[Packetfence-users] Optional software install problems

2011-11-08 Thread Morris, Andi
Hi all, I'm just attempting to install PacketFence on a RedHat Enterprise 6 server and have run into the dependency problems laid out here: http://packetfence.org/bugs/view.php?id=1319 The answer on the bug report states the PacketFence have updates the admin guide with the following

[Packetfence-users] Version 3.0.3 will not install, dependency errors

2011-11-22 Thread Morris, Andi
I'm trying to install packetfence again, and with yesterday's new version being available I'm now getting the errors below. Can anyone shed any light on what I need to do please? Error: Package: packetfence-3.0.3-1.el6.noarch (Packetfence) Requires: perl-IPTables-Parse Error:

[Packetfence-users] Nessus subscription for trialling PacketFence

2011-11-22 Thread Morris, Andi
Hi all, I'm setting up PacketFence in a development network environment to trial it against other vendors. Does anyone know if there is any issue with using the Nessus homefeed for the test purpose, but then upgrading to the professional if the system goes into the production environment?

Re: [Packetfence-users] Version 3.0.3 will not install, dependency errors

2011-11-22 Thread Morris, Andi
). But for all the others, what if you install EPEL? On 11-11-22 7:07 AM, Morris, Andi wrote: I'm trying to install packetfence again, and with yesterday's new version being available I'm now getting the errors below. Can anyone shed any light on what I need to do please? Error: Package: packetfence

Re: [Packetfence-users] Version 3.0.3 will not install, dependency errors

2011-11-22 Thread Morris, Andi
://download.fedora.redhat.com/pub/epel/6/x86_64/repoview/letter_p.group.html On 11-11-22 8:12 AM, Morris, Andi wrote: EPEL is already installed. From: Francois Gaudreault [mailto:fgaudrea...@inverse.ca] Sent: 22 November 2011 13:03 To: packetfence-users@lists.sourceforge.netmailto:packetfence-users

Re: [Packetfence-users] Version 3.0.3 will not install, dependency errors

2011-11-22 Thread Morris, Andi
of the /etc/yum.repo.d/epel.repo file? On 11-11-22 10:25 AM, Morris, Andi wrote: Tried yum clean all. Still getting the error message. Error: Cannot retrieve repository metadata (repomd.xml) for repository: epel. Please verify its path and try again. Cheers, Andi From: Francois Gaudreault

Re: [Packetfence-users] Version 3.0.3 will not install, dependency errors

2011-11-22 Thread Morris, Andi
-users@lists.sourceforge.net Subject: Re: [Packetfence-users] Version 3.0.3 will not install, dependency errors Can you retry by uncommenting the baseurl line, and comment the mirrorlist line? Do a yum clean all after. Then retry. On 11-11-22 10:43 AM, Morris, Andi wrote: [epel] name=Extra

[Packetfence-users] Packetfence service will not start

2011-11-23 Thread Morris, Andi
Hi all, After a bit of a struggle yesterday to get my packetfence installation working I now have it installed and have run through the installer and configuration script successfully. However I get the following errors when I run service packetfence start Starting PacketFence...Checking

Re: [Packetfence-users] Packetfence service will not start

2011-11-23 Thread Morris, Andi
Thanks for the very informative answer Francois, So, would I be correct in saying that: Internal - refers to the networks that the endpoints sit on, that Packetfence controls the switchports of to configure vlans between, registration, isolation and production/inline vlans. Management - refers

Re: [Packetfence-users] Packetfence service will not start

2011-11-24 Thread Morris, Andi
Thanks all, I've had this running through my head all night and I understand it a lot more now. I'm sure this won't be the last question I have on here though ;) Again, appreciate your patience. Cheers, Andi From: Derek Wuelfrath [mailto:dwuelfr...@inverse.ca] Sent: 23 November 2011 16:15 To:

[Packetfence-users] Configuring radius with active directory

2011-12-06 Thread Morris, Andi
I'm trying to setup radius to authenticate clients with my active directory database so that I can utilise the 802.1x on the switches. However I've got to the section where I need to add my server to the domain after configuring samba and it is failing. I don't know whether it's related or

[Packetfence-users] Configuring radius with active directory

2011-12-06 Thread Morris, Andi
I'm trying to setup radius to authenticate clients with my active directory database so that I can utilise the 802.1x on the switches. However I've got to the section where I need to add my server to the domain after configuring samba and it is failing. I don't know whether it's related or

