[PacketFence-users] Resolve AD-User from EAP-TLS certificate

2024-01-16 Thread Matthies, Heiko via PacketFence-users
Hey folks, we're currently implementing certificate based authentication on our mobile devices. While the authentication works fine, I wonder if there is a way to resolve the corresponding AD-User from the CommonName or E-Mail field of the certificate. I know that I can setup my realm to

Re: [PacketFence-users] Strange Behavior on Version 12.1.0

2023-01-11 Thread Matthies, Heiko via PacketFence-users
Hi Peter, we've had this issue too, we've ended up disabling the "Use Connector" radio button on the corresponding switch/switch group. This does seem to work around the issue, while snmp connection still works fine. Mit freundlichen Grüßen i.A. Heiko Matthies IT

Re: [PacketFence-users] Issues doing captive-portal auth with FortiGate and FortiAPs

2022-12-08 Thread Matthies, Heiko via PacketFence-users
_MODULE_FAIL, ('Reply-Message' => "Network device does not support this mode of operation")]; } If I read this correctly, the FortiAP sends CLI-Access as connection type but as it seems, this is not supported in radius.pm. Is this a bug? Kind Regards, Heiko Matthies Von: Ma

Re: [PacketFence-users] Issues doing captive-portal auth with FortiGate and FortiAPs

2022-12-05 Thread Matthies, Heiko via PacketFence-users
08 Datenschutz: Ausführliche Informationen zum Umgang mit Ihren personenbezogenen Daten bei ASAP erhalten Sie auf unserer Website unter www.asap.de\datenschutz.Von: Matthies, Heiko via PacketFence-users Gesendet: Donnerstag, 1. Dezember 2022 17:42 An: packetfence-users@lists.sourceforge.net Cc:

[PacketFence-users] Issues doing captive-portal auth with FortiGate and FortiAPs

2022-12-01 Thread Matthies, Heiko via PacketFence-users
Greetings, we are currently testing out packetfence captive-portal auth in connection with FortiGate and FortiAPs. I followed the instructions from the following mailing list post:

Re: [PacketFence-users] Upgrade-Script breaks system

2022-10-24 Thread Matthies, Heiko via PacketFence-users
Hello Nicolas, another information which maybe useful to you. After I logged into the GUI and tried to rejoin my domain, the same issue (timeout) occurs. I think the system tries to reinsert the ruleset from the v12 iptables.conf and bricks the system doing so. Kind Regards, Heiko Matthies

Re: [PacketFence-users] Upgrade-Script breaks system

2022-10-24 Thread Matthies, Heiko via PacketFence-users
Hello Nicolas, I compared the current iptables.conf with the iptables.conf.example and found only one difference: #-A input-management-if --protocol tcp --match tcp --dport 1025 --jump ACCEPT This line is uncommented in production as we used the haproxy dashboard in the past. I don't think this

Re: [PacketFence-users] Upgrade-Script breaks system

2022-10-24 Thread Matthies, Heiko via PacketFence-users
Hello Nicolas, I suppose, Michael will provide the needed logs and information for you. As we have still not upgraded our main packetfence instance, I could reproduce the issue if needed. Just hit me up, if you need further information about this issue. Kind regards, Heiko Matthies

[PacketFence-users] Issues with machine authentication using MS-CHAPv2

2022-10-18 Thread Matthies, Heiko via PacketFence-users
Hello Guys, i'm trying to implement machine- and user authentication on Windows 10 Clients via MS-CHAPv2 using Packetfence v11.1. While the user authentication works like a charm, I'm having trouble setting up the machine authentication. I got the following log information from the radius

Re: [PacketFence-users] Captive portal customizations gone after upgrade

2022-10-10 Thread Matthies, Heiko via PacketFence-users
Hi Jake, this is to be expected as packetfence overrides the content of the captive-portal folder with each update (as far as I know). The only thing saved are the customizations made in the Web-UI (customization under the connection profile). Our current workaround is to save the css/image

