Packetfence Administration Guide for Version 4.0.5 Packetfence Administration Guide by Inverse Inc

Total Page:16

File Type:pdf, Size:1020Kb

Packetfence Administration Guide for Version 4.0.5 Packetfence Administration Guide by Inverse Inc PacketFence Administration Guide for version 4.0.5 PacketFence Administration Guide by Inverse Inc. Version 4.0.5 - August 2013 Copyright © 2008-2013 Inverse inc. Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation; with no Invariant Sections, no Front-Cover Texts, and no Back-Cover Texts. A copy of the license is included in the section entitled "GNU Free Documentation License". The fonts used in this guide are licensed under the SIL Open Font License, Version 1.1. This license is available with a FAQ at: http://scripts.sil.org/OFL Copyright © Barry Schwartz, http://www.crudfactory.com, with Reserved Font Name: "Sorts Mill Goudy". Copyright © Raph Levien, http://levien.com/, with Reserved Font Name: "Inconsolata". Table of Contents About this Guide ................................................................................................................. 1 Other sources of information ......................................................................................... 1 Introduction ....................................................................................................................... 2 Features .................................................................................................................... 2 Network Integration .................................................................................................... 5 Components .............................................................................................................. 6 System Requirements .......................................................................................................... 7 Assumptions .............................................................................................................. 7 Minimum Hardware Requirements ................................................................................. 7 Operating System Requirements .................................................................................... 8 Installation ........................................................................................................................ 9 OS Installation ............................................................................................................ 9 Software Download .................................................................................................... 11 Software Installation .................................................................................................. 11 Configuration .................................................................................................................... 13 First Step ................................................................................................................. 13 Web-based Administration Interface .............................................................................. 14 Global configuration file (pf.conf) ................................................................................. 14 Apache Configuration ................................................................................................. 14 SELinux .................................................................................................................... 15 Roles Management .................................................................................................... 15 Authentication .......................................................................................................... 16 Network Devices Definition (switches.conf) .................................................................... 18 Default VLAN/role assignment ...................................................................................... 21 Inline enforcement configuration .................................................................................. 21 Hybrid mode ............................................................................................................ 22 DHCP and DNS Server Configuration (networks.conf) ........................................................ 22 Production DHCP access ............................................................................................. 23 Routed Networks ....................................................................................................... 25 FreeRADIUS Configuration ............................................................................................ 28 Starting PacketFence Services ...................................................................................... 33 Log files .................................................................................................................. 33 Passthrough ............................................................................................................. 34 Configuration by example ................................................................................................... 35 Assumptions ............................................................................................................. 35 Network Interfaces .................................................................................................... 36 Switch Setup ............................................................................................................ 37 switches.conf ............................................................................................................ 38 pf.conf .................................................................................................................... 39 networks.conf ........................................................................................................... 41 Inline enforcement specifics ........................................................................................ 42 Optional components ......................................................................................................... 44 Blocking malicious activities with violations ................................................................... 44 Compliance Checks .................................................................................................... 48 RADIUS Accounting .................................................................................................... 51 Oinkmaster ............................................................................................................... 52 Floating Network Devices ............................................................................................ 52 Guests Management .................................................................................................. 54 Statement of Health (SoH) .......................................................................................... 57 Apple Wireless Profile Provisioning ............................................................................... 59 SNMP Traps Limit ...................................................................................................... 60 Copyright © 2008-2013 Inverse inc. iii Billing Engine ........................................................................................................... 60 Portal Profiles ........................................................................................................... 61 OAuth2 Authentication ............................................................................................... 62 Gaming Devices Registration ....................................................................................... 63 Operating System Best Practices .......................................................................................... 64 Iptables ................................................................................................................... 64 Log Rotations ........................................................................................................... 64 Logrotate (recommended) ........................................................................................... 64 Log4perl ................................................................................................................... 64 High Availability ........................................................................................................ 65 Performance optimization ................................................................................................... 72 MySQL optimizations .................................................................................................. 72 Captive Portal Optimizations ....................................................................................... 75 Frequently Asked Questions ................................................................................................ 76 Technical introduction to VLAN enforcement .......................................................................... 77 Introduction ............................................................................................................. 77 VLAN assignment techniques ....................................................................................... 77 More on SNMP traps VLAN isolation ............................................................................. 78 Technical introduction to Inline enforcement .......................................................................... 81 Introduction ............................................................................................................
