From: Nicholas P. <09...@gm...> - 2019-06-11 01:11:02
|
Felipe, What are you using to de-authorize the port? Radius? CoA? SNMP? Also, what's the make of the switch? I've had the best luck with physical ports using SNMP because it typically "downs" the port before "upping" it. This causes the client to request a new DHCP lease and avoids some of the issues with CoA. A caveat is devices connected through phone switchports. It can be inconvenient if someone is on the phone with the helpdesk when their phone and PC go up/down. I hope this is helpful, *Nicholas P. Pier* Network & Virtualization Engineer *CCNP RS, PCSNSE7, VCIX6-DCV, VCIX6-NV* On Mon, Jun 10, 2019 at 9:50 AM Felipe Rodrigues via PacketFence-users < pac...@li...> wrote: > Hi guys, > > I have the same problem here. I have been using one physical interface in > my scenario with a Registration and Isolation VLAN associated to this > interface. The portal works great and I can see the Disconnect-Request and > Disconnect-ACK via Wireshark. > > The problem is the same: The client is not redirected to the new VLAN. If > I disconnected and connected again, than I received the correct VLAN. > > Any Ideia? > > > ------------------------------ > *De:* Ivan Saliu via PacketFence-users < > pac...@li...> > *Enviado:* segunda-feira, 10 de junho de 2019 05:51 > *Para:* pac...@li... > *Cc:* Ivan Saliu > *Assunto:* Re: [PacketFence-users] Issues with PacketFence Captive Portal > configuration > > > Hi Nicholas, > > > > I do agree with you that the flow should be that one. > > So far I’ve noticed that these points works perfectly: > > - User connects to SSID and is sent to registration VLAN if their node > isn't pre-registered. If the node has been registered, the go immediately > to the VLAN associated with their role and this flow stops. > - If they're sent to the registation VLAN: > - Packetfence provides DHCP and DNS for registration VLAN. > - DNS queries from the client are leveraged to redirect them to > packetfence for captive portal. Most modern browsers and OSs should > do this automatically. > > > > After these one though I get to the login page, I log in successfully but > I get the error: Unable to detect network connectivity try restarting your > web browser or opening a new tab to see if your access has been > successfully enabled. > > After this I’m stuck, the client is not redirected to the new VLAN and I > keep the old IP Address. > > > > PacketFence is deployed in the following way: > > > > 2 NICs, one NIC operates as a Management interface with Radius and DHCP > Daemons listening here. The 2nd NIC operates as a Registration Interface, > does DNS and DHCP. > > > > This is deployed in Hyper-V so this is a forced mode, I cannot use a > single interface and build on top VLANs since Hyper-V doesn’t support > multiple tagging on this. > > Also another question: the Registration VLAN, should PacketFence handle > the routing? Because right now there is a Cisco 4500 in VSS that is doing > the routing. > > What I’ve also noticed is that the second NIC it is not reachable from > outside the subnet but honestly I think this should be how it works since > it is supposed to be in an Isolated VLAN. > > > > Cannot wrap my head around what I’m missing/what I do wrong. > > > > Ivan > > > > *From:* Nicholas Pier [mailto:09...@gm...] > *Sent:* domenica 9 giugno 2019 03:06 > *To:* pac...@li... > *Cc:* Ivan Saliu <iva...@ki...> > *Subject:* Re: [PacketFence-users] Issues with PacketFence Captive Portal > configuration > > > > Hi Ivan, > > > > I think this is mostly likely a configuration issue. It sounds like you > may be expecting the controller to receive information about the captive > portal. This may be possible, but it's not how I've deployed packetfence in > the past. Instead, Radius and DNS do most of the work I've only worked with > 7.x controller code and don't know what's changed since... however the > typical workflow I've experienced is as follows: > > > > - User connects to SSID and is sent to registration VLAN if their node > isn't pre-registered. If the node has been registered, the go immediately > to the VLAN associated with their role and this flow stops. > - If they're sent to the registation VLAN: > > > - Packetfence provides DHCP and DNS for registration VLAN. > - DNS queries from the client are leveraged to redirect them to > packetfence for captive portal. Most modern browsers and OSs should do this > automatically. > - If the user successfully authenticates, packetfence sends a > radius message back to the controller to change their VLAN and place them > on a different subnet. > - Client obtains a new lease and can access the network. > > > > I don't know much about your setup, but if its not routed, and clients are > placed on the same vlan as packetfence (not a routed deployment). Are you > leveraging packetfence for DHCP and DNS on the registration VLAN? > > > > Best wishes, > > > > *Nicholas P. Pier* > Network & Virtualization Engineer > *CCNP RS, PCSNSE7, VCIX6-DCV, VCIX6-NV* > > > > > > On Sat, Jun 8, 2019 at 7:45 PM Ivan Saliu via PacketFence-users < > pac...@li...> wrote: > > Hello Guys, > > > > I’m experiencing a lot of issues in configuring PacketFence’s Captive > Portal (Version 9.0.1) with Cisco’s WLC (5508, software version 8.1). > > Basically I’ve tried to deploy the solution in two ways: > > > > - The “Network Guide” one, where there is only 1 VLAN with ACLs > on the WLC to permit only traffic to DHCP/DNS servers and PacketFence > Portal. The issue here is the fact that the redirection does not work at > all. The Radius parameter with the URL redirection is not filled with data > and so the WLC doesn’t redirect at all the traffic. This is an issue > because I do not like the user experience, since being force to type an URL > to log in and register the device is not good. > > - The second type of deployment I’ve tried to do is an interface > in Registration mode, on a dedicated VLAN managed entirely by PacketFence, > trying to use the VLAN change to grant internet access. In this case the > Captive Portal works fine, but once I log into it is not recognized > internet access and I get an error saying that internet access cannot be > validated. If I try to disconnect the client and reconnect it, the VLAN is > changed properly and everything works fine, but again this is not a good > user experience and I cannot put in a production environment something that > doesn’t work properly. This would also be my preferred solution since it > grants the best approach to security of course since I would be able to > isolate the Registration VLAN and then with Access-List prohibit access to > corporate network once the client in registered. > > > > Do you have any idea on how to solve these issues? I do think it is most > likely a misconfiguration on PacketFence or maybe I’m trying to implement > something that it is not supported by Cisco with its WLC?! > > > > Any help on this would be greatly appreciated, > > Ivan > > _______________________________________________ > PacketFence-users mailing list > Pac...@li... > https://lists.sourceforge.net/lists/listinfo/packetfence-users > <https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.sourceforge.net%2Flists%2Flistinfo%2Fpacketfence-users&data=02%7C01%7C%7Cca40dbcd713649b3549408d6ed982760%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636957635087799358&sdata=yTHbwbzRGARz7TpQL4%2FjQhbJjyvRCAdRrljlCVBdrfM%3D&reserved=0> > > > -- > Questo messaggio e' stato analizzato con Libra ESVA ed e' risultato non > infetto. > Clicca qui per segnalarlo come spam. > <https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fesva.percassi.it%2Fcgi-bin%2Flearn-msg.cgi%3Fid%3DC717F400D3.A41D3&data=02%7C01%7C%7Cca40dbcd713649b3549408d6ed982760%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636957635087819374&sdata=DtdOqPAHoJYG1%2FdMm24mW3Rv%2BhpsJW%2FpUUzWz5htN1Q%3D&reserved=0> > Clicca qui per metterlo in blacklist > <https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fesva.percassi.it%2Fcgi-bin%2Flearn-msg.cgi%3Fblacklist%3D1%26id%3DC717F400D3.A41D3&data=02%7C01%7C%7Cca40dbcd713649b3549408d6ed982760%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C636957635087829392&sdata=Iet5tedpRTYpFMvGSiozoaO0f43vZjc42eHjVy7gZL4%3D&reserved=0> > _______________________________________________ > PacketFence-users mailing list > Pac...@li... > https://lists.sourceforge.net/lists/listinfo/packetfence-users > |