Re: [Packetfence-users] Configuring radius with active directory

2011-12-06 Thread Morris, Andi
... On 11-12-06 6:52 AM, Morris, Andi wrote: I'm trying to setup radius to authenticate clients with my active directory database so that I can utilise the 802.1x on the switches. However I've got to the section where I need to add my server to the domain after configuring samba

Re: [Packetfence-users] Configuring radius with active directory

2011-12-06 Thread Morris, Andi
and realm attributes. Let me know if it works better. On 11-12-06 10:50 AM, Morris, Andi wrote: Ok cheers, here they are with domain names and IP addresses edited. Krb5.conf: [logging] default = FILE:/var/log/krb5libs.logFILE:///\\var\log\krb5libs.log kdc = FILE:/var/log/krb5kdc.logFILE:///\\var\log

Re: [Packetfence-users] Configuring radius with active directory

2011-12-07 Thread Morris, Andi
:40 AM, Morris, Andi wrote: No difference after editing the smb.conf as suggested. Out of interest, should the realm and the workgroup be the same? From: Francois Gaudreault [mailto:fgaudrea...@inverse.ca] Sent: 06 December 2011 16:14 To: packetfence-users@lists.sourceforge.netmailto:packetfence

Re: [Packetfence-users] Configuring radius with active directory

2011-12-07 Thread Morris, Andi
it tells you? On 11-12-07 4:02 AM, Morris, Andi wrote: I see, well in our case I have the two set the same, should this affect anything? Samba is not telling me that the workgroup is wrong. Cheers, Andi From: Francois Gaudreault [mailto:fgaudrea...@inverse.ca] Sent: 06 December 2011 16:57

Re: [Packetfence-users] Configuring radius with active directory

2011-12-08 Thread Morris, Andi
been installed for some reason. Cheers, Andi From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 07 December 2011 14:41 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] Configuring radius with active directory Interestingly testparm reported that it couldn't

Re: [Packetfence-users] Configuring radius with active directory

2011-12-08 Thread Morris, Andi
-12-08 6:26 AM, Morris, Andi wrote: failed: Preauthentication failed -- Francois Gaudreault, ing. jr fgaudrea...@inverse.camailto:fgaudrea...@inverse.ca :: +1.514.447.4918 (x130) :: www.inverse.cahttp://www.inverse.ca Inverse inc. :: Leaders behind SOGo (www.sogo.nuhttp://www.sogo.nu

Re: [Packetfence-users] Configuring radius with active directory

2011-12-08 Thread Morris, Andi
by default, you need to install it (samba-winbind). On 11-12-08 9:35 AM, Morris, Andi wrote: A small update since my last post. I ran: net ads join -U usern...@domain.co.ukmailto:usern...@domain.co.uk createcomputer=Servers/SCS and got prompted to enter username's password, then got back: Using short

Re: [Packetfence-users] Configuring radius with active directory

2011-12-08 Thread Morris, Andi
/ntlm_auth --request-nt-key --username=%{% {Stripped-User-Name}:-%{mschap:User-Name:-None}} --challenge=% {mschap:Challenge:-00} .nt-response=%{mschap:NT-Response:-00} From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 08 December 2011 14:50 To: packetfence-users@lists.sourceforge.net Subject: Re

Re: [Packetfence-users] Configuring radius with active directory

2011-12-08 Thread Morris, Andi
Thanks Francois, Apologies but I'm not sure what you mean there. Do you mean replace the . before nt-reponse with a --? If so then I've just tried that and the error remains the same. If you meant something else could you please clarify? Also the closing } bracket is there, it just didn't

Re: [Packetfence-users] Configuring radius with active directory

2011-12-08 Thread Morris, Andi
-08 11:06 AM, Morris, Andi wrote: Thanks Francois, Apologies but I'm not sure what you mean there. Do you mean replace the . before nt-reponse with a --? If so then I've just tried that and the error remains the same. If you meant something else could you please clarify? Also the closing

Re: [Packetfence-users] Radius server ignoring requests from known switch

2011-12-09 Thread Morris, Andi
] Radius server ignoring requests from known switch Andi, Do you have the packetfence-freeradius2 package installed? Did you change the db credentials in /etc/raddb/sql.conf? On 11-12-09 8:42 AM, Morris, Andi wrote: I have configured a Cisco 3550 to connect via dot1x to the packetfence server

Re: [Packetfence-users] Radius server ignoring requests from known switch

2011-12-09 Thread Morris, Andi
I suggest option 1. On 11-12-09 9:39 AM, Morris, Andi wrote: Oh this is highly confusing. I rebooted my packetfence server just now, and now I cannot start radius at all. This is possibly due to me running a yum update last night. The errors I get when trying to start radiusd -X now