Recommended publications
  • Technical Impacts of DNS Privacy and Security on Network Service Scenarios
    - Technical Impacts of DNS Privacy and Security on Network Service Scenarios ATIS-I-0000079 | April 2020 Abstract The domain name system (DNS) is a key network function used to resolve domain names (e.g., atis.org) into routable addresses and other data. Most DNS signalling today is sent using protocols that do not support security provisions (e.g., cryptographic confidentiality protection and integrity protection). This may create privacy and security risks for users due to on-path nodes being able to read or modify DNS signalling. In response to these concerns, particularly for DNS privacy, new protocols have been specified that implement cryptographic DNS security. Support for these protocols is being rapidly introduced in client software (particularly web browsers) and in some DNS servers. The implementation of DNS security protocols can have a range of positive benefits, but it can also conflict with important network services that are currently widely implemented based on DNS. These services include techniques to mitigate malware and to fulfill legal obligations placed on network operators. This report describes the technical impacts of DNS security protocols in a range of network scenarios. This analysis is used to derive recommendations for deploying DNS security protocols and for further industry collaboration. The aim of these recommendations is to maximize the benefits of DNS security support while reducing problem areas. Foreword As a leading technology and solutions development organization, the Alliance for Telecommunications Industry Solutions (ATIS) brings together the top global ICT companies to advance the industry’s business priorities. ATIS’ 150 member companies are currently working to address network reliability, 5G, robocall mitigation, smart cities, artificial intelligence-enabled networks, distributed ledger/blockchain technology, cybersecurity, IoT, emergency services, quality of service, billing support, operations and much more.
    [Show full text]
  • Captive Portal Detection Error May Be Triggered If There Is HTTP 302 Response Code Received PRS-325375 While Connecting to IVE
    Pulse Connect Secure Release Notes 8.1 R4 Build 37085: July 2015 Revision 01 Contents Introduction......................................................................................................................... 1 Interoperability and Supported Platforms ............................................................................ 2 Noteworthy changes in 8.1r4 Release ................................................................................ 2 Problems Resolved in 8.1R4 Release ................................................................................ 2 Known Issues in 8.1R3.2 release ....................................................................................... 4 Problems Resolved in 8.1R3.1 Release ............................................................................. 4 Pulse Connect Secure New Features in 8.1R3 ................................................................... 5 Noteworthy changes in this Release................................................................................... 6 Problems Resolved in 8.1R3 Release ................................................................................ 6 Known Issues in this release .............................................................................................. 7 Pulse Connect Secure Access New Features in 8.1R2 Release ........................................ 8 Disable TLS 1.0 ....................................................................................................... 8 New Functionality to create role mapping rules
    [Show full text]
  • Filtering and Identifying Web Activity by User Name
    Wavecrest®TechBrief Filtering and Identifying Web Activity by User Name www.wavecrest.net When a company implements a Web filtering and monitoring solution, it typically wants to filter and monitor the Web traffic flowing through its network by user name versus IP address for various reasons. Some of these reasons include curtailing casual surfing, protecting against security threats, and conserving bandwidth. Furthermore, a company’s Acceptable Use Policy (AUP) is usually based on user names and/or groups of user names. Therefore, the application that enforces and monitors the company’s AUP needs to identify Web activity by user name. IP addresses can be dynamic, and sometimes more than one employee can log on to a computer, and hence, more than one user name will be using the same IP address. Many an IT administrator is tasked with ensuring that the company’s employees are going through the proxy that is in place, so that Web activity can be monitored by user name. To get user names and authenticate users, IT administrators can choose any of the proxy configuration options and authentication methods described below. Depending on the company’s preference, one proxy configuration option may be more favorable than the other. Here, we will discuss applying browser settings manually, pushing out group policies using Active Directory (AD), using a captive portal, and installing client software. We will also touch on the different ways that you can authenticate your Internet users using our CyBlock products. Applying Browser Settings Manually Applying browser settings involves identifying a proxy server which is required if you need user names.
