Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I'm going to have to rethink BYOD on our system as we can't get it to work on ruckus.

 

We have a simple, non-VLAN network (although split into several subnets) and the switches are a right mixture so adding a seperate VLAn for wireless will be tricky. But we do have a zonedirector and a smoothwall box. The ZD is has various AP's on all the subnet attached providing wireless for all of our domain PCs, and the smoothwall is behind our firewall and provides the filtering.

 

Is it possible to create a new WLAN on the ruckus, which uses the Smoothwall for DHCP/DNS and as its default gateway, allowing us to give either open access or some form of password protected access, allowing filtered internet access through smoothwall but keeping off our main network?

 

If any has got an idiot guide, I'd be grateful! I've tried various options but none have worked very well so far.

Posted (edited)

At Smoothwall we're currently in the last phases of a development which should solve exactly this problem for you. We're hoping to go into beta testing within three weeks.

 

Happy to discuss this in more detail with you if you'd like to know more and possibly help us during the beta testing programme.

 

Feel free to call / email

 

Phil

 

Philip SmithProduct Manager

 

[email protected]

+44 1489 886 100 Ext 545

Edited by philipksmith
Posted
That sounds ideal. I gather there is the facility to have DNS/DHCP on the smoothwall device, but our license obviously doesn't include this as its not appearing in any of the menu options.
Posted
@Sheridan which Smoothwall product are you using. Certainly with a UTM product this is very doable. Either with a SSL logon page, or with future developments 802.11x on the cards.
Posted
We've got the 1200 here, and I've found the ssl settings but its the dns and dhcp stuff I seem to be missing. As I want to separate the guest vlan completely it seemed ideal to use a spare port on our smoothwall box as the gateway.
  • 2 weeks later...
Posted

Having just installed a test version of Smoothwall's new BYOD software I can confirm it looks really good. Load test is Tuesday....

 

Many thanks for your visit to sunny Derbyshire @philipksmith.

 

I think the 1200 units are licenced differently, you could get the SSL log on page to work if you set up a DHCP server etc... I suspect it may well be worth a chat with support or your friendly account manager.

Posted
Having just installed a test version of Smoothwall's new BYOD software I can confirm it looks really good. Load test is Tuesday....

 

Many thanks for your visit to sunny Derbyshire @philipksmith.

 

I think the 1200 units are licenced differently, you could get the SSL log on page to work if you set up a DHCP server etc... I suspect it may well be worth a chat with support or your friendly account manager.

 

What's the difference from the current BYOD system that smoothwall offers? Any BYOD improvements will be greatly received here as it's something I'm trying to push heavily.

Posted

The new smoothwall system uses 802.1x to do the authentication. So end user only enters log on details once, and the system just works... Where as the captive portal systems need you to log on each session.

 

End result, less moans of apps not working (as ssl captive portal page didn't come up) and much quicker access as you don't have to type credentials each time.

Posted

D: I wants.

 

I use 802.11x for our main network & it just works i.e all domain joined machines do 802.11x onto our domain wireless. Certain users (IT :p) can also auth against it for our phones & it's great, I just walk on site and I'm on our wireless.

 

As for our guest network, yeah that's a standard open network with smoothwall BYOD on it at the moment & I get a lot of complaints that logging in each day (or whenever the session expires) is a pain in the backside. I can understand this, typing your username/password on say.. an iphone constantly would drive me insane.

Posted

@DrCheese that's what I said when I saw a development presentation.

 

It should be available in a short while, once tested. I think we are looking at a few weeks rather than months with a bit if luck.

 

The only proviso is the smoothwall box needs to be dhcp for all the byod traffic, and your wireless is pointed to the smoothwall box for radius auth and accounting.

 

I am testing on ruckus, but it is standard radius setup.

  • Thanks 1
Posted

This looks really interesting and I look forward to trying it out. Will definitely make our BYOD offering a bit less painful with the login process.

 

@robk are you using your smoothie as the radius server for you main wireless network as well or just your BYOD network?

Posted

That link still goes haywire but the doc works. Cheers!

 

Unless I can get dhcp on my 1200 I'm stuck though. If smoothwall won't play ball we might have to look at an alternative.

Posted
Strange how your 1200 wont do DHCP surely its the same as the 1000 but just a bigger version? Its a shame it wont do DHCP, have you spoken to any of the smoothwall guys? Maybe they might be able to help?
Posted
if it is a license restriction how much would it be to have DHCP added to the box? I would say its worth it? Did you get the box from smoothwall or the LA? I take it you do have full admin access to the box? Its just a tick box to enable DHCP in these boxes.
Posted
I gather the utm product is firewall and filtering the swg is filtering only. I suspect adding the dhcp from one product to the other may be doable, but I have not heard anything from smoothwall on that.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...