[Packetfence-users] Nessus/Snort rules

2011-12-13 Thread Morris, Andi
I'm trying to configure Packetfence so that fairly standard Nessus and Snort rules are reported as violations. Things like lack of antivirus software as an example of a Nessus rule, and infected traffic for snort rules. However I cannot seem to find a sensible place to find these violation

[Packetfence-users] Production vlan URL redirect

2012-01-10 Thread Morris, Andi
Hi, Is there any way using Packetfence to redirect the user's browser to a specific webpage once they are registered and on the network? We would like our users to see the student portal each time they open their browser. Cheers, Andi From 1st November 2011

Re: [Packetfence-users] Production vlan URL redirect

2012-01-10 Thread Morris, Andi
Sallee Godfather of Bandwidth System Engineer University of Mary Hardin-Baylor 900 College St. Belton, Texas 76513 Fone: 254-295-4658 Phax: 254-295-4221 From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: Tuesday, January 10, 2012 6:05 AM To: packetfence-users@lists.sourceforge.net Subject

Re: [Packetfence-users] Production vlan URL redirect

2012-01-10 Thread Morris, Andi
-users] Production vlan URL redirect GPO with a forced home URL in IE? :P On 12-01-10 10:33 AM, Morris, Andi wrote: Ah that's a shame, I'm not planning on using Packetfence as an inline device. Thanks, Andi From: Sallee, Stephen (Jake) [mailto:jake.sal...@umhb.edu] Sent: 10 January 2012 15:04

Re: [Packetfence-users] dot1x authenticating, but no ip address

2012-01-13 Thread Morris, Andi
The switchport needs to be in trunk mode, and put your management vlan as the native vlan: switchport trunk native vlan 703 Then use eth0 to set the management ip address. On 12-01-13 9:11 AM, Bill Arlofski wrote: On 01/13/12 08:21, Morris, Andi wrote: Thanks Francois, those were ideas I hadn't

Re: [Packetfence-users] dot1x authenticating, but no ip address

2012-01-13 Thread Morris, Andi
Cheers for your help Bill and Francois. -Original Message- From: Bill Arlofski [mailto:waa-packetfe...@revpol.com] Sent: 13 January 2012 15:19 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] dot1x authenticating, but no ip address On 01/13/12 10:09, Morris

[Packetfence-users] SOH

2012-01-13 Thread Morris, Andi
I'm trying to enable soh on my dot1x clients. I have the client configured for NAP, and have edited the eap.conf file, uncommenting the two lines as per the admin guide, then restarted the radius service. However I get a 404 not found when trying to access https://admin_ip:1443/soh Does

Re: [Packetfence-users] SOH

2012-01-13 Thread Morris, Andi
Is there an easy way to tell what version I'm running (sorry for the stupid questions!) -Original Message- From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 13 January 2012 17:01 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] SOH I thought I

Re: [Packetfence-users] PacketFence upgrade [WAS: SOH]

2012-01-16 Thread Morris, Andi
:21 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] PacketFence upgrade [WAS: SOH] On 13/01/12 12:01 PM, Morris, Andi wrote: I thought I was, but I'm just checking now. Yum update packetfence suggests that I'm up to date. If you installed by following our guides

[Packetfence-users] Passthrough list not working

2012-01-17 Thread Morris, Andi
Hi again all, I'm trying to configure a passthrough so that users in the registration vlan can access a website in order for them to download a tool to configure their dot1x settings. I have the following in my pf.conf: [trapping] # # trapping.range # # Comma-delimited list of address

[Packetfence-users] Enabling SoH results in radius failure

2012-01-20 Thread Morris, Andi
Hi all, Since enabling SoH and creating a violation for no antivirus my clients no longer get authenticated via radius. Commenting out the two soh lines in the eap.conf and restarting the radius service results in authentication working again. The first thing I found from running in debug

Re: [Packetfence-users] Passthrough list not working

2012-01-20 Thread Morris, Andi
Are there any more thoughts on why my passthroughs are not working? Cheers, Andi -Original Message- From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 18 January 2012 14:54 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] Passthrough list not working

Re: [Packetfence-users] Enabling SoH results in radius failure

2012-01-23 Thread Morris, Andi
netsh nap client set enforce id=$ID admin=enable On 12-01-20 11:04 AM, Francois Gaudreault wrote: Hi Andi, What PacketFence tells you in its log? On 12-01-20 10:33 AM, Morris, Andi wrote: Hi all, Since enabling SoH and creating a violation for no antivirus my clients no longer get authenticated via

Re: [Packetfence-users] Enabling SoH results in radius failure

2012-01-23 Thread Morris, Andi
Will do, it is working well with Windows 7 at the moment, and from googling it appears that Vista is also the same ID. I'll just give it a go with as many OS flavours as possible and see what happens. Cheers, Andi From: Francois Gaudreault [mailto:fgaudrea...@inverse.ca] Sent: 23 January 2012

Re: [Packetfence-users] vlan change between isolation/registration - normal needing to be forced

2012-01-24 Thread Morris, Andi
Hi Francois, Here are the results of the snmp walk for the ifindex oid: MIBNameOIDType Value RFC1213-MIB ifIndex.1 1.3.6.1.2.1.2.2.1.1.1 Integer 1 RFC1213-MIB ifIndex.2 1.3.6.1.2.1.2.2.1.1.2 Integer 2 RFC1213-MIB

Re: [Packetfence-users] vlan change between isolation/registration - normal needing to be forced

2012-01-24 Thread Morris, Andi
; } Restart PF afterward. On 12-01-24 10:39 AM, Morris, Andi wrote: Hi Francois, Here are the results of the snmp walk for the ifindex oid: MIBNameOIDType Value RFC1213-MIB ifIndex.1 1.3.6.1.2.1.2.2.1.1.1 Integer 1 RFC1213-MIB ifIndex.2

Re: [Packetfence-users] vlan change between isolation/registration - normal needing to be forced

2012-01-25 Thread Morris, Andi
Hi Olivier, Hopefully this should be more than enough information for you: Cisco IOS Software, C3550 Software (C3550-IPBASE-M), Version 12.2(50)SE, RELEASE SOFTWARE (fc1) Copyright (c) 1986-2009 by Cisco Systems, Inc. Compiled Fri 27-Feb-09 23:46 by weiliu Image text-base: 0x3000, data-base:

[Packetfence-users] URL redirection not taking place

2012-01-25 Thread Morris, Andi
Hi again all, I have since noticed that although the vlan switch is working properly now, the progress bar still times out and the user is presented with Unable to detect network activity. If they manually open a new window then access does as it should, suggesting that the redirection is not

Re: [Packetfence-users] URL redirection not taking place

2012-01-26 Thread Morris, Andi
. Did you try with another browser (like Chrome)? On 12-01-25 11:38 AM, Morris, Andi wrote: Hi again all, I have since noticed that although the vlan switch is working properly now, the progress bar still times out and the user is presented with Unable to detect network activity

[Packetfence-users] Radius no longer authenticating users

2012-01-27 Thread Morris, Andi
Hi all, Since yesterday my PF server has stopped authenticating users. The only things that I can think may be related are: - A week or so back I added a new DNS server into the PF development network, and changed all the relevant entries that I could think of in the PF config.

Re: [Packetfence-users] Radius no longer authenticating users

2012-01-27 Thread Morris, Andi
:43 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] Radius no longer authenticating users Rejoin the machine to the domain and it should fix it. On 12-01-27 8:54 AM, Morris, Andi wrote: Hi all, Since yesterday my PF server has stopped authenticating users. The only

Re: [Packetfence-users] Radius no longer authenticating users

2012-01-27 Thread Morris, Andi
To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] Radius no longer authenticating users What about adding an entry in your /etc/hosts file: domain.local 192.168.110.34 That way you will be able to use your external DNS. On 12-01-27 10:15 AM, Morris, Andi wrote: I understand

Re: [Packetfence-users] URL redirection not taking place

2012-01-27 Thread Morris, Andi
Andi, And you see the proper IP on the PC right? When you open a new tab, you can browse without problem? On 12-01-26 10:54 AM, Morris, Andi wrote: Hi Francois, Since e-mailing I have noticed that there is a bug logged about the redirection for IE. However, the two browsers I tried were IE8

Re: [Packetfence-users] URL redirection not taking place

2012-01-30 Thread Morris, Andi
Thanks Francois. I had no idea that the lack of internet would affect the way Packetfence would work in that way. I'll do my best to get internet access piped over to my dev network today to resolve that issue. Regarding the isolation network being in the trapping range, I did wonder about

Re: [Packetfence-users] URL redirection not taking place

2012-01-30 Thread Morris, Andi
Ah, I see, I actually had that set to the management interface of the packetfence server. I need to try and figure out the routing so that I can allow access to one IP from several different production vlans, but that sounds perfectly feasible. Cheers, Andi -Original Message- From:

Re: [Packetfence-users] Violations retriggering vlans still not quite behaving correctly

