Jump to content
  • entry
    1
  • comments
    6
  • views
    216

BYOD with Smoothwall & Ruckus


Like most schools we have been looking for a solution for BYOD devices for some time.

 

We have been using Smoothwall for web filtering for a number of years, together with Ruckus wireless.

 

Although the combination of transparent proxy and SSL log on page in smoothwall with no wireless security works well, it does have the issue of having to enter log on details every time a device is used, and of course apps don't always display the log on page, or give any indication that authentication has timed out.

 

We are now researching mobile devices, and have been allowed to trail a class set of ipads by Jigsaw 24. Before we gave students ipads we felt it was a good idea to allow the staff to get us to them first. The 10 ipads deployed over Christmas brought issues of "Wireless dropping out" which actually is authentication has timed out and the app in use doesn't say so to a head.

 

When we heard about Smoothwall's BYOD project I asked to be considered as a test site. A week later I was invited to join a production team meeting on the project....

 

The new Smoothwall system builds a radius server into the UTM box. To the end user, they connect to a wireless network, get asked for a username and password and have to confirm they are happy with the certificate used for the 802.1X network. That's it, every time the device connects the stored credentials are used to connect and Smoothwall has the authentication for the correct groups etc.

 

To the network manager, this is a really quick and simple fix for a big problem. Any wireless that supports radius authentication and accounting should work. The Smoothwall box need to be the DHCP server and default route for the BYOD wireless network which is how the system works. Only radius authed clients get a ip address from DHCP, and the internal logic in Smoothwall then has the User.

 

Over Easter members of Smoothwall's Development team paid a visit to Sunny Ashbourne and left us a working test box. Installation basically consisted of a new wireless SSID on the ruckus system, assigned to a unused vlan which it then connected to the UTM, add the ip address of the Smoothwall to Ruckus for radius, and the Ruckus zonedirector ip to Smoothwall input shared secret and done!

 

We thought all had gone too well, and expected the whole thing to fall over within days...

 

This morning was I day... 30 ipads deployed to students, and I am happy to say that apart from a couple of devices that didn't like Live@edu everything worked perfectly.

 

I look forward to moving this onto our production smoothwall box when the beta is released which I suspect should be quite soon now.

 

My thanks to the Staff at Smoothwall for their assistance.

6 Comments


Recommended Comments

tom_newton

Posted

Thanks for the feedback Rob, we're really grateful for the effort you went to to accommodate our developers for a day or so :)
john

Posted

Sounding good work from the team as ever :) Well done to all involved :)
timbo343

Posted

Wow, liking this, cant wait for it to apear to the resr of us, then ill have to update my how to guide on here.
AndyNDuffy

Posted

Am really looking forward to upgrading when its ready. Like the author we currently have a similar BYOD solution using a HP managed wireless solution with no security on the SSID and presenting users with the redirection page but we also have the free version of Smoothwall running DHCP.

 

I would be really keen to hear how others are managing the whole BTOD thing - I'd like to stay with Smoothwall if I can but if someone has a good alternative I'd like to hear about it.

 

Cheers

Andy

tom_newton

Posted

Patches in test right now. Will keep you posted on release, fire me your details if you want to be in the early adopters' list :)
timbo343

Posted

Patches in test right now. Will keep you posted on release' date=' fire me your details if you want to be in the early adopters' list :)[/quote']

 

Yep, would like to be an early adopter here. What details do you need?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...