Re: [PacketFence-users] Error after upgrade PF from 5.0.2 to 5.1

2015-05-27 Thread Durand fabrice
Hello Minh, i suppose you are running centos. Did you find this file libasync_wmi_lib.so.0 ? What happen if you do a ldconfig ? Did you try to reinstall wmi from PacketFence repo ? Regards Fabrice Le 2015-05-27 04:05, Minh Trung a écrit : Hello experts, I did follow as the procedure upgrade

Re: [PacketFence-users] registered users 'stuck' in registration network

2015-05-27 Thread Durand fabrice
Hello, the thing is with a WLC you send the deauth request to the wlc himself. For aerohive you send the request to the AP, so if the device move from one AP to another then packetfence must know that the device move. It's why we added roaming support for aerohive in PacketFence. So the

[PacketFence-users] Error after upgrade PF from 5.0.2 to 5.1

2015-05-27 Thread Minh Trung
Hello experts, I did follow as the procedure upgrade docs but after restart all services, i can not logon to webpage admin. Here is the some info may helpful: /usr/local/pf/bin/pfcmd configreload hard Couldn't require pf::api::local : Can't load

Re: [PacketFence-users] registered users 'stuck' in registration network

2015-05-27 Thread Gary Ossewaarde
We are currently running 3.5.1, with an upgrade planned for this summer. I was curious if we were the only ones running into this or not. It seems to mostly effect Android phones and Windows machines, but I have take no notice of age being a huge factor.

[PacketFence-users] 802.1x authentication

2015-05-27 Thread Sohaib Afourid
Hello, i've been trying to set up Packetfence as part of a three month internship. i'm using a Cisco Catalyst 3560 switch and Centos 6.6 on a virtualbox as a host for Packetfence, and my own personal laptop as a client. at first I set up freeradius (independently) succefully using PEAP. It worked

Re: [PacketFence-users] Cisco WLC HTTP authentication - multiple roles/subnets vs one portal

2015-05-27 Thread J Nelson
Fabrice, well, I spoke too soon. Just as I was feeling pretty good about things - i discovered that apple IOS will not load the captive web portal page. It looks like the redirect is happening, just no love on the IOS side. I know OSX, Windows 7, and Droid are working, but not Apple IOS. I

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Fabrice DURAND
First you have to run radius in debug mode to see why it failed. radiusd -d /usr/local/pf/raddb -X Le 2015-05-27 09:28, Sohaib Afourid a écrit : Hello, i've been trying to set up Packetfence as part of a three month internship. i'm using a Cisco Catalyst 3560 switch and Centos 6.6 on a

Re: [PacketFence-users] pfcmd not running properly under V5

2015-05-27 Thread Louis Munro
On May 26, 2015, at 16:49 , Boris Epstein borepst...@gmail.com wrote: mysql select switch,port,read_time,mac,ifInOctets,ifOutOctets from ifoctetslog where mac='00:25:64:40:05:47' order by read_time desc; Empty set (0.00 sec) mysql But the OWA shows me the location, IP and other

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Boris Epstein
Hello there, Are you still running freeradius? If so, what is your plan for interfacing between freeradius and PF? Boris. On Wed, May 27, 2015 at 9:28 AM, Sohaib Afourid sohaibafou...@gmail.com wrote: Hello, i've been trying to set up Packetfence as part of a three month internship. i'm

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Boris Epstein
Yes, but in his case all it means is that MAB succeeded. His switch seems to try 802.1x first and then switch to MAB if authentication fails. When using MAB, PacketFence will always authenticate successfully at the RADIUS level. It’s only later when sent to the captive portal that actual

Re: [PacketFence-users] pfcmd not running properly under V5

2015-05-27 Thread Boris Epstein
Louis, I don't consciously populate any tables in that databases - or choose to not populate them, for that matter:) I just count on the software to run as it is, for the most part:) I suspect there may be some modules/functionality missing for some reason. Messages such as this one lead me to

Re: [PacketFence-users] pfcmd not running properly under V5

2015-05-27 Thread Louis Munro
Hi Boris, That’s an “interesting” behaviour. We have been rewriting pfcmd from scratch and the new one in 5.0+ differs in what it supports. It looks to me like the new pfcmd does not support the fingerprint command (that’s what the error means) yet does provide the usage message. That message

Re: [PacketFence-users] Upgrade from 4.7.0 to 5.0.2

2015-05-27 Thread Steve Allen
Hi Derek I have upgraded again today and followed the upgrade documentation steps from 4.7.0 to 5.1.0. I had the same problems so I tried what you suggested and removed the use pf::os and now everything seems to be working OK. Can you explain what use pf::os was used for? By removing it have I

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Louis Munro
On May 27, 2015, at 11:33 , Sohaib Afourid sohaibafou...@gmail.com wrote: Found Auth-Type = EAP # Executing group from file /usr/local/pf/raddb/sites-enabled/packetfence-tunnel +group authenticate { [eap] Request found, released from the list [eap] EAP/mschapv2 [eap] processing type

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Jason 'XenoPhage' Frisvold
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 5/27/15 11:49, Sohaib Afourid wrote: And i'm not using Active Directory or Windows Server. Where are you going to store user credentials? If you're not using AD, are you going to use LDAP? Or are you planning on using all local accounts via

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Louis Munro
On May 27, 2015, at 11:58 , Jason 'XenoPhage' Frisvold xenoph...@godshell.com wrote: Where are you going to store user credentials? If you're not using AD, are you going to use LDAP? Or are you planning on using all local accounts via packetfence? (I *think* it supports that, but isn't

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Sohaib Afourid
well there are two radius instances, the one in /etc/raddb and the one in /usr/local/pf i changed the ports for the first one 1645 for auth and 1646 for acct and 1812/1813 for the pf radius. the first instance is stopped while the pf radiusd is launched. 2015-05-27 15:28 GMT+02:00 Sohaib Afourid

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Sohaib Afourid
I meant switch config, i'm using a cisco catalyst 3560. 2015-05-27 17:18 GMT+02:00 Sohaib Afourid sohaibafou...@gmail.com: Again, thank you very much for your time and patience. In my router configuration i followed the device guide provided by packetfence. Once i plug my laptop in the

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Louis Munro
There is not authentication attempt in the output that you sent. We can’t help you if there is no error. Make sure to send at least one authentication to Radius so there is something to debug. -- Louis Munro lmu...@inverse.ca :: www.inverse.ca +1.514.447.4918 x125 :: +1 (866) 353-6153 x125

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Sohaib Afourid
I know, and I'm gratefull for that, but still, nobody has answered my question, and my case is not explained in the documentation. the only think i changed in etc/raddb is the eap type, i set it to PEAP because i don't want to use a client certificate. What i need right now is for someone to

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Louis Munro
On May 27, 2015, at 10:40 , Sohaib Afourid sohaibafou...@gmail.com wrote: I know, and I'm gratefull for that, but still, nobody has answered my question, and my case is not explained in the documentation. the only think i changed in etc/raddb is the eap type, i set it to PEAP because i don't

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Sohaib Afourid
Can you at least explain to me a scenario for packetfence with 802.1x authentication with mysql. 2015-05-27 16:23 GMT+02:00 Sohaib Afourid sohaibafou...@gmail.com: well there are two radius instances, the one in /etc/raddb and the one in /usr/local/pf i changed the ports for the first one

[PacketFence-users] Error in krb5.tt template

2015-05-27 Thread Holger.Patzelt
Hi folks, I suppose there is some error in the template for the migration.pl script: The default_realm is hard coded into the template, with which one finds oneself bound to INVERSE.LOCAL instead of the correct realm :-) I will post this as a bug, too. Regads, Holger

Re: [PacketFence-users] Cisco WLC HTTP authentication - multiple roles/subnets vs one portal

2015-05-27 Thread J Nelson
Here is what even more awesome - I just fired up my first PF test install. Same CentOS, same PF Version, same WLC Webauth, and it works for IOS. But, what is interesting, is that on my first, test PF install, after logging in at the captive portal, I got a server not found error, so you had me

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Louis Munro
Let me save you some time. 1. Don’t use virtualbox. It has issues with VLANs. If you must use virtualization then use VMWare. 2. Don’t mess with the /etc/raddb 3. Wipe out what you have done and reinstall. 4. Follow the documentation. Step by step. Then, if it still does not work, come back and

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Sohaib Afourid
Again, thank you very much for your time and patience. In my router configuration i followed the device guide provided by packetfence. Once i plug my laptop in the specified port, the authentcation cloud pops up (since i configured my Windows 7 client for peap authentication, i also added the CA

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Boris Epstein
Louis, Correct me if I am wrong but doesn't the fact that you have been allowed to join a VLAN signify that you have passed the port-level security authentication? Boris. On Wed, May 27, 2015 at 10:56 AM, Louis Munro lmu...@inverse.ca wrote: On May 27, 2015, at 10:40 , Sohaib Afourid

