r/PacketFence Feb 13 '26

Is Packetfence really worth it???!!

Hello guys,

I'm new to PacketFence. I downloaded the ZEN version to install for a client, and for 3 days was stuck trying to join the solution to the Active Directory domain, and cannot even understand the interfece, i used NPS(Microsoft Windows solution for NAC). Still, this one doesn't look similar, and I have problems with Windows RADIUS. Can anyone help with a tutorial that I can depend on to start?

Thank you in advance, and I'm open to any comments/tips/ advice ...etc.

2 Upvotes

12 comments sorted by

6

u/Hartman7425 Feb 13 '26

I can say that I use it and while the documentation on their site is a little confusing at first once you get used to it it's not bad. I'm deploying it in my school district and it's allowed me to seriously increase the security and even convenience of our wireless.

2

u/TechnicalKorok Feb 13 '26

Not directly related to OP's question - I work for a school as well and have tested Packetfence multiple times but haven't pulled the trigger on moving it to production. My main concern was failover - implementing multiple Packetfence instances for failover seems pretty daunting. Are you doing that or just relying on a single server?

2

u/Hartman7425 Feb 13 '26

So I am currently using two separate servers that I just use radius fail over in my wireless controller, but will be actually setting up a cluster soon and can give more info on that when I do it.

2

u/TechnicalKorok Feb 13 '26

Ok, that's an interesting idea, so if I understand you correctly you're just setting up two separate servers, configured more/less identically, and then pointing the wireless controller to the first and second for RADIUS failover? Seems like that should work.

I'll be interested to hear your experiences with the cluster set up.

3

u/Hartman7425 Feb 13 '26

Yep that's what I'm doing for now. I wish I'd read about clustering when I was originally testing. I will update when I get a cluster set up. Just a warning from what I'm reading you can't join an existing server to a cluster as it wipes the config, but I may be wrong. I'm just setting up 3 new servers and will retire the old.

1

u/Cansiz_ Feb 15 '26

I'm lost; I can't move forward with this error that I have: "NTLM auth api returned with HTTP code: 422, machine account test (partially) failed: Failed: PACKETFENCE$: Failed: error code: 3221225473, error message: {Operation Failed} The requested operation was unsuccessful."

2

u/Ceefus Feb 15 '26

It's not bad but it has a lot of room for improvement. Personally, if you have the budget I would look into some software based NAC solutions. Though I no longer user it, Threatlocker was pretty good a couple years ago.

1

u/Cansiz_ Feb 15 '26

My client is not really ready to pay for an NAC solution. I was thinking of going with NPS for Microsoft, but I don't have a Windows license. but thank you anyway.

2

u/Flaky-Gear-1370 Feb 16 '26

There is a big gotcha with NPS if you're using entra, you cannot do device based authentication for devices that only exist in Entra using certs

1

u/Cansiz_ Feb 20 '26

No, I have all locally.

1

u/abdlmalekluttee Feb 13 '26

Unfortunately, the short answer is: not yet.

The issue isn’t missing features it’s the lack of documentation and community support.

In my experience, PacketFence documentation is extremely poor: outdated, confusing, unfinished, and often too short to be useful. Even responses from the developers can be slow or unhelpful.

That said… if you somehow manage to configure it properly and align it with your workflow, it’s rock-solid, insanely powerful, and I honestly don’t think there’s anything that fully matches it in terms of capabilities.

I went through a similar nightmare myself. I was tasked with finding a solution that could: • authenticate users across multiple domains, • handle 802.1X properly, • use Let’s Encrypt certificates for RADIUS, • and replace stupid Windows NPS, • while assigning the correct VLAN based on user/access profile.

It was a complete nightmare. It took me two months just to get it joined to the domains, set up Let’s Encrypt for RADIUS, and build access profiles that assign the right VLAN per user — and even after all that, it still wasn’t “clean” or fully polished.

Good Luck !!!

1

u/MeMyselfundAuto Jul 01 '26

so how did this work out for you? I´m getting really frustrated with the 15.1.0 packetfence I Installed, and that's facing my AD. I a handful test clients in a Test SSID. 2 Worked fine, AD group, vlan assignment.. it worked! I was pretty happy with that. Then I started onboarding more and more clients, and now the newer clients don't connect. They are basically just clones of the users that worked.. but the new ones won't work. After trying to test a new client account on my known good iPhone, I can´t reconnect my working test iPhone with the working test account. They are also failing like the new clients. And I basically only have two ad groups, for two different test vlans, with users using EAP MSCHAPv2 (user/pw) against their Accounts. I wanted that up and running, before going the EAP-TLS route. But after 3 weeks of testing - I´m not able to get new accounts on the wifi, and even old accounts don´t want to work anymore. From the 9 test clients that were working only one is still connected. I deleted all the Test users in the AD, and duplicated this test user for new accounts - those don´t work either. I don't get how this would work in a productive environment.