Jump to content

Recommended Posts

Posted

nslookup on the client gives:

 

Nslookup google.co.uk

Server: google-public-dns-a.google.com

Address: 8.8.8.8

 

Non-authoritative answer:

Name: google.co.uk

addresses: 173.194.44.84, 173.194.44.88, 173.194.44.95

 

Also, i can ping google.co.uk and it pings fine.

 

Im my Services >> DNS >> DNS Proxy i have got:

 

Interfaces:

Port1 - Main network domain = ticked

Port 1-1_BYOD-Staff = Ticked

Port 1-2_BYOD_Student = Ticked

 

Advanced

Forward SRV & SOA Records = Not ticked

 

Just changed DHCP settings so in Services >> DHCP >> DHCP Services they now read for BYOD-Staff

Network: 192.168.12.0

Netmask: 255.255.252.0

Primary DNS: 172.16.24.8

Default Gateway: 192.168.12.1

Enabled: Ticked

 

- Tested... nslookup:

cannot find server for address 172.16.24.8

 

Setting Pri DNS back to 8.8.8.8

Posted

If you're using IE on the XP laptop it won't support transparent HTTPS connections if HTTPS filtering is turned on for the web proxy auth method. Try using Firefox/Chrome etc and https google/gmail should work.

 

Have a look at the web filter logs, if it says something along the lines of "Transparent HTTPS connection not supported by web client" then that's the issue.

  • Thanks 1
Posted
Now its working you might want to change the subnet mask in ruckus to just allow the smoothwall ip. Change the /22 to/32 and any other ip will be blocked, without stopping smoothwall auth.
  • Thanks 1
  • 1 month later...
  • 3 months later...
Posted
Just wanted to say a MASSIVE thank you to Timbo343 for the guide that you wrote. I followed it to the T and my Ruckus/Smoothwall setup now works flawlessly. Just need to start tagging ports now....
  • 2 months later...
Posted

Dear all,

 

Thanks for the guide really helpful. However, with your setup I have to authenticate twice, once to Ruckus, once to Smoothwall. What is the best method to only have to authenticate once?

 

Thanks in advance,

Bobby

Posted
You could do an ident by location, config ruckus to use zero-it where the autoconfig app installs to your device or you can get 802.11x working on the smoothwall. Ive not gone down the 802.11x route as i cannot get the smoothwall to lookup the groups the users are part of so it sees everyone as default so prevents you from allowing say Post16 onto the post16 SSID.
  • 8 months later...
Posted
Ok, ive decided to get the Smoothie to dish out the DHCP addresses which is working all well and good and change the settings on the core switch with the settings you suggested.

 

On the smoothie i have got:

 

Networking > Interfaces

Ive created virtual devices on Port 1

so i have got:

Port1 - Main Domain

172.16.24.8

255.255.248.0

 

port1-1 - BYOD-Staff

192.168.12.1

255.255.252.0

 

Port1-2 - BYOD-Students

192.168.16.1

255.255.248.0

 

Services > DHCP Server

BYOD-Staff

Network: 192.168.12.0

Netmask: 255.255.252.0

Default Gateway: 192.168.12.1

Pri DNS: 8.8.8.8

Sec DNS: 8.8.4.4

 

BYOD-Students

Network: 192.168.16.0

Netmask: 255.255.248.0

Default Gateway: 192.168.16.1

Pri DNS: 8.8.8.8

Sec DNS: 8.8.4.4

 

Ive got the Auth page on ruckus to display and then when i authenticate fine i cannot get out.

 

How do i route the traffic from the 192 addresses to the net through the filtering?

 

I am trying to follow this guide but am having trouble with the smoothwall interfaces. If I try and add another it won't allow me to choose a parent interface. The parent interface is setup as a basic interface. Does anyone know where I may be going wrong?

Posted
Not too sure where you are going wrong. Ive just created a new vlan2.1 on interface 2 with the role as basic interface. Just changed my interface 5 to basic and i can now select it. Maybe @CJF might be able to help when he next comes on.
Posted
Not too sure where you are going wrong. Ive just created a new vlan2.1 on interface 2 with the role as basic interface. Just changed my interface 5 to basic and i can now select it. Maybe @CJF might be able to help when he next comes on.

 

I have recently spoken to smoothwall and they tell me it cant be done unless i add another nic. Basically because port 1 is our internal nic with an ip already set i cant create a sub virtual interface off this. Im sure i have done it before though because a parent interface implies child interfaces surely?

Posted
That's strange. My interface 1 is connected to our core switch and within Interface 1 is all the VLANs for the wireless too. Interface 4 for me is our external interface which connects to the BT FTTC modem thingy. That's all i have connected to the smoothwall.
  • 1 month later...
Posted
I am having the same issues that timbo343 had originally. I don't get the SSL login page but I am able to ping google. I have configured the networks in restricted subnets and have provided external access for the relevant networks. DNS proxy is correct and I have also tried turning off https but it doesn't do anything. I get a server not found in firefox. The odd thing is I couldn't get to the ruckus auth page originally so I added a static dns entry for ruckus and that worked, so I thought I'll add a static entry for smoothwall which did look like it was going to work as in it took longer to give me the page not found message lol
  • 5 months later...
Posted
We have been trying to set up a BYOD VLAN for a while which means the people connected to it will get unfiltered internet while still going through the smoothwall box. However unlike timbo343 we didn't set up any VLANs before we got a smoothwall box and we can't figure out how to set it up with it all integrated into our system's. We have tried a few different options from different posts with no such luck. If anybody has any idea's please can you suggest them as it has now been on our jobs to do list for a while.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...