PacketFence NAC Setup & Integration
Budget: $250 – $750 USD
I want a fully working PacketFence deployment that gives me complete control over who and what can use my network.
Scope of work
• Install the latest stable PacketFence on a fresh server (your call on Ubuntu or Rocky/CentOS, as long as it is a supported platform).
• Enable Network Access Control so devices are automatically placed in the right VLAN or have the correct ACLs applied. If RADIUS CoA is the best fit for my gear, please implement it; otherwise explain the alternative you choose.
• Integrate with my switching and wireless stack—BDCom, Zyxel, and Ubiquiti UniFi. These models must talk cleanly to PacketFence via SNMP/SSH and RADIUS, with automatic quarantine and remediation working in a live demo.
• Configure RADIUS authentication:
– 802.1X for corporate laptops and staff logins against Active Directory/LDAP.
– MAC Authentication Bypass for printers, IoT, and any device that can’t speak 802.1X.
• Build a branded captive portal (logo and colour palette supplied) that supports guest self-registration, policy acceptance, and a BYOD onboarding flow. The page must load over HTTPS with either Let’s Encrypt or my internal CA—whichever you confirm is most practical.
• Provide a guest role and VLAN that can only reach the internet and any other subnets I explicitly allow.
• Document everything in a clear handover guide: diagrams, switch configs, PacketFence policies, and certificate renewal steps.
Acceptance test
1. Plug a Windows laptop into a test port, log in with an AD account, and watch it land in the correct production VLAN.
2. Connect a printer and verify it passes through MAB into the IoT role.
3. Join a phone to the guest SSID, complete the self-registration form, and confirm it reaches the internet but not the corporate network.
Deliverables
• Configured PacketFence virtual or bare-metal server
• Switch/UniFi config snippets and RADIUS dictionaries
• Captive portal theme files
• Step-by-step documentation (PDF or Markdown)
I will provide remote access to the server, switch/UniFi controllers, and a small lab environment for validation. Let me know your estimated timeline and any questions about the gear so we can get started right away.
Scope of work
• Install the latest stable PacketFence on a fresh server (your call on Ubuntu or Rocky/CentOS, as long as it is a supported platform).
• Enable Network Access Control so devices are automatically placed in the right VLAN or have the correct ACLs applied. If RADIUS CoA is the best fit for my gear, please implement it; otherwise explain the alternative you choose.
• Integrate with my switching and wireless stack—BDCom, Zyxel, and Ubiquiti UniFi. These models must talk cleanly to PacketFence via SNMP/SSH and RADIUS, with automatic quarantine and remediation working in a live demo.
• Configure RADIUS authentication:
– 802.1X for corporate laptops and staff logins against Active Directory/LDAP.
– MAC Authentication Bypass for printers, IoT, and any device that can’t speak 802.1X.
• Build a branded captive portal (logo and colour palette supplied) that supports guest self-registration, policy acceptance, and a BYOD onboarding flow. The page must load over HTTPS with either Let’s Encrypt or my internal CA—whichever you confirm is most practical.
• Provide a guest role and VLAN that can only reach the internet and any other subnets I explicitly allow.
• Document everything in a clear handover guide: diagrams, switch configs, PacketFence policies, and certificate renewal steps.
Acceptance test
1. Plug a Windows laptop into a test port, log in with an AD account, and watch it land in the correct production VLAN.
2. Connect a printer and verify it passes through MAB into the IoT role.
3. Join a phone to the guest SSID, complete the self-registration form, and confirm it reaches the internet but not the corporate network.
Deliverables
• Configured PacketFence virtual or bare-metal server
• Switch/UniFi config snippets and RADIUS dictionaries
• Captive portal theme files
• Step-by-step documentation (PDF or Markdown)
I will provide remote access to the server, switch/UniFi controllers, and a small lab environment for validation. Let me know your estimated timeline and any questions about the gear so we can get started right away.
Related categories:
Linux
Mobile App Development
Mac OS
Active Directory
Ubuntu
Network Administration
Documentation
Network Security