    [Show full text]
  • 9 Caching Proxy Server
    webXaccelerator: Owner's Guide by Luis Soltero, Ph.D., MCS Revision 1.06 February 10, 2010 (v1.2.3.10-RELEASE) Copyright © 2010 Global Marine Networks, LLC Table of Contents 1 Quick Start..............................................................................................................................................5 2 Introduction.............................................................................................................................................8 3 Initial Installation and Configuration......................................................................................................9 3.1 Connections.....................................................................................................................................9 3.2 Power-up..........................................................................................................................................9 3.3 Power-down...................................................................................................................................10 3.4 Web Administrator........................................................................................................................10 3.5 LAN Setup.....................................................................................................................................10 3.6 WAN Setup....................................................................................................................................11 3.7 WAN2 (Backup WAN) Setup........................................................................................................13
    [Show full text]
  • Tunneled Internet Gateway Wi-Fi Access for Mobile Devices in High-Security Environments Table of Contents
    WHITE PAPER TUNNELED INTERNET GATEWAY Wi-FI ACCESS FOR MOBILE DEVICES IN High-SECURitY ENVIRONMENTS TABLE OF CONTENTS THE ChALLENGE: Wi-FI ACCESS FOR MOBILE DEVICES IN high-SECURitY ENVIRONMENTS 3 ARUBA TUNNELED INTERNET GATEWAY SOLUtiON 3 HOW thE TUNNELED INTERNET GATEWAY WORKS 3 APPENDIX 5 TOPOLOGY DIAGRAMS 8 ABOUT ARUBA NETWORKS, INC. 9 WHITE PAPER TUNNELED INTERNET GATEWAY THE CHALLENGE: WI-FI ACCESS FOR MOBILE HOW THE TUNNELED INTERNET GATEWAY WORKS DEVICES IN HIGH-SECURITY ENVIRONMENTS Summary Since the debut of the iPhone in 2007, the private sector The Tunneled Internet Gateway is enabled through software has seen a proliferation of personal mobile devices used in configuration to any new or existing controller-based Aruba the workplace. Government customers, while slower to WLAN. Mobile users connect their devices to the Internet adopt commercially available mobile devices in the gateway SSID, creating an encrypted session with an Aruba workplace, recognize the cost and productivity advantages Mobility Controller deployed in the restricted network. and are looking for ways to increase their usage and speed- up adoption. The controller maintains logical separation between Internet sessions and restricted sessions using a Common Criteria Many civilian and military organizations have already begun EAL4+ validated firewall, then routes Internet traffic through large-scale acquisitions of commercial off-the-shelf (COTS) an additional encrypted data tunnel to a router attached to a mobile devices for distribution to relevant personnel. The commercial Internet service provider. The result is a secure, February 2013 purchase by the U.S. Department of Defense simple and low-cost network overlay with strong separation of 630,000 Apple iOS-based mobile devices is just one between restricted and Internet data.
    [Show full text]
  • Anyconnect Captive Portal Detection and Remediation
    Contents Introduction Prerequisites Requirements Components Used Background Information Captive Portal Remediation Requirements Captive Portal Hotspot Detection Captive Portal Hotspot Remediation False Captive Portal Detection AnyConnect Behavior Captive Portal Incorrectly Detected with IKEV2 Workarounds Disable the Captive Portal Feature Introduction This document describes the Cisco AnyConnect Mobility Client captive portal detection feature and the requirements for it to function correctly. Many wireless hotspots at hotels, restaurants, airports, and other public places use captive portals in order to block user access to the Internet. They redirect HTTP requests to their own websites that require users to enter their credentials or acknowledge terms and conditions of the hotspot host. Prerequisites Requirements Cisco recommends that you have knowledge of the Cisco AnyConnect Secure Mobility Client. Components Used The information in this document is based on these software versions: ● AnyConnect Version 3.1.04072 ● Cisco Adaptive Security Appliance (ASA) Version 9.1.2 The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command. Background Information Many facilities that offer Wi-Fi and wired access, such as airports, coffee shops, and hotels, require users to pay before they obtain access, agree to abide by an acceptable
    [Show full text]
  • Ten Strategies of a World-Class Cybersecurity Operations Center Conveys MITRE’S Expertise on Accumulated Expertise on Enterprise-Grade Computer Network Defense
    Bleed rule--remove from file Bleed rule--remove from file MITRE’s accumulated Ten Strategies of a World-Class Cybersecurity Operations Center conveys MITRE’s expertise on accumulated expertise on enterprise-grade computer network defense. It covers ten key qualities enterprise- grade of leading Cybersecurity Operations Centers (CSOCs), ranging from their structure and organization, computer MITRE network to processes that best enable effective and efficient operations, to approaches that extract maximum defense Ten Strategies of a World-Class value from CSOC technology investments. This book offers perspective and context for key decision Cybersecurity Operations Center points in structuring a CSOC and shows how to: • Find the right size and structure for the CSOC team Cybersecurity Operations Center a World-Class of Strategies Ten The MITRE Corporation is • Achieve effective placement within a larger organization that a not-for-profit organization enables CSOC operations that operates federally funded • Attract, retain, and grow the right staff and skills research and development • Prepare the CSOC team, technologies, and processes for agile, centers (FFRDCs). FFRDCs threat-based response are unique organizations that • Architect for large-scale data collection and analysis with a assist the U.S. government with limited budget scientific research and analysis, • Prioritize sensor placement and data feed choices across development and acquisition, enteprise systems, enclaves, networks, and perimeters and systems engineering and integration. We’re proud to have If you manage, work in, or are standing up a CSOC, this book is for you. served the public interest for It is also available on MITRE’s website, www.mitre.org. more than 50 years.
