Sunteți pe pagina 1din 19

<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-

com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word"
xmlns:m="http://schemas.microsoft.com/office/2004/12/omml"
xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:SimSun;
panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
{font-family:SimSun;
panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
{font-family:"Times New Roman \, serif";
panose-1:0 0 0 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
{mso-style-priority:99;
mso-style-link:"Plain Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
color:windowtext;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
color:black;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";
color:black;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;
color:black;}
span.PlainTextChar
{mso-style-name:"Plain Text Char";
mso-style-priority:99;
mso-style-link:"Plain Text";
font-family:"Calibri","sans-serif";}
span.EmailStyle22
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.EmailStyle23
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle24
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.EmailStyle25
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle26
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle27
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle28
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Hi Fabrice,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Thank you for the suggestion. I
removed the rule and just leave the rule catch_all to test. I&#8217;m able to pass
the the permission to register. However, after I pass it, the error &#8220;Your
network should be enabled
within a minute or two. If it is not reboot your computer&#8221;. I checked the
pf.log, it said the reassignment required. I only enabled registration vlan here as
we do want clients have limited access (not able to access production). Do I have
to create a normal
vlan or if there&#8217;s something I can do to avoid VLAN change?
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">In addition, I kept my switch mode
to registration instead of production.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:unknown] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Updating node user_agent with useragent:
'WeChat/6.5.6.37 CFNetwork/808.3 Darwin/16.3.0'
(captiveportal::PacketFence::DynamicRouting::Application::process_user_agent)<o:p><
/o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Static User-Agent lookup data initialized
(pf::useragent::_init)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] User default has authenticated on the portal.
(Class::MOP::Class:::after)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Reevaluating access of device.
(captiveportal::PacketFence::DynamicRouting::Module::Root::unknown_state)<o:p></o:p
></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] re-evaluating access (manage_register called)
(pf::enforcement::reevaluate_access)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:55 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] is currentlog connected at (10.1.5.50) ifIndex 1
registration (pf::enforcement::_should_we_reassign_vlan)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:56 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:56 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Connection type is WIRELESS_MAC_AUTH. Getting role
from node_info (pf::role::getRegisteredRole)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:56 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Username was defined &quot;7c:01:91:25:f9:eb&quot; -
returning role 'RSPEmployee' (pf::role::getRegisteredRole)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:56 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] PID: &quot;helen_chen&quot;, Status: reg Returned
VLAN: (undefined), Role: RSPEmployee
(pf::role::fetchRoleForNode)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:56 httpd.portal(2419)
WARN: [mac:7c:01:91:25:f9:eb] No parameter RSPEmployeeVlan found in
conf/switches.conf for the switch 10.1.5.50
(pf::Switch::getVlanByName)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:56 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] Reassignment required (current Role = registration
but should be in Role RSPEmployee)
(pf::enforcement::_should_we_reassign_vlan)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 27 22:41:56 httpd.portal(2419)
INFO: [mac:7c:01:91:25:f9:eb] switch port is (10.1.5.50) ifIndex 1 connection type:
WiFi MAC Auth (pf::enforcement::_vlan_reevaluation)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<div>
<p class="MsoNormal"><span style="color:#1F497D">Thank you for your
help,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;---<o:p></o:p></span></p>
<p class="MsoNormal"><b><span
style="color:#595959"><o:p>&nbsp;</o:p></span></b></p>
<p class="MsoNormal"><b><span style="color:#595959">Helen</span></b><span
style="color:#1F497D"><o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Durand fabrice [mailto:fdurand@inverse.ca]
<br>
<b>Sent:</b> Tuesday, March 28, 2017 7:18 AM<br>
<b>To:</b> packetfence-users@lists.sourceforge.net<br>
<b>Subject:</b> Re: [PacketFence-users] help with you do not have permission to
register a device with this username<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p>Hello Helen,<span style="font-size:12.0pt"><o:p></o:p></span></p>
<p>there is only one rule:<br>
[RSPEmployee rule RSPEmployee]<br>
<br>
description=RSPEmployees<br>
<br>
class=authentication<br>
<br>
match=all<br>
<br>
action0=set_role=RSPEmployee<br>
<br>
action1=set_access_duration=5D<br>
<br>
condition0=memberOf,equals,CN=wirelessauth,OU=System Function Account,OU=Special
Account,DC=DDDDDDD,DC=DDDDDDDD,DC=com<o:p></o:p></p>
<p><o:p>&nbsp;</o:p></p>
<p>So if the user is not memberOf the group specified then it will have no
role.<o:p></o:p></p>
<p>What you can do first if the user is suppose to match the group is to use pftest
cli tool to check if the rule match.<o:p></o:p></p>
<p>You can also use adsiedit.mmc to check if the useraccount contain the correct
group oid.<o:p></o:p></p>
<p>The last thing, you can create a catch_all rule as last resort. (if no rule
match before then use the last one as catch all).<o:p></o:p></p>
<p>Regards<o:p></o:p></p>
<p>Fabrice<o:p></o:p></p>
<p><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class="MsoNormal">Le 2017-03-27 � 03:57, Helen Chen a
�crit&nbsp;:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="color:#1F497D">Hi Fabrice,</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">How&#8217;s your weekend goes?