2012-02-08 Thread Morris, Andi
Hi Francois, This has confused me, I cannot see any reference to an unreg vlan in the switches.conf, nor the admin guide. I do have a registration vlan and isolation vlan declared on the default switch, for some reason when I copied and pasted the switches.conf below it didn't put the top

Re: [Packetfence-users] Violations retriggering vlans still not quite behaving correctly

2012-02-15 Thread Morris, Andi
the violations after updating/changing the filters? On 12-02-10 5:36 AM, Morris, Andi wrote: Hi Francois, thanks for looking into this. Here is the debug output, it is quite long sorry. The processes that were taking place during this time were: Power on registered laptop Plug in network cable

[Packetfence-users] Radius bad password retry

2012-02-16 Thread Morris, Andi
Hi all, Is there a way for the radius server to ask for the username/password combination again if the user gets it wrong? By default it seems to just fail them outright, and the only way I can see of getting the prompt to re-occur is to pull the network cable and plug in again, or reboot the

Re: [Packetfence-users] Violations retriggering vlans still not quite behaving correctly

2012-02-20 Thread Morris, Andi
Did the files given shed any light on these violations retriggering? Cheers, Andi -Original Message- From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 15 February 2012 10:33 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] Violations retriggering

Re: [Packetfence-users] Violations retriggering vlans still not quite behaving correctly

2012-02-22 Thread Morris, Andi
your tests (service packetfence restart). Thanks. On 12-02-20 8:35 AM, Morris, Andi wrote: Did the files given shed any light on these violations retriggering? Cheers, Andi -Original Message- From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 15 February 2012 10:33

Re: [Packetfence-users] OpenVAS vs Nessus

2012-02-28 Thread Morris, Andi
Hi Jakee, Currently we're looking to use the SoH to cover the MS users, and snort violations to monitor the network for other threats. I'm no Apple fan, but I know that the only virus trouble we've seen on our network has been from MS operating systems, so we figured that this was the best

Re: [Packetfence-users] Autoregistration, customise redirect page

2012-03-05 Thread Morris, Andi
Subject: Re: [Packetfence-users] Autoregistration, customise redirect page Hi Andi, On 03/01/2012 09:58 AM, Morris, Andi wrote: Hi all, I've realised that authenticating users via dot1x negates our need for them to register their devices, at least for our purposes, so with the help

[Packetfence-users] Cisco Wireless Lan Controller 5500

2012-03-12 Thread Morris, Andi
Hi, Has anyone successfully setup a WLC 5500 in packetfence? I would very much like to get one working, but the documentation for the 4400 is to be contributed, and there is also no option to add the 5500 in the switches interface. Is this something that would be possible? Cheers, Andi

Re: [Packetfence-users] Cisco Wireless Lan Controller 5500

2012-03-12 Thread Morris, Andi
. Thanks. On 12-03-12 7:08 AM, Morris, Andi wrote: Hi, Has anyone successfully setup a WLC 5500 in packetfence? I would very much like to get one working, but the documentation for the 4400 is “to be contributed”, and there is also no option to add the 5500 in the switches interface

Re: [Packetfence-users] Cisco Wireless Lan Controller 5500

2012-03-13 Thread Morris, Andi
: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 12 March 2012 15:56 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] Cisco Wireless Lan Controller 5500 AHA! (Sort of) solved it. By removing the option to validate server certificate on the client's wlan connections

Re: [Packetfence-users] SoH for Linux Mac OS

2012-04-04 Thread Morris, Andi
If SoH is enabled is this supposed to still allow connections from Mac OS? My Mac is currently failing to authenticate and when I check the radius logs I can see that it is failing the SoH. Removing SoH from the eap.conf allows the Mac to connect. Cheers, Andi -Original Message-

Re: [Packetfence-users] SoH for Linux Mac OS

2012-04-04 Thread Morris, Andi
using unlang. Thanks. On 12-04-04 4:53 AM, Morris, Andi wrote: If SoH is enabled is this supposed to still allow connections from Mac OS? My Mac is currently failing to authenticate and when I check the radius logs I can see that it is failing the SoH. Removing SoH from the eap.conf allows

[Packetfence-users] Extra dot1x balloons

2012-04-11 Thread Morris, Andi
Hi all, I have PF configured to auto-register users than connect via dot1x, and this works a treat, however when they get successfully registered they are prompted with another balloon asking them to click to open a browser window, which is confusing when this step is being taken care of by our

Re: [Packetfence-users] Extra dot1x balloons

2012-04-12 Thread Morris, Andi
the progress bar, then get redirected successfully. Cheers, Andi -Original Message- From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 11 April 2012 19:16 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] Extra dot1x balloons Oh yes, of course. Apologies I

[Packetfence-users] I've lost my web gui!

