<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=PACKETFENCE_-_Administration_Documentation</id>
	<title>PACKETFENCE - Administration Documentation - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=PACKETFENCE_-_Administration_Documentation"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=PACKETFENCE_-_Administration_Documentation&amp;action=history"/>
	<updated>2026-05-02T18:23:15Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=PACKETFENCE_-_Administration_Documentation&amp;diff=858&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=PACKETFENCE_-_Administration_Documentation&amp;diff=858&amp;oldid=prev"/>
		<updated>2026-01-17T07:04:41Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 07:04, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Internal Architecture and Core Components ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Internal Architecture and Core Components ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=PACKETFENCE_-_Administration_Documentation&amp;diff=718&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;Category:Wiki  == Internal Architecture and Core Components ==  === Service-Oriented Architecture === PacketFence is composed of multiple specialized services communicating locally and via RADIUS, HTTP(S), and database backends.  Key services include: * &#039;&#039;&#039;pfconfig&#039;&#039;&#039; – Centralized configuration daemon * &#039;&#039;&#039;pf::radius&#039;&#039;&#039; – Authentication, authorization, and accounting * &#039;&#039;&#039;pf::snmp&#039;&#039;&#039; – Network device interaction * &#039;&#039;&#039;pfqueue&#039;&#039;&#039; – Asynchronous task processing...&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=PACKETFENCE_-_Administration_Documentation&amp;diff=718&amp;oldid=prev"/>
		<updated>2025-12-20T16:33:55Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  == Internal Architecture and Core Components ==  === Service-Oriented Architecture === PacketFence is composed of multiple specialized services communicating locally and via RADIUS, HTTP(S), and database backends.  Key services include: * &amp;#039;&amp;#039;&amp;#039;pfconfig&amp;#039;&amp;#039;&amp;#039; – Centralized configuration daemon * &amp;#039;&amp;#039;&amp;#039;pf::radius&amp;#039;&amp;#039;&amp;#039; – Authentication, authorization, and accounting * &amp;#039;&amp;#039;&amp;#039;pf::snmp&amp;#039;&amp;#039;&amp;#039; – Network device interaction * &amp;#039;&amp;#039;&amp;#039;pfqueue&amp;#039;&amp;#039;&amp;#039; – Asynchronous task processing...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Wiki]]&lt;br /&gt;
&lt;br /&gt;
== Internal Architecture and Core Components ==&lt;br /&gt;
&lt;br /&gt;
=== Service-Oriented Architecture ===&lt;br /&gt;
PacketFence is composed of multiple specialized services communicating locally and via RADIUS, HTTP(S), and database backends.&lt;br /&gt;
&lt;br /&gt;
Key services include:&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;pfconfig&amp;#039;&amp;#039;&amp;#039; – Centralized configuration daemon&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;pf::radius&amp;#039;&amp;#039;&amp;#039; – Authentication, authorization, and accounting&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;pf::snmp&amp;#039;&amp;#039;&amp;#039; – Network device interaction&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;pfqueue&amp;#039;&amp;#039;&amp;#039; – Asynchronous task processing&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;pfdhcp&amp;#039;&amp;#039;&amp;#039; – DHCP fingerprinting and enforcement&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;pfdetect&amp;#039;&amp;#039;&amp;#039; – Violation detection engine&lt;br /&gt;
&lt;br /&gt;
Service control example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
systemctl status packetfence&lt;br /&gt;
systemctl restart packetfence-config&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Database Model ===&lt;br /&gt;
PacketFence uses:&lt;br /&gt;
* MariaDB/MySQL for persistent state&lt;br /&gt;
* Redis for queues, caching, and real-time decisions&lt;br /&gt;
&lt;br /&gt;
Key tables:&lt;br /&gt;
* node – Endpoint identity and status&lt;br /&gt;
* violation – Active and historical violations&lt;br /&gt;
* locationlog – Switchport tracking&lt;br /&gt;
* auth_log – Authentication events&lt;br /&gt;
&lt;br /&gt;
Query example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
