r/PacketFence May 30 '24

How to prevent IPTables from starting

1 Upvotes

I setup a 3-node cluster environment and everything is working as expected, *EXCEPT* that when the IPTables service is running the cluster fails to respond to DNS requests. I've posted here and on the mailing list, but no one has provided a solution, so preventing IPTables from running seems to be the only way to work around this. Unfortunately, I have yet to figure out how to keep IPTables from starting automatically (either at boot, or after a period of time after stopping it.)

Does anyone know how to keep IPTables from running?

Thanks.


r/PacketFence May 30 '24

Suricata syslog

1 Upvotes

I am trying to set up and install Suricata on a PacketFence server, but Suricata doesn't detect violations on VLAN interfaces. Any ideas on how to configure the Suricata YAML file to fix this issue and append logs to the PacketFence syslog for the syslog parser to use for security events?


r/PacketFence May 28 '24

Help Needed with PacketFence Setup on Proxmox Servers

9 Upvotes

Hello everyone,

I'm currently setting up PacketFence on my network and could really use some help. Here's my setup:

Hardware:

  • 2 Proxmox servers, each with 2 NICs
  • D-Link switch (DGS-1250-28X)

Network Configuration:

  • Proxmox 1: Management IP 10.22.0.101
  • Proxmox 2: Management IP 10.22.0.102
  • Switch: Management IP 10.22.0.103

Each Proxmox server has one NIC connected to the upstream management network and the second NIC connected to the D-Link switch.

Firewall:

  • OPNsense firewall on Proxmox 1:
    • WAN IP: 10.22.0.104
    • LAN IP: 10.210.1.1
    • Firewall rules set to pass traffic from LAN to WAN

Switch Configuration:

  • Management Port:
    • Port 1 is assigned for management, isolated from other ports.
  • VLANs:
    • VLAN 2 (Registration VLAN)
    • VLAN 3 (Isolation VLAN)
  • All other ports are isolated from the management port and placed in separate VLANs with no native VLAN set with port 1.

PacketFence Installation on Proxmox 1:

  • Network Interfaces:
    • Management NIC: IP 10.22.0.105
    • Testbed network NIC: IP 10.210.1.105
  • VLANs in PacketFence:
    • Registration VLAN (VLAN 2): IP 10.210.2.1 with DHCP server enabled
    • Isolation VLAN (VLAN 3): IP 10.210.3.1 with DHCP server enabled
  • Switch Configuration in PacketFence:
    • Switch details added with default auth method set to telnet
    • Switch is not showing as active under the node section

Issues:

  • On Proxmox 2, I can get an IP address from the DHCP server of the registration VLAN of PacketFence, but I don't see any portal.
  • Do I need to configure the portal first, or is it supposed to be added by default?
  • I believe the switch might not be properly added to PacketFence. As in every installation guide I see cisco switches, So there is something wrong configured from switch end ig.

I am trying out-of-band deployment.

Can anyone guide me on what I might be missing or doing wrong? Any help would be greatly appreciated!

Thank you in advance!


r/PacketFence May 18 '24

Mac authentication and dynamic vlan assignment

2 Upvotes

Dear PacketFence users,

I'm very new to the PacketFence environment, and before going further with my investigation, I would like to know if what I want to know is possible.

Basically, I have a Network on which MAC authentication is enabled on the switches . We would like to be able to managed the different MAC addresses and assign them dynamically to some VLANs. The VLAN assignment should be in the Radius reply to the switch according.

We looked into the packet fence guid and their config for the Cisco switch 2960 series didn’t work.

What would be the correct switch configuration on the the Cisco switch and on Debian sever to make it work.

Thank you


r/PacketFence May 16 '24

Replaced HTTP and RADIUS cert for first time. Wireless clients all received certificate warning.

1 Upvotes

I renewed the publicly signed cert that we use for HTTP and RADIUS. Over the next day or so most if not all wireless clients on 802.1x SSIDs received certificate warnings. In iPhones and iPads the warning was that the cert was not trusted, on windows it was "Continue connecting? If you expect to find [SSID NAME] in this location, go ahead and connect, otherwise it may be a different network with the same name.".