2012-04-18 Thread Morris, Andi
Hi all, I'm just configuring our live servers (been on a dev network until now). I set everything up following the admin guide, and everything was going well and I could access the web interface successfully. Until I started to customise the pf.conf and setup freeradius on the box.

Re: [Packetfence-users] New install of v3.3, freeradius issues

2012-04-19 Thread Morris, Andi
. Cheers, Andi From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 19 April 2012 10:49 To: packetfence-users@lists.sourceforge.net Subject: [Packetfence-users] New install of v3.3, freeradius issues Hi, I've done a fresh install of v3.3 and used the packaged packetfence-freeradius2, but my

Re: [Packetfence-users] gaming consoles and 802.1x auth

2012-04-25 Thread Morris, Andi
We are rolling dot1x out in our halls of residence over the next few months. The switches we are using don't really play nicely with MAB (Cisco 2950). I currently have a call on hold with the PF guys, which I'm going to open up again once I have my live servers in, but I think the idea is to

Re: [Packetfence-users] Allow helpdesk staff access to areas of webadmin

2012-04-25 Thread Morris, Andi
Apologies, I've just found it in the FAQ. Andi From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 25 April 2012 15:38 To: packetfence-users@lists.sourceforge.net Subject: [Packetfence-users] Allow helpdesk staff access to areas of webadmin Hi, I'm trying to find where in the admin guide

Re: [PacketFence-users] Can't call method check_pwd... error from captive portal login page

2012-04-26 Thread Morris, Andi
I believe the part you need to edit in the radius.pm is: my $radiusServers = [ { 'host' = 'server1:1819', secret = 'secret' }, Change server1 to your servername, and add the secret Cheers, Andi. From: Adrian Mulgrew [mailto:adrian.mulg...@gmail.com] Sent: 26 April 2012 16:46 To:

Re: [PacketFence-users] [Packetfence-users] New install of v3.3, freeradius issues

2012-04-27 Thread Morris, Andi
Thanks Francois, Removing the mschap.bkp file solved the problem. Cheers, Andi -Original Message- From: Francois Gaudreault [mailto:fgaudrea...@inverse.ca] Sent: 24 April 2012 14:04 To: packetfence-users@lists.sourceforge.net Subject: Re: [Packetfence-users] New install of v3.3,

[PacketFence-users] Snort integration and updates

2012-05-02 Thread Morris, Andi
Hi all, I'm starting to get to the point now where I'm looking to implement the snort IDS that packetfence ties integrates with but I have a question regarding the way that the violations are triggered. I'm fairly sure I understand how snort and packetfence integrate: Snort contains several

Re: [PacketFence-users] Add DNS entry

2012-07-02 Thread Morris, Andi
by WISPr, and it's a feature... On 12-07-02 6:48 AM, Morris, Andi wrote: Hi all, Hopefully a relatively simple one, but I can’t seem to find an answer anywhere else. I’d like to add a DNS entry to the captive portal for www.apple.com http://www.apple.com and set it to 0.0.0.0 which

Re: [PacketFence-users] Changing SSL Certs

2012-07-04 Thread Morris, Andi
HI Mark, You need to specify the new certificates in /pf/conf/ssl-certificates.conf I believe. Cheers, Andi -Original Message- From: Mark Holmes [mailto:mark.hol...@nuffield.ox.ac.uk] Sent: 04 July 2012 16:37 To: packetfence-users@lists.sourceforge.net Subject: [PacketFence-users]

Re: [PacketFence-users] expire.node

2012-07-09 Thread Morris, Andi
Thanks Francois that's very helpful. We are already seeing lots of users connecting to our open registration SSID but never registering, and the system isn't even live yet, so I'd imagine that number will only increase and eventually it will be very impractical to delete the nodes from the web

[PacketFence-users] starting packetfence services

2012-07-13 Thread Morris, Andi
Hi all, I'm having trouble getting my packetfence services to start since yesterday and I'm unsure why. The only thing I changed yesterday was to add a cron job to do a sql dump and a copy of the conf and /etc/raddb folders over to a windows server each night. I did the exact same thing to

Re: [PacketFence-users] starting packetfence services

2012-07-13 Thread Morris, Andi
Message- From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 13 July 2012 11:25 To: packetfence-users@lists.sourceforge.net Subject: [PacketFence-users] starting packetfence services Hi all, I'm having trouble getting my packetfence services to start since yesterday and I'm unsure why