mysql -u pf -p pf -e &amp;quot;SELECT mac,status FROM node;&amp;quot;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authentication and Authorization Workflows ==&lt;br /&gt;
&lt;br /&gt;
=== 802.1X Authentication Flow ===&lt;br /&gt;
1. Endpoint sends EAPOL&lt;br /&gt;
2. Switch forwards to PacketFence RADIUS&lt;br /&gt;
3. PacketFence evaluates:&lt;br /&gt;
   * Identity source&lt;br /&gt;
   * Role mapping&lt;br /&gt;
   * Compliance state&lt;br /&gt;
4. RADIUS returns VLAN or ACL&lt;br /&gt;
&lt;br /&gt;
Supported EAP methods:&lt;br /&gt;
* EAP-TLS&lt;br /&gt;
* PEAP-MSCHAPv2&lt;br /&gt;
* EAP-TTLS&lt;br /&gt;
&lt;br /&gt;
Test RADIUS manually:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
radtest user password 127.0.0.1 0 testing123&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== MAC Authentication Bypass (MAB) ===&lt;br /&gt;
Used for:&lt;br /&gt;
* Printers&lt;br /&gt;
* IoT&lt;br /&gt;
* Headless devices&lt;br /&gt;
&lt;br /&gt;
MAC normalization example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
00:11:22:33:44:55 → 001122334455&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Authorization rules can assign:&lt;br /&gt;
* Registration VLAN&lt;br /&gt;
* Isolation VLAN&lt;br /&gt;
* Production VLAN&lt;br /&gt;
&lt;br /&gt;
== Enforcement Techniques ==&lt;br /&gt;
&lt;br /&gt;
=== VLAN Enforcement ===&lt;br /&gt;
Dynamic VLAN assignment via RADIUS attributes:&lt;br /&gt;
* Tunnel-Type&lt;br /&gt;
* Tunnel-Medium-Type&lt;br /&gt;
* Tunnel-Private-Group-ID&lt;br /&gt;
&lt;br /&gt;
Example RADIUS reply:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
Tunnel-Type = VLAN&lt;br /&gt;
Tunnel-Medium-Type = IEEE-802&lt;br /&gt;
Tunnel-Private-Group-ID = &amp;quot;20&amp;quot;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Inline Enforcement ===&lt;br /&gt;
PacketFence acts as Layer 2 bridge:&lt;br /&gt;
* Traffic inspection&lt;br /&gt;
* HTTP redirection&lt;br /&gt;
* Real-time blocking&lt;br /&gt;
&lt;br /&gt;
Inline interfaces must be defined explicitly:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
pfcmd pfconfig show Inline&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== ACL and Downloadable ACLs (dACL) ===&lt;br /&gt;
Supported on advanced switches (Cisco, Aruba, Juniper)&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
permit tcp any any eq 443&lt;br /&gt;
deny ip any any&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Policy Engine and Role Mapping ==&lt;br /&gt;
&lt;br /&gt;
=== Role Evaluation Logic ===&lt;br /&gt;
Roles are computed using:&lt;br /&gt;
* Authentication source&lt;br /&gt;
* Device profiling&lt;br /&gt;
* Compliance state&lt;br /&gt;
* Location&lt;br /&gt;
* Time-based rules&lt;br /&gt;
&lt;br /&gt;
Role priority example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
if violation → isolation&lt;br /&gt;
else if unmanaged → registration&lt;br /&gt;
else → production&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Policy Example: Contractor Access ===&lt;br /&gt;
Conditions:&lt;br /&gt;
* LDAP group = contractors&lt;br /&gt;
* Time = business hours&lt;br /&gt;
&lt;br /&gt;
Result:&lt;br /&gt;
* Role: contractor_access&lt;br /&gt;
* VLAN: 30&lt;br /&gt;
* ACL: restricted_internet&lt;br /&gt;
&lt;br /&gt;
== Device Profiling and Fingerprinting ==&lt;br /&gt;
&lt;br /&gt;
=== DHCP Fingerprinting ===&lt;br /&gt;
PacketFence inspects:&lt;br /&gt;
* Option 55&lt;br /&gt;
* Vendor Class Identifier&lt;br /&gt;
&lt;br /&gt;
Example fingerprint:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
MSFT 5.0 → Windows&lt;br /&gt;
android-dhcp-10 → Android&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SNMP-Based Profiling ===&lt;br /&gt;
Used to:&lt;br /&gt;
* Discover switch port&lt;br /&gt;
* Bounce ports&lt;br /&gt;
* Apply VLAN changes&lt;br /&gt;
&lt;br /&gt;
SNMP test:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
snmpwalk -v2c -c public switch-ip sysDescr&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== High Availability and Scalability ==&lt;br /&gt;
&lt;br /&gt;
=== Active/Active Clustering ===&lt;br /&gt;
Requirements:&lt;br /&gt;
* Shared database&lt;br /&gt;
* Redis replication&lt;br /&gt;
* Load balancer (LVS, HAProxy)&lt;br /&gt;
&lt;br /&gt;
Node status:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
