[PacketFence-users] Cisco WLC WebAuth Portal HTTPS/Signed Cert/Apple devices

2018-01-20 Thread Justin Nelson via PacketFence-users
I have been searching and searching but cant find an answer.

My WLC/Packetfence works great for straight HTTP webauth.  We must now have
everything on HTTPS.

my issue is trying to figure out how to get the webauth portal into an
HTTPS state with a valid signed cert.

So, I have my PF management address IP, which has a DNS name and signed
cert (a wildcard cert) - and thats all well and good.

then I have my captive portal IP/dns name, no matter what, I always get
prompted that its untrusted.  IOS devices especially do not react well to
this.  the only way to get redirected, is to attempt to go to a non HTTPS
site, THEN you get redirected with a warning about a non-secure cert, but
you can at least authenticate.

and lastly, is the device registation page.  It seems that HTTP is always
allowed.  If i change the ACL's to only allow HTTPS to all things
packetfence, then the portal stops working for everything: webauth portal
and device registration.

any details on how I can lock this all down to HTTPS, get a valid cert
happening on the portal page, and not allow HTTP on the device registration
page??

I'm on 4.5.1

thanks...
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Error trying to install on Centos 7

2018-01-20 Thread Justin Nelson via PacketFence-users
i temporarily just set the gpg check to zero's in:
/etc/yum.repos.d/packetfence.repo

and then I could install.

On Sat, Jan 20, 2018 at 2:34 PM, Durand fabrice via PacketFence-users <
packetfence-users@lists.sourceforge.net> wrote:

> Hello Justin,
>
> try that:
>
> yum clean all --enablerepo=packetfence
>
> yum makecache --enablerepo=packetfence
>
> yum install packetfence --enablerepo=packetfence
>
> Regards
>
> Fabrice
>
> Le 2018-01-20 à 15:06, Justin Nelson via PacketFence-users a écrit :
>
> I'm getting the same error trying to install it.  Just tried it.
>
> any manual workaround?
>
>
> On Fri, Jan 19, 2018 at 8:16 PM, Durand fabrice via PacketFence-users <
> packetfence-users@lists.sourceforge.net> wrote:
>
>> Hello Peter,
>>
>> My bad, i updated this lib but didn't signed it.
>>
>> It's fixed now.
>>
>> Regards
>>
>> Fabrice
>>
>>
>>
>> Le 2018-01-17 à 16:44, Truax, Peter via PacketFence-users a écrit :
>>
>> We are getting an error when installing PacketFence on Centos 7.
>>
>>
>>
>>
>>
>> Retrieving key from file:///etc/pki/rpm-gpg/RPM-GP
>> G-KEY-PACKETFENCE-CENTOS
>>
>> Importing GPG key 0xA0030E2C:
>>
>> Userid  : “Inverse Support (RPM package signing) <
>> supp...@inverse.ca>”
>>
>> Fingerprint  : b022 c48d 3d63 73d7 fc25 6a8c 3a2a a003 0e2c
>>
>> Package   : packetfence-release-1.2-6.el7.centos.noarch
>> (installed)
>>
>> From : /etc/pki/rpm-gpg/RPM-GPG-KEY-P
>> ACKETFENCE-CENTOS
>>
>> Is this ok [y/N]: y
>>
>> warning: 
>> /var/cache/yum/x86_64/7/packetfence/packages/perl-Net-Nessus-REST-0.7.0-2.1.noarch.rpm:
>> Header V3 DSA/SHA1 Signature, key ID 55e70a3a: NOKEY
>>
>> retrieving key from file:///etc/pki/rpm-gpg/RPM-GP
>> G-KEY-PACKETFENCE-CENTOS
>>
>>
>>
>> The GPG keys listed for the “PacketFence Repository” repository are
>> already installed but they are not correct for this package.
>>
>> Check that the correct key URLs are configured for this repository.
>>
>>
>>
>> Failing package is: perl-Net-Nessus-REST-0.7.0-2.1.noarch
>>
>> GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GP
>> G-KEY-PACKETFENCE-CENTOS
>>
>>
>>
>>
>> Looking at the repository at https://packetfence.org/downlo
>> ads/PacketFence/RHEL7/devel/x86_64/RPMS/, it seems that
>> perl-Net-Nessus-REST-0.7.0-2.1.noarch.rpm was updated about a week ago.
>> Not sure if that has anything to do with the error.
>>
>>
>>
>> Regards,
>>
>>
>>
>> *Peter Truax*
>>
>> *Network Administrator*
>>
>> (360) 688-2240
>>
>> St. Martin’s University
>>
>> 5000 Abbey Way E
>>
>> Lacey, WA 98503
>>
>>
>>
>>
>>
>>
>> --
>> Check out the vibrant tech community on one of the world's most
>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>
>>
>>
>> ___
>> PacketFence-users mailing 
>> listPacketFence-users@lists.sourceforge.nethttps://lists.sourceforge.net/lists/listinfo/packetfence-users
>>
>>
>>
>> 
>> --
>> Check out the vibrant tech community on one of the world's most
>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>> ___
>> PacketFence-users mailing list
>> PacketFence-users@lists.sourceforge.net
>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>>
>>
>
>
> --
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>
>
>
> ___
> PacketFence-users mailing 
> listPacketFence-users@lists.sourceforge.nethttps://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>
>
> 
> --
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> ___
> PacketFence-users mailing list
> PacketFence-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Sponsor emails not enconding

