bullandroo Posted April 6, 2017 Posted April 6, 2017 Hi Guys, I have downloaded and installed Packetfence ZEN on my Hyper-V Server recently which is connected to Cisco Catalyst 2960 Switch. My objective is to use it as a HotSpot for our group of restaurants, where i guests can connect to the guest wifi (Aruba Instant 103) via there social media accounts or cell #. All our restaurants are connected via VPN (Fortigate) to the Head Office where the PacketFence VM (Hyper-V server) is based. I have managed to configure Packetfence in VLAN Enforcement mode i am not sure what configuration do i need for the switch and the AP. I have attached the current layout of my network which doesn't seem to be complete if someone can fill in the blanks :-)
bullandroo Posted April 12, 2017 Author Posted April 12, 2017 (edited) hi @Geoff, your post on the below link very much answers my above question but i have a small question below http://www.edugeek.net/forums/wireless-networks/119855-packetfence.html Question: if you see my current setup where i have my sites connected via VPN to the head office where head office got a cisco 2960 which supports 802.1X but the sites have mixed managed/unmanaged switches. do you think 802.1X will work for me ? if yes do i configure it on port # 2 ? Edited April 12, 2017 by bullandroo
Geoff Posted April 12, 2017 Posted April 12, 2017 If you have any unmanaged switches you cannot control end points access via those switches using 802.1X. If they don't support SNMP traps / config either then there's no easy way round this for a remote site. The only way you could do it is to have a seperate install of packetfence at the remote site doing Arp poision / dhcp /etc. I try to avoid that these days and stick to 802.1X. Therefore I would simply CYA and write up something to your boss / powers that be that the site does not support NAC due to the switches and that I recommend an upgrade of the infrastructure at that site (besides they must be pretty rubbish / old switches if they don't do 802.1X in this day and age).
bullandroo Posted April 13, 2017 Author Posted April 13, 2017 hi @Geoff, thanks for the prompt reply this site is a restaurant with a very basic IT infrastructure where we are currently using Wandafi which is a hotspot service and it authenticate users via radius and we pay them for every user. the only thing i want to do is to get the same job by myself and say good bye to them. Thanks again for your prompt response.
Geoff Posted April 13, 2017 Posted April 13, 2017 Presumably this is for guests at the resturant using the wifi? If that is all you need you might want to use a pfSense based router and use the captive portal function it has. You will need to configure it for self registration if you are doing what I think you are. Here is the forum post detailing how: https://forum.pfsense.org/index.php/topic,57260.msg305604.html#msg305604
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now