</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Please see attached for rules that
I set for RSPEmployee source.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">In addition, please see the
authen.conf file below:</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[root@PFZen ~]# cat
/usr/local/pf/conf/authentication.conf</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[local]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=Local
Users</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">type=SQL</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[file1]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=Legacy
Source</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">stripped_user_name=yes</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">path=/usr/local/pf/conf/admin.conf</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">type=Htpasswd</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[file1 rule
admins]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=All
admins</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">class=administration</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">match=all</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action0=set_access_level=ALL</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[sms]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=SMS-based
registration</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">sms_carriers=100056,100057,100061,100058,100059,100060,100062
,100063,100071,100064,100116,100066,100117,100112,100067,100065,100068,100069,10007
0,100118,100115,100072,100073,100074,100075,100076,100077,100085,100086,100080,1000
79,100081,100083,100082,100084,100087,100088,100111,100089,100090,100091,100092,100
093,100094,100095,100096,100098,100097,100099,100100,100101,100113,100102,100103,10
0104,100106,100105,100107,100108,100109,100114,100110,100078,100122</span><o:p></o:
p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">type=SMS</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">create_local_account=no</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[sms rule
catchall]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">class=authentication</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">match=all</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action0=set_role=guest</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action1=set_access_duration=1D</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[email]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=Email-based
registration</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">email_activation_timeout=10m</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">type=Email</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">create_local_account=no</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">allow_localdomain=yes</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[email rule
catchall]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">class=authentication</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">match=all</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action0=set_role=guest</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action1=set_access_duration=1D</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[sponsor]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=Sponsor-based
registration</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">email_activation_timeout=30m</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">type=SponsorEmail</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">create_local_account=no</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">allow_localdomain=yes</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[sponsor rule
catchall]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">class=authentication</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">match=all</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action0=set_role=guest</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action1=set_access_duration=1D</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[null]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=Null
Source</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">type=Null</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">email_required=no</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[null rule
catchall]</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">description=catchall</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">class=authentication</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">match=all</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action0=set_role=guest</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action1=set_access_duration=1D</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">[RSPEmployee]</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">description=Employee</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">password=DDDDDD</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">scope=sub</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">binddn=CN=wirelessauth,OU=System
Function Account,OU=Special
Account,DC=DDDDDD,DC=DDDDDDD,DC=com</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">basedn=dc=DDDDDD,dc=DDDDDDD,dc=com</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">email_attribute=mail</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">usernameattribute=sAMAccountName</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">connection_timeout=5</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">stripped_user_name=no</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">encryption=none</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">port=389</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">type=AD</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">host=DDDDDDDD</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[RSPEmployee rule
RSPEmployee]</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">description=RSPEmployees</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">class=authentication</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">match=all</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action0=set_role=RSPEmployee</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action1=set_access_duration=5D</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">condition0=memberOf,equals,CN=wirelessauth,OU=System Function
Account,OU=Special Account,DC=DDDDDDD,DC=DDDDDDDD,DC=com</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[AdminIT]</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">description=AdminIT</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">password=DDDDD!
</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">scope=sub</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">binddn=CN=wirelessauth,OU=System
Function Account,OU=Special
Account,DC=DDDDDDDDD,DC=DDDDDDD,DC=com</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">basedn=OU=IT,OU=Special
Account,DC=resourcepro0,DC=resourcepro,DC=com</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">email_attribute=mail</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">usernameattribute=sAMAccountName</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">connection_timeout=5</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">stripped_user_name=no</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">encryption=none</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">port=389</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">type=AD</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">host=1DDDDDD</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[AdminIT rule
AdminLogin]</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">description=</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">class=administration</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">match=all</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action0=mark_as_sponsor=1</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">condition0=memberOf,equals,CN=wirelessauth,OU=System Function
Account,OU=Special Account,DC=DDDDDDDDD,DC=DDDDDDDDD,DC=com</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">[RSPVisitors]</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">description=RSPVisitors</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">dynamic_routing_module=AuthModule</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">sponsorship_cc=helen_chen@XXXXXXX</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">email_activation_timeout=30m</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">type=SponsorEmail</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">create_local_account=yes</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">allow_localdomain=yes</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">[RSPVisitors rule
RSPVisitors]</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">description=Visitors</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">class=authentication</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">match=all</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action0=set_role=guest</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">action1=set_access_duration=1D</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;---</span><o:p></o:p></p>
<p class="MsoNormal"><b><span
style="color:#595959">&nbsp;</span></b><o:p></o:p></p>
<p class="MsoNormal"><b><span style="color:#595959">Helen
</span></b><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Durand fabrice [<a
href="mailto:fdurand@inverse.ca">mailto:fdurand@inverse.ca</a>]
<br>
<b>Sent:</b> Saturday, March 25, 2017 9:17 AM<br>
<b>To:</b> <a href="mailto:packetfence-users@lists.sourceforge.net">packetfence-
users@lists.sourceforge.net</a><br>
<b>Subject:</b> Re: [PacketFence-users] help with you do not have permission to
register a device with this username</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p>Hi Helen,<o:p></o:p></p>
<p>sorry for the late reply.<o:p></o:p></p>
<p>Did you defines any rules in the RSPEmployee source ?<o:p></o:p></p>
<p>Also can you post your authentication.conf file (without sensible
info)<o:p></o:p></p>
<p>Regards<o:p></o:p></p>
<p>Fabrice<o:p></o:p></p>
<p>&nbsp;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<div>
<p class="MsoNormal">Le 2017-03-24 � 05:59, Helen Chen a
�crit&nbsp;:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="color:#1F497D">Hi Fabrice,</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Just an
update.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">WLC: I enabled MAC filter and I
did change the NAC to ISE NAC.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">PF: I changed the radius secret to
PF default value, of course I did the change on WLC side accordingly as
well.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp; I set the
switch rule &nbsp;from production to registration.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Then I get the captive portal up.
However, I still get the You do not have permission to register a device with this
username. PF.log please see below:</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:28 httpd.portal(2435)
INFO: [mac:unknown] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:28 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:28 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:29 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Authenticating user using sources :
RSPEmployee,AdminIT
(captiveportal::PacketFence::DynamicRouting::Module::Authentication::Login::authent
icate)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:30 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] [RSPEmployee] Authentication successful for
helen_chen
(pf::Authentication::Source::LDAPSource::authenticate)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:30 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Authentication successful for 'helen_chen' in source
RSPEmployee (AD) (pf::authentication::authenticate)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:30 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] User helen_chen has authenticated on the portal.
(Class::MOP::Class:::after)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:30 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:30 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:30 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Successfully authenticated helen_chen
(captiveportal::PacketFence::DynamicRouting::Module::Authentication::Login::authent
icate)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:30 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:30 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] User helen_chen has authenticated on the portal.
(Class::MOP::Class:::after)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
WARN: [mac:7c:01:91:25:f9:eb] Calling match with empty/invalid rule class.
Defaulting to 'authentication' (pf::authentication::match)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Using sources RSPEmployee for matching
(pf::authentication::match)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] User helen_chen has authenticated on the portal.
