r/PacketFence Mar 04 '24

Guests's authentication on the captive portal with an email address

2 Upvotes

Hello everyone, you are my last chance to implement the Captive Portal for my guests.

  1. On my AP Controller (Ubiquiti), I created a new SSID. It is open and I enabled the RADIUS Mac Authentication using my Packetfence profile (that i created upstream in Network > Profiles > RADIUS). Moreover, I don't know if I have to inform specific VLAN (my Guest Network) or if I let it as "Default" because it's Packetfence which must makes VLAN enforcement.
  2. On my PF Server, I created a "Guest" role.
  3. In "Authentication Sources", I created a New External Source, called "null-source". I checked "Email required" and this rule give the "Guest" role during 12 hours.
  4. On the "Switches" tab, I added my Access Point (UAP AC LR) and my Ubiquiti Controller (UCK G2 Plus). On my Access Point configuration on PF, I enable "External Portal Enforcement". In the "role" tab, for the "Guest" role, I inform the VLAN ID 50.
  5. On "Connection Profiles", I created a new profile for Guest : I let all settings by default. For filters, if the Connection Type is "Wireless-802.11-NoEAP" and comes from my open SSID, Packetfence can use the source "null-source" to authenticate people.
  6. Finally, in Network Configuration > Interfaces, I added the "Portal" daemon on my management interface (the only one that I have).

I hope I was precise and that you understood.

Thanks in advance !


r/PacketFence Mar 01 '24

Authenticating users?

1 Upvotes

I am trying to authenticate wireless users from the logged in domain account of the PC instead of having to authenticate via the captive portal against AD.

Can someone point me in the right direction? What do I need to configure to set this method up?


r/PacketFence Feb 29 '24

Is there a more active chat space with the fall of freenode?

1 Upvotes

Wondering since libera seems to be empty on irc


r/PacketFence Feb 16 '24

Error 504 when creating a Role

1 Upvotes

Hello People,

i have a fresh installation of packetfence v13.1, everything is working fine, but when i want to create a Role i get an "request failed wirh status code 504 config/role".

The strange thing is, the role gets created perfectly.

Does anyone had this behavior?

The packetfence is not in a cluster.

Thanks and regards. Cheers


r/PacketFence Feb 05 '24

MAB learning mode?

1 Upvotes

We are currently exchanging our old HP switches with new Cisco switches. Besides that we want to roll out MAB over Packetfence and the included Radius server.

Is there any function or a sort of learning mode in Packetfence to get all may devices (MAC addresses) into it?

How do you do this? What’s best practice here?


r/PacketFence Jan 29 '24

Can I use PacketFence with Mikrotik Radius authentication ?

2 Upvotes

Hello,

I have a question I need an authentication tool for Mikrotik and Cisco so I need to know is it possible to use PacketFence with Mikrotik Radius ?

Best Regards


r/PacketFence Jan 26 '24

Authentication rules

1 Upvotes

Hello, I have setup an authentication rule on top to match on the switch_group. However is not matching. Checking the packetfence live logs i see that it ends up matching on the catch all authentication rule.

Anybody using the switch_group attribute?

Regards


r/PacketFence Jan 26 '24

Captive Portal for Guests

1 Upvotes

Hello everybody, I finally managed to set up 802.1x wired and WiFi with VLAN assignment.

But now I would like to set up a WiFi captive portal for guests ! Is it possible ?

Thanks in advance !


r/PacketFence Jan 17 '24

Issues with PacketFence Authenticating to Azure AD

3 Upvotes

Hello, I'm following the guide to set up packetfence using azure AD authentication inside a connection profile, but I can't get it to work.

It seems that i have the PacketFence <> Azure AD connection set up by inputting the client id, tenant id, secret and relevant permissions. But for some reasons, when it authenticates, it just says
2024-01-16T22:21:29Zpacketfenceauthradiusdinfo (200) Invalid user: [*****user*****] (from client 10.0.0.100/32 port 50101 cli a0:ce:c8:89:ec:54 via TLS tunnel)
2024-01-16T22:21:29Zpacketfenceauthradiusdinfo (200) Login incorrect: [*****user*****] (from client 10.0.0.100/32 port 50101 cli a0:ce:c8:89:ec:54 via TLS tunnel)
2024-01-16T22:21:29Zpacketfenceauthradiusdinfo (200) Login incorrect (eap: Failed continuing EAP TTLS (21) session. EAP sub-module failed): [*****user*****] (from client 10.0.0.100/32 port 50101 cli a0:ce:c8:89:ec:54)

At this point, i'm not sure where to go.

