Jump to content

Recommended Posts

Posted
I gave up on Ruckus guest access as it only seems to work if it can be arsed. Works on iPads most the time, macs sometimes, Windows phones with a pause and android phones if the wind is blowing in the right direction. We just made a WLAN with isolated clients and rolled the key out to the students to use. We do use guest access for actual guests to the building though just to keep tabs on it.
Posted
I gave up on Ruckus guest access as it only seems to work if it can be arsed. Works on iPads most the time, macs sometimes, Windows phones with a pause and android phones if the wind is blowing in the right direction. We just made a WLAN with isolated clients and rolled the key out to the students to use. We do use guest access for actual guests to the building though just to keep tabs on it.

 

What version of Ruckus firmware are you using because Ruckus guest access works fantastically for us. I've set it up so that either IT, reception or the librarian can issue guest passes with ease. It works just fine on iPads, iPhones, Macs, and Windows 7, 8, and 8.1. Haven't tried it on a range of Android devices, but despite the wide range of hardware and OS builds out there with the thousands of possible configurations, it should still work fine on most.

Posted
I don't have the version at hand but updated it about 4 weeks ago to the latest version. Sometimes it worked but often it just did not want to know. Also students bringing in Macs with admin passwords they did not know was painful. I think the final straw for me was when quite a few students wanted to use Surface RT's.
Posted
I don't have the version at hand but updated it about 4 weeks ago to the latest version. Sometimes it worked but often it just did not want to know. Also students bringing in Macs with admin passwords they did not know was painful. I think the final straw for me was when quite a few students wanted to use Surface RT's.

 

I suspect you might be talking about the Zero-IT config rather than the Guest WLAN feature in Ruckus? Otherwise, I don't know why a student lacking an admin password on a computer would have anything to do with it?

Posted (edited)
Hmm I feel I am so near to getting this working, yet so far!

 

I've got AD authentication working, and using the youtube example above I've managed to get a hotspot service set up and zero-it provisioning working, with a WLAN for staff and another for students.

 

This seems to work, a user select the 'open' wlan and then when any web page is requested the authentication page appears. After successful authentication the zero-it installer comes in and adds the correct WLAN on the test pc (in this case an iMac).

 

But thats where it stops, the mac stays connected to the hotspot wlan and ignores the specific wlan that is assigned to the user's group. The zero it part seems to configure this correctly and thats where it falls apart as you can't go any further!

 

Sheridan, this behaviour is the default for most devices. They will keep the WiFi SSID that you are using for the provisioning unless you remove it from the memory of the device (Preferred Networks on a Mac, and you have to tell iOS to "forget" the provisioning network). In fact, I find that open (non-secured) SSIDs are usually preferred by many devices when they are aware of multiple SSIDs in the area they can access. We made this step part of our BYOD setup instructions for students and staff.

 

Another method that we have used is to setup the "open" or provisioning WLAN to be used for enrolling iPads and Macs to our MDM system. The MDM system then installs the appropriate WiFi profile. This isn't making use of Zero-IT, but we switched to this because it gave us a bit more control over everything. However, the end-user still needs to tell their device to "forget" the provisioning WLAN or they will keep connecting back to it.

 

This isn't the fault of the Ruckus WiFi system though.

Edited by seawolf
Posted
Has anyone implemented a robust byod system with anything like Aruba or a similar competitor?

 

I share your frustrations as well on setting up BYOD and we use Aruba.

 

I'm still trying to get my head around offering a simple, secure guest wireless system.

 

Aruba works well but I'm having difficulty setting up VLANs and and the sheer complicatedness of it all.

 

Currently we use a transparent Smoothwall proxy, Aruba Captive Portal and DHCP MAC address filtering. It works and is rock solid but a lot of admin and we have no tracking of devices. That worries me.

