Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-23 Thread pro fence via PacketFence-users
Hi, on my first server, both local server ip and the vip are listening on eth0 also inPthe interface configuration, the portal is only listening on the local server ip. Port 80 is listening like this : local_server_ip:80 0.0.0.0:* LISTEN 9627/httpd vip_ip:80

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-22 Thread pro fence via PacketFence-users
Hi Fabrice, Thanks for the reply, here is what i have in the pre_auth ACL : [image: acls.png] do you see something wrong ? On Mon, 22 Jul 2019 at 14:54, Fabrice Durand via PacketFence-users < packetfence-users@lists.sourceforge.net> wrote: > Hello Pro fence, > > packetfence manage the port

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-22 Thread Fabrice Durand via PacketFence-users
Hello Pro fence, packetfence manage the port that needs to be open, so you don't have to do anything. Btw it looks that the issue you have is related to the acl you made on the WLC. (check is there is some hit) What you can do is to capture the traffic on the device your are testing with

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-21 Thread pro fence via PacketFence-users
Hi, For somebody who would encounter the same issue, to solve the last error, you need to add a new radius client. Does anybody know exactly what ports need to be open for the VIP besides radius, http for the portal to pop up ? I mean in the log i have the right ACL and the

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-19 Thread pro fence via PacketFence-users
HI For somebody who would encounter the same issue, to solve the last error, you need to add a new radius client. Does anybody know exactly what ports need to be open for the VIP besides radius, http for the portal to pop up ? regards, On Thu, 18 Jul 2019 at 17:00, pro fence wrote: > Hi

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-19 Thread pro fence via PacketFence-users
Hi, does anybody know how to add a radius client ? Regards, On Thu, 18 Jul 2019 at 17:00, pro fence wrote: > Hi Fabrice, > > to be more precise i am going to use the ip adresses of the installation > guide to show you my configuration : > > to answer your question, yes, cluster.conf is

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-19 Thread pro fence via PacketFence-users
For somebody who would encounter the same issue, to solve the last error, you need to add a new radius client, and don't forget to change the switch url in packetfence GUI to reflect the VIP. Regards, On Thu, 18 Jul 2019 at 17:00, pro fence wrote: > Hi Fabrice, > > to be more precise i am

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-18 Thread pro fence via PacketFence-users
Hi Fabrice, to be more precise i am going to use the ip adresses of the installation guide to show you my configuration : to answer your question, yes, cluster.conf is replicated on the 3 servers with the command: # /usr/local/pf/bin/cluster/sync --from=192.168.1.5 --api-user=user

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-18 Thread Fabrice Durand via PacketFence-users
Hello Pro fence, it looks that you miss-configured your cluster. Did you copy the file cluster.conf on each servers ? Regards Fabrice Le 19-07-18 à 06 h 49, pro fence via PacketFence-users a écrit : Hello, does anyone ever encountered the following error using a VIP, from radius : "

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-18 Thread pro fence via PacketFence-users
Hello, does anyone ever encountered the following error using a VIP, from radius : " Ignoring request to auth address MANAGEMENT_IP port 1812 bound to server packetfence from unknown client loadBalancer_IP port 8905 proto udp" the VIP sends the request using a different ip than the one

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-17 Thread Durand fabrice via PacketFence-users
Yes, only the VIP is need on the WLC. The WLC send a request to the VIP and the radius load-balancer will forward to one of the radius server in the cluster. Regards Fabrice Le 19-07-17 à 05 h 14, pro fence via PacketFence-users a écrit : Hi Fabrice, do you mean that the VIP needs to be

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-17 Thread pro fence via PacketFence-users
Hi Fabrice, do you mean that the VIP needs to be configured as the radius server in the WLC ? Thanks, Regards, On Tue, 16 Jul 2019 at 23:16, Durand fabrice via PacketFence-users < packetfence-users@lists.sourceforge.net> wrote: > Hello, > > only the VIP needs to be configured as the radius

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-16 Thread Durand fabrice via PacketFence-users
Hello, only the VIP needs to be configured as the radius server. Regards Fabrice Le 19-07-16 à 11 h 53, Domingos Varela via PacketFence-users a écrit : Hello, Does your wlc have hits in the statistics of communication with radius servers? Do you have the IPs of the servers in wlc's ACL?

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-16 Thread Domingos Varela via PacketFence-users
Hello, Does your wlc have hits in the statistics of communication with radius servers? Do you have the IPs of the servers in wlc's ACL? Thanks Cumprimentos, *Domingos Varela* Tel. +244 923 229 330 | Luanda - Angola pro fence via PacketFence-users escreveu no dia terça, 16/07/2019 à(s) 16:41:

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-16 Thread pro fence via PacketFence-users
Hi, thank you for your reply, i have configured the 3 radius servers on the wlc, but i thought that more needs to be done so that the WLC could link the vip with the ssid ? or maybe i am missing something ? problem is when i try to connect to the ssid,nothing happens know Regards, On Tue, 16

Re: [PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-16 Thread Domingos Varela via PacketFence-users
Hi, wlc needs to know who the radius server will communicate with it, so I think you have to configure the three radius servers in wlc, the virtual IP will only redirect the requests to the servers. If you configure the virtual IP the request will be made, but you may have problems in the

[PacketFence-users] [PF 9.0.1] Cisco WLC and Virtual IP

2019-07-16 Thread pro fence via PacketFence-users
Hi, i have a 3 servers' cluster configured with a Virtual IP, do you guys know what needs to be changed or configured on the cisco WLC for the VIP to make sure that when the user connects to the ssid it goes through the VIP ? Any help would be appreciated, Thanks, Regards,