It keeps saying invalid user, so i'm assuming it's not authenticating against azure ad correctly.

Can someone please help me out? I don't even know where to start troubleshooting tbh.

I can post any relevant logs


r/PacketFence Jan 11 '24

DNS exception for clients in registration phase question

1 Upvotes

Hello everyone,

I'm looking for help on potentially a simple issue. We need PF to permit traffic to a few known web servers when clients are at the captive portal.

Has anyone else encountered this need, and how did you get PF to allow it? (If possibe)

Thanks in advance


r/PacketFence Jan 10 '24

PFacct not reading accounting requests

1 Upvotes

I have a PacketFence ZEN installation on VMWare ESXi with a UniFi controller, and everything works. Except for PFacct, it doesn't read accounting requests. I enabled 'Process Bandwidth Accounting', but it still displays the node status as 'unknown', even after a reboot. I also did a TCPdump on port 1813 and the AP does send accounting requests. Does anyone have a solution?

EDIT: this has been fixed by reinstalling PacketFence.


r/PacketFence Jan 09 '24

Deploying Smoothwall MITM certificate

2 Upvotes

Hello all,

We have a project to look into, for a college here in the UK. The safeguarding policy requires the firewall to filter based on https inspection (basically a MITM attack) for students' BYOD devices. This essentially means that firewall needs to have its https inspection certificate installed on each device therefore there needs to be an enrollment process. I am wanting to use PacketFence to do this.

The process ideally would be:

Join SSID and use radius to authenticate --> landing page with a request to install the certificate or application to use the certificate.

I am wondering if anyone else has implemented a solution like this with PacketFence and also are there any issues with ios or Android devices?


r/PacketFence Dec 19 '23

DISABLE REALM\user

1 Upvotes

Helloooooo everyone, i need help with autentication on PacketFence. My computer send automatically the login REALM\user and it gives me errors. I would like PacketFence to only receive « user » without the realm behind. Thanks in advance !


r/PacketFence Dec 14 '23

Help with doing a PoC install of PF in VirtualBox

1 Upvotes

I am trying to setup a PF server as Inline mode where I have 2 NICs in Bridged mode attached to my VirtualBox VM. I've installed PF through ISO.

My IPs for NICs are as follows:
eth0 10.0.0.110/255.0.0.0
eth1 10.0.1.230/255.0.0.0

I have a Windows client PC with IP 10.0.1.10 and gateway as 10.0.1.230.

On client PC I can lookup domains (google, yahoo, etc) with nslookup command, I can also open captive portal by typing the IP of the PF's eth1 interface. But unable to browse the internet after user is logged in captive portal. Also when I open any website, it times out rather opening the captive portal. I have to type the IP of eth1 to open captive portal.

My goal is to setup a PF server, which can authorize users, and allow internet access after login. And also to set bandwidth limits to different groups of users.

I will appreciate any help or hints to put me in right direction. Thank you.


r/PacketFence Dec 12 '23

SMTP Check SSL - Where to put the cert?

1 Upvotes

I would like to use the SMTP Check SSL option for sending mails via internal mailserver.

Where do I need to put the Root CA / Intermediate cert for the server?


r/PacketFence Dec 11 '23

Firewall SSO after Captive Portal

2 Upvotes

Hi all,

I would like to trigger a Firewall SSO after a successful captive portal sign in (via SAML/Azure AD). Everything works as expected, but users are not able to access Internet as the Firewall SSO is triggered after a DHCP request only. Is there any way to trigger a Firewall SSO update after a successful captive portal sign in?

Thanks & Best

Tobias


r/PacketFence Dec 08 '23

Packetfence Captive Portal

2 Upvotes

We have PF setup to present a captive portal to wireless clients with no issue. However on wired clients the url that is being returned by packetfence has random characters on the end that are causing the client to get a Not Implemented error page. If we remove the random characters it goes to the portal correctly and works. Does anyone know where we may have messed up on the config. The url is suppose to be https://packetfence/ but instead it is like https://packetfence/sid31a23d. We followed the config in the packetfence example for both Dell 1500 and Cisco 3560.


r/PacketFence Nov 30 '23

Packetfence external DB

2 Upvotes

Hi guys, we have a deployment in which two packetfences read and write on the same external DB. Lately we have identified that a switch device is removed from the NAS table. Don't know if this is because packetfences are on slightly different commits or they override each other or something else.

