s d same. > > Regards, > Kehinde > > On Wed, Aug 23, 2017 at 2:32 PM, Fabrice Durand via > PacketFence-users <packetfence-users@lists.sourceforge.net > <mailto:packetfence-user

Re: [PacketFence-users] Disable Self Registration on PacketFence 7.2

2017-08-23 Thread Fabrice Durand via PacketFence-users
Hello Chandra, Create a new Root portal module and add a authentication login, then create a new connection profile , add a filter based on per example the ssid and assign a Root portal module that only do login. To detect the network connectivity packetfence try to fetch a gif on internet, so

Re: [PacketFence-users] Captive portal SSL not using defined cert after PF7 upgrade

2017-08-23 Thread Fabrice Durand via PacketFence-users
Haproxy terminate the ssl tunnel and not apache anymore (for the portal). So just this file is enough /usr/local/pf/conf/ssl/server.pem Regards Fabrice Le 2017-08-23 à 03:24, Will Halsall via PacketFence-users a écrit : > > I just added the intermediate certificate to the cat process: > >

Re: [PacketFence-users] Multiple Nessus scan policies possible on PF?

2017-08-23 Thread Fabrice Durand via PacketFence-users
If Nessus support it then why not but it need to be coded in teh Nessus6 module. Regards Fabrice Le 2017-08-23 à 03:01, Akala Kehinde a écrit : > Hello Fabrice, > > Basically what I was trying to ask is if it's possible to attache more > than 1 scan policy to a Nessus scan engine. Don't think

Re: [PacketFence-users] PF just refuses to join AD domain??

2017-08-23 Thread Fabrice Durand via PacketFence-users
Hello Akala, does ip_forward is enable ? does the time of the packetfence server is the same as the AD server ? Regards Fabrice Le 2017-08-23 à 02:38, Akala Kehinde a écrit : > Hello Fabrice, > > Kindly see below: > > [root@pfence pf]# chroot /chroots/MYDOMAIN wbinfo -u > could not obtain

Re: [PacketFence-users] Packetfence-ZEN-7.2.0 bandwidth violation not working

2017-08-17 Thread Fabrice Durand via PacketFence-users
sr/local/pf/run/radius-acct.sock -t 300 > > radmin: Failed connecting to /usr/local/pf/run/radius-acct.sock: No > such file or directory > > > > Regards > > Emmanuel > > > > *From: *Fabrice Durand via PacketFence-users > <packetfence-u

Re: [PacketFence-users] R: R: R: network-access-detection

2017-08-17 Thread Fabrice Durand via PacketFence-users
; dhcp_max_lease_time=86400 > > fake_mac_enabled=disabled > > dhcpd=enabled > > dhcp_end=192.168.30.246 > > type=inlinel2 > > netmask=255.255.255.0 > > dhcp_default_lease_time=86400 > > > > *Da:*Fabrice Durand via PacketFence-users > [mailto:packetf

Re: [PacketFence-users] R: R: R: R: R: network-access-detection

2017-08-17 Thread Fabrice Durand via PacketFence-users
cketfence-users@lists.sourceforge.net> > *Cc:* Alessandro Canella <alessandro.cane...@itcare.it> > <mailto:alessandro.cane...@itcare.it> > *Oggetto:* [PacketFence-users] R: R: R: network-access-detection > > > > Fabrice, > > > >

Re: [PacketFence-users] Packetfence-ZEN-7.2.0 bandwidth violation not working

2017-08-17 Thread Fabrice Durand via PacketFence-users
raddebug ... Le 2017-08-17 à 06:12, Emmanuel Togo a écrit : > > Hello Fabrice, > > raddebuf command is not available. > > > Regards > > Emmanuel > > > > > *From:* Durand fabrice via PacketFence-users >

Re: [PacketFence-users] Packetfence

2017-08-11 Thread Fabrice Durand via PacketFence-users
Hello Rachid, your issue is with the reevaluate access, check in the log why the deauth is not working. Regards Fabrice Le 2017-08-11 à 08:06, Rachid Boutarene via PacketFence-users a écrit : > > Hello , I contact you to ask if you can help me? > > I had installed successful Packet fence and

Re: [PacketFence-users] Android wireless provisioning error

2017-08-11 Thread Fabrice Durand via PacketFence-users
Hello Akala, can you send me your profiles.conf and portal_modules.conf and provisioning.conf ? Regards Fabrice Le 2017-08-11 à 07:15, Akala Kehinde via PacketFence-users a écrit : > HI guys, > > Any thoughts on this? > > Regards, > Kehinde > > On Tue, Aug 8, 2017 at 7:44 PM, Akala Kehinde