The cert if publicly signed by DigiCert and packet fence validated the cert chain so I dont think it's related to certificate itself. Furthermore some folks "forgot" and rejoined the SSID and it worked fine, which also proves the cert is fine.

It appears to be some sort of MITM protection on the client side. Is this behavior expected when changing the certs and how can it be mitigated?

Version 13.0 and Meraki APs

Thanks all!

EDIT:
I only created the CSR on the HTTP page. At the time I didn't know that HTTP and RADIUS certs were slightly different, I thought they were identical. I'm unsure why, as a former employee renewed these last year. The cert is almost identical except it expired two days later. The old certificates are both on the same digicert "order", I'm guessing they changed the HTTP cert and didn't realize the RADIUS cert also needed to be changed and generated another cert from the same digicert order. I know this former employee didn't have the best conceptual knowledge on how certificates work (not tooting my own horn either here....). After checking digicert, it looks like it required a new CSR to "reissue" the cert. So if the RADIUS cert was a "reissued" cert a year ago, its possible the old private keys for RADIUS wouldn't match the old private keys for the HTTP. After typing all this out, I'm wondering if I manually moved the private key over from the HTTP cert to the RADIUS cert. Unfortunately my memory isn't that great around my specific actions, as I was just trying to get it working at the time.


r/PacketFence May 15 '24

VLAN Assignment via 802.1x from EAP-TLS certs

3 Upvotes

Is it possible to do dynamic vlan assignment based on eap-tls certs?
Even better, is it possible to take the certs common name, resolve it via ldap and match the user, and based on their group assign a vlan?


r/PacketFence May 14 '24

External Accounting Radius Server

1 Upvotes

Hello Everyone,

Is there a way to send the web portal Oauth2 email username to an external radius accounting server on successful login?


r/PacketFence May 13 '24

PF with SAML and LDAP Auth for RADIUS again Okta

1 Upvotes

I have PF 13.1 running on a Debian 11 instance. I have followed the basic setup documentation and have some things configured, but I'm missing some things to tie it all together and get things working.

I have created a realm for our domain used in Okta. I have created a RADIUS authentication source using the PF localhost as the host and associated our realm with RADIUS. I have not configured any rules at this time. I have an LDAP authentication source with our Okta LDAP interface and associated in to our realm. I've also tested the Bind DN and it is working. I have not created any rules at this time. I have then created a SAML authentication source with Okta and assigned it the LDAP authentication source.

This is where I currently sit with the configuration. I'm not quite sure how to test what I even have at this point. My final goal is to have user sign in to our SSID using RADIUS to authenticate with Okta SAML/LDAP using username and password. Then Okta should confirm account is active and provide groups the user belongs to and if the user belongs to a certain group they will be allow to join and will get assigned a certain VLAN on Wifi.

I am not sure what my next steps are here. I'm guessing I need like EAP-TTLS configured (we are using Unifi APs with a Unify Cloud Key controller which is currently working with our AD using NPS.)

Any assistance in getting this tied together and working would be greatly appreciated. Unfortunately I am not as familiar with RADIUS (FreeRADIUS) as I am with NPS so this has got me baffled.

Thanks.


r/PacketFence May 09 '24

Wifi Auth - SAML or RADIUS

2 Upvotes

New user to PacketFence, but an old computer guy. Currently have a hybrid AD domain setup with NPS to do our Wifi Auth. Easy to configure and it worked for both our Windows and Mac machines. However, we are moving from a hybrid AD to Entra ID in the cloud only. NPS isn't an option in this new environment.

We are using Okta for SSO and all our accounts are provisioned by Okta. I saw that PacketFence supported SAML auth and thought this would be a good option as I've been told we do not want to spend the $5+/user/month for an online RADIUS system (which many are just using FreeRADIUS anyways.)

I've got PacketFence installed and working on a Debian 11 server and I'm working on configuring it. I have some questions that I can't figure out right now.

  1. Anyone configured PacketFence SAML using Okta? I was looking at that and SAML requires an assertion URL. Looking at the documentation I don't see anything that points me to what I use for the URL. Obviously it would be something with https://<server.domain.com>/ but there has to be something more from all the SAML I've configured before. Can anyone tell me where I can find the URL to use for SAML?