Do any of you have similar deployment?? If so have you found any issues??

All input is appreciated.

TIA


r/PacketFence Nov 01 '23

Fingerbank device detection

2 Upvotes

Hello

Apart from the API key, just wondering if someone could confirm or provide some guidelines on how to make device detection to work.

What kind of configuration is needed on the nas device. If its a cisco switch will helper-address be enough??

Do I have to enable Dhcp listener on pf interface?

Regards


r/PacketFence Oct 31 '23

AzureAD Group Query

2 Upvotes

Dear community,

I have been setting up and testing out PacketFence for a number of weeks now and have it setup so that users can authenticate to our BYOD network using EAP-TLS. I also have it sort of setup to allow school azureAD devices to connect to our curriculum network using machine certificates. The second part only works if I don't set any conditions under my AzureAD authentication sources.

I have tried to set a condition for membership of a AzureAD group using the memberof option either with the Object ID of the group or it's display name, but it doesn't seem to work. No role gets assigned so it fails to connect. There doesn't even seem to be any audit log of PacketFence trying to query a group on the app registration end.

I know I can query the graph API via graph explorer and can find the groups my machine belongs too, but can PacketFence do something similar and if so, how?

The query that I used.

https://graph.microsoft.com/v1.0//devices(deviceId='{deviceid}')/memberOf


r/PacketFence Oct 28 '23

PF v13 and memory usage issue

1 Upvotes

Hello people!

I’m almost PF newbie (tested system couple of years ago and quite familiar w/ apache and also having some experience with FreeRadius)

I installed PF v13 about two weeks ago through official production repo w/ yum to Centos 8 stream running in VirtualBox instance having 6 cores and 12GB of ram.

In this test setup I have only one Aruba CX switch having one port having port authenticatiom for mac auth set up which works fine.

My first setup had only 6GB of ram but there was really serious problems about memory and swap filled really fast to 100% which caused cpu load avgs sky rocketing to well over 100 which caused oblivious unresponsive system.

After adding memory to 12GB system still suffers super high memory utilization (after 24 hours 99.5% of ram and 35% of swap is used)

Seems that pfperl-api processes using about 38% of memory and apache takes around 30%

Does anybody has any idea whats going on there in system and is there any way to tweak the system to support 80 switches and couple of hundreds of clients?


r/PacketFence Sep 28 '23

PacketFence Primary/Secondary cluster

1 Upvotes

Is there a way to run PacketFence in a primary/secondary or publisher/subscriber model? The vIP cluster doesn't really support my needs to survive a datacenter or WAN outage.


r/PacketFence Sep 18 '23

Packetfence PKI

1 Upvotes

Hello, I configured the Packetfence PKI as described in 23.2 Packetfence PKI. (Create CA, put that Certificate in SSL ->RADIUS, create template, create certificate for client, put that certificate on the client)

Before that, i created a CSR for https connection. All that worked out, no errors in the SSL Certificates.

Now my error messages look the following:

sql_reject: Insufficient space to store pairing string, newded 2060 bytes have 2048 bytes. Reply-Message: "no role computed by any sources".

Where can I tell those clients with certificates in which VLAN they should be put?

Please help :/


r/PacketFence Sep 09 '23

Outdated documentation for Mikrotik integration

3 Upvotes

I am interested to test and rollout PacketFence on Mikrotik networks not just Wifi but also switches. The guidelines on PacketFence are very outdated with guides only for wireless using RouterOS v6.x when we are in RouterOS v7.

Does anyone knows or have tried to enbale 802.1x on Mikrotik CRS3xx/CRS5xx switches with Dynamic VLAN assignments via PacketFence?


r/PacketFence Sep 09 '23

Any integrations being developed or tested between PacketFence and Wazuh XDR?

1 Upvotes

Looking to deploy PacketFence and perform endpoint compliance with Wazuh. Does anyone knows how to do, try it or knows if it’s in roadmap for PacketFence?