Re: [PacketFence-users] Compatibility double check for our environment

2017-08-11 Thread Fabrice Durand via PacketFence-users
Hello Yan, Le 2017-08-10 à 23:27, Yan Kimiko via PacketFence-users a écrit : > > Thank you Durand. > > > /Currently we are in classifying and preparing period. We’ll consider > buying inverse consulting once we really need help. As we are in > China, we have also to make sure inverse selling

Re: [PacketFence-users] wmi query without result, how do I trigger an action

2017-08-08 Thread Fabrice Durand via PacketFence-users
Hello Cristian, can you put the log of pfqueue in TRACE and retry , you will have more debug to understand what happen. Edit conf/log/conf.d/pfqueue.conf ### pfqueue logger ### log4perl.rootLogger = TRACE, QUEUE_SYSLOG Regards Fabrice Le 2017-08-07 à 09:23, Cristian Mammoli via

Re: [PacketFence-users] R: R: network-access-detection

2017-08-08 Thread Fabrice Durand via PacketFence-users
Hello Alessandro, you probably missconfigured the dns. Can you give me your networks.conf ? Regards Fabrice Le 2017-08-07 à 11:51, Alessandro Canella via PacketFence-users a écrit : > > I’ve retried and checked traffic. > > > > As wrotten, I’m in inline, users authenticate but GIF cannot

Re: [PacketFence-users] Assign role based on device class

2017-08-04 Thread Fabrice Durand via PacketFence-users
Hello Cristian, you can do that: [smartphones_by_devclass] filter = node_info.device_class operator = is value = Smartphones/PDAs/Tablets [employees_ssid] filter = ssid operator = is value = aprapfdot1x [set_smartphone_role:smartphones_by_devclass_ssid] scope = RegisteredRole role =

Re: [PacketFence-users] Possible having same registration VLAN on GUEST and STAFF SSIDs??

2017-07-28 Thread Fabrice Durand via PacketFence-users
https://packetfence.org/doc/PacketFence_Network_Devices_Configuration_Guide.html#_cisco_2 Le 2017-07-28 à 12:21, Akala Kehinde via PacketFence-users a écrit : > Hello guys, > > Below is my AP (Cisco 1242 AG) configuration in an OOB setup: > > When I tried configuring SSID GUEST to be in same

Re: [PacketFence-users] Possible having same registration VLAN on GUEST and STAFF SSIDs??

2017-07-28 Thread Fabrice Durand via PacketFence-users
Yes it's possible but you have to play with the vlan filters. Regards Fabrice Le 2017-07-28 à 12:22, Akala Kehinde via PacketFence-users a écrit : > Or is it possible to have 2 different registration VLANs?? > > Regards, > Kehinde > > On Fri, Jul 28, 2017 at 6:21 PM, Akala Kehinde

Re: [PacketFence-users] Error communicatin with Nessus

2017-07-28 Thread Fabrice Durand via PacketFence-users
Hello Akala, if nessus run on the same server then try 127.0.0.1 for the server ip. Also what return : netstat -nlp | grep 8834 Regards Fabrice Le 2017-07-28 à 12:09, Akala Kehinde via PacketFence-users a écrit : > Just FYI, the Nessus server runs on the PF server. > > Regards, > Kehinde >

Re: [PacketFence-users] DHCP doesnt reply

2017-07-28 Thread Fabrice Durand via PacketFence-users
Hello Luís, can you paste your networks.conf and pf.conf please ? Regards Fabrice Le 2017-07-28 à 10:37, Luís Torres via PacketFence-users a écrit : > > Hello, > > > > Im new to packetfence and Im trynig to put the captive portal > working..., Im integrating with a Cisco WLC5500. > > If I

Re: [PacketFence-users] Bad Request 400 on Packetfence PKI

2017-07-28 Thread Fabrice Durand via PacketFence-users
Hello Akala, can you check what you have in the packetfence pki logs ? /usr/local/packetfence-pki/logs Regards Fabrice Le 2017-07-28 à 11:51, Akala Kehinde via PacketFence-users a écrit : > Hello Antoine, > > I still get the error even though the output below looks good: > > [root@egelsbach

Re: [PacketFence-users] Portal Personalization

2017-07-25 Thread Fabrice Durand via PacketFence-users
Hello Yohann, can you check if those 2 packages are installed: cairo-1.14.2-1.el7.x86_64 pycairo-1.8.10-8.el7.x86_64 Regards Fabrice Le 2017-07-25 à 05:10, LE GALL Yohann a écrit : > > Hi Fabrice, > > > > Yes, I’m living in Brittany. > > > > I’ve found exactly the same file with a grep

Re: [PacketFence-users] No suricata.yaml file present in PF 7.x

2017-07-18 Thread Fabrice Durand via PacketFence-users
Hello Kehinde, in my opinion the better setup to do is to use security onion and send the syslog to PacketFence. Regards Fabrice Le 2017-07-18 à 06:44, Akala Kehinde via PacketFence-users a écrit : > Hallo guys, > > The suricata.yaml file is missing in PF7.x. I'm trying to do a > Suricata

Re: [PacketFence-users] R: radius rejected.