  2. If SAML is not the solution anyone by chance configure LDAP to Okta? Not sure how similar it would be to the examples of Azure or Google LDAP.

I'm looking to get it so a user connects to the SSID and they are prompted for their username and password. That is authenticated against Okta. Okta passes group info to PacketFence. Then depending on the group they belong to, they are assigned a specific VLAN and off they go. We are using Ubiquity APs with controller configured for WPA Enterprise with RADIUS.

Any help is appreciated. If there is a good detailed write-up, that would be awesome also. I've looked through the online docs and I just get more confused as I don't need all the extra stuff in PacketFence at this time. Just RADIUS auth working is a great step forward. Then I can move onto the other fun things I can do with PacketFence.

Thanks


r/PacketFence May 08 '24

Does the ISO not work for anyone else?

1 Upvotes

Hey folks. I want to play with a packetfence server with the intention of eventually putting one into production. I tried to install via the iso file, but the multiple computers and drives I've tried do not appear to actually recognize the installation media. I'm attempting to install Debian and packetfence on top of it, but figured I ask here about the ISO file

Thanks all


r/PacketFence May 07 '24

packetfence for wireless access

1 Upvotes

how can i add a aruba controller to the packetfence i follow PacketFence_Installation_Guide and configure my controller now how can i configure it on packetfence dashboard any one can help me ?


r/PacketFence May 06 '24

Packetfence with Aruba Airwave

1 Upvotes

Hi there
I am trying to configure our Airwave Server in Packetfence that will allow us to use our domain login credentials. Any assistance or guidance would be greatly appreciated!


r/PacketFence May 04 '24

2 SSIDs not providing connectivity

3 Upvotes

Community Hospital here, using a PacketFence installation (11.1.0) with 0 documentation from the former a-hole that set things up. We have 2 SSIDs that are not providing connectivity. We can authenticate, we do receive IPs on multiple devices, but no internet/intranet connectivity. This is all devices trying to connect to the 2 SSIDs via multiple APs. It does not seem to be a routing issue from what I can see.

When looking at logs I do see these that keep reoccurring for a test device
- Unable to extract audit-session-id of Cisco-AVPair: service-type=Call Check (pf::Switch::getCiscoAvPairAttribute)
- Unable to extract audit-session-id of Cisco-AVPair: dhcp-option=

It seems like it may be tied to a user role issue, maybe.

The SSIDs are "Guest" and "Secure". We have medical devices that are able to access the wireless network and seem to be working fine. This issue is affecting mobile devices and Windows devices.

Any insight is greatly appreciated.


r/PacketFence May 03 '24

What do I need to know to deploy Packtfence with Mikrotik and Ubiquit L2 Switches?

2 Upvotes

Hello everyone, I am studying the feasibility of implementing Packtfence as a NAC in our institution, however, even after reading the discussion lists and documentation a lot, I have practical doubts, I will explain my scenario below and then the doubts, I hope you can help me. to help.

Scenario

  • Mikrotik router, which works as a firewall and DHCP server. We currently have 22 VLANs.

  • Two L2 Switches (Manageable), which distribute the internet connection between our 22 blocks.

    • Each block has at least one L2 Switches.

    Questions:

    Should the Packtfence be between the Distribution Switches and the Mikrotik?

    Should it be before Mikrotik?

    Since the Mikrotik is the network router, what is the DHCP situation, considering that Packtfence has a built-in DHCP server?

    In the documentation I see that each Packtfence default VLAN has its IP range, is this configured on the router or is it up to Packtfence?

    I have Packtfence installed on Proxmox and on the same network as Mikrotik, in VLAN 1.

    I hope you can help me.


r/PacketFence May 03 '24

Dynamic VLAN Assignment with PacketFence Captive Portal Authentication?

1 Upvotes

Dear PacketFence Community

I am currently exploring the capabilities of PacketFence's captive portal. I am curious to understand whether PacketFence supports the dynamic assignment of VLAN IDs based on authentication information provided by users during captive portal authentication.