pfcmd cluster status&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== RADIUS Load Distribution ===&lt;br /&gt;
Best practices:&lt;br /&gt;
* Multiple PacketFence nodes&lt;br /&gt;
* Switch-side RADIUS failover&lt;br /&gt;
* Short RADIUS timeouts&lt;br /&gt;
&lt;br /&gt;
== Security Concepts and Hardening ==&lt;br /&gt;
&lt;br /&gt;
=== Trust Boundaries ===&lt;br /&gt;
PacketFence separates:&lt;br /&gt;
* Access layer enforcement&lt;br /&gt;
* Control plane decisions&lt;br /&gt;
* Management interfaces&lt;br /&gt;
&lt;br /&gt;
=== Certificate Management ===&lt;br /&gt;
Critical for EAP-TLS:&lt;br /&gt;
* Internal CA or external PKI&lt;br /&gt;
* Certificate revocation&lt;br /&gt;
* Short-lived certs&lt;br /&gt;
&lt;br /&gt;
Certificate validation:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
openssl x509 -in client.crt -text -noout&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Least Privilege Administration ===&lt;br /&gt;
Admin roles:&lt;br /&gt;
* Super Admin&lt;br /&gt;
* Security Admin&lt;br /&gt;
* Helpdesk&lt;br /&gt;
* Read-only&lt;br /&gt;
&lt;br /&gt;
CLI access should be restricted:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
chmod 750 /usr/local/pf/bin/*&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== REST API and Automation ==&lt;br /&gt;
&lt;br /&gt;
=== API Authentication ===&lt;br /&gt;
Uses token-based authentication.&lt;br /&gt;
&lt;br /&gt;
Token creation:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
curl -X POST https://pf/api/v1/login \&lt;br /&gt;
-d &amp;#039;username=admin&amp;amp;password=secret&amp;#039;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common API Use Cases ===&lt;br /&gt;
* Register a node&lt;br /&gt;
* Trigger re-evaluation&lt;br /&gt;
* Query violations&lt;br /&gt;
&lt;br /&gt;
Example node registration:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
curl -X POST https://pf/api/v1/node \&lt;br /&gt;
-H &amp;quot;Authorization: Bearer TOKEN&amp;quot; \&lt;br /&gt;
-d &amp;#039;mac=00:11:22:33:44:55&amp;#039;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Command-Line Operations ==&lt;br /&gt;
&lt;br /&gt;
=== Node Management ===&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
pfcmd node view 00:11:22:33:44:55&lt;br /&gt;
pfcmd node deregister 00:11:22:33:44:55&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Violation Handling ===&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
pfcmd violation list&lt;br /&gt;
pfcmd violation close --id 3&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Service Diagnostics ===&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
journalctl -u packetfence-radius&lt;br /&gt;
tail -f /usr/local/pf/logs/packetfence.log&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
=== Authentication Failures ===&lt;br /&gt;
Check:&lt;br /&gt;
* RADIUS shared secret&lt;br /&gt;
* Time synchronization&lt;br /&gt;
* Certificate validity&lt;br /&gt;
&lt;br /&gt;
Debug RADIUS:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
radiusd -X&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Devices Stuck in Registration VLAN ===&lt;br /&gt;
Possible causes:&lt;br /&gt;
* Role mapping mismatch&lt;br /&gt;
* Violation not closed&lt;br /&gt;
* Switch ignoring RADIUS attributes&lt;br /&gt;
&lt;br /&gt;
Verify role:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
pfcmd node view MAC&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SNMP Enforcement Failures ===&lt;br /&gt;
Check:&lt;br /&gt;
* SNMP version mismatch&lt;br /&gt;
* Write community permissions&lt;br /&gt;
* Interface indexing&lt;br /&gt;
&lt;br /&gt;
Test port bounce:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
pfcmd switch bounce --switch-id 1 --port 24&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Web Interface Issues ===&lt;br /&gt;
Check:&lt;br /&gt;
* Apache/Nginx status&lt;br /&gt;
* SELinux&lt;br /&gt;
* Certificate chain&lt;br /&gt;
&lt;br /&gt;
Logs:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
/usr/local/pf/logs/httpd_error.log&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
&lt;br /&gt;
* https://packetfence.org&lt;br /&gt;
* https://github.com/inverse-inc/packetfence&lt;br /&gt;
* https://packetfence.org/documentation/&lt;br /&gt;
* https://packetfence.org/support/&lt;br /&gt;
* https://www.freeradius.org&lt;br /&gt;
* https://en.wikipedia.org/wiki/Network_access_control&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>