2017-07-17 Thread Fabrice Durand via PacketFence-users
Hello Alessandro, You need to use eapol_test for eap test: %eapol_test -c -a -p -s Example config file: network={ ssid="test" key_mgmt=IEEE8021X eap= pairwise=CCMP TKIP group=CCMP TKIP WEP104 WEP40 phase2="auth=MSCHAPV2" identity="" password="" }

Re: [PacketFence-users] Machine authentication

2017-07-10 Thread Fabrice Durand via PacketFence-users
manner the error is not shown in radius.log but machine >>> authentication is still not working. Also as the preceding email the >>> domain (DM) is correctly joined and tested with wbinfo. But if I try >>> a radtest vs my domain I obtain an Access-Reject. Any suggestio o

Re: [PacketFence-users] Machine authentication

2017-07-10 Thread Fabrice Durand via PacketFence-users
and tested with wbinfo. But if I try >> a radtest vs my domain I obtain an Access-Reject. Any suggestio on >> how to troubleshoot this problem? I would like to go in production >> but with those results I have to leave. >> >> >> Thanks >> >> >&

Re: [PacketFence-users] Machine authentication

2017-07-10 Thread Fabrice Durand via PacketFence-users
like to go in production but > with those results I have to leave. > > > Thanks > > > Luca > > > Inviato da Outlook <http://aka.ms/weboutlook> > > > > -------------------- > *Da:* Fabrice Durand via PacketFen

Re: [PacketFence-users] Machine authentication

2017-07-10 Thread Fabrice Durand via PacketFence-users
Hello Luca, add a realm dm.loc and assign it to your domain and restart radius. Regards Fabrice Le 2017-07-10 à 05:58, luca comes via PacketFence-users a écrit : > > I've found this error in radius.log > > > ERROR: mschap_machine: Program returned code (1) and output 'Reading > winbind reply

Re: [PacketFence-users] Join Active Directory fails,Debian

2017-06-29 Thread Fabrice Durand via PacketFence-users
Hello Lucas, first edit domain.conf and remove anything and do a "pfcmd configreload hard" in order to retreive the config in admin Next be sure that domain name are in upper case and retry and ip forward is enable. Regards Fabrice Le 2017-06-29 à 08:30, Lucas Beier via PacketFence-users a

Re: [PacketFence-users] node database errors after upgrade?

2017-06-14 Thread Fabrice Durand via PacketFence-users
Hello Denis, you will have to compare the current schema and the schema from this file : https://github.com/inverse-inc/packetfence/blob/devel/db/pf-schema-6.4.0.sql Connect to the db pf and do :explain node; and compare ... regards Fabrice Le 2017-06-14 à 11:16, denis via PacketFence-users

Re: [PacketFence-users] VLAN Enforcement

2017-06-14 Thread Fabrice Durand via PacketFence-users
Hello Rafael, vlan 10 is for registration so it's normal that you don't have internet access. Regards Fabrice Le 2017-06-12 à 16:14, Diogo Rafael via PacketFence-users a écrit : > > Hi, > > Im trying to implement VLAN Enforcement on my environment but im > having some troubles > > I have

Re: [PacketFence-users] PF 7.1 remove inline mode

2017-06-14 Thread Fabrice Durand via PacketFence-users
Hello Darryl, in fact you just have to modify networks.conf and cluster.conf to remove inline related config. (bin/pfcmd configreload hard) Regards Fabrice Le 2017-06-13 à 18:12, Sokolowski, Darryl via PacketFence-users a écrit : > > Hi all, > > let me say I’m loving this product! Good work

Re: [PacketFence-users] Fw: Bandwidth Violation

2017-06-09 Thread Fabrice Durand via PacketFence-users
Hello Mancharagopan Ponnampalam, first are you using PacketFence in inline mode ? If it's inline mode you need to be sure that pfbandwidthd is enable. Also if you are using radius then you need to have the accounting from the AP/Switch. Regards Fabrice Le 2017-06-09 à 12:28,

Re: [PacketFence-users] VLAN Filter for MAB devices

2017-06-09 Thread Fabrice Durand via PacketFence-users
Hi Hello Kehinde, MAB is exactly what you need , also for that create a violation that will autoreg printer, it will be easier than vlan filters. Regards Fabrice Le 2017-06-08 à 07:51, Akala Kehinde via PacketFence-users a écrit : > Hallo, > > Hallo guys, > > Want to knw if it's possible to

<    2   3   4   5   6   7