2018-01-20 Thread Durand fabrice via PacketFence-users

Hello Luís,

i am not an expert of the localization but did you tried to change the 
charset of your browser to see if there is a difference ?


Regards

Fabrice



Le 2018-01-20 à 04:13, Luís Torres via PacketFence-users a écrit :


Hello Fabrice,

still the same:

"

Ol�,

tess tess Solicitando acesso de convidado a rede.

Acesso n�o autorizado caso n�o seja convidado.

Aqui est�o as informa��es fornecidas pelo convidado no formul�rio de 
inscri��o.:"


LT

Em 2018-01-20 02:29, Durand fabrice via PacketFence-users escreveu:


Hello Luís,

edit the po file (conf/locales/...) and once done in /usr/local/pf do 
a make translation.


Regards

Fabrice


Le 2018-01-19 à 10:37, Luís Torres via PacketFence-users a écrit :


Hello,

" a informa�ao"

This is how emails to sponsor aproving is showing . Seems is not 
encoding in the properly charset


How I cant change this on the "emails-guest_sponsor_activation.html"

Many thanks



--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org!http://sdm.link/slashdot


___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users



--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org!http://sdm.link/slashdot

___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net 


https://lists.sourceforge.net/lists/listinfo/packetfence-users




--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot


___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Error trying to install on Centos 7

2018-01-20 Thread Durand fabrice via PacketFence-users

Hello Justin,

try that:

yum clean all --enablerepo=packetfence

yum makecache --enablerepo=packetfence

yum install packetfence --enablerepo=packetfence

Regards

Fabrice


Le 2018-01-20 à 15:06, Justin Nelson via PacketFence-users a écrit :

I'm getting the same error trying to install it.  Just tried it.

any manual workaround?


On Fri, Jan 19, 2018 at 8:16 PM, Durand fabrice via PacketFence-users 
> wrote:


Hello Peter,

My bad, i updated this lib but didn't signed it.

It's fixed now.

Regards

Fabrice



Le 2018-01-17 à 16:44, Truax, Peter via PacketFence-users a écrit :


We are getting an error when installing PacketFence on Centos 7.

Retrieving key from
file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PACKETFENCE-CENTOS

Importing GPG key 0xA0030E2C:

Userid : “Inverse Support (RPM package signing)
>”

Fingerprint : b022 c48d 3d63 73d7 fc25 6a8c 3a2a a003 0e2c

Package : packetfence-release-1.2-6.el7.centos.noarch (installed)

From     :
/etc/pki/rpm-gpg/RPM-GPG-KEY-PACKETFENCE-CENTOS

Is this ok [y/N]: y

warning:

/var/cache/yum/x86_64/7/packetfence/packages/perl-Net-Nessus-REST-0.7.0-2.1.noarch.rpm:
Header V3 DSA/SHA1 Signature, key ID 55e70a3a: NOKEY

retrieving key from
file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PACKETFENCE-CENTOS

The GPG keys listed for the “PacketFence Repository” repository
are already installed but they are not correct for this package.

Check that the correct key URLs are configured for this repository.

Failing package is: perl-Net-Nessus-REST-0.7.0-2.1.noarch

GPG Keys are configured as:
file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PACKETFENCE-CENTOS


Looking at the repository at
https://packetfence.org/downloads/PacketFence/RHEL7/devel/x86_64/RPMS/
,
it seems that perl-Net-Nessus-REST-0.7.0-2.1.noarch.rpm was
updated about a week ago. Not sure if that has anything to do
with the error.

Regards,

*Peter Truax*

*Network Administrator*

(360) 688-2240 

St. Martin’s University

5000 Abbey Way E

Lacey, WA 98503




--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org!http://sdm.link/slashdot


___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net

https://lists.sourceforge.net/lists/listinfo/packetfence-users





--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net

https://lists.sourceforge.net/lists/listinfo/packetfence-users





--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot


___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Error trying to install on Centos 7

2018-01-20 Thread Justin Nelson via PacketFence-users
I'm getting the same error trying to install it.  Just tried it.

any manual workaround?


On Fri, Jan 19, 2018 at 8:16 PM, Durand fabrice via PacketFence-users <
packetfence-users@lists.sourceforge.net> wrote:

> Hello Peter,
>
> My bad, i updated this lib but didn't signed it.
>
> It's fixed now.
>
> Regards
>
> Fabrice
>
>
>
> Le 2018-01-17 à 16:44, Truax, Peter via PacketFence-users a écrit :
>
> We are getting an error when installing PacketFence on Centos 7.
>
>
>
>
>
> Retrieving key from file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PACKETFENCE-CENTOS
>
> Importing GPG key 0xA0030E2C:
>
> Userid  : “Inverse Support (RPM package signing) <
> supp...@inverse.ca>”
>
> Fingerprint  : b022 c48d 3d63 73d7 fc25 6a8c 3a2a a003 0e2c
>
> Package   : packetfence-release-1.2-6.el7.centos.noarch
> (installed)
>
> From : /etc/pki/rpm-gpg/RPM-GPG-KEY-PACKETFENCE-CENTOS
>
> Is this ok [y/N]: y
>
> warning: /var/cache/yum/x86_64/7/packetfence/packages/perl-Net-
> Nessus-REST-0.7.0-2.1.noarch.rpm: Header V3 DSA/SHA1 Signature, key ID
> 55e70a3a: NOKEY
>
> retrieving key from file:///etc/pki/rpm-gpg/RPM-GPG-KEY-PACKETFENCE-CENTOS
>
>
>
> The GPG keys listed for the “PacketFence Repository” repository are
> already installed but they are not correct for this package.
>
> Check that the correct key URLs are configured for this repository.
>
>
>
> Failing package is: perl-Net-Nessus-REST-0.7.0-2.1.noarch
>
> GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-
> GPG-KEY-PACKETFENCE-CENTOS
>
>
>
>
> Looking at the repository at https://packetfence.org/
> downloads/PacketFence/RHEL7/devel/x86_64/RPMS/, it seems that
> perl-Net-Nessus-REST-0.7.0-2.1.noarch.rpm was updated about a week ago.
> Not sure if that has anything to do with the error.
>
>
>
> Regards,
>
>
>
> *Peter Truax*
>
> *Network Administrator*
>
> (360) 688-2240
>
> St. Martin’s University
>
> 5000 Abbey Way E
>
> Lacey, WA 98503
>
>
>
>
>
>
> --
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>
>
>
> ___
> PacketFence-users mailing 
> listPacketFence-users@lists.sourceforge.nethttps://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>
>
> 
> --
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> ___
> PacketFence-users mailing list
> PacketFence-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] users stay in registration VLAN after authentication success

2018-01-20 Thread Durand fabrice via PacketFence-users

Hello Tom,


Le 2018-01-20 à 03:02, tom lo a écrit :

Hi Durand,


Thanks for your reply and please see if my understanding is correct
about the locationlog.
If the locationlog is correct, from mysql, I should see one entry when
a device reach captive portal, and another entry immediately after the
authentication complete, with matching start / end time?
If the locationlog is wrong, the new entry may be missing even the
authentication is completed?
In fact when PacketFence receive a radius request , it will update the 
location log, so just after the registration on the captive portal 
Packetfence need to know where the device is to send a disconnection.
And if the disconnection succeed you will see a new entry in the 
locationlog.


I checked a log from an issue reported few hours ago. User
"12:34:56:33:22:11" completed the authentication at 11:11am, but there
is no entry about the updated role (staff) for this device until the
user retry the connection at 13:06.  Is this a kind of wrong
locationlog?

Yes probably if you see no locationlog entry was found in the log.
But it can also be a issue with a cache on the controller,if there is no 
new radius request each time the device connect on the ssid per example.


I also found another mysql output for a device which had a smooth VLAN
re-direction in its 1st try. mysql output shows one entry when a
device reach captive portal, and another entry after the
authentication complete with matching start / end time.

Also, for your information, we are using Ruckus ZoneDirector and the
SSID setting is mac-auth.

I'll check with users in real-time to see about the queue and mysql
output, and let you know the result.


The following is the related log / mysql output for the issue reported.

Before "Jan 20 11:11:59" do you see "INFO: [mac:12:34:56:33:22:11] handling
radius autz request" ? if no then the device is on the registration 
network but PacketFence never receive the radius request !


Jan 20 11:11:59 httpd.portal(6296) INFO: [mac:12:34:56:33:22:11]
re-evaluating access (manage_register called)
(pf::enforcement::reevaluate_access)
Jan 20 11:11:59 httpd.portal(6296) WARN: [mac:12:34:56:33:22:11] Can't
re-evaluate access because no open locationlog entry was found
(pf::enforcement::reevaluate_access)
Jan 20 11:15:29 httpd.aaa(2033) INFO: [mac:12:34:56:33:22:11] Updating
locationlog from accounting request
(pf::api::handle_accounting_metadata)
Jan 20 13:06:53 httpd.aaa(2033) INFO: [mac:12:34:56:33:22:11] handling
radius autz request...

select * from locationlog where mac="12:34:56:33:22:11";
+---+-+--+--+--+---+-+---+--+-+-+-+---++---++
| mac   | switch  | port | vlan | role |connection_type 
  | connection_sub_type | dot1x_username| ssid| start_time  
| end_time| switch_ip   |switch_mac| stripped_user_name 
| realm | session_id |
+---+-+--+--+--+---+-+---+--+-+-+-+---++---++
| 12:34:56:33:22:11 | 172.18.4.61 | 0| 50   | staff
|Wireless-802.11-NoEAP | NULL| 12:34:56:33:22:11 |SSID_A   
| 2018-01-20 13:06:53 | -00-00 00:00:00 | 172.18.4.61| 11:22:33:44:55:0d | 
12:34:56:33:22:11  | null  | NULL   |
| 12:34:56:33:22:11 | 172.18.4.61 | 0| 501  | registration 
|Wireless-802.11-NoEAP | NULL| 12:34:56:33:22:11 |SSID_A   
| 2018-01-20 11:10:51 | 2018-01-20 11:11:12 | 172.18.4.61| 11:22:33:44:55:09 | 
12:34:56:33:22:11  | null  | NULL   |
| 12:34:56:33:22:11 | 172.18.4.61 | 0| 501  | registration 
|Wireless-802.11-NoEAP | NULL| 12:34:56:33:22:11 |SSID_A   
| 2018-01-20 11:11:12 | 2018-01-20 11:11:38 | 172.18.4.61| 11:22:33:44:55:0d | 
12:34:56:33:22:11  | null  | NULL   |
+---+-+--+--+--+---+-+---+--+-+-+-+---++---++
Really strange , it look that something closed the locationlog just 
before you register on the portal.

Can you disable update locationlog on accounting and retry ?
Regards
Fabrice



Regards,
Tom


On Sat, Jan 20, 2018 at 10:01 AM, Durand fabrice via PacketFence-users
 wrote:

Hello Tom,

just after a radius request, can you check in the database if the
locationlog is correct ? (the radius request is suppose to update the
locationlog)

And also when it failed.

select * from locationlog where 

Re: [PacketFence-users] Sponsor emails not enconding

2018-01-20 Thread Luís Torres via PacketFence-users
 

Hello Fabrice, 

still the same: 

" 

Ol�, 

tess tess Solicitando
acesso de convidado a rede. 

Acesso n�o autorizado caso n�o seja
convidado. 

Aqui est�o as informa��es fornecidas pelo convidado no
formul�rio de inscri��o.:" 

LT 

Em 2018-01-20 02:29, Durand fabrice
via PacketFence-users escreveu: 

> Hello Luís, 
> 
> edit the po file
(conf/locales/...) and once done in /usr/local/pf do a make translation.

> 
> Regards 
> 
> Fabrice 
> 
> Le 2018-01-19 à 10:37, Luís Torres via
PacketFence-users a écrit : 
> 
>> Hello, 
>> 
>> " a informa�ao" 
>>

>> This is how emails to sponsor aproving is showing . Seems is not
encoding in the properly charset 
>> 
>> How I cant change this on the
"emails-guest_sponsor_activation.html" 
>> 
>> Many thanks 
>> 
>>
--
>>
Check out the vibrant tech community on one of the world's most
>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>> 
>>
___
>> PacketFence-users
mailing list
>> PacketFence-users@lists.sourceforge.net
>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
> 
>
--
>
Check out the vibrant tech community on one of the world's most
>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
> 
>
___
> PacketFence-users
mailing list
> PacketFence-users@lists.sourceforge.net
>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]




Links:
--
[1] http://sdm.link/slashdot
[2]
https://lists.sourceforge.net/lists/listinfo/packetfence-users
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] users stay in registration VLAN after authentication success

2018-01-20 Thread tom lo via PacketFence-users
Hi Durand,


Thanks for your reply and please see if my understanding is correct
about the locationlog.
If the locationlog is correct, from mysql, I should see one entry when
a device reach captive portal, and another entry immediately after the
authentication complete, with matching start / end time?
If the locationlog is wrong, the new entry may be missing even the
authentication is completed?

I checked a log from an issue reported few hours ago. User
"12:34:56:33:22:11" completed the authentication at 11:11am, but there
is no entry about the updated role (staff) for this device until the
user retry the connection at 13:06.  Is this a kind of wrong
locationlog?

I also found another mysql output for a device which had a smooth VLAN
re-direction in its 1st try. mysql output shows one entry when a
device reach captive portal, and another entry after the
authentication complete with matching start / end time.

Also, for your information, we are using Ruckus ZoneDirector and the
SSID setting is mac-auth.

I'll check with users in real-time to see about the queue and mysql
output, and let you know the result.


The following is the related log / mysql output for the issue reported.

