Installation Guide
Total Page:16
File Type:pdf, Size:1020Kb
Installation Guide PacketFence v11.0.0 Version 11.0.0 - September 2021 Table of Contents 1. About this Guide . 2 1.1. Other sources of information . 2 2. Introduction . 3 3. System Requirements . 4 3.1. Assumptions . 4 3.2. Minimum Hardware Requirements. 4 3.3. Operating System Requirements . 4 4. Installation . 6 4.1. Installing PacketFence from the ZEN. 6 4.2. Installing PacketFence on existing Linux . 7 5. Getting Started . 10 5.1. Going Through the Configurator . 10 5.2. Connecting PacketFence to Microsoft Active Directory . 11 5.3. Configuring Cisco Catalyst 2960 Switch. 11 5.4. Adding the Switch to PacketFence. 13 5.5. Configuring the Connection Profile . 13 5.6. Configuring Microsoft Windows Supplicant . 14 5.7. Testing. 14 5.8. Alerting . 14 6. Enabling the Captive Portal . 15 6.1. Creating Authentication Source for Guests. 15 6.2. Configure switchport for Web Authentication . 15 6.3. Adjust Switch Configuration in PacketFence. 16 6.4. Enabling Portal on Management Interface . 16 6.5. Configuring the Connection Profile . 17 6.6. Testing. 17 7. Authentication Sources . 18 7.1. Email Authentication for Guests. 19 7.2. Adding SMS Authentication for Guests . 20 8. Introduction to Role-based Access Control . 22 8.1. Adding Roles. 22 8.2. Using the Employee Role . 23 8.3. Using the Corporate_Machine Role . 23 9. Supported Enforcement Modes . 25 9.1. Technical Introduction to Inline Enforcement . 25 9.2. Technical Introduction to Out-of-band Enforcement . 26 9.3. Technical Introduction to Hybrid Enforcement. 30 9.4. Technical Introduction to RADIUS Enforcement. 31 9.5. Technical Introduction to DNS Enforcement . 31 10. Adding Inline Enforcement to Existing Installation . 33 10.1. Introduction . 33 10.2. Preparating the Operating System. 33 10.3. Adding Inline Interface . 33 10.4. Network Devices. 35 10.5. Adding Connection Profile for Inline . 35 10.6. Testing the Inline Configuration . 35 10.7. Advanced Inline Topics . 36 11. Adding VLAN Enforcement to Existing Installation . 37 11.1. Introduction . 37 11.2. Adding the Registration, Isolation and Other Interface . 38 11.3. Network Devices. 39 11.4. Adding Connection Profile for Registration. 40 12. Troubleshooting PacketFence . 42 12.1. RADIUS Audit Log . 42 12.2. Log files . 42 12.3. RADIUS Debugging. 42 13. Authentication Mechanisms . 44 13.1. Microsoft Active Directory (AD). 44 13.2. OAuth2 Authentication. 51 13.3. Eduroam . 55 13.4. SAML Authentication . 58 13.5. Billing Engine . 60 13.6. External API Authentication . 74 13.7. Azure AD integration. 75 13.8. Google Workspace LDAP Integration . 77 14. Advanced Portal.