(Class::MOP::Class:::after)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
WARN: [mac:7c:01:91:25:f9:eb] Calling match with empty/invalid rule class.
Defaulting to 'authentication' (pf::authentication::match)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
INFO: [mac:7c:01:91:25:f9:eb] Using sources RSPEmployee for matching
(pf::authentication::match)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
WARN: [mac:7c:01:91:25:f9:eb] Use of uninitialized value in concatenation (.) or
string at /usr/local/pf/html/captive-
portal/lib/captiveportal/PacketFence/DynamicRouting/Module/Authentication.pm
line 139.</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">(captiveportal::PacketFence::DynamicRouting::Module::Authenti
cation::execute_actions)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
WARN: [mac:7c:01:91:25:f9:eb] Use of uninitialized value in concatenation (.) or
string at /usr/local/pf/html/captive-
portal/lib/captiveportal/PacketFence/DynamicRouting/Module/Authentication.pm
line 139.</span><o:p></o:p></p>
<p class="MsoNormal"><span
style="color:#1F497D">(captiveportal::PacketFence::DynamicRouting::Module::Authenti
cation::execute_actions)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
WARN: [mac:7c:01:91:25:f9:eb] Cannot find unregdate () or role() for user.
(captiveportal::PacketFence::DynamicRouting::Module::Authentication::execute_action
s)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:31 httpd.portal(2435)
WARN: [mac:7c:01:91:25:f9:eb] Execute actions of module
default_policy&#43;default_registration_policy&#43;default_login_policy did not
succeed.
(captiveportal::PacketFence::DynamicRouting::Module::done)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:34 httpd.portal(2437)
INFO: [mac:unknown] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:34 httpd.portal(2437)
INFO: [mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Mar 24 05:50:34 httpd.portal(2437)
INFO: [mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">If I don&#8217;t keep the mode
production, then the WLC will shown the client status as &#8220;WEBAUTH_REQ&#8221;,
and I got the captive.apple.com page pop up automatically but without anything
showing and then it will display
some kind of error.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Would you please shed some lights
what I need to check next?</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Wish you a happy weekend. Thank
you so much for the help.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;---</span><o:p></o:p></p>
<p class="MsoNormal"><b><span
style="color:#595959">&nbsp;</span></b><o:p></o:p></p>
<p class="MsoNormal"><b><span style="color:#595959">Helen
</span></b><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Helen Chen [<a
href="mailto:Helen_Chen@resourcepro.com.cn">mailto:Helen_Chen@resourcepro.com.cn</a
>]
<br>
<b>Sent:</b> Wednesday, March 22, 2017 3:38 PM<br>
<b>To:</b> <a href="mailto:packetfence-users@lists.sourceforge.net">packetfence-
users@lists.sourceforge.net</a><br>
<b>Subject:</b> Re: [PacketFence-users] help with you do not have permission to
register a device with this username</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Hi Fabrice,</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">I&#8217;d like to share more
information with you.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">I tried to add one local MAC
filter on WLC side and then I&#8217;m able to get the ip address and have captive
portal shown up. So, which means the the controller mac filter function should be
fine. Can you shed some
lights on if there&#8217;s anything I can check on PF MAC authen?
</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Thank you for your
help.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;---</span><o:p></o:p></p>
<p class="MsoNormal"><b><span
style="color:#595959">&nbsp;</span></b><o:p></o:p></p>
<p class="MsoNormal"><b><span style="color:#595959">Helen
</span></b><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Helen Chen
<br>
<b>Sent:</b> Wednesday, March 22, 2017 10:25 AM<br>
<b>To:</b> <a href="mailto:packetfence-users@lists.sourceforge.net">packetfence-
users@lists.sourceforge.net</a><br>
<b>Subject:</b> RE: [PacketFence-users] help with you do not have permission to
register a device with this username</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Hi Fabrice,</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Sorry, just found out all your
questions. Please see my answers below.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoPlainText">&nbsp;<o:p></o:p></p>
<p class="MsoPlainText">Are you using flexconnect in your setup ? if it's the case
then you have to define the acl as a flex connect acl. &#8211; We didn&#8217;t use
flexconnect on our current test AP.
