PacketFence
DeveloperCommunity headed by Inverse Inc.
ReleaseDecember 22, 2004 (2004-12-22)
Stable release
14.0.0 / September 6, 2024; 2 years ago (2024-09-06)
Written inPerl, Golang, JavaScript
Operating systemLinux
Size14.2MB
TypeNetwork access control
LicenseGNU General Public License
Websitepacketfence.org
Repository

PacketFence is an open-source network access control (NAC) system that provides the following features: registration, detection of abnormal network activities, proactive vulnerability scans, isolation of problematic devices, remediation through a captive portal, 802.1X, wireless integration and User-Agent / DHCP fingerprinting.

The company that develops PacketFence, Inverse Inc. was acquired by Akamai Technologies on February 1, 2021.[1]

PacketFence version 10 supports Red Hat Enterprise Linux 7 and its derivatives, notably CentOS, and Debian Stretch. Inverse Inc. has also been releasing a version of PacketFence dubbed the "Zero Effort NAC", a standalone virtual appliance with a preconfigured PacketFence installation for easy NAC deployment.

PacketFence version 11 added support for Red Hat Enterprise Linux 8 and it's derivatives, notably CentOS, and Debian Bullseye.

Design and functionality

PacketFence supports inline and out-of-band enforcement of network access policies. In inline mode, traffic from connected devices passes through the PacketFence server. In out-of-band deployments, access is controlled through network equipment using SNMP or RADIUS, without requiring user traffic to pass through the server. These modes can be combined within the same deployment, for example by using out-of-band enforcement on managed switches and inline enforcement on older wireless access points.[2]

Authentication options include IEEE 802.1X through an integrated FreeRADIUS server, as well as integration with LDAP directories and Active Directory. Guest access can use self-registration through a captive portal, approval by an employee sponsor, or confirmation by email or SMS. Network policies can assign devices to different VLANs according to user identity, device type or compliance status.[3]

PacketFence integrates with Fingerbank to identify devices using information such as DHCP fingerprints, DHCP vendor identifiers, MAC address vendor information and browser user agents. Device classifications can be used to trigger security events. Fingerbank integration also supports detection of changes in device type and deviations from expected network behaviour.[4]

Further reading

  • Marcotte, Ludovic; Gehl, Dominik (2007-04-01). "PacketFence". Linux Journal. Retrieved 2009-03-11.
  • Wallen, Jack (2007-12-18). "SolutionBase: Use PacketFence to stop unwanted network traffic". Techrepublic. Retrieved 2015-11-25.
  • Wallen, Jack (2007-12-20). "SolutionBase: Installing and configuring Network Access Control with PacketFence". Techrepublic. Retrieved 2015-11-25.
  • Wallen, Jack (2007-12-21). "SolutionBase: Administer PacketFence with ease via Web interface". Techrepublic. Retrieved 2015-11-25.
  • Balzard, Regis; Gehl, Dominik (2008-01-01). "PacketFence Revisited". Linux Journal. Retrieved 2009-03-11.
  • Gehl, Dominik; Balzard, Regis (2008-08-20). "PacketFence 1.7 offers client-free open-source NAC". LinuxWorld.com. Archived from the original on 2008-08-25. Retrieved 2009-03-11.
  • Buford, Cory (2008-09-23). "Securing your network with PacketFence". Linux.com. Archived from the original on 2009-03-04. Retrieved 2009-03-11.
  • Bilodeau, Olivier (2011-12-01). "PacketFence: Because NAC doesn't have to be hard!" (PDF). Insecure Magazine. Retrieved 2012-02-23.

References

  1. ^ "Akamai Technologies, Inc. Acquires Inverse". www.packetfence.org. Retrieved 2021-06-22.
  2. ^ "PacketFence Installation Guide". PacketFence. Retrieved 6 October 2026.
  3. ^ "Features". PacketFence. Retrieved 6 October 2026.
  4. ^ "PacketFence Installation Guide". PacketFence. Retrieved 6 October 2026.