Jump to content

Recommended Posts

Posted

One of our SMT goes to mcdonalds and gets on free wireless without having to mess around with wpads or proxy urls and wants to know why we can't have such an effortless system here.

 

Obviously McD have some kind of transparent proxying going on.

 

Currently our setup is wpad/pac.

 

We tried transparent proxy before wpad but ssl didn't work and getting round that seemed to involve dodgy Man-in-the-middle decrypting packets.

 

So I'm wondering what commercial solutions exist for transparent proxies?

Posted
We used a Smoothwall UTM that did that just fine with Ruckus managed wireless. We had a guest portal to hold things secure from the students so that was a passkey but that was all we had once through that it just worked and was fine.
Posted

I gave up on smoothwall express. It didn't work and I had no idea why and no idea how to find out.

 

I went back to our self built wpad proxy and figured out how to make transparency work, ssl too.

 

although seems there's a problem with app store...

Guest Guest
Posted
Try endian firewall. It's a turnkey dans guardian based firewall/proxy.
Posted
We do it here too, 2 vlans, one is guest - goes to a smoothwall with transparent authentication, the guest ssid is just open, basic filtering on the smoothwall - not ideal but it works.
Posted
We did it in Smoothwall, we now do it with Lightspeed :)

 

I have just thought, no we don't. We do it with Ruckus. Not sure where my brain was when i posted the above. Ruckus deals with our guest pass generation and login page for users. Lightspeed just deals with the filtering on the SSID / VLAN.

 

Heads a shed.

Posted (edited)
All you need is pfsense, its also got Proxying like Dansguardian and squid and it has captive portal. Have used it in cafe's and the likes myself! Piece of cake to configure and easy to manage as it looks just like a normal router interface. Edited by cpjitservices
Posted
I was thinking of setting up an un-routable Vlan and sticking a domestic adsl broadband router onto it. That way I'm not using my £6000 BB connection so people can view youtube videos. I could still use opendns if filtering was an issue.
Posted
I gave up on smoothwall express. It didn't work and I had no idea why and no idea how to find out.

 

I went back to our self built wpad proxy and figured out how to make transparency work, ssl too.

 

although seems there's a problem with app store...

 

Do you use an upstream cache peer for filtering? I was building a Squid proxy for this very purpose and found out there is a bug in Squid that when using SSL bumping with a cache peer it will actually send SSL traffic to the cache peer unencrypted. After reading that I gave up on the project as it was a deal breaker. I don't know if it has been fixed yet.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...