<o:p></o:p></p>
<p class="MsoPlainText">&nbsp;<o:p></o:p></p>
<p class="MsoPlainText">Also can you take a capture of the advance tab off your
ssid ?<o:p></o:p></p>
<p class="MsoNormal"><img border="0" width="720" height="374" id="Picture_x0020_1"
src="cid:image001.jpg@01D2A7B0.A5C54FA0"><o:p></o:p></p>
<p class="MsoNormal"><img border="0" width="498" height="254" id="Picture_x0020_2"
src="cid:image002.png@01D2A7B0.A5C54FA0"><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoPlainText">From the vlan 51 are you able to reach the portal ip ?
&#8211; I put the VLAN 51 gateway on our layer 3 switch (172.17.0.1). While my PF
management /portal IP is in VLAN 254, which is our production VLAN. I&#8217;m able
to ping portal IP.<o:p></o:p></p>
<p class="MsoPlainText">&nbsp;<o:p></o:p></p>
<p class="MsoPlainText">Why don't you have a dhcp server defined in the interface
guest ? &#8211; I use the ip-helper on the layer 3 switch to point the DHCP to
172.17.254.254(PF registration interface). Do I still need to do this?
<o:p></o:p></p>
<p class="MsoPlainText">&nbsp;<o:p></o:p></p>
<p class="MsoPlainText">Do you have another choice in Nac State like radius NAC ?
&#8211; SNMP NAC\ISE NAC\None<o:p></o:p></p>
<p class="MsoPlainText">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">What happen if you remove the radius config for this ssid and
try to connect &#8211; Do you mean I disable the AAA Server and try? I can try that
and get back to you. But I did try to disable MAC filter, then I&#8217;m able to
get the IP address and
captive portal redirection.<o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;---</span><o:p></o:p></p>
<p class="MsoNormal"><b><span
style="color:#595959">&nbsp;</span></b><o:p></o:p></p>
<p class="MsoNormal"><b><span style="color:#595959">Helen
Chen</span></b><o:p></o:p></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span
style="color:windowtext"> Durand fabrice [<a
href="mailto:fdurand@inverse.ca">mailto:fdurand@inverse.ca</a>]
<br>
<b>Sent:</b> Wednesday, March 22, 2017 9:35 AM<br>
<b>To:</b> <a href="mailto:packetfence-users@lists.sourceforge.net">packetfence-
users@lists.sourceforge.net</a><br>
<b>Subject:</b> Re: [PacketFence-users] help with you do not have permission to
register a device with this username</span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p>Hello Helen,<o:p></o:p></p>
<p>i ask you&nbsp; some questions multiples times about your issue but you never
answered, so first answer the questions.<o:p></o:p></p>
<p>Also you need mac filter.<o:p></o:p></p>
<p>Fabrice<o:p></o:p></p>
<p>&nbsp;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<div>
<p class="MsoNormal">Le 2017-03-21 � 04:34, Helen Chen a
�crit&nbsp;:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">Hi,<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">I disabled mac filter on WLC2500 and finally have my endpoint
gained ip address from PF and redirected to the registration page. Can we do user
authentication? I added AD in the source. However, it shown &#8220;You do not have
permission to register
a device with this username&#8221; after I input my domain credentials. Please see
the pf.log , profile. Conf and authentication.conf below.<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal"><b>PF Log:</b><o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO: [mac:unknown]
Instantiate profile RSP (pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Authenticating user using sources : RSPEmployee,AdminIT
(captiveportal::PacketFence::DynamicRouting::Module::Authentication::Login::authent
icate)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] [RSPEmployee] Authentication successful for helen_chen
(pf::Authentication::Source::LDAPSource::authenticate)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Authentication successful for 'helen_chen' in source
RSPEmployee (AD) (pf::authentication::authenticate)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] User helen_chen has authenticated on the portal.
(Class::MOP::Class:::after)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Successfully authenticated helen_chen
(captiveportal::PacketFence::DynamicRouting::Module::Authentication::Login::authent
icate)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] User helen_chen has authenticated on the portal.
