PacketFence - An Open Source Network Access Control System

PacketFence

Recientemente Inverse has announced the release of version 8.2 of PacketFence. For all those readers who do not know or have not heard about PacketFence we can say that This is a fully free (GPL v2), compliant and recognized network compliance solution (NPC).

Es a quite ideal option when trying to unify the different security technologies in the final equipment, such as antivirus, host intrusion prevention, vulnerability reports, user or authentication system and strengthen the security of the access network.

PacketFence can be used to efficiently secure both small networks and very large heterogeneous networks.

Alson we can use an agent, they allow compliance checks, configurations and more endpoints connected to your network. PacketFence can ensure that agents (or clients) are installed during the registration process and then for each new connection

Among the main monitoring and control features of the application we find:

  • Flexible VLAN management and role-based access control
  • Guest access: bring your own device (BYOD)
  • Portal Profiles
  • More built-in rape types
  • Automatic registration
  • PKI and EAP-TLS support
  • Expiration
  • Device management
  • Firewal integration
  • Bandwidth accounting
  • Floating network devices
  • Flexible authentication
  • Microsoft Active Directory integration
  • Routed networks
  • Gradual deployment
  • Compatible Hardware

From which we can highlight that with PacketFence gives us the possibility to monitor the devices connected in a network and to be able to manage their stay in it in which we can limit your time on the network, amount of band to use, apply Firewall policies.

PacketFence is a non-intrusive solution that works with a multitude of network devices (wired or wireless) such as 3Com, Aerohive, Brocade, Cisco, Dell / Force10, Enterasys, Extreme Networks, Huawei, Intel, Meru Network, Mojo Networks, Motorola, Netgear, Nortel / Avaya, Ruckus, Ubiquiti, Xirrus, and more.

New version of Update 8.2

This new update release brings with it some new features, but mostly several fixes.

Although esa "minor" version, this version 8.2 is a major update, bringing many additions and improvements.

Of the new features that can be highlighted, we can find a new authentication source with which a «password of the day» can be established and also the “Web Mojo” authentication was added.

Additionally, support was added for server clusters located on multiple Layer 3 and Voice over IP networks and downloadable ACLs for the Aruba 5400 network switch.

Lastly, the developers ask to take into account that mac wired and ethernet-noeap authentication have been merged.

Bugs fixed: download SAML metadata in management pack, various pfdhcp issues fixed, "DNS" false positives removed, and a few others.

Finally, From the list of improvements available with this version 8.2, we can highlight:

  • Maintenance script improvements (new Golang patching possibilities, Rsyslog restart).
  • Reorganization of the IPtables rules.
  • Using MySQL backend for pfdhcp options.
  • The change was made from 4 Gio to 18 Eio (exbioctet) of the maximum bandwidth balance.
  • Network switch filters can now be used instead of the switch module that is created during a Radius connection.
  • Improved trapping of configuration errors in the pfdetect.conf configuration file.
  • HAProxy statistics are now / var / run with explicit names.
  • Pfdns now uses the standard Golang library.
  • CoA support for Meraki network switches was added.
  • Advanced filtering of connection profiles is improved.
  • Adding a test function in the SMTP alert system.

How to install PacketFence on Linux?

Application offers us two installers for the different Linux distributions, one in deb format and one in rpm format this link.

For the rest of the distributions we can use the source code and compile the application.


Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.