Jump to content

Recommended Posts

Posted

I bought some Unifi access points last year for the school i work for. Until last year we only had a flat layer 2 network but now i have setup a layer 3 network with HP Procurve switches. I am now setting up Wi-Fi which will be used for both school owned laptops and BYO devices. Firstly I am trying to get it working for school owned devices with certificates which I got mostly working except the devices do not get assigned to the VLAN I have specified in NPS. They get an IP address from VLAN 2 which is the management VLAN for the access points. I havn't been able to figure out why this is not working so can anyone help me who has configured it before.

Also, I would like to know the authentication methods I should be using to make sure it has the best security possible. Can anyone who has configured Wi-Fi for BYOD tell me what do I need to do so that students and staff can connect their devices to the school network. If I use certificates for authentication, should I be creating multiple certificates for different groups of users and computers.

We have another problem that students will plug their devices into the Ethernet ports so is there a way to prevent them from doing so by not giving them access via wired network.

Posted (edited)
I bought some Unifi access points last year for the school i work for. Until last year we only had a flat layer 2 network but now i have setup a layer 3 network with HP Procurve switches. I am now setting up Wi-Fi which will be used for both school owned laptops and BYO devices. Firstly I am trying to get it working for school owned devices with certificates which I got mostly working except the devices do not get assigned to the VLAN I have specified in NPS. They get an IP address from VLAN 2 which is the management VLAN for the access points. I havn't been able to figure out why this is not working so can anyone help me who has configured it before.

Also, I would like to know the authentication methods I should be using to make sure it has the best security possible. Can anyone who has configured Wi-Fi for BYOD tell