Jump to content

Ruckus BYOD - possible android problem - not tested on apple products


Recommended Posts

Posted (edited)

We have had a ruckus system running brilliantly for months and i'm really happy with it, in fact i cannot praise it enough.

 

There has been one little niggle though which has been bothering me and that is to do with BYOD either Staff or Students. I'm in two minds on which way to go with this.

 

At the moment i have an open SSID (BYOD-STAFF) for Staff, a SSID (BYOD-STUDENTS) and a SSID (BYOD-POST16) for students where users will connect to and authenticate against Active Directory and if they are part of the relevant member group in AD they are granted access. This is working fine however the connection isn't encrypted. They are then passed to the smoothwall for SSL login to the net as WPA on Smoothwall and the ruckus group membership don't work so i cannot let on staff connect to the staff SSID, anyway that's another story.

 

I have seen and tested, which i have got setup but hidden at the moment, a SSID called Provision which is open and a test SSID for staff called BYOD-STAFF-En which is encrypted. A member of staff connects to the provision SSID, which gives the user an IP address from the main domain for a little while, logs into a walled garden, inputs their username and password and they download the prov.exe on windows or prov.apk if on android. Once the profile has been downloaded the user, i have found if using...

a) a laptop, needs to turn the wireless off and then back on again and the laptop connects to the relevant SSID which the profile has given.

b) an android device, will not pass me over to the relevant SSID, even if i turn the wireless off and on, it still doesn't work. The only way i have got it to work is to disconnect or forget the provision SSID.

c) i have tried it on an apple device however the apple device is locked to IrisConnect so i cannot install google chrome as safari doesn't work.

 

I thought this profile moved the device over to the SSID automatically this making it easy for the user. At the moment, it does't seem straight forward for the average user.

 

Has anyone else had this problem or are people doing it the former way i have mentioned. I would really like to get the latter working to see how it goes.

 

Thanks

Edited by timbo343
Posted

I contacted support about the very same issue, I can only get it to work with osX.

 

They said that you have to turn your wifi off then on again but with iOS and android you need to forget the provision network and then it will auto connect to the network from the profile you installed.

Posted
I contacted support about the very same issue, I can only get it to work with osX.

 

They said that you have to turn your wifi off then on again but with iOS and android you need to forget the provision network and then it will auto connect to the network from the profile you installed.

 

We've been using this setup just fine for 9 months. The only catch is that in both OS X and iOS you have to forget the provisioning SSID or the device might reconnect to it in the future (and you'll get "my WiFi isn't working" complaints). The other option is to use Zero-IT config, which can be limited so it only works for certain AD groups.

Posted
I have configured the BYOD-STAFF-En to use ZeroIT activation which still results in the problem.

 

What version of firmware are you using? There have been a few issues caused and solved with ZeroIT in a couple of firmware updates over the past year.

Posted
The latest version 9.6

 

I haven't tried 9.6 yet so I can't really say. Have you tried rolling back to the latest firmware prior to 9.6? There was a really bad bug in the first version of 9.5 that completely broke ZeroIT for OSX (it still worked with iOS though).

 

*WARNING: rolling back the firmware may reset your ZoneDirector to factory config so make SURE you have a good config backup first.

  • Thanks 1
Posted
hmmmm, ill try, not too keen on going back to the latest version of 9.5. Ive got to do both boxes as they are in failover mode at the moment. Ill try to see if someone can test this on 9.5 first. What version are you on?
Posted
hmmmm, ill try, not too keen on going back to the latest version of 9.5. Ive got to do both boxes as they are in failover mode at the moment. Ill try to see if someone can test this on 9.5 first. What version are you on?

 

Just logged onto the VPN to check. we're using version 9.5.1.0 build 50 currently.

 

It is a pain to rollback I know (had to do it when I encountered the bug at the start of the year after upgrading from 9.4 to 9.5). I took Ruckus a couple of weeks to fix it, but they did in the end (see email from Ruckus Support below)

 

 

This email is to update you that we have uploaded 9.5.1 firmware in to our support site and this is the fix for the MAC clients who are facing issues with Zero-It, please upgrade the firmware and let us know for any issues.

 

Feel free to contact us for any clarifications or assistance, we are glad to assist you.

 

Best Regards,

Srinivas Pithani

[/Quote]

  • Thanks 1
Posted

We rolled back to 9.5 and as been as stable as any of the previous builds.

 

Instead of using a provisioning WLAN, on each WLAN enable captive portal against you AD and select ZeroIT, this way you don't need a provisioning network.

 

If you have made the WLAN SSIDs obvious then people will know which one applies to them.

 

Choose names that include, staff, pupils, guest etc....

 

I'm not sure how this will work if also have specified an encryption type, at a guess it will prompt of the key, before anything else, but then it may ask you to auth after. I haven't test this theory out yet but perhaps someone can confirm what I'm saying...

