tom_newton Posted February 28, 2013 Posted February 28, 2013 Folks, Anyone using 802.1x to secure their wireless? I'd be interested to hear your thoughts on how well it works, and to learn how you have it set up - particularly if you're a Smoothwall user... Tom
cscott Posted March 1, 2013 Posted March 1, 2013 Hi Tom, yes we are, works really well. Wireless access points are configured for 802.1x authentication against a RADIUS server, it's only used by devices owned by us which are all joined to our windows domain and we have our Smoothwall configured for transparent authentication. Really I suppose best thing I can say is "it works" doesn't cause us any bother.
DMcCoy Posted March 1, 2013 Posted March 1, 2013 I don't know if it's still there, but a couple of years ago I was using 802.1x for both wired and wireless devices, AD credentials for wireless users to connect which dropped them into a vlan connected to a smoothwall box. 802.1x works on most wireless devices, setting proxies and app/proxy support etc are still an issue.
MYK-IT Posted March 1, 2013 Posted March 1, 2013 Currently use 802.1x EAP for our domain joined laptops with Ruckus authenticating against our RADIUS Server then assigning to appropriate VLAN that is configured on our Smoothwall UTM-1000 appliance. Not tried on wired and/or non-domain devices as yet.
cpjitservices Posted March 1, 2013 Posted March 1, 2013 not a Smoothie user here but have implemented it in our PFSense/Juniper based network... We use PacketFence PacketFence: Open Source NAC (Network Access Control) Works a charm!
Duke5A Posted March 1, 2013 Posted March 1, 2013 We're using it on a managed Cisco wireless network. A pair of W2k8 R2 Radius servers are used to handle authentication against AD to join the network and a pair of Squid proxies setup for Kerberos handle student and staff web traffic. When it was originally setup the Radius server would allow you to join based off of computer and/or user credentials. I discovered that students were using their AD accounts to join private phones to our network. To stop it I changed the wireless policy for student computers in AD to only use computer authentication and then denied the top level student user group access in the Radius policy. All in all, the setup works great.
AngryTechnician Posted March 1, 2013 Posted March 1, 2013 (edited) Yes, we use it for almost all wireless devices. Windows laptops authenticate using EAP-TLS with their machine certificate from the on-site CA, while iPads and staff-owned devices use a username & password via EAP-MSCHAPv2. Different VLANs are assigned depending on Windows group membership of the supplied account (accounts not in an authorised group are rejected). The RADIUS server is a Sever 2008 R2 box with the NPS role installed. We are a Smoothwall user, currently using a mixture of Kerberos and IP auth (plus NTLM just for Java, because Java sucks). Edited March 1, 2013 by AngryTechnician
tom_newton Posted March 1, 2013 Author Posted March 1, 2013 Interesting - thanks folks. @AngryTechnician (or anyone else authing ipads etc like this) - would you be interested in talking to some of my developer friends, we have a better plan than putting folk in vlans based on auth, which would involve passing the 802.1x auth straight to the smoothie for fully granular filtering and logging, but we need to know that our solution would fit into our customers' networks. Drop me a PM if you'd be willing to spare 30 mins
brainchylde Posted March 2, 2013 Posted March 2, 2013 Interesting - thanks folks. @AngryTechnician (or anyone else authing ipads etc like this) - would you be interested in talking to some of my developer friends, we have a better plan than putting folk in vlans based on auth, which would involve passing the 802.1x auth straight to the smoothie for fully granular filtering and logging, but we need to know that our solution would fit into our customers' networks. Drop me a PM if you'd be willing to spare 30 mins Interesting as we are going to be looking at new filtering soon and a larger wireless deployment. We have 802.1x at the moment in the form of Eduroam and many of my counterparts in our sector are struggling with the filtering issue. We have many thousands of students and the provision of wireless seamlessly is a big thing for us. Eduroam complicates the matter as we don't want to break the roaming experience for users by placing proxy settings on the device.
tom_newton Posted March 2, 2013 Author Posted March 2, 2013 Drop me an email brainchylde I think we might have something fun brewing :-)
brainchylde Posted March 2, 2013 Posted March 2, 2013 Drop me an email brainchylde I think we might have something fun brewing :-) Done
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now