(Class::MOP::Class:::after)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) WARN:
[mac:7c:01:91:25:f9:eb] Calling match with empty/invalid rule class. Defaulting to
'authentication' (pf::authentication::match)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Using sources RSPEmployee for matching
(pf::authentication::match)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Found source RSPEmployee in session.
(Class::MOP::Class:::around)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] User helen_chen has authenticated on the portal.
(Class::MOP::Class:::after)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) WARN:
[mac:7c:01:91:25:f9:eb] Calling match with empty/invalid rule class. Defaulting to
'authentication' (pf::authentication::match)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) INFO:
[mac:7c:01:91:25:f9:eb] Using sources RSPEmployee for matching
(pf::authentication::match)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) WARN:
[mac:7c:01:91:25:f9:eb] Use of uninitialized value in concatenation (.) or string
at /usr/local/pf/html/captive-
portal/lib/captiveportal/PacketFence/DynamicRouting/Module/Authentication.pm line
139.<o:p></o:p></p>
<p
class="MsoNormal">(captiveportal::PacketFence::DynamicRouting::Module::Authenticati
on::execute_actions)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) WARN:
[mac:7c:01:91:25:f9:eb] Use of uninitialized value in concatenation (.) or string
at /usr/local/pf/html/captive-
portal/lib/captiveportal/PacketFence/DynamicRouting/Module/Authentication.pm line
139.<o:p></o:p></p>
<p
class="MsoNormal">(captiveportal::PacketFence::DynamicRouting::Module::Authenticati
on::execute_actions)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) WARN:
[mac:7c:01:91:25:f9:eb] Cannot find unregdate () or role() for user.
(captiveportal::PacketFence::DynamicRouting::Module::Authentication::execute_action
s)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3466) WARN:
[mac:7c:01:91:25:f9:eb] Execute actions of module
default_policy&#43;default_registration_policy&#43;default_login_policy did not
succeed. (captiveportal::PacketFence::DynamicRouting::Module::done)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3444) INFO: [mac:unknown]
Instantiate profile RSP (pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3444) INFO:
[mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></p>
<p class="MsoNormal">Mar 21 03:54:53 httpd.portal(3444) INFO:
[mac:7c:01:91:25:f9:eb] Instantiate profile RSP
(pf::Portal::ProfileFactory::_from_profile)<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal"><b>Authentication role:</b><o:p></o:p></p>
<p class="MsoNormal">[Employee]<o:p></o:p></p>
<p class="MsoNormal">description=Employee<o:p></o:p></p>
<p class="MsoNormal">password=XXXX<o:p></o:p></p>
<p class="MsoNormal">scope=sub<o:p></o:p></p>
<p class="MsoNormal">binddn=CN=wirelessauth,OU=System Function Account,OU=Special
Account,DC=xxxxx0,DC=xxxxx,DC=com<o:p></o:p></p>
<p class="MsoNormal">basedn=dc=xxxx0,dc=xxxx,dc=com<o:p></o:p></p>
<p class="MsoNormal">email_attribute=mail<o:p></o:p></p>
<p class="MsoNormal">usernameattribute=sAMAccountName<o:p></o:p></p>
<p class="MsoNormal">connection_timeout=5<o:p></o:p></p>
<p class="MsoNormal">stripped_user_name=no<o:p></o:p></p>
<p class="MsoNormal">encryption=none<o:p></o:p></p>
<p class="MsoNormal">dynamic_routing_module=AuthModule<o:p></o:p></p>
<p class="MsoNormal">port=389<o:p></o:p></p>
<p class="MsoNormal">type=AD<o:p></o:p></p>
<p class="MsoNormal">host=x.x.x.x<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">[Employee rule Employee]<o:p></o:p></p>
<p class="MsoNormal">description=RSPEmployees<o:p></o:p></p>