Posted

My BYOD SSIDs are all known by staff, student or post16 and all have authenticate against AD and have zero-it selected.

 

My only worry is that the SSIDs aren't encrypted. Does this mean traffic over these SSIDs is viewable if the connection isnt encrypted or does the encryption only stop anons accessing the SSIDs?

Posted
I think you can use dynamic psk but I never got it working properly. The smoothwall WPA enterprise option may work soon with ruckus roles correctly, apparently it's a bug in how the MAC address is dealt with I think I saw a smoothwall kb article regarding this if/when it's fixed it may be the best solution.
Posted (edited)

I would quite happily use the WPA enterprise with smoothwall but until the roles/auth settings in ruckus talk to smoothwall and vise versa then i wont be using it.

 

The bug is everyone needs to be part of the default group which kinda defeats the point of having seperate SSIDs and roles as everyone can join the one SSID which is inpracticle. The smoothwall isnt talking back to AD to find iut what groups the user is in. Plus the ruckus policies and setup is far easier to manage and configure than the smoothwall, also is the first thing clients hit so im thinking why go furthrr down the line when yiu can stop it at the first connection.

 

How is it a problem with MAC addresses?

Edited by timbo343
Posted
Finally got provisioning hotspot auto config working by rolling back the firmware to 9.5. Need to see now if 9.6 supports the auto config, im sure it does, but maybe i was just missing something.
Posted

Ruckus' DPSK and Zero-IT config are working well for me. Credentials are passed and are encrypted (HTTPS) and authentication is handled via WPA2 and a PSK. Not sure what issue you are really facing here.

 

Yes, the provisioning/activation SSID has to be forgotten. This is not an issue with the Ruckus system, but rather the device OS. Devices will tend to remember any SSID they connect to and especially connect to open SSIDs like the Zero-IT/Activation one you use for a Ruckus deployment. Forget it and the device connects just fine to the requisite SSID.

 

Android phones are a pain simply for two reasons: Androids by default won't accept apps that are not from the Android market so this has to be turned off in the settings, and second; the OS is so fragmented each and every device handles the provisioning file so differently - I end up copying and pasting the DPSK into the device manually quite a lot.

Posted
I'm finding if I enable zero-IT and Web Captive/Portal it never provides access to the portal/zero-it and only asks for a wifi password. I'm on firmware 9.6. It seems this only works on 9.5? I would like to get this work if possible so I can use DPSK rather than having the BYOD network open with Captive Portal. @Distinove @timbo123 what firmware are you using?
Posted

I am using the latest version of 9.5 as i downgraded from 9.6. I have an S4 and 9.5 works with that. Once the phone connects to the provisioning SSID it gets a DHCP address from the domain. The apk downloads to the phone and installs wifiautoconfig4.1. Just remember to run this once installed as this will automatically change the SSID on the phone. Sometimes i had to forget the provisioning network so it would autoconnect to the correct network. I have reverted back to an open network and they authenticate via AD with a AD group. This way our DHCP addresses aren't taken up with random devices and keeps everything separate.

 

I have a smoothwall and I just wish that it would work correctly as a radius server. If ruckus is configured to use the smoothwall as a radius server, the roles don't work so everyone is set as default which i am waiting to get fixed from smoothwall. This means that i cannot restrict only staff and Post16 to use the wireless.

Posted (edited)

We have ruckus setup here with a provisioning wlan and separate SSIDs for pupils, sixth form and staff which are also in separate VLANS. We don't use smoothwall but have set our filter to filter the traffic based on IP address. Therefore a user logged into the sixth form wlan - vlan - ip range gets sixth form level filtering without authenticating to our filter. Our filter doesn't know who the devices belong to - but our ruckus controller does, and the logs are sent to a syslog server so they can be cross referenced if any issues arise.

 

You are correct about the auto network jumping. It works quite well on Macs and iOS devices, but not at all on others. We don't use the prov.apk on android because different browsers deal with the file differently and users need to have 'third party app stores' allowed in their security settings. It was all too complicated so we just tell android users to click the manually set up your connection link on the ruckus portal, copy their unique key, and connect to the correct wlan and paste the key in.

 

To restrict pupils from utilizing the BYOD facility, we only allow users with the AD security group BYOD_Pupils to access the pupils SSID using ruckus groups. We then assign users rights in AD by adding them to the group.

 

We're on 9.5... I'll leave it a bit before upgrading.

 

I'm not far from you @timbo343 if you want to pop down and see how ours is working for us?

Edited by IrritableTech
Posted

AliG: There should be no password on your activation/hotspot SSID. Options here are set to Open/None for Authentication and Encryption.

 

I am running 9.6.0.0 build 267

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...