Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

Internet Related/Filtering/Firewall

Internet Related forum sponsored by
Internet Related Forum Sponsored by Smoothwall

Woes with your internet connection or maybe having filtering issues (that are not security related) post them here.

Go Back   EduGeek.net Forums > Technical > Internet Related/Filtering/Firewall
Reply
 
LinkBack Thread Tools Search Thread
Sponsored Links
Old 20-11-2009, 11:06 AM   #1
 
badders's Avatar
 
Join Date: Apr 2007
Location: Cumbria
Posts: 48
uk uk england
Thanks: 16
Thanked 3 Times in 2 Posts
Rep Power: 6 badders is on a distinguished road
Default Smoothwall/Ruckus guest WLAN

Is anybody using Smoothwall and Ruckus and managed to get a guest WLAN working. We have no problem setting up a school WLAN for domain attached devices, but would like to enable students to use their own laptops to access the internet by authenticating against thier AD account. We've got as far as setting up another WLAN for students that asks for authentication using the Ruckus portal to authorize the device but then when we try to browse the internet Smoothwall blocks access due to the local user of the laptop being an unauthorised user. Would we have to use VLans with a separate DHCP server?
  Reply With Quote
Old 20-11-2009, 11:37 AM   #2
 
tom_newton's Avatar
 
Join Date: Sep 2006
Location: Leeds
Posts: 1,958
uk uk yorkshire
Thanks: 171
Thanked 260 Times in 194 Posts
Rep Power: 59 tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of
Default

I wonder how the traffic is hitting Smoothie... if you want authentication, non-domain users *should* get a popup if they are presented with an ntlm handshake. Is ruckus proxying the traffic first?

You could potentially give "unauthenticated IPs" some very limited web access? You'd lose a bit of visibility though.
  Reply With Quote
Old 20-11-2009, 01:51 PM   #3
 
badders's Avatar
 
Join Date: Apr 2007
Location: Cumbria
Posts: 48
uk uk england
Thanks: 16
Thanked 3 Times in 2 Posts
Rep Power: 6 badders is on a distinguished road
Default

We.ve manually set smoothwall as the proxy in the non-domain client, but we don't seem to get a pop-up asking for username/password. Would this be related to the SSL login settings in smoothwall?
  Reply With Quote
Old 20-11-2009, 03:40 PM   #4
 
tom_newton's Avatar
 
Join Date: Sep 2006
Location: Leeds
Posts: 1,958
uk uk yorkshire
Thanks: 171
Thanked 260 Times in 194 Posts
Rep Power: 59 tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of
Default

Are you using NTLM on the domain?
  Reply With Quote
Old 20-11-2009, 04:23 PM   #5
 
badders's Avatar
 
Join Date: Apr 2007
Location: Cumbria
Posts: 48
uk uk england
Thanks: 16
Thanked 3 Times in 2 Posts
Rep Power: 6 badders is on a distinguished road
Default

Smoothwall is set to use NTLM identification.

Last edited by badders; 20-11-2009 at 04:24 PM.. Reason: Wrong info
  Reply With Quote
Old 20-11-2009, 04:33 PM   #6
 
pantscat's Avatar
 
Join Date: Oct 2005
Posts: 47
uk
Thanks: 5
Thanked 1 Time in 1 Post
Rep Power: 0 pantscat is an unknown quantity at this point
Default

Change it to NTLM authentication and hey-presto! I bet it will work...

Actually... scrap that. NTLM identification should work too...

Last edited by pantscat; 20-11-2009 at 04:44 PM.. Reason: Bad advice!
  Reply With Quote
Old 01-12-2009, 10:00 AM   #7
 
badders's Avatar
 
Join Date: Apr 2007
Location: Cumbria
Posts: 48
uk uk england
Thanks: 16
Thanked 3 Times in 2 Posts
Rep Power: 6 badders is on a distinguished road
Default

Tried both NTLM authentication and NTLM identifcation, a guest trying to access the internet still gets the unauthenticated ip/ username not allowed. I was expecting a popup box from smoothwall asking for a username password if the logged on account is not located in AD. Is this possible?
  Reply With Quote
Old 01-12-2009, 03:31 PM   #8
 
tom_newton's Avatar
 
Join Date: Sep 2006
Location: Leeds
Posts: 1,958
uk uk yorkshire
Thanks: 171
Thanked 260 Times in 194 Posts
Rep Power: 59 tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of
Default

OOh... guest.. hmm. If they are not authed, the smoothie would probably pass the "who are ye request" back to the Ruckus box, and it may get filtered there. A tough one.

Maybe we can set this situation up at BETT if we can find an AD. Or perhaps we can borrow a ruckus for 5.
  Reply With Quote
Old 01-12-2009, 03:43 PM   #9
 
DMcCoy's Avatar
 
Join Date: Oct 2005
Location: Isle of Wight
Posts: 2,674
uk uk isle of wight
Thanks: 6
Thanked 300 Times in 254 Posts
Rep Power: 69 DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future DMcCoy has a brilliant future
Default

Windows will helpfully return the details of the current user. You will need to use basic authentication to get IE to prompt. We had to run an additional instance of smoothwall due to only being able to use one auth method.
  Reply With Quote
Old 01-12-2009, 05:24 PM   #10
 
tom_newton's Avatar
 
Join Date: Sep 2006
Location: Leeds
Posts: 1,958
uk uk yorkshire
Thanks: 171
Thanked 260 Times in 194 Posts
Rep Power: 59 tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of
Default

..which we promise to fix ASAP (we're working on it, honest )
  Reply With Quote
Old 01-12-2009, 08:48 PM   #11
 
Edu-IT's Avatar
 
Join Date: Nov 2007
Posts: 3,451
uk
Thanks: 183
Thanked 226 Times in 211 Posts
Rep Power: 55 Edu-IT has much to be proud of Edu-IT has much to be proud of Edu-IT has much to be proud of Edu-IT has much to be proud of Edu-IT has much to be proud of Edu-IT has much to be proud of Edu-IT has much to be proud of Edu-IT has much to be proud of Edu-IT has much to be proud of Edu-IT has much to be proud of
Default

Quote:
Originally Posted by tom_newton View Post
OOh... guest.. hmm. If they are not authed, the smoothie would probably pass the "who are ye request" back to the Ruckus box, and it may get filtered there. A tough one.

Maybe we can set this situation up at BETT if we can find an AD. Or perhaps we can borrow a ruckus for 5.
You could use the one on the EG stand?
  Reply With Quote
Reply

EduGeek.net Forums > Technical > Internet Related/Filtering/Firewall

Similar Threads
Thread Thread Starter Forum Replies Last Post
RUCKUS help - Guest access & the internet via Proxy jamin100 Networks 15 01-10-2009 11:49 PM
Ruckus Managed Wireless Causing A Ruckus! CPLTD Our Advertisers 4 21-08-2009 09:25 AM
Caretakers wlan blacksheep General Chat 36 01-05-2009 03:02 PM
WLAN suggestions Domino Networks 18 25-10-2007 12:29 PM


Tags
guest wlan , ruckus , smoothwall


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:01 PM.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.
Copyright EduGeek.net




website uptime

© 2005 - 2009 EduGeek.net
SERVER: 4
no new posts