[PacketFence-users] Suggestion - switch names

2012-07-20 Thread Morris, Andi
Hi all, Just a minor suggestion for a feature really. How about a name field for the switches.conf? Currently I add the switch name as a comment in the file, but it would be very very handy to be able to see this information in the web gui. Even more so if this information could somehow be

[PacketFence-users] OS Classes from DHCP

2012-07-23 Thread Morris, Andi
Hi all, I've noticed recently that PacketFence isn't populating the OS Class field like it used to. Is the information for this field taken from having the PF server as the last ip helper address of the production vlans? My packetfence servers are always the last ip helper entry for each

[PacketFence-users] Interface declaration gateway confusion

2012-07-31 Thread Morris, Andi
Hi all, Somehow I've confused myself with the required gateway addresses for the network cards in my packetfence server. Is this correct? In my pf.conf file these are set to the actual gateway for each vlan. In my networks.conf file the gateway and dns for the registration and isolation

Re: [PacketFence-users] Interface declaration gateway confusion

2012-07-31 Thread Morris, Andi
Thanks Francois, I think the confusion came because it seemed to work no matter what I put for the gateway field in pf.conf, so the snort template thing would explain it. Cheers for your help, Andi -Original Message- From: Francois Gaudreault [mailto:fgaudrea...@inverse.ca] Sent: 31

Re: [PacketFence-users] Secondary PF server radius issues

2012-08-07 Thread Morris, Andi
You were absolutely right Francois, this was actually a problem with how a secondary radius server is configured on the switch. Cheers for your reply and apologies for the noise on the list. Andi -Original Message- From: Francois Gaudreault [mailto:fgaudrea...@inverse.ca] Sent: 02

[PacketFence-users] DHCP listener information disappared

2012-09-03 Thread Morris, Andi
Hi all, A curious one today, last Friday my nodes tab on the web interface was populated with device names and OS type retrieved from the DHCP listener, however the new registrations that came in over the weekend and today are not populating these fields, bar one exception. It's happening

Re: [PacketFence-users] DHCP listener information disappared

2012-09-03 Thread Morris, Andi
Looks like a restart of the DHCPlistener service resolved this easily enough. Cheers, Andi From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 03 September 2012 13:43 To: packetfence-users@lists.sourceforge.net Subject: [PacketFence-users] DHCP listener information disappared Hi all

[PacketFence-users] Freeradius upgrade

2012-09-11 Thread Morris, Andi
Hi all, No doubt some of you will have seen that FreeRadius announced a new version yesterday (version 2.2.0) and with it a security exploit found in the previous version (version 2.1.12). Is there any foreseen issues with running an upgrade on the pre-packaged version of freeradius that is

[PacketFence-users] Packetfence.log warnings

2012-09-18 Thread Morris, Andi
Hi all, I'm seeing a lot of repeated warnings in my packetfence.log and I just want to double check that they can safely be ignored. Everything appears to be working ok. An example of the two types of warning I regularly see are below. The IP address has been doctored from the original. 1)

Re: [PacketFence-users] Packetfence.log warnings

2012-09-18 Thread Morris, Andi
?) but I expect there is a reason for that. Mark -Original Message- From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 18 September 2012 10:04 To: packetfence-users@lists.sourceforge.net Subject: [PacketFence-users] Packetfence.log warnings Hi all, I'm seeing a lot of repeated

Re: [PacketFence-users] Packetfence.log warnings

2012-09-18 Thread Morris, Andi
than the ones configured on your WLC - There is an ACL between PF and your controller that would block port 3799 You should investigate tcpdump and using the debug functions on the controller. Thanks. On 2012-09-18 6:19 AM, Morris, Andi wrote: Cheers Mark, that's reassuring. As for point 2

Re: [PacketFence-users] Packetfence.log warnings

2012-09-19 Thread Morris, Andi
another IP than the ones configured on your WLC - There is an ACL between PF and your controller that would block port 3799 You should investigate tcpdump and using the debug functions on the controller. Thanks. On 2012-09-18 6:19 AM, Morris, Andi wrote: Cheers Mark, that's reassuring

Re: [PacketFence-users] Packetfence.log warnings

2012-09-20 Thread Morris, Andi
Thanks. I think when I get an opportunity I'll update the server from 3.3.2 to the latest version, and see if I'm still getting the warnings. Cheers, Andi -Original Message- From: Olivier Bilodeau [mailto:obilod...@inverse.ca] Sent: 19 September 2012 15:05 To:

