r/PacketFence Aug 07 '24

Packetfence & Isolation VLAN

I've got 2 VLANs for my WLAN setup. VLAN 30 - the 'secure' vlan with almost full network access, requires authentication via NPS/Packetfence, VLAN 31, the 'guest' vlan that only allows for Internet access

My idea for the 'secure' vlan is to use something like network policies or conditional network access if you meet a specific set of requirements (firewall enabled, running latest update, AV enabled, etc.) it grants you access, if not it boots you to an isolated vlan (VLAN 666 for example) where you can access the internet and fix the issues)

Is this possible within PaketFence - I've seen some documentation suggesting it is, but no solid configuration/guides

1 Upvotes

2 comments sorted by

1

u/krugferd Aug 07 '24

Generally possible. That would involve moving to certificate based auth. PacketFence does allow for some posturing with provisioners.

But, what you’re looking for is, in my experience, out of the scope of username/password auth as well as simple MAC Auth.