[PacketFence-users] Upgrade-Script breaks system

2022-10-10 Thread Matthies, Heiko via PacketFence-users
Hello, I wanted to upgrade my Packetfence 11.1 instance to 12.0 using the recommended steps from the upgrade-guide: 31.3. Full upgrade (for PacketFence versions 11.1.0 and later) Run following script to perform a full upgrade: /usr/local/pf/addons/upgrade/do-upgrade.sh This procedure worked

[PacketFence-users] Captive Portal with N2000-Series not working

2022-06-24 Thread Matthies, Heiko via PacketFence-users
Greetings, I'm currently trying to implement a captive portal authentication for my wired clients on a Dell N2048P in my test lab. I followed the instructions provided by the packetfence documentation

[PacketFence-users] Variable for access duration in RADIUS filter

2021-09-29 Thread Matthies, Heiko via PacketFence-users
Hello, I'm currently trying to set the RADIUS session-timeout on my switch using the corresponding filters in PacketFence. Setting a static value works like a charm, but I didn't found the matching variable yet. My goal is to use the value returned from the authentication source (e.g. my EAP

Re: [PacketFence-users] Office365 authentications fail on captive portal

2021-09-23 Thread Matthies, Heiko via PacketFence-users
, Sep 21, 2021 at 5:22 AM Matthies, Heiko via PacketFence-users mailto:packetfence-users@lists.sourceforge.net>> wrote: Hello, I'm currently trying out the captive portal module from packetfence and having difficulties with the OIDC Authentication. I believe I set up the OIDC

[PacketFence-users] Office365 authentications fail on captive portal

2021-09-21 Thread Matthies, Heiko via PacketFence-users
Hello, I'm currently trying out the captive portal module from packetfence and having difficulties with the OIDC Authentication. I believe I set up the OIDC authentication source correctly as I get redirected back from the Microsoft page. After that, the following error message occurs:

[PacketFence-users] Office365 authentications fail on captive portal

2021-09-21 Thread Matthies, Heiko via PacketFence-users
Hello, I'm currently trying out the captive portal module from packetfence and having difficulties with the OIDC Authentication. I believe I set up the OIDC authentication source correctly as I get redirected back from the Microsoft page. After that, the following error message occurs: OAuth2

Re: [PacketFence-users] Best Practice for devices from partner companies

2021-09-08 Thread Matthies, Heiko via PacketFence-users
eature=results_main> On Sep 6, 2021, at 8:38 AM, Matthies, Heiko via PacketFence-users mailto:packetfence-users@lists.sourceforge.net>> wrote: Hello, I'm looking for a way to integrate devices from partner companies into our network. I planned to provide a extra VLAN at every s

[PacketFence-users] Best Practice for devices from partner companies

2021-09-06 Thread Matthies, Heiko via PacketFence-users
Hello, I'm looking for a way to integrate devices from partner companies into our network. I planned to provide a extra VLAN at every site which allows nothing but basic internet access without a captive portal. They normally use certificate based authentication via EAP-TLS which leads me to

Re: [PacketFence-users] 802.1x Authentication produces REST-API Timeout

2021-06-15 Thread Matthies, Heiko via PacketFence-users
Hello Nicolas, thank you. I could indeed see snmp-traffic to my switch which was getting no response. The only difference between the production switch and my lab device is the firmware and the number of ports. LAB-Switch: Cisco C1000-8P-2G-L - Firmware 15.2(7)E3 Production-Switch: Cisco

[PacketFence-users] 802.1x Authentication produces REST-API Timeout

2021-06-14 Thread Matthies, Heiko via PacketFence-users
Greetings, I’m currently integrating PacketFence into our company network. Last week I created a cluster consisting of 3 nodes (one node per Site). While my test device works at every switch I connect it to, every new device gets rejected with the following radius.log message: Jun 14