Jump to content

Recommended Posts

Posted (edited)

I've just submitted this to smoothwall support, but wondered if anyone else has done this here?

 

I'm trying to show usernames on our smoothwall safegaurding reports. Currently domain users show fine on reports but our BYOD users just show as an IP address.

 

I've setup both Radius authentication and accounting our the Unify BYOD Wi-Fi side as so:

 

 

Image1.jpg

 

so .10 is our radius server and .6 is our smoothwall server.

 

But I don't know what to do on the Smoothwall side. Anyone done this before?

Edited by supportman
Posted
Have you set up your authentication policies for BYOD network?

 

Yeah this is what you need to be looking at - You need to enable 802.11x & then have core auth active on your BYOD network in Smoothwall as that's how it pulls the username, not RADIUS accounting.

  • Thanks 2
Posted (edited)

We push our accounting to central radius servers, radius servers then to relevant smoothwall, very simple to setup and works well. (you do have to add nps servers in as authorised clients on the BYOD page on smoothwall)

 

Like others say web proxy should be on core auth.

 

I had UniFi previously working for this but just removed our last controller so don’t have config to compare sadly.

 

The custom browser or browser extension isn’t needed for this, neither would be very feasible on a BYOD device tbh.

 

Happy to have a team’s call if we can help! PM me.

Edited by CrootUK
Posted (edited)
Sorry if being a sausage, but do you not want 1813 for accounting.

 

That's a very good point lol and probably why its not working! Don't forget to setup core authentication for your BYOD network. Should work fine then.

 

Also, make sure you have RADIUS Accounting (1813) and Authentication (1812) enabled on the correct port under 'Network' > 'Smoothwall Access'

Edited by Netwacky87
Posted
Have you set up your authentication policies for BYOD network?

 

Yeh sorry for being slow here, but our BYOD network is all setup and working great using a windows NPS radius server for authentication.

 

All I want to do is show the usernames in the smoothwall reports instead of the the IP addresses and I was told that radius accounting was the way to go with this. Is that not the case?

Posted
Are your BYOD users filtered based on their AD account they logged into the wifi with (assuming this is how your BYOD is set up)?
Posted
Are your BYOD users filtered based on their AD account they logged into the wifi with (assuming this is how your BYOD is set up)?

 

Yeh they authenticate with the NPS server and we set a rule that only certain AD groups (6th form and staff in this case) can connect to our BYOD Wi-Fi.

 

Problem is when the BYOD users show up in smoothwall reports, its just an IP address which is pretty useless for safeguarding stuff.

Posted
Yeh they authenticate with the NPS server and we set a rule that only certain AD groups (6th form and staff in this case) can connect to our BYOD Wi-Fi.

Problem is when the BYOD users show up in smoothwall reports, its just an IP address which is pretty useless for safeguarding stuff.

 

But is Smoothwall then wbefiltering users based on their AD account? Or does it filtered by location (so everyone on the BYOD gets the same filtering)?

 

I only ask because if you have got filtering based on username working but the usernames don't appear in the reports then somethings gone pretty weird and your probably stuck waiting for support to get back to you.

 

But if you're using ident by location rather than by username, then the answer (as DrCheese suggested) to change to core authentication so the smoothwall pulls the username from your NTFS to identify the users should fix it.

 

Although, hopefully smoothwall have gotten back to you by now and this is a moot point.

Posted
But is Smoothwall then wbefiltering users based on their AD account? Or does it filtered by location (so everyone on the BYOD gets the same filtering)?

 

I only ask because if you have got filtering based on username working but the usernames don't appear in the reports then somethings gone pretty weird and your probably stuck waiting for support to get back to you.

 

But if you're using ident by location rather than by username, then the answer (as DrCheese suggested) to change to core authentication so the smoothwall pulls the username from your NTFS to identify the users should fix it.

 

Although, hopefully smoothwall have gotten back to you by now and this is a moot point.

The BYOD users are using the transparent proxy currently.

 

Looks like I need to change our entire radius setup then! ouch

Posted (edited)
The BYOD users are using the transparent proxy currently.

 

Looks like I need to change our entire radius setup then! ouch

 

Transparent proxy is correct for BYOD, could you share some screenshots? as I am not convinced you need to change much at all.

 

Like I mentioned before happy to do a team’s call if your a school worker not an MSP lol… if its of help, i’m not from smoothwall or an MSP myself but we do use smoothwall in our schools so familiar with them.

Edited by CrootUK
  • Thanks 1
Posted

All that happens is an accounting packet gets sent, I would assume they read the username and framed IP, and tie the two up. Going back to my other post, are you sure, 100%, SW is accepting accounting on 1812 and not the standard 1813.

 

Transparent works, at least in Netsweeper which I imagine has a less refined (although functionally sound) RADIUS setup. Its a super basic concept.

Posted
The BYOD users are using the transparent proxy currently.

 

Looks like I need to change our entire radius setup then! ouch

 

As @CrootUK says, Transparent proxy is right for BYOD.

But what do you have auth set to currently? Needs to be core auth & then you point your Unifi controller at your smoothwall for Radius.

Posted (edited)
[ATTACH=CONFIG]73274[/ATTACH]

Big thanks for all your help with this one guys.

 

It was actually staring at me right in the face after smoothwall 2nd line support noticed the packets were arriving on port 1812 rather than 1813.

 

Its literally in the screenshot I posted although I think I was thrown off because Unify shows 1813 in the entry form but it was set to 1812.

 

I simply changed the radius accounting port to 1813 in our unify setup and its all working perfectly now. Simple as that!

 

Image2.jpg

 

We can now finally report safeguarding concerns for our BYOD network. A huge leap forward!

Edited by supportman
  • Thanks 1
Posted

Got it working finally using the correct port for radius accounting and adding to the Smoothwall firewall.

 

You can check in Smoothwall by going to Security >> User Activity

 

The IP's should now match a username if its working.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...