<p class="MsoNormal">class=authentication<o:p></o:p></p>
<p class="MsoNormal">match=all<o:p></o:p></p>
<p class="MsoNormal">action0=set_role=Employee<o:p></o:p></p>
<p class="MsoNormal">action1=set_access_duration=5D<o:p></o:p></p>
<p class="MsoNormal">condition0=memberOf,equals,CN=wirelessauth,OU=System Function
Account,OU=Special Account,DC=xxxxxxxx,DC=xxxxxxxx,DC=com<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">[AdminIT]<o:p></o:p></p>
<p class="MsoNormal">description=AdminIT<o:p></o:p></p>
<p class="MsoNormal">password=xxxxx<o:p></o:p></p>
<p class="MsoNormal">scope=sub<o:p></o:p></p>
<p class="MsoNormal">binddn=CN=wirelessauth,OU=System Function Account,OU= Special
Account,DC=xxxxxxxx,DC=xxxxxxxx,DC=com
<o:p></o:p></p>
<p class="MsoNormal">basedn=OU=IT,OU=Special
Account,DC=xxxxx0,DC=xxxxxx,DC=com<o:p></o:p></p>
<p class="MsoNormal">email_attribute=mail<o:p></o:p></p>
<p class="MsoNormal">usernameattribute=sAMAccountName<o:p></o:p></p>
<p class="MsoNormal">connection_timeout=5<o:p></o:p></p>
<p class="MsoNormal">stripped_user_name=no<o:p></o:p></p>
<p class="MsoNormal">encryption=none<o:p></o:p></p>
<p class="MsoNormal">dynamic_routing_module=AuthModule<o:p></o:p></p>
<p class="MsoNormal">port=389<o:p></o:p></p>
<p class="MsoNormal">type=AD<o:p></o:p></p>
<p class="MsoNormal">host=x.x.x.x<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">[AdminIT rule AdminLogin]<o:p></o:p></p>
<p class="MsoNormal">description=<o:p></o:p></p>
<p class="MsoNormal">class=administration<o:p></o:p></p>
<p class="MsoNormal">match=all<o:p></o:p></p>
<p class="MsoNormal">action0=mark_as_sponsor=1<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">[Visitors]<o:p></o:p></p>
<p class="MsoNormal">description=Visitors<o:p></o:p></p>
<p class="MsoNormal">dynamic_routing_module=AuthModule<o:p></o:p></p>
<p class="MsoNormal"><a
href="mailto:sponsorship_cc=helen_chen@xxxxxxxx.com">sponsorship_cc=helen_chen@xxxx
xxxx.com</a><o:p></o:p></p>
<p class="MsoNormal">email_activation_timeout=30m<o:p></o:p></p>
<p class="MsoNormal">type=SponsorEmail<o:p></o:p></p>
<p class="MsoNormal">create_local_account=yes<o:p></o:p></p>
<p class="MsoNormal">allow_localdomain=yes<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">[Visitors rule Visitors]<o:p></o:p></p>
<p class="MsoNormal">description=Visitors<o:p></o:p></p>
<p class="MsoNormal">class=authentication<o:p></o:p></p>
<p class="MsoNormal">match=all<o:p></o:p></p>
<p class="MsoNormal">action0=set_role=guest<o:p></o:p></p>
<p class="MsoNormal">action1=set_access_duration=1D<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal"><b>Profile.conf</b><o:p></o:p></p>
<p class="MsoNormal">[RSP]<o:p></o:p></p>
<p class="MsoNormal">dot1x_recompute_role_from_portal=0<o:p></o:p></p>
<p class="MsoNormal">filter=connection_type:Wireless-802.11-
NoEAP,connection_type:Wireless-802.11-EAP<o:p></o:p></p>
<p class="MsoNormal">description=RSP_Global<o:p></o:p></p>
<p class="MsoNormal">sources=Employee,AdminIT,Visitors<o:p></o:p></p>
<p class="MsoNormal">#<o:p></o:p></p>
<p class="MsoNormal"># Copyright (C) 2005-2017 Inverse inc.<o:p></o:p></p>
<p class="MsoNormal">#<o:p></o:p></p>
<p class="MsoNormal"># See the enclosed file COPYING for license information
(GPL).<o:p></o:p></p>
<p class="MsoNormal"># If you did not receive this file, see<o:p></o:p></p>
<p class="MsoNormal"># <a
href="http://www.fsf.org/licensing/licenses/gpl.html">http://www.fsf.org/licensing/
licenses/gpl.html</a><o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">Would you please help with this?<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">Thank you,<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;---<o:p></o:p></p>
<p class="MsoNormal"><b><span style="font-