    [Show full text]
  • Secure Magazine
    When it comes to information security, most of us will remember this year as the year when an industry giant suffered a huge incident with extensive ramifications. Naturally, I'm talking about the RSA breach back in March, when the company experienced privileged data loss. We've seen privacy snafus, data breaches, a rise of mobile malware and financial fraud. What can we expect next year? Unfortunately, probably more of the same. In any case, I wish you a successful 2012. Stay safe! Mirko Zorz Editor in Chief Visit the magazine website at www.insecuremag.com (IN)SECURE Magazine contacts Feedback and contributions: Mirko Zorz, Editor in Chief - [email protected] News: Zeljka Zorz, Managing Editor - [email protected] Marketing: Berislav Kucan, Director of Marketing - [email protected] Distribution (IN)SECURE Magazine can be freely distributed in the form of the original, non-modified PDF document. Distribution of modified versions of (IN)SECURE Magazine content is prohibited without the explicit permission from the editor. Copyright (IN)SECURE Magazine 2011. www.insecuremag.com IT pros can't resist peeking at information and other sensitive data including, privileged information for example, other people’s Christmas bonus details. • 42 percent of those surveyed said that in their organizations' IT staff are sharing passwords or access to systems or applications • 26 percent said that they were aware of an IT staff member abusing a privileged login to illicitly access sensitive information • 48 percent of respondents work at companies that are still not changing their IT security staff will be some of the most privileged passwords within 90 days – a informed people at the office Christmas party violation of most major regulatory compliance this year.
    [Show full text]
  • Browser History Stealing with Captive Wi-Fi Portals
    Browser History Stealing with Captive Wi-Fi Portals Adrian Dabrowski, Georg Merzdovnik, Nikolaus Kommenda, Edgar Weippl [email protected] Twitter: @atrox_at 2016-05-26 Public Wi-Fi Hotspots ● Like a well in a village Internet ● We gather there, pull up a bucket or two of “Internet” ● Look at the sign from the sponsor ● … and move on. What is a “Captive Portal”? Why Captive Portal ● Omnipresent in Wi-Fi Hotspots ● Used by you probably right now (in this very hotel) ● Has an elevated position on the network ● Man-in-the-Middle by design ● Sponsors of a Wi-Fi want us to see their messages (and accept the disclaimer) ● There is no standard for that ● Let's inject it into your traffic… Browser History Stealing, again? ● Baron, 2002 ● :visited link color TODO: ● Ruderman, 2000 Groundhog ● :visited can load images ● Jang, 2010 ● Sites are actively trying to steal history History, so what? ● Culture & Language ● Amazon.fr, Amazon.jp ● Sexual orientation ● grindr.com, transblog.de ● Other websites that give ● Partnership status interesting insights ● Okcupid.com, parship.com ● Medical conditions ● Employer ● Political campaigns ● intranet.ibm.com ● Religious communities Source: MindSource April 1996 BOF; Client State Tracking with Netscape Cookies; M. Strata Rose; [email protected] Source: MindSource April 1996 BOF; Client State Tracking with Netscape Cookies; M. Strata Rose; [email protected] Cookies (or not enough state for HTTP) ● Two kinds ● Session cookies: usually forgotten when browser closed ● Persistent cookies: stored on disk with expiry date ● Only depend on the FQDN and Protocol ● XSS ● XSRF ● HTTP set cookie also used for HTTPS – Insecure set cookies mixed into the cookies over HTTPS http://cnn.com (+cookies) 302 redirect login.hotspotsys.com/login login.hotspotsys.com/login <html>….
