Software update: PacketFence 7.0.0

Spread the love

An NAC system can be used to secure a network environment. This allows, based on pre-set policies, network devices to be automatically blocked if an undesirable situation occurs. Think of unknown network devices of visitors, a worm that is trying to spread or an authorized device that is equipped with a different operating system via a boot flop or live CD. PacketFence is such a nac system, with support for 802.1x and vlan isolation, which allows a network device to be placed in the correct vlan after analysis. For more information, please refer to this page and to the 32nd [In]Secure Magazine, in which an article about this package can be found. The developers have released version 7.0.0 with the following changes:

PacketFence v7.0 released

The Inverse team is pleased to announce the immediate availability of PacketFence v7.0. This is a major release with new features, enhancements and important bug fixes. This release is considered ready for production use and upgrading from previous versions is strongly advised. Here are the changes included in this release:

New Features:

  • Added provisioning support for SentinelOne
  • Added MariaDB Galera cluster support
  • All services are now handled by systemd
  • IPv6 network stack in PacketFence
  • New Golang-based HTTP dispatcher
  • New Golang-based pfsso service to handle the firewall SSO requests
  • Revamped Web administration interface

Enhancements:

  • SNMP traps are now handled in pfqueue
  • Added the ability to grant CLI write access for Extreme Networks switches
  • Added a distributed cache for the accounting information to safely disable the SQL accounting records in active/active clusters
  • Reduced the number of ipset calls when adding ports for Active Directory
  • pfmon tasks have their own configuration file
  • new command “pfcmd pfmon” – for running pfmon tasks via pfcmd
  • CentOS repositories (packetfence and packetfence-devel) packages are now signed
  • Added way to unregister devices that were inactive for a certain amount of time (maintenance.node_unreg_window)
  • Added a new last_seen column to nodes table to track their last activity (Authentication, HTTP portal, DHCP)
  • Delete nodes based on the new last_seen column instead of looking at the last DHCP packet
  • iplog: Floored lease time for “tolerance”
  • Can now restart the switchport where a node is connected from the administration interface
  • Added interface description to location entries
  • New pffilter filtering engine
  • Ability to manage multiple “active” endpoints behind a single switchport
  • pfdhcplistner now runs as a master-worker style service
  • Added a winbindd wrapper for the PacketFence managed winbindd processes
  • Added a caddy middleware for rate limiting the concurrent connections
  • Updated the Ruckus SmartZone module to use the most recent webauth technique available
  • Added vsys support for PaloAlto firewall SSO modules
  • Portal Profile has been renamed to Connection Profile
  • Moved common flows / process of DHCP processors in base class
  • Removed PacketFence-Authorization-Status attribute from the RADIUS replies to prevent RADIUS replies from being discarded due to an unknown attribute
  • Added option to fetch users one by one in the NTLM cache instead of all together
  • New parallel testing infrastructure
  • Roles are now stored in a configuration file for easier backup and management
  • Tightened up HAproxy’s SSL termination security
  • Tightened up Apache’s encryption security by requiring TLS v1.2 support only and restricted cipher suites
  • Clickjacking attack prevention enforcement for recent browsers
  • Cross-site scripting (XSS) filtering is now requested from your browser
  • Dell N2000 series support
  • All logging is now done through syslog
  • IP forwarding is now activated by default per PacketFence package installation
  • Added more fine grain stats for the captive portal
  • Many documentation improvements

Bug Fixes:

  • Fixed addition of an UDP SRV record port as a TCP port
  • Restored pf::api compatibility to Sourcefire module
  • Avoid opening a double entry with wrong accounting values
  • Added the ability to “format” the CN when using PKI
  • pfdhcplistener doesn’t work on a monitor interface
  • pfqueue stats: Outstanding Task Counters isn’t accurate
  • pfdhcplistener: Segfaulting when keepalive transitions quickly from backup/master/backup
  • pfdhcplistener takes a minute to die
  • captive-portal: i18n labels for dynamic fields

See the complete list of changes and the UPGRADE.asciidoc file for notes about upgrading.

Version number 7.0.0
Release status Final
Operating systems Linux
Website PacketFence
Download
License type GPL
You might also like