size:10.0pt;color:#1F497D">&nbsp;</span></b><o:p></o:p></p>
<p class="MsoNormal"><b><span style="font-
size:10.0pt;color:#1F497D">&nbsp;</span></b><o:p></o:p></p>
<p class="MsoNormal"><b><span style="color:#595959">Helen
</span></b><o:p></o:p></p>
<p class="MsoNormal">&nbsp;<o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-
size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;"><br>
<br>
<br>
<br>
<br>
</span><o:p></o:p></p>
<pre>------------------------------------------------------------------------------
<o:p></o:p></pre>
<pre>Check out the vibrant tech community on one of the world's
most<o:p></o:p></pre>
<pre>engaging tech sites, Slashdot.org! <a
href="http://sdm.link/slashdot">http://sdm.link/slashdot</a><o:p></o:p></pre>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-
size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;"><br>
<br>
<br>
<br>
<br>
</span><o:p></o:p></p>
<pre>_______________________________________________<o:p></o:p></pre>
<pre>PacketFence-users mailing list<o:p></o:p></pre>
<pre><a href="mailto:PacketFence-users@lists.sourceforge.net">PacketFence-
users@lists.sourceforge.net</a><o:p></o:p></pre>
<pre><a href="https://lists.sourceforge.net/lists/listinfo/packetfence-
users">https://lists.sourceforge.net/lists/listinfo/packetfence-
users</a><o:p></o:p></pre>
</blockquote>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New
Roman&quot;,&quot;serif&quot;">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New
Roman , serif&quot;,&quot;serif&quot;"><br>
<br>
<br>
<br>
</span><o:p></o:p></p>
<pre>------------------------------------------------------------------------------
<o:p></o:p></pre>
<pre>Check out the vibrant tech community on one of the world's
most<o:p></o:p></pre>
<pre>engaging tech sites, Slashdot.org! <a
href="http://sdm.link/slashdot">http://sdm.link/slashdot</a><o:p></o:p></pre>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New
Roman , serif&quot;,&quot;serif&quot;"><br>
<br>
<br>
<br>
</span><o:p></o:p></p>
<pre>_______________________________________________<o:p></o:p></pre>
<pre>PacketFence-users mailing list<o:p></o:p></pre>
<pre><a href="mailto:PacketFence-users@lists.sourceforge.net">PacketFence-
users@lists.sourceforge.net</a><o:p></o:p></pre>
<pre><a href="https://lists.sourceforge.net/lists/listinfo/packetfence-
users">https://lists.sourceforge.net/lists/listinfo/packetfence-
users</a><o:p></o:p></pre>
</blockquote>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New
Roman , serif&quot;,&quot;serif&quot;">&nbsp;</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New
Roman&quot;,&quot;serif&quot;"><br>
<br>
<br>
<o:p></o:p></span></p>
<pre>------------------------------------------------------------------------------
<o:p></o:p></pre>
<pre>Check out the vibrant tech community on one of the world's
most<o:p></o:p></pre>
<pre>engaging tech sites, Slashdot.org! <a
href="http://sdm.link/slashdot">http://sdm.link/slashdot</a><o:p></o:p></pre>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New
Roman&quot;,&quot;serif&quot;"><br>
<br>
<br>
<o:p></o:p></span></p>
<pre>_______________________________________________<o:p></o:p></pre>
<pre>PacketFence-users mailing list<o:p></o:p></pre>
<pre><a href="mailto:PacketFence-users@lists.sourceforge.net">PacketFence-
users@lists.sourceforge.net</a><o:p></o:p></pre>
<pre><a href="https://lists.sourceforge.net/lists/listinfo/packetfence-
users">https://lists.sourceforge.net/lists/listinfo/packetfence-
users</a><o:p></o:p></pre>
</blockquote>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New
Roman&quot;,&quot;serif&quot;"><o:p>&nbsp;</o:p></span></p>
</div>
</body>
</html>

S-ar putea să vă placă și