    [Show full text]
  • Captive Portal
    User module Captive Portal APPLICATION NOTE USED SYMBOLS Used Symbols Danger – important notice, which may have an influence on the user’s safety or the function of the device. Attention – notice on possible problems, which can arise in specific cases. Information, notice – information, which contains useful advice or special interest. GPL License Source codes under GPL license are available free of charge by sending an email to: [email protected]. Conel s.r.o., Sokolska 71, 562 04 Usti nad Orlici, Czech Republic Manual issued in CZ, October 6, 2014 i CONTENTS Contents 1 Description of user module 1 2 Configuration 2 2.1 Global ......................................... 2 2.2 Welcome page .................................... 4 2.3 QoS .......................................... 4 3 How to create own welcome page 6 3.1 Simple page ...................................... 6 3.2 Login page ...................................... 6 3.3 Ban page ....................................... 7 3.4 Customized original URL .............................. 7 3.5 Example ........................................ 7 4 Status Overview 9 5 Recommended literature 10 ii LIST OF FIGURES List of Figures 1 Web Interface ..................................... 1 2 Global configuration form .............................. 3 3 Welcome page configuration form ......................... 4 4 QoS configuration form ............................... 5 iii LIST OF TABLES List of Tables 1 Available services .................................. 9 2 Connected customers ................................ 9 iv 1. DESCRIPTION OF USER MODULE 1. Description of user module User module Captive Portal is not contained in the standard router firmware. Uploading of this user module is described in the Configuration manual (see [1, 2]). Please note that this module is compatible only with firmware 4.0.0 or later in v2 routers! The user module is v3 routers platform compatible.
    [Show full text]
  • Clustering Quick Installation Guide
    ClusteringQuickInstallationGuide forPacketFenceversion5.3.1 ClusteringQuickInstallationGuide byInverseInc. Version5.3.1-July2015 Copyright©2015Inverseinc. Permissionisgrantedtocopy,distributeand/ormodifythisdocumentunderthetermsoftheGNUFreeDocumentationLicense,Version 1.2oranylaterversionpublishedbytheFreeSoftwareFoundation;withnoInvariantSections,noFront-CoverTexts,andnoBack-Cover Texts.Acopyofthelicenseisincludedinthesectionentitled"GNUFreeDocumentationLicense". ThefontsusedinthisguidearelicensedundertheSILOpenFontLicense,Version1.1.ThislicenseisavailablewithaFAQat:http:// scripts.sil.org/OFL Copyright©ŁukaszDziedzic,http://www.latofonts.com,withReservedFontName:"Lato". Copyright©RaphLevien,http://levien.com/,withReservedFontName:"Inconsolata". TableofContents AboutthisGuide.............................................................................................................. 1 Assumptions.....................................................................................................................2 Installation....................................................................................................................... 3 Step1:Installthereplicateddatabase........................................................................ 3 Step2:Serverconfiguration..................................................................................... 9 Step3:Createanewcluster.................................................................................. 10 Step4:Connectaslavepacketfenceserver..............................................................11
    [Show full text]
  • Captive Portal Authentication Via Facebook
    Grandstream Networks, Inc. Captive Portal Authentication via Facebook Table of Content SUPPORTED DEVICES ................................................................................................ 4 INTRODUCTION ............................................................................................................ 5 CAPTIVE PORTAL SETTINGS ..................................................................................... 6 Policy Configuration Page ................................................................................................................7 Landing Page Redirection ....................................................................................................... 10 Pre-Authentication Rules ........................................................................................................ 10 Post-Authentication Rules ....................................................................................................... 10 Guest Page ................................................................................................................................... 11 CONFIGURATION STEPS........................................................................................... 12 Create Facebook App .................................................................................................................... 12 Configure Captive Portal Policy with Facebook Authentication ....................................................... 17 Using GWN Master GUI (Standalone mode) ..........................................................................
    [Show full text]