Posted
We have given up with Ruckus after 2 years of trying to get it working properly and are now heading down the Meraki route now as we can then see what websites that the students go on in case of issues. Having spent 2 days on trying to get the 2 test APs sent out to us by Cisco, we have built a new DHCP server running 2012 plugged into the transparent proxy via a mini switch which goes into the core switch and out that way. Bit of a hassle to set up, but with more than one brain and a few hours with the door shut it all started working as expected. (stupidly used a desktop and not a rack mountable PC as a base so we now have to work out where to put it...)
Posted
Its stories like this that are making me consider Areohive, no need for captive portal. You can use PPSK and give everyone their own personal key on the same secure SSID, AD membership can be used to define what VLAN they get put on. You can also set a concurrency limit to stop them from sharing keys. Not that I'm looking at BYOD per se but saw the uses for guest access.
Posted
Its stories like this that are making me consider Areohive, no need for captive portal. You can use PPSK and give everyone their own personal key on the same secure SSID, AD membership can be used to define what VLAN they get put on. You can also set a concurrency limit to stop them from sharing keys. Not that I'm looking at BYOD per se but saw the uses for guest access.

 

You can do the same with Ruckus.

 

It's stories like this that make me think some people have misconfigured networks and they would have the same problems with ANY system....

Posted
Thanks for the info, as you can guess I have enough info on the Areohive system to make a judgement on that. Hopefully I will be in the same position with Ruckus by the end of next week.
Posted
Just looking through the manual and I can see where some people here have been having problems particularly with iOS devices. As they always want to connect to the open SSID, this is almost the exact same issue I had with Meru at my previous establishment. Looking at the Ruckus solution I would not be going down the zero it route, and the need to have dedicated SSIDs for each role all seems messy when compared with Areohive. It definitely gives me a new list of questions when I am having my Ruckus demo so thanks again @seawolf
Posted
Just looking through the manual and I can see where some people here have been having problems particularly with iOS devices. As they always want to connect to the open SSID, this is almost the exact same issue I had with Meru at my previous establishment. Looking at the Ruckus solution I would not be going down the zero it route, and the need to have dedicated SSIDs for each role all seems messy when compared with Areohive. It definitely gives me a new list of questions when I am having my Ruckus demo so thanks again @seawolf

 

No worries. The open SSID problem is easily taken care of by simply forgetting the provisioning network once everything is configured. We didn't find it to be a problem as we put this step in our BYOD instructions.

Posted

We have BYOD and Guest wlans working on our Ruckus/Smoothwall setup and it's fine but it does require the use of VLANs. A very good guide was written by someone on here - and I apologise to him profusely for remembering his name, but it did take a bit of time and patience.

 

As for the self provisioning - it works on iOS devices but you need to 'forget' the provisioning WLAN as others have said. I couldn't get it to work on Android devices at all, although that was quite a few months ago and it may be better now.

Posted (edited)

Document updated for you all.

 

We don't self provision due to some devices accepting the config file and others not so just having a WLAN where people can hop on and off would be the best idea.

 

Our BYOD WLANs aren't secure as there is a problem with 802.1x and smoothwall. If you read some of my posts on here you will find that ruckus cannot use the smoothwall as a radius server as the authentication groups don't work correctly when looking back at AD however i have heard this is going to change in the future.

Setting up BYOD with Smoothwall & Ruckus 04.03.14.docx

Edited by timbo343
  • Thanks 2
  • 5 weeks later...
Posted
Has anyone actually managed to get Ruckus (Guest access) and iPads working with a WPAD to provide Internet access through a proxy? I have everything working as it should except for the fact that browsing the Internet (Safari or Chrome) fails for any site outside of our network. Bizarrely, using other apps (like Facebook, Twitter, Skype, etc) all work correctly!?!
Posted (edited)
You need to get your head round that first, took me a while as well and I believe a number of posts on here will point you in the right direction.

 

But, in a nutshell ;) - You'll need switches that are managed, you'll need to setup the VLANs on all your switches (obviously, only those that will have traffic flowing for each VLAN), 'tag' the trunks/uplinks to each Edge switch with the associate VLANS, setup DHCP helper on your Core Switch for the VLANs to point at your DHCP server, Setup a DHCP scope for the BYOD with the gateway set to the IP address of your Core Switch, 'tag' the port that has the AP plugged into for your guest VLAN (you'll need to tag it with the other VLANs as well if you have other SSIDs for on it and management so that ZoneDirector can still access it), setup the SSID on the ZoneDirector to be associated with a particular VLAN and, errr, that is about it. I think, working from memory. May have missed out a step but hopefully it'll help.

