+ Reply to Thread
Results 1 to 11 of 11

Thread: Smoothwall/Ruckus guest WLAN

  Share/Bookmark
  1. #1

    Reputation Reputation
    badders's Avatar
    Join Date
    Apr 2007
    Location
    Cumbria
    Posts
    85
    Thank Post
    22
    Thanked 5 Times in 4 Posts
    Rep Power
    12

    Default Smoothwall/Ruckus guest WLAN

    Is anybody using Smoothwall and Ruckus and managed to get a guest WLAN working. We have no problem setting up a school WLAN for domain attached devices, but would like to enable students to use their own laptops to access the internet by authenticating against thier AD account. We've got as far as setting up another WLAN for students that asks for authentication using the Ruckus portal to authorize the device but then when we try to browse the internet Smoothwall blocks access due to the local user of the laptop being an unauthorised user. Would we have to use VLans with a separate DHCP server?

  2. #2


    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    2,489
    Thank Post
    272
    Thanked 342 Times in 259 Posts
    Rep Power
    78

    Default

    I wonder how the traffic is hitting Smoothie... if you want authentication, non-domain users *should* get a popup if they are presented with an ntlm handshake. Is ruckus proxying the traffic first?

    You could potentially give "unauthenticated IPs" some very limited web access? You'd lose a bit of visibility though.

  3. #3

    Reputation Reputation
    badders's Avatar
    Join Date
    Apr 2007
    Location
    Cumbria
    Posts
    85
    Thank Post
    22
    Thanked 5 Times in 4 Posts
    Rep Power
    12

    Default

    We.ve manually set smoothwall as the proxy in the non-domain client, but we don't seem to get a pop-up asking for username/password. Would this be related to the SSL login settings in smoothwall?

  4. #4


    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    2,489
    Thank Post
    272
    Thanked 342 Times in 259 Posts
    Rep Power
    78

    Default

    Are you using NTLM on the domain?

  5. #5

    Reputation Reputation
    badders's Avatar
    Join Date
    Apr 2007
    Location
    Cumbria
    Posts
    85
    Thank Post
    22
    Thanked 5 Times in 4 Posts
    Rep Power
    12

    Default

    Smoothwall is set to use NTLM identification.
    Last edited by badders; 20-11-2009 at 03:24 PM. Reason: Wrong info

  6. #6

    Reputation

    Join Date
    Oct 2005
    Posts
    77
    Thank Post
    5
    Thanked 2 Times in 2 Posts
    Rep Power
    10

    Default

    Change it to NTLM authentication and hey-presto! I bet it will work...

    Actually... scrap that. NTLM identification should work too...
    Last edited by pantscat; 20-11-2009 at 03:44 PM. Reason: Bad advice!

  7. #7

    Reputation Reputation
    badders's Avatar
    Join Date
    Apr 2007
    Location
    Cumbria
    Posts
    85
    Thank Post
    22
    Thanked 5 Times in 4 Posts
    Rep Power
    12

    Default

    Tried both NTLM authentication and NTLM identifcation, a guest trying to access the internet still gets the unauthenticated ip/ username not allowed. I was expecting a popup box from smoothwall asking for a username password if the logged on account is not located in AD. Is this possible?

  8. #8


    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    2,489
    Thank Post
    272
    Thanked 342 Times in 259 Posts
    Rep Power
    78

    Default

    OOh... guest.. hmm. If they are not authed, the smoothie would probably pass the "who are ye request" back to the Ruckus box, and it may get filtered there. A tough one.

    Maybe we can set this situation up at BETT if we can find an AD. Or perhaps we can borrow a ruckus for 5.

  9. #9

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    2,926
    Thank Post
    8
    Thanked 351 Times in 298 Posts
    Rep Power
    79

    Default

    Windows will helpfully return the details of the current user. You will need to use basic authentication to get IE to prompt. We had to run an additional instance of smoothwall due to only being able to use one auth method.

  10. #10


    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    2,489
    Thank Post
    272
    Thanked 342 Times in 259 Posts
    Rep Power
    78

    Default

    ..which we promise to fix ASAP (we're working on it, honest )

  11. #11

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    Edu-IT's Avatar
    Join Date
    Nov 2007
    Posts
    4,023
    Thank Post
    196
    Thanked 287 Times in 267 Posts
    Rep Power
    76

    Default

    Quote Originally Posted by tom_newton View Post
    OOh... guest.. hmm. If they are not authed, the smoothie would probably pass the "who are ye request" back to the Ruckus box, and it may get filtered there. A tough one.

    Maybe we can set this situation up at BETT if we can find an AD. Or perhaps we can borrow a ruckus for 5.
    You could use the one on the EG stand?

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Replies: 19
    Last Post: 14-03-2010, 06:31 PM
  2. Ruckus Managed Wireless Causing A Ruckus!
    By CPLTD in forum Our Advertisers
    Replies: 4
    Last Post: 21-08-2009, 09:25 AM
  3. Caretakers wlan
    By blacksheep in forum General Chat
    Replies: 36
    Last Post: 01-05-2009, 03:02 PM
  4. WLAN suggestions
    By Domino in forum Networks
    Replies: 18
    Last Post: 25-10-2007, 12:29 PM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts