[prev in list] [next in list] [prev in thread] [next in thread]
List: packetfence-users
Subject: Re: [PacketFence-users] MAC bypass and recommendations
From: Fabrice Durand via PacketFence-users <packetfence-users () lists ! sourceforge ! net>
Date: 2020-01-15 21:19:09
Message-ID: 44c37960-f3f1-75c9-6514-10e61ffe9cff () inverse ! ca
[Download RAW message or body]
[Attachment #2 (multipart/alternative)]
Hello Oskar,
in fact when you do mac authentication the status of the node in
packetfence is the "User" in that case.
So just reg the mac and assign a role and you will be ok.
Regards
Fabrice
Le 20-01-14 à 16 h 40, oskar svedman via PacketFence-users a écrit :
>
> Hi,
> Need some guidelines and help with packetfence.
>
> I have setup it and I can authenticate Windows PC's with 802.1x with
> our AD.
>
> We have 150 users. 50% computers and 50% thin clients and a lot of
> printers.
>
> I need to use MAC bypass for our thin clients and printers. My first
> idea was to create a user for each device in our AD with the MAC
> address as username/password. But our AD does not accept it because of
> a password policy + I would rather avoid having all devices as users
> in our AD.
>
> How can it be done, can I create users in PacketFance for devices
> using MAC bypass? Or what is the recommended way to setup it?
>
> I only need two vlans on our network. One for our main network that
> computers using 802.1x and other devices with MAC bypass will be
> placed in and one Guest network with no authentication there all other
> devices will be placed in.
>
> Using Cisco 2960 access switches.
>
> Thanks for any inputs you can provide
>
>
>
> _______________________________________________
> PacketFence-users mailing list
> PacketFence-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
--
Fabrice Durand
fdurand@inverse.ca :: +1.514.447.4918 (x135) :: www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence (http://packetfence.org)
[Attachment #5 (text/html)]
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Hello Oskar,</p>
<p>in fact when you do mac authentication the status of the node in
packetfence is the "User" in that case.</p>
<p>So just reg the mac and assign a role and you will be ok.</p>
<p>Regards</p>
<p>Fabrice<br>
</p>
<div class="moz-cite-prefix">Le 20-01-14 Ã 16 h 40, oskar svedman
via PacketFence-users a écrit :<br>
</div>
<blockquote type="cite"
cite="mid:CAGdemDpq8HfVf6WM57FFgoNcCKN_jiAPdN4L+qZiH7faWpFRnA@mail.gmail.com">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<div dir="ltr">
<p class="MsoNormal" style="margin:0cm 0cm
8pt;line-height:107%;font-size:11pt;font-family:Calibri,sans-serif"><span
lang="EN-US">Hi,<br>
Need some guidelines and help with packetfence.<br>
<br>
I have setup it and I can authenticate Windows PC's with
802.1x with our AD.<br>
<br>
We have 150 users. 50% computers and 50% thin clients and a
lot of printers.<br>
<br>
I need to use MAC bypass for our thin clients and printers.
My first idea was
to create a user for each device in our AD with the MAC
address as
username/password. But our AD does not accept it because of
a password policy +
I would rather avoid having all devices as users in our AD.<br>
<br>
How can it be done, can I create users in PacketFance for
devices using MAC
bypass? Or what is the recommended way to setup it?<br>
<br>
I only need two vlans on our network. One for our main
network that computers using
802.1x and other devices with MAC bypass will be placed in
and one Guest
network with no authentication there all other devices will
be placed in.<br>
<br>
Using Cisco 2960 access switches.<br>
<br>
Thanks for any inputs you can provide</span></p>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<pre class="moz-quote-pre" \
wrap="">_______________________________________________ PacketFence-users mailing \
list <a class="moz-txt-link-abbreviated" \
href="mailto:PacketFence-users@lists.sourceforge.net">PacketFence-users@lists.sourceforge.net</a>
<a class="moz-txt-link-freetext" \
href="https://lists.sourceforge.net/lists/listinfo/packetfence-users">https://lists.sourceforge.net/lists/listinfo/packetfence-users</a>
</pre>
</blockquote>
<pre class="moz-signature" cols="72">--
Fabrice Durand
<a class="moz-txt-link-abbreviated" \
href="mailto:fdurand@inverse.ca">fdurand@inverse.ca</a> :: +1.514.447.4918 (x135) :: \
<a class="moz-txt-link-abbreviated" href="http://www.inverse.ca">www.inverse.ca</a> \
Inverse inc. :: Leaders behind SOGo (<a class="moz-txt-link-freetext" \
href="http://www.sogo.nu">http://www.sogo.nu</a>) and PacketFence (<a \
class="moz-txt-link-freetext" \
href="http://packetfence.org">http://packetfence.org</a>) </pre> </body>
</html>
_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic