Re: [PacketFence-users] Mac auth

2018-11-08 Thread Tomasz Karczewski via PacketFence-users
Hi, You have to create vlan filters for that or manually assign roles that put devices in proper vlan. From: Wifi Guy via PacketFence-users Sent: Thursday, November 8, 2018 12:01 PM To: packetfence-users@lists.sourceforge.net Cc: Wifi Guy Subject: [PacketFence-users] Mac auth Hi

Re: [PacketFence-users] Mac auth

2018-11-08 Thread Murilo Calegari via PacketFence-users
Hi, I'm no PacketFence expert, but I believe you have to create a Node (this function was just corrected in PF 8.2) and set its Bypass Role. If this doesn't work, try to set it to Registered, with a specific role, and an Unregistration date set to something before January 18th 2038. Regards,

Re: [PacketFence-users] Mac auth

2018-11-08 Thread Ludovic Zammit via PacketFence-users
Hello Wifi Guy, You don’t need to use the bypass role/vlan to do that. You import your node in PacketFence with a CSV file or you create it manually. The node has to be registered and set a proper role. That role has a VLAN id under the switch configuration in PacketFence. Once the port will

[PacketFence-users] Mac auth

2018-11-08 Thread Wifi Guy via PacketFence-users
Hi Can someone tell me where I need to fill in MAC addresses of Clients into PF when I only want to do basic MAC authentication without AD integration. So what we want to setup is a local database of MAC addresses which will be authenticated via Radius with our switches and ideally get

Re: [PacketFence-users] Aruba Instant and PAcketfence

2018-11-08 Thread Ludovic Zammit via PacketFence-users
Hello Moi toi, It’s because you did not configure any source on the connection profile to authenticate your computer. We are seeing that you try to do 802.1x EAP PEAP computer authentication. Create a AD source that check for ServicePrincipalName instead of SAMAccountName. Add a rule to

Re: [PacketFence-users] getting started - interface questions

2018-11-08 Thread Jessica Cohen via PacketFence-users
Apologies, just noticed I copied and pasted wrong. It should have been: BEFORE [root@PacketFence-ZEN ~]# route -n Kernel IP routing table Destination Gateway Genmask Flags Metric RefUse Iface 0.0.0.0 192.168.50.10.0.0.0 UG0 00 eth0

[PacketFence-users] NAC administration interface

2018-11-08 Thread Jessica Cohen via PacketFence-users
Can you manage the NAC from any interface? Or is only accessible from the management interface? ___ PacketFence-users mailing list PacketFence-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/packetfence-users

[PacketFence-users] FW: Mac auth

2018-11-08 Thread Truax, Peter via PacketFence-users
Hi WiFi, Others have given good advice, But I didn’t see this method mentioned. Open a browser and go to https://x.x.x.x/status . Where x.x.x.x is the ip of your pf management address. This should bring up a login screen. Login as whatever user you have configured. Inside, it will show any

[PacketFence-users] Simple MAB configuration thoughts

2018-11-08 Thread mehdi.mjahad--- via PacketFence-users
Hi, We're trying to setup a wired MAC-based authorization system to dynamically assign VLANs. We don't want to use RADIUS (not suitable for our needs), just MAB. We don't have any AD but already a list of all MACs addresses, which may be formatted to any format if needed. We thought

[PacketFence-users] Aruba Instant and PAcketfence

2018-11-08 Thread moi toi via PacketFence-users
Hello, I'm testing Packetfence for removing or a "Aruba clearpass" for radius authentication on Aruba 105 iAP It's the PacketFence 8.1.0 Zen I want to authenticate a computer with 8021.x The authentication is working and send the ROLE : Réponse RADIUS: MS-MPPE-Encryption-Policy =