[PacketFence-users] more packetfence.log warnings

2012-09-20 Thread Morris, Andi
Hi again all, I'm now seeing the following in my packetfence.log. It's happened a few times today and I've manually restarted the DHCPlistener process in the admin GUI each time I've seen it. I can't tell if it stops anything working, but it happens every few hours. Sep 20 16:45:40

Re: [PacketFence-users] more packetfence.log warnings

2012-09-20 Thread Morris, Andi
it a go. Cheers, Andi -Original Message- From: Olivier Bilodeau [mailto:obilod...@inverse.ca] Sent: 20 September 2012 16:54 To: packetfence-users@lists.sourceforge.net Subject: Re: [PacketFence-users] more packetfence.log warnings Hi Andi, On 09/20/2012 11:48 AM, Morris, Andi wrote: Hi again

[PacketFence-users] Logrotate

2012-09-24 Thread Morris, Andi
Hi all, In the admin guide it mentions that a logrotate script is given in the addons folder, and this should be added to the existing logrotate jobs if required. I have added the script to the bottom of my logrotate.conf file, but upon further investigation the packetfence logs seem to be

Re: [PacketFence-users] Poll (!): how do you HA your PF?

2012-12-12 Thread Morris, Andi
I'm also very interested in the methods people use for PF HA. At the moment I just have a spare PF box configured and ready to switch on should the primary fail, but it's on my to-do list to get a proper HA setup. It's interesting to ready that people aren't happy with the failover with DRDB.

Re: [PacketFence-users] Allowing some sites past captiveportal

2012-12-12 Thread Morris, Andi
Ah I'm not sure. I'm not using inline mode. I have it working ok but not in inline mode. From: st3fan0 ste [mailto:st3fan...@hotmail.com] Sent: 12 December 2012 14:48 To: packetfence-users@lists.sourceforge.net Subject: Re: [PacketFence-users] Allowing some sites past captiveportal this

[PacketFence-users] Edit user from command line

2013-04-22 Thread Morris, Andi
Hi all, I have a user that has registered their device under a username including the domain prefix, including the backslash. This has resulted in us not being able to edit the node details (we need to force it to unregistered to re-setup the device). The error I see when trying to edit is:

[PacketFence-users] Captive portal passthroughs not working

2013-05-29 Thread Morris, Andi
Hi all, I have a fresh installation of version 4.0.1 on RHEL 6.4. All was going swimmingly and my open setup network was pushing users to the Packetfence AUP acceptance page as it does out of the box. In previous versions what I have done is edit the

Re: [PacketFence-users] Captive portal passthroughs not working

2013-05-30 Thread Morris, Andi
/ but keeping any trailing paths. Anyone have any ideas why this is happening? Cheers, Andi From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent: 29 May 2013 16:15 To: packetfence-users@lists.sourceforge.net Subject: [PacketFence-users] Captive portal passthroughs not working Hi all, I have

[PacketFence-users] Version 4.0.1 and proxy passthrough

2013-06-28 Thread Morris, Andi
I'm looking to implement a new Packfence deployment on another part of our network, to mimic the one we setup for the halls of residence last year with great success. However I've setup version 4.0.1 and struggled to get proxy passthrough to work to allow users to the setup pages when trapped

Re: [PacketFence-users] Version 4.0.1 and proxy passthrough

2013-07-01 Thread Morris, Andi
] Version 4.0.1 and proxy passthrough Hello Andi, you can try the actual devel version, it's the release candidate. Regards Fabrice Le 2013-06-28 13:16, Fabrice DURAND a écrit : Hello Andi, it is include in the coming 4.0.2 version. Regards Fabrice Le 2013-06-28 12:02, Morris, Andi a écrit : I'm

Re: [PacketFence-users] Version 4.0.1 and proxy passthrough

2013-07-22 Thread Morris, Andi
=crl.comodoca.com,ocsp.comodoca.com,oursetupurl.uni.com Obviously with our own setup URL, not the one above. I just get redirected back the capitive portal whenever I try to visit the setup site. Can anyone please advise? Cheers, Andi From: Morris, Andi [mailto:amor...@cardiffmet.ac.uk] Sent

Re: [PacketFence-users] Version 4.0.1 and proxy passthrough

2013-07-22 Thread Morris, Andi
That's great news. Thanks. From: Ludovic Marcotte [mailto:lmarco...@inverse.ca] Sent: 22 July 2013 12:25 To: packetfence-users@lists.sourceforge.net Subject: Re: [PacketFence-users] Version 4.0.1 and proxy passthrough On 2013-07-22 4:22 AM, Morris, Andi wrote: I now have 4.0.2 running, and I'm

  1   2   3   4   >