Jan 20 11:11:59 httpd.portal(6296) INFO: [mac:12:34:56:33:22:11]
re-evaluating access (manage_register called)
(pf::enforcement::reevaluate_access)
Jan 20 11:11:59 httpd.portal(6296) WARN: [mac:12:34:56:33:22:11] Can't
re-evaluate access because no open locationlog entry was found
(pf::enforcement::reevaluate_access)
Jan 20 11:15:29 httpd.aaa(2033) INFO: [mac:12:34:56:33:22:11] Updating
locationlog from accounting request
(pf::api::handle_accounting_metadata)
Jan 20 13:06:53 httpd.aaa(2033) INFO: [mac:12:34:56:33:22:11] handling
radius autz request...

select * from locationlog where mac="12:34:56:33:22:11";
+---+-+--+--+--+---+-+---+--+-+-+-+---++---++
| mac   | switch  | port | vlan | role |
connection_type   | connection_sub_type | dot1x_username| ssid
| start_time  | end_time| switch_ip   |
switch_mac| stripped_user_name | realm | session_id |
+---+-+--+--+--+---+-+---+--+-+-+-+---++---++
| 12:34:56:33:22:11 | 172.18.4.61 | 0| 50   | staff|
Wireless-802.11-NoEAP | NULL| 12:34:56:33:22:11 |
SSID_A   | 2018-01-20 13:06:53 | -00-00 00:00:00 | 172.18.4.61
| 11:22:33:44:55:0d | 12:34:56:33:22:11  | null  | NULL   |
| 12:34:56:33:22:11 | 172.18.4.61 | 0| 501  | registration |
Wireless-802.11-NoEAP | NULL| 12:34:56:33:22:11 |
SSID_A   | 2018-01-20 11:10:51 | 2018-01-20 11:11:12 | 172.18.4.61
| 11:22:33:44:55:09 | 12:34:56:33:22:11  | null  | NULL   |
| 12:34:56:33:22:11 | 172.18.4.61 | 0| 501  | registration |
Wireless-802.11-NoEAP | NULL| 12:34:56:33:22:11 |
SSID_A   | 2018-01-20 11:11:12 | 2018-01-20 11:11:38 | 172.18.4.61
| 11:22:33:44:55:0d | 12:34:56:33:22:11  | null  | NULL   |
+---+-+--+--+--+---+-+---+--+-+-+-+---++---++


Regards,
Tom


On Sat, Jan 20, 2018 at 10:01 AM, Durand fabrice via PacketFence-users
 wrote:
> Hello Tom,
>
> just after a radius request, can you check in the database if the
> locationlog is correct ? (the radius request is suppose to update the
> locationlog)
>
> And also when it failed.
>
> select * from locationlog where mac="ab:cd:ef:12:34:56";
>
> Last thing, can you verify if the queue is full when this problem occur
> (from the admin gui in queue)
>
> Regards
> Fabrice
>
>
> Le 2018-01-16 à 20:33, tom lo via PacketFence-users a écrit :
>>
>> Hi,
>>
>>
>> We checked packetfence.log and did a comparison between working and
>> non-working VLAN redirection.
>>
>> When VLAN redirection works properly, "re-evaluating access" related
>> log has no warning.
>>
>> Jan 12 12:07:18 httpd.portal(3102) INFO: [mac:ab:cd:ef:12:34:56]
>> re-evaluating access (manage_register called)
>> (pf::enforcement::reevaluate_access)
>> Jan 12 12:07:18 httpd.portal(3102) INFO: [mac:ab:cd:ef:12:34:56] is
>> currentlog connected at (172.18.4.62) ifIndex 0 registration
>> (pf::enforcement::_should_we_reassign_vlan)
>> Jan 12 12:07:18 httpd.portal(3102) INFO: [mac:ab:cd:ef:12:34:56]
>> Instantiate profile default
>> (pf::Portal::ProfileFactory::_from_profile)
>> Jan 12