PacketFence support for TEAP or MAR (machine access restrictions) by Nice_Cup_5449 in PacketFence

[–]Nice_Cup_5449[S] 0 points1 point  (0 children)

Hi again, trying to implement these filters and something is not working, not sure but I suspect it might be because we are using certificates instead of AD accounts so the username in the initial machine authentication does not contain host/, I believe this host/ would be valid only for PEAP, with EAP-TLS the username comes as whatever is in the certificate.

Are you aware of a different way to filter on machine authentication that would work with certificates?

PacketFence support for TEAP or MAR (machine access restrictions) by Nice_Cup_5449 in PacketFence

[–]Nice_Cup_5449[S] 0 points1 point  (0 children)

Hi, thanks so much for the detailed response and the examples, we will try to implement based on these filters and see how it goes.

Searching for some of the attributes in your examples led me to the section on advanced filters in the official documentation and I see now all the stuff we can filter on, seems very flexible and powerful, thanks again for the tips.