 

Pete

 

I've done vLans with UnManaged Switches (HP 1810's & HP 1800's) if you can do IP Routing on the core switch for DHCP relay this will be fine.

 

We didn't have IP Routing on any switches at previous place so I just set the SonicWall appliance we had with sub sub interfaces for the vLans and used the built-in DHCP and basic filtering for the BOYD devices and it was good enough for us.

 

We used the domain DHCP for college devices and the SonicWall for BOYD DHCP as getting the DHCP relay working on the SonicWall and talking to the Domain DHCP server was a bain.

Edited by Davit2005
Posted

There are couple of bits in this thread which I am responding to in 1 place:

 

>>Just looking through the manual and I can see where some people here have been having problems particularly with iOS devices. As they always want to connect to the open SSID.

Have you tried the on-boarding feature that is available in 9.6 onward? This removes the need to use a Hotspot WLAN for Zero-IT/D-PSK, just a single open WLAN for guest access and Zero-IT which is easier. I find that once the iOS device has its D-PSK and the user connects to the Secure WLAN then the device remembers it rather than jumping back to the open provisioning WLAN. In 9.8 (currently schedule for general availability May) you can also have 3 options for this on boarding portal - guest only, guest+Zero-IT, Zero-IT only. If its still an issue then you will have to get users do the "Forget WLAN" as unfortunately we can't force iOS devices to prioritise the WLAN connection order like you can on computers.

 

>>Has anyone actually managed to get Ruckus (Guest access) and iPads working with a WPAD to provide Internet access through a proxy? I have everything working as it should except for the fact that browsing the Internet (Safari or Chrome) fails for any site outside of our network. Bizarrely, using other apps (like Facebook, Twitter, Skype, etc) all work correctly!?!

>>P.S. Everything works fine if I manually enter the URL to the WPAD in the WiFi settings.

In the good old days when I was a young lad (pre-iOS 4.2) WPAD worked perfectly - just enabled HTTP Proxy / Auto and it would find WPAD host/file via DNS. Apple in their infinite wisdom decided to change this in subsequent versions of iOS so you have to enable Auto AND put the full WPAD URL in as it no longer uses DNS lookup (so no longer really "Auto")!! This is the issue with using "consumer" devices in an "Enterprise" network i.e. they are designed for consumer use/features (don't think many people have a non-transparent proxy at home). Its then always the Enterprise network vendors fault when something doesn't work... Android doesn't natively support WPAD so yuo can't even have one type of provisioning configuration for all devices unless you overlay an MDM solution.

 

I use Freeproxy for my WPAD testing with Chrome and it works Ok. When troubleshooting WPAD issues always start with ah very basic WPAD file and work up to a more complex one as you verify things work. I wrote a Ruckus WPAD deployment App Note which should be available through your Ruckus partner - that has a lot of good info in it. Some additional tips:

- If you are using WPAD on a WLAN with client isolation and the proxy is on the same subnet as clients/ZD then you need to add an Allow rule for the proxy IP to the Guest Access Restricted Subnets

- Similarly if you ar eusign L3/L4 Access Controls on the WLAN you need to add and allow rule for the proxy IP

- If you are using Guest Access or Web Portal then you need to add an exception for the ZD IP in the WPAD file so it can access it directly for redirection to work properly

 

Ultimately, either scrap your non-transparent proxy and move to a transparent proxy which solves all these client config issues, else have transparent proxy redirect your users to the non-transparent proxy (only works for HTTP traffic as I tested it and doesn't support proxy web authentication). I tested using a Microtik RB750 which has transparent redirection and NAT features to achieve this - think you can also do it on Smoothwall and Squid (which does support transparent HTTPS is you install the SSL Bump module). If you need any details on how I set it up with my RB750 send me a PM.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...