[PacketFence-users] Packet fence and external portal page

2015-05-27 Thread Kenroy Bennett
Hi everyone, I am deploying Wifi service and would like users to be redirected to a web page when they first access content on the web. On this web page I would like that code entered by the user to validated against a database . If the code is valid I would have the user be

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Louis Munro
On May 27, 2015, at 12:08 , Sohaib Afourid sohaibafou...@gmail.com wrote: but right now I can't even get/ don't clearly understand how packetfence works with 802.1x and a captive portal, i've been asking for an explanation scenario but no one has provided it yet. thank you. To be

Re: [PacketFence-users] 802.1x authentication

2015-05-27 Thread Louis Munro
On May 27, 2015, at 13:33 , Boris Epstein borepst...@gmail.com wrote: Louis, Correct me if I am wrong but doesn't the fact that you have been allowed to join a VLAN signify that you have passed the port-level security authentication? Yes, but in his case all it means is that MAB

Re: [PacketFence-users] OpenWRT + PacketFence with Dynamic VLAN support

2015-05-27 Thread Chris Abel
Thanks so much Earl. Your hostapd.sh patch is working perfectly for me as well. Great to have PF work with the latest version of OpenWRT. On Thu, May 21, 2015 at 4:02 PM, Earl Robinson e...@v-studios.com wrote: I've got it working! The solution was merging your version of

Re: [PacketFence-users] Bug in Palo Alto SSO/SSO in general.

2015-05-27 Thread Tim DeNike
the iplog_history table keeps getting bigger and bigger, so the webui shows the same IP again and again and again and again. IMHO, it should only show another entry if the IP changes. On Thu, May 21, 2015 at 9:37 AM, Derek Wuelfrath dwuelfr...@inverse.ca wrote: Hello Tim, As far as I can

[PacketFence-users] Portal Profile Files Documentation

2015-05-27 Thread Michael Stone
Hi, Is there any documentation or guidance on the files created for each portal profile? By trial and error I've worked out that login.html is the main landing page and a few other things but many of the other files are a mystery. For example, I'm trying to work out how to change the welcome

Re: [PacketFence-users] Upgrade from 4.7.0 to 5.0.2

2015-05-27 Thread Derek Wuelfrath
Steve, I had the same problems so I tried what you suggested and removed the use pf::os and now everything seems to be working OK. Glad to hear! Can you explain what use pf::os was used for? It is an older class no longuer in PacketFence… was used before Fingerbank integration. By removing

Re: [PacketFence-users] Error after upgrade PF from 5.0.2 to 5.1

2015-05-27 Thread Minh Trung
Hello, I already installed wmi but seems it not link... [root@vmvnnetsec01 ld.so.conf.d]# yum install wmi --enablerepo=packetfence Loaded plugins: fastestmirror, refresh-packagekit, security Setting up Install Process Loading mirror speeds from cached hostfile epel/metalink | 4.6 kB

Re: [PacketFence-users] Error after upgrade PF from 5.0.2 to 5.1

2015-05-27 Thread Durand fabrice
OK so first let's go in /etc/ld.so.conf.d and check if there is a wmi.conf file if no create it and add /lib/python inside and retry ldconfig. Also to install from packetfence repo you just have to launch yum install wmi --enablerepo=packetfence Regards Fabrice Le 2015-05-27 21:15, Minh

Re: [PacketFence-users] Error after upgrade PF from 5.0.2 to 5.1

2015-05-27 Thread Fabrice Durand
wmi-1.3.14-4.el6.art.x86_64 is not coming from packetfence repo but from atomic repo. So remove wmi, disable epel, atomic repo and reinstall win from packetfence repo. Le 27 mai 2015 23:02:23 GMT-04:00, Minh Trung mvtrun...@gmail.com a écrit : Hello, I already installed wmi but seems it not

Re: [PacketFence-users] Error after upgrade PF from 5.0.2 to 5.1

2015-05-27 Thread Minh Trung
Hello Fabrice, Yes, i am using CentOS 6.6 Here is the file that i found: [root@vmvnnetsec01 logs]# find / -name libasync_wmi_lib.so.0 /lib/python/libasync_wmi_lib.so.0 You have new mail in /var/spool/mail/root [root@vmvnnetsec01 logs]# ldconfig [root@vmvnnetsec01 logs]# I can not found

Re: [PacketFence-users] Portal Profile Files Documentation

2015-05-27 Thread Leja, Maciej
I don’t think there’s any documentation on this but I’ve asked something similar before… the exact text sits in this file: ../pf/conf/en/LC_MESSAGES/packetfence.po We started customizing the .po file and to activate the changes you do this: for TRANSLATION in de en es fr he_IL it nl pl_PL