Jump to content

Recommended Posts

Posted

Folks,

 

Anyone using 802.1x to secure their wireless?

I'd be interested to hear your thoughts on how well it works, and to learn how you have it set up - particularly if you're a Smoothwall user...

 

Tom

Posted

Hi Tom, yes we are, works really well.

 

Wireless access points are configured for 802.1x authentication against a RADIUS server, it's only used by devices owned by us which are all joined to our windows domain and we have our Smoothwall configured for transparent authentication. Really I suppose best thing I can say is "it works" doesn't cause us any bother.

Posted
I don't know if it's still there, but a couple of years ago I was using 802.1x for both wired and wireless devices, AD credentials for wireless users to connect which dropped them into a vlan connected to a smoothwall box. 802.1x works on most wireless devices, setting proxies and app/proxy support etc are still an issue.
Posted

Currently use 802.1x EAP for our domain joined laptops with Ruckus authenticating against our RADIUS Server then assigning to appropriate VLAN that is configured on our Smoothwall UTM-1000 appliance.

 

Not tried on wired and/or non-domain devices as yet.

Posted
We're using it on a managed Cisco wireless network. A pair of W2k8 R2 Radius servers are used to handle authentication against AD to join the network and a pair of Squid proxies setup for Kerberos handle student and staff web traffic. When it was originally setup the Radius server would allow you to join based off of computer and/or user credentials. I discovered that students were using their AD accounts to join private phones to our network. To stop it I changed the wireless policy for student computers in AD to only use computer authentication and then denied the top level student user group access in the Radius policy. All in all, the setup works great.
Posted (edited)

Yes, we use it for almost all wireless devices. Windows laptops authenticate using EAP-TLS with their machine certificate from the on-site CA, while iPads and staff-owned devices use a username & password via EAP-MSCHAPv2. Different VLANs are assigned depending on Windows group membership of the supplied account (accounts not in an authorised group are rejected).

 

The RADIUS server is a Sever 2008 R2 box with the NPS role installed.

 

We are a Smoothwall user, currently using a mixture of Kerberos and IP auth (plus NTLM just for Java, because Java sucks).

Edited by AngryTechnician
Posted

Interesting - thanks folks.

@AngryTechnician (or anyone else authing ipads etc like this) - would you be interested in talking to some of my developer friends, we have a better plan than putting folk in vlans based on auth, which would involve passing the 802.1x auth straight to the smoothie for fully granular filtering and logging, but we need to know that our solution would fit into our customers' networks. Drop me a PM if you'd be willing to spare 30 mins

Posted
Interesting - thanks folks.

@AngryTechnician (or anyone else authing ipads etc like this) - would you be interested in talking to some of my developer friends, we have a better plan than putting folk in vlans based on auth, which would involve passing the 802.1x auth straight to the smoothie for fully granular filtering and logging, but we need to know that our solution would fit into our customers' networks. Drop me a PM if you'd be willing to spare 30 mins

 

Interesting as we are going to be looking at new filtering soon and a larger wireless deployment. We have 802.1x at the moment in the form of Eduroam and many of my counterparts in our sector are struggling with the filtering issue. We have many thousands of students and the provision of wireless seamlessly is a big thing for us. Eduroam complicates the matter as we don't want to break the roaming experience for users by placing proxy settings on the device.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...