[PacketFence-users] Creat violation to auth reject user

2017-11-29 Thread Yan via PacketFence-users
Hi users, As I check the audit log, I find there are few users always fail the 802.1x authentication but still keeps connecting. Can I create a violation on this item ? For example, if a user fails the authentication continually for 10 times with the same device, create a violation and tell

Re: [PacketFence-users] USB-C docks and MAB

2017-11-29 Thread Jes Kasper Klittum via PacketFence-users
Good question. I guess you can just register it with the REJECT role? Jes -Oprindelig meddelelse- Fra: Jason 'XenoPhage' Frisvold [mailto:xenoph...@godshell.com] Sendt: 29. november 2017 15:30 Til: Jes Kasper Klittum ; packetfence-users@lists.sourceforge.net Emne: Re:

[PacketFence-users] Chained authentication

2017-11-29 Thread Welber Silveira - NTI via PacketFence-users
Hi List, I´m trying packetfence 7.3 and I can assure it is a great piece of software. Thank you. My goal is to use chained authentication ( SMS + Facebook ). It looks good but after a sucessfull authentication the result is 2x PIDs. One for SMS (phone numer) and other for Facebook

Re: [PacketFence-users] VLAN filter rule to temporarily allow specific switch

2017-11-29 Thread Fabrice Durand via PacketFence-users
Hello Yan, you also need to register the device. so something like that: [pf_ssid] filter = ssid operator = is value = PF-Wireless [SG1_switch] filter = switch._ip operator = is value = 172.11.5.121 [reg_by_switch:pf_ssid_switch] scope = RegistrationRole action = modify_node action_param =

Re: [PacketFence-users] USB-C docks and MAB

2017-11-29 Thread Jason 'XenoPhage' Frisvold via PacketFence-users
Can you "blacklist" the dock MAC addresses? ie, what happens if someone without that BIOS option set logs in while connected to a dock? Now you have a dock on the network that could be used, inadvertently, and you likely don't know it's there. On 11/28/17 02:15, Jes Kasper Klittum wrote: > Hi

[PacketFence-users] VLAN filter rule to temporarily allow specific switch

2017-11-29 Thread Yan via PacketFence-users
Hi users, I want to add a VLAN filter rule to temporarily pass one specific switch (IP 172.11.5.121) and keep the others as normal. Is below rule okay to do this ? [pf_ssid] filter = ssid operator = is value = PF-Wireless [SG1_switch] filter = switch._ip operator = is value =