PacketFence-VM

PacketFence-VM

Docker app from hoody424's Repository

Overview

Installs PacketFence, the open source network access control (NAC) system, as a virtual machine in the Unraid VM tab. PacketFence itself does not run in Docker; this container is only the installer. It downloads the official PacketFence ZEN appliance (about 8 GB, MD5-checked), converts its VMware disk into an Unraid vdisk, creates the VM and starts it. Then the container stops. The VM is a normal Unraid VM: start, stop, edit and back it up in the VM tab. Running the container again never changes an existing VM. Needs: VMs enabled (Settings > VM Manager), 16 GB of free memory and 4 cores for the VM, about 40 GB free in the VM storage during the import (the vdisk is 200 GB thin-provisioned, about 21 GB used). After the start: open the VM's VNC console in the VM tab. The first network card gets its address by DHCP. Console login root / p@ck3tf3nc3 (change it). Then open https://VM-address:1443 and go through the configurator.

PacketFence VM for Unraid

PacketFence is an open source network access control (NAC) system: 802.1X/RADIUS, captive portal, VLAN assignment, device profiling. Template: packetfence-vm.xml, image: ghcr.io/hoody424/packetfence-vm (source in image/).

PacketFence does not run as a Docker container. It brings its own DHCP, DNS, RADIUS and firewall and expects a whole machine. The vendor ships it as the ZEN appliance, a ready-made VMware VM. This container is an installer, like Macinabox: it turns that appliance into a normal VM in the Unraid VM tab and stops.

What the container does

  1. Finds the newest PacketFence release that has a ZEN appliance, or the version you set.
  2. Uses PacketFence-ZEN-v<version>.zip from the Downloads or VM storage folder if it is already there, otherwise downloads it (about 8 GB) and checks the MD5.
  3. Unpacks zip → OVA → VMDK and converts the VMDK with qemu-img into <VM storage>/<VM name>/vdisk1.img.
  4. Creates the VM through libvirt (Debian, SeaBIOS, Q35, virtio disk and network, VNC console) and starts it.

Running the container again does nothing while a VM with that name exists. To start over, remove the VM in the VM tab with Remove VM & Disks. If only the VM definition is gone but the vdisk is still there, the container reuses the vdisk.

Requirements

  • VMs enabled: Settings > VM Manager.
  • For the VM: 4 cores and 16 GB of memory (PacketFence's minimum).
  • During the import: about 40 GB free in the VM storage. The vdisk is 200 GB thin-provisioned and uses about 21 GB at first.

Settings

Setting Default Meaning
VM name PacketFence Name in the VM tab and folder name in the VM storage
PacketFence version latest Or a version such as 15.2.0
CPU cores / Memory (GB) 4 / 16 VM size, editable later in the VM tab
Network br0 Bridge for the network card: br0, br0.10 (VLAN 10) or vhost0. Start with one card, as PacketFence's guide says; br0,br0.10 adds a second one
MAC address empty Fixed MAC for the first card, e.g. for a DHCP server that only serves known MACs. Empty = random; the log shows it
VNC keyboard en-us Keyboard layout of the console, for example de
Start VM / VM autostart yes / no
VM storage /mnt/user/domains/ Your VM storage path
Downloads /mnt/user/isos/ Where the zip is stored
Source file (advanced) empty Your own .zip, .ova or .vmdk (container path) or a URL
Vdisk type / bus (advanced) raw / virtio

The container needs the libvirt socket (to create the VM) and reads its own mounts through the Docker socket, read-only, to know the host path of the VM storage. The PacketFence icon is copied to /boot/config/plugins/dynamix.vm.manager/templates/images, where Unraid looks for custom VM icons.

First start of the VM

  1. Open the VM's VNC console in the VM tab. The first network card gets its address by DHCP.
  2. Console login: root / p@ck3tf3nc3. Change this password. ip a shows the address.
  3. Open https://<VM address>:1443 and go through the configurator (network, admin account, Fingerbank key). The appliance runs the QEMU guest agent, so Open WebUI in the VM's menu in the VM tab opens this page once the VM has an address.

See the PacketFence Installation Guide for the configuration that follows (switches, RADIUS, Active Directory).

Support

Requirements

VM Manager enabled (Settings > VM Manager). The VM needs 16 GB of free memory, 4 CPU cores and about 40 GB free in the VM storage.

Related apps

Details

Repository
ghcr.io/hoody424/packetfence-vm:latest
Last Updated2026-10-11
First Seen2026-10-11

Runtime arguments

Network
bridge
Shell
bash
Privileged
false

Template configuration

VM nameVariable

Name of the VM in the VM tab and of its folder in the VM storage. Letters, digits, '.', '_' and '-'.

Target
VM_NAME
Default
PacketFence
Value
PacketFence
PacketFence versionVariable

latest, or a version with a ZEN appliance such as 15.2.0.

Target
PF_VERSION
Default
latest
Value
latest
CPU coresVariable

Virtual CPU cores. PacketFence asks for at least 4.

Target
CPUS
Default
4
Value
4
Memory (GB)Variable

VM memory in GB. PacketFence asks for at least 16.

Target
RAM_GB
Default
16
Value
16
NetworkVariable

Unraid bridge for the VM's network card: br0, br0.10 for VLAN 10, or vhost0. PacketFence's guide says to start with one card; a comma-separated list (br0,br0.10) adds more.

Target
NETWORK
Default
br0
Value
br0
MAC addressVariable

Optional MAC for the first network card, for example when your DHCP server only serves known MACs. Empty = random (shown in the container log).

Target
MAC_ADDRESS
VNC keyboardVariable

Keyboard layout of the VNC console, for example en-us, de, fr.

Target
VNC_KEYMAP
Default
en-us
Value
en-us
Start VMVariable

Start the VM right after it is created.

Target
START_VM
Default
yes|no
Value
yes
VM autostartVariable

Start the VM when the array starts (same as the Autostart switch in the VM tab).

Target
AUTOSTART
Default
no|yes
Value
no
VM storagePathrw

Your VM storage (Settings &gt; VM Manager &gt; Default VM storage path). The vdisk goes to VM-name/vdisk1.img in here.

Target
/domains
Default
/mnt/user/domains/
Value
/mnt/user/domains/
DownloadsPathrw

Where the ZEN appliance zip is downloaded to. An existing PacketFence-ZEN-vVERSION.zip here or in the VM storage is used instead of downloading.

Target
/downloads
Default
/mnt/user/isos/
Value
/mnt/user/isos/
Keep downloadVariable

Keep the downloaded zip after the import (no deletes it).

Target
KEEP_DOWNLOAD
Default
yes|no
Value
yes
Source fileVariable

Optional: your own .zip, .ova or .vmdk, as a container path (for example /downloads/PacketFence-ZEN-v15.2.0.zip), or a URL. Empty = official download.

Target
SOURCE
Vdisk typeVariable

raw is the Unraid default.

Target
VDISK_TYPE
Default
raw|qcow2
Value
raw
Vdisk busVariable

virtio is fastest; the appliance boots from all three.

Target
VDISK_BUS
Default
virtio|sata|scsi
Value
virtio
libvirtPathrw

libvirt socket, used to create the VM. Do not change.

Target
/var/run/libvirt
Default
/var/run/libvirt
Value
/var/run/libvirt
Docker socketPathro

Only used to read the host path of VM storage for the VM definition.

Target
/var/run/docker.sock
Default
/var/run/docker.sock
Value
/var/run/docker.sock
VM iconsPathrw

Unraid's folder for custom VM icons; the PacketFence icon is copied here. Remove to use the Debian icon.

Target
/icons
Default
/boot/config/plugins/dynamix.vm.manager/templates/images
Value
/boot/config/plugins/dynamix.vm.manager/templates/images
VM storage host pathVariable

Only needed without the Docker socket: the host path of VM storage, for example /mnt/user/domains.

Target
DOMAINS_HOST_PATH