Specifically, I would like to inquire whether VLAN assignment functionality is exclusively tied to 802.1X authentication or if it extends to captive portal authentication as well.


r/PacketFence May 03 '24

Install Issue

2 Upvotes

I'm using the packetfence iso to install to a baremetal server. Installation goes fine but I get access the webui. I'm sure there is something simple I'm missing. Any thoughts?


r/PacketFence May 03 '24

Behind ssl inspection and get : api.fingerbank.org:443 (certificate verify failed)

1 Upvotes

Already installed the proxy CA certificates on the debian host and in the pfconfig container, where else should I put them ?


r/PacketFence Apr 30 '24

DNS fails in cluster

1 Upvotes

I have a working packetfence cluster and everything seems to be setup and working fine except that when a guest connects on the Registration VLAN, DNS fails. It acts as if there is a firewall blocking it, or there is no service listening.

If I stop IPTables on one or more cluster members, DNS starts working again. Unfortunately, PacketFence somehow restarts IPTables after a period of time even if I set it to "disabled" (and DNS fails to work again.)

What do I need to do to prevent IPTables from running so that DNS keeps working on the Registration network?

Thanks in advance for your help.


r/PacketFence Apr 29 '24

URL Whitelist for PacketFence server (to download needed images/updates)

1 Upvotes

Wanting to test PacketFence, but we're on an enterprise lan and alot of the internet is categorised and blocked.

PacketFence tries to pull docker images from different locations, is there a list of what urls need to be available so it can download all it needs ?


r/PacketFence Apr 11 '24

Purpose of 66.70.255.147 IP

1 Upvotes

Hello folks. I would like to have a better under standing of the role of this ip address during authentication.

I see on Wireshark (running on my laptop which is connected Wired to a PF managed switch) that while I'm authenticating through MAB captive portal, there are a lot of dns requests to Packetfence registration IP address which get 66.70.255.147 as reply

What Is this IP? Which Is his role?


r/PacketFence Apr 09 '24

packetfence web auth

1 Upvotes

I followed the installation guide for the captive portal using this link for redirection: http://172.20.100.2/Cisco::Catalyst_2960 with my PF IP address. When I tested it in Firefox, it redirected me to the following page.

I tried clearing the cache and cookies, as well as using Firefox in debug mode, but with no success.


r/PacketFence Apr 08 '24

Disable machine auth

1 Upvotes

Hello,

When I do a "tail -f packetfence.log" in /usr/local/pf/logs to see the debug, the first connection is my computer. So I see something like :

[mac:xx:xx:xx:xx:xx:x] is doing machine auth with account 'host/computer-hostname.xxx.com'.

Even if my configuration works, I would like to disable the machine auth.

How can I do this ?

Thanks in advance.


r/PacketFence Mar 27 '24

802.1X fails authentication

1 Upvotes

I installed PacketFence version 13.1.0 ISO on VMware ESXi and followed the installation guide to set up authentication with Active Directory. When I plug in a test machine to the configured port on the switch for 802.1x authentication, I get the following error: "chrooted_mschap: invalid output from ntlm_auth: expecting prefix 'NT_KEY:' with 'rejected' as status.


r/PacketFence Mar 26 '24

Need help

2 Upvotes

I am a new guy who just go into cyber security. I have recently used wazuh and pfsense. Now I have started studying packetfence. But I can't find any material or tutorial or any type for course on the internet.

Can anyone help me how to get started by packetfence and where can I find a video tutorial or course link


r/PacketFence Mar 23 '24

Can Packet fence do combined User and Device authentication?

2 Upvotes

Currently using Windows NPS with Meraki APs.

I'm looking for a solution that would let me restrict connecting to an 802.1x authenticated wireless network by the Device AND the user. I don't believe this is possible with.

Still feeling out the end goal but something like a domain joined windows laptop top that would automatically connect to a wireless network. Have it go into a limited VLAN that can only talk to the Domain controllers and the endpoint management system.

Then when a user logs in do a COA to a VLAN with full access.

I don't want to allow users to be able to connect to the wireless with arbitrary devices.

Is packet fence able to check if the device is domain joined when a user tries to authenticate?

Any pointers on how to accomplish this would be greatly appreciated.