[PacketFence-users] TTLS Issues

2021-05-12 Thread Nathan, Josh via PacketFence-users
Hello, So, in my continuing saga of getting a new setup going for how we use PacketFence, I am trying to get EAP-TTLS working. Yesterday, I had it working for a little while. Then I started adding some more settings to get things ready for production, did some "clean up", and discovered it no

Re: [PacketFence-users] Post-Auth for RADIUS

2021-05-06 Thread Nathan, Josh via PacketFence-users
Is there any way to get PacketFence to do any other debug logs? Without anything showing in either packetfence.log or the audit logs via the console, I feel like I'm up a creek without a paddle. What are my options? With my 9.0 install, everything works fine except for Pixel devices (and I

Re: [PacketFence-users] Post-Auth for RADIUS

2021-04-30 Thread Nathan, Josh via PacketFence-users
I don't know if it helps, but I'm doing PEAP authentication with MSCHAPv2. I tried using the Provisioner, but that doesn't work from my Pixel 3a. So I'm just manually putting in the connection information. I do have a legit certificate. And of course, the phone is authenticating... it's just

Re: [PacketFence-users] Post-Auth for RADIUS

2021-04-26 Thread Nathan, Josh via PacketFence-users
Hello Ludovic, OK, I made those changes, then did a "pfcmd service pf restart". No dice. Exact same results. Here's the end of the raddebug again in case that helps. Still nothing in packetfence.log. (17) Mon Apr 26 15:46:04 2021: Debug: Received Access-Request Id 93 from 172.20.50.76:43555

Re: [PacketFence-users] Post-Auth for RADIUS

2021-04-22 Thread Nathan, Josh via PacketFence-users
9161 631 m: +49 (0) 152 3452 0056 >> a: >> w: Hammersteiner Straße 50, 79400 Kandern >> bfacademy.de >> <https://urldefense.com/v3/__http://bfacademy.de/__;!!GjvTz_vk!Gh7_gb4ulBDLBsfliq32776EAGf4dgeMb6C4VmGLDzKUEgQ50QhydedmISt3FAmr$> >> >> >> >> >> On Thu, Ap

Re: [PacketFence-users] Post-Auth for RADIUS

2021-04-22 Thread Nathan, Josh via PacketFence-users
, 2021 at 3:52 PM Ludovic Zammit wrote: > >> Hello Nathan, >> >> Show me the output of: >> >> grep 58:cb:52:37:5d:ab /usr/local/pf/logs/packetfence.log >> >> Thanks, >> >> >> Ludovic Zammit >> lzam...@inverse.ca :: +1.514.447.4918 (x14

Re: [PacketFence-users] Post-Auth for RADIUS

2021-04-16 Thread Nathan, Josh via PacketFence-users
ic Zammit > lzam...@inverse.ca :: +1.514.447.4918 (x145) :: www.inverse.ca > Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence > (http://packetfence.org) > > > > > > > > > On Apr 15, 2021, at 9:48 AM, Nathan, Josh via PacketFence-users < >

[PacketFence-users] Post-Auth for RADIUS

2021-04-15 Thread Nathan, Josh via PacketFence-users
Hello, So, I'm trying to configure a 10.2 Zen version of PF. Our user authentication happens via RADIUS. So I configured our RADIUS server under the "Internal Sources" section, and everything is now "mostly" working. My devices authenticate, but the Authentication Rules don't seem to be taking

Re: [PacketFence-users] EAP-TLS Auth Failure

2021-03-24 Thread Nathan, Josh via PacketFence-users
server identity on the windows >> for that connection or Issue a certificate for RADIUS from the PKI that you >> are using. >> >> >> >> Uncheck the first one at the top. >> >> Thanks, >> >> >> Ludovic Zammit >> lzam...@inverse.ca

[PacketFence-users] EAP-TLS Auth Failure

2021-03-23 Thread Nathan, Josh via PacketFence-users
Hello, Well, I'm not sure what I missed, but after following the installation guide for using the built-in PKI provider, I have been unable to get TLS working. I'm trying to prep a new virtual server for replacing our existing one. I have the ZEN version with PF 10.2.0. The error I'm running

Re: [PacketFence-users] Configurator Issues

2021-01-28 Thread Nathan, Josh via PacketFence-users
Well, I decided to just load the ZEN version, and that seems to be working for me. So I'll move forward with that. Joshua Nathan *IT Supervisor* Black Forest Academy p: +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056 a: w: Hammersteiner Straße 50, 79400 Kandern bfacademy.de On Tue, Jan 26,

[PacketFence-users] Configurator Issues

2021-01-26 Thread Nathan, Josh via PacketFence-users
Hello, I'm trying to do a fresh install of PacketFence 10.2 on CentOS 7 within a virtual machine. I installed and updated CentOS 7. I did install it with the Gnome Desktop since I do prefer to have a graphical interface. I disabled the firewall, disabled SELinux, and even disabled

Re: [PacketFence-users] Log Expiration

2019-09-27 Thread Nathan, Josh via PacketFence-users
Hi, > > On 27/09/2019 11:40, Nathan, Josh via PacketFence-users wrote: > > I tried to find it in log.conf and pf.conf, and I don't seem to have a > > packetfence.logrotate file anywhere... > > Take a look at /etc/logrotate.d/packetfence > > -- > Nico

[PacketFence-users] Log Expiration

2019-09-27 Thread Nathan, Josh via PacketFence-users
Hello, So, I am having trouble finding where I can set the expiration time for the various log files. It used to be in the configuration pages of the admin console, but it doesn't seem to be there anymore. Just to make sure that I'm not hanging onto any user data any longer than necessary, I'd

Re: [PacketFence-users] PF UniFi OOB, not using UniFi-controller?

2018-11-30 Thread Nathan, Josh via PacketFence-users
We actually did do something like this, but I'm going to be honest, we haven't really tested it in a long time (firmware updates might have broken it), and the problem is that the only way we found to make it would was to attempt the command on every antenna. We just programmed the script to

[PacketFence-users] RADIUS Proxy

2018-04-19 Thread Nathan, Josh via PacketFence-users
Hello All, OK, I am somewhat abandoning trying to use LDAP as I thought RADIUS might be easier. I'm trying to use JumpCloud's Radius-as-a-Service. If I tell my AP to use their RADIUS server directly, authentication works. However, I'd like to use PacketFence as a go-between to use dynamic

Re: [PacketFence-users] LDAP Source Problem

2018-04-06 Thread Nathan, Josh via PacketFence-users
OK, I tried defining my LDAP source separately in the mod-available section (and of course adding the sym link in mods-enabled). Made sure the references within the packetfence-tunnel file had ldap enabled as well. For what it's worth, I've also moved this to a test-bed running PacketFence 7.4.0.

[PacketFence-users] LDAP Source Problem

2018-03-21 Thread Nathan, Josh via PacketFence-users
Hello, So, I'm having some trouble setting up an LDAP authentication source in PacketFence version 6.0.1. It tests successfully, and doing an ldapsearch test comes back without issue. In fact, from the registration VLAN, through the PacketFence Captive Portal it works! However, with the

Re: [PacketFence-users] Unifi APs and CoA

2018-02-10 Thread Nathan, Josh via PacketFence-users
Hey Just FYI... Running both the Guest and RADIUS-Assigned VLANs on the same AP (separate SSIDs, of course), does NOT work on Unifi's 3.8.15 firmware. It works with firmware version 3.8.3, broke at 3.8.6, and it's working again at least as of 3.9.19. So if you need that firmware version, it

Re: [PacketFence-users] VERY Slow Database

2017-10-17 Thread Nathan, Josh via PacketFence-users
> > Btw in the new packetfence version we limit that. > > Regards > > Fabrice > > > > Le 2017-10-17 à 04:12, Nathan, Josh via PacketFence-users a écrit : > > So, we have a PacketFence 6.0.1 installation, and it's been plugging along > for almost two years now.

Re: [PacketFence-users] Packetfence 7.2.0 Cannot set authentication rules in radius source.

2017-10-17 Thread Nathan, Josh via PacketFence-users
I ran into that as well. What fixed it for me, is that there are two values in the source with default numbers. The port and the timeout or whatever, I think. You need to FILL IN those values. Leaving them auto-completed didn't work for me for some reason. I just entered in the same numbers

[PacketFence-users] VERY Slow Database

2017-10-17 Thread Nathan, Josh via PacketFence-users
So, we have a PacketFence 6.0.1 installation, and it's been plugging along for almost two years now. However, its database has gotten REALLY slow. The PacketFence admin page actually times out when trying to load the Node list (only 25 entries per page selected). The server isn't being stressed

Re: [PacketFence-users] help - PF not starting after a reboot

2017-09-29 Thread Nathan, Josh via PacketFence-users
When I had a similar problem, recently, I was directed to restart the packetfence-config service. And then afterward I found I also needed to restart the packetfence-mariadb service for subsequent issues. Joshua Nathan *IT Technician* Black Forest Academy p: +49 (0) 7626 9161 630 m: +49 (0)

Re: [PacketFence-users] Service Disappeared

2017-09-27 Thread Nathan, Josh via PacketFence-users
ketfence-config > > /usr/local/pf/bin/pfcmd service pf restart > > Le 2017-09-26 à 09:16, Nathan, Josh via PacketFence-users a écrit : > > OK. That gives me: > > Failed to connect to config service for namespace resource::URI_Filters, > retrying > > > And th

Re: [PacketFence-users] Service Disappeared

2017-09-26 Thread Nathan, Josh via PacketFence-users
owing: > > /usr/local/pf/bin/pfcmd service pf start > > > Regard > > Fabrice > > > > Le 2017-09-26 à 04:43, Nathan, Josh via PacketFence-users a écrit : > > Sorry, to be a little more specific... it seems that at least a number of > the files are stil

[PacketFence-users] Service Disappeared

2017-09-26 Thread Nathan, Josh via PacketFence-users
Strange issue... I just did a clean install of PacketFence 7.2.0 on a CentOS 7 server. However, at some point over night, my PacketFence service disappeared. The directory and configurations seem to all still be in place, but the service is gone. Is there a way to readily recreate that?

Re: [PacketFence-users] Service Disappeared

2017-09-26 Thread Nathan, Josh via PacketFence-users
Sorry, to be a little more specific... it seems that at least a number of the files are still in /etc/systemd/system... but when I issue "systemctl start packetfence", I get: Failed to start packetfence.service: Unit not found. Joshua Nathan *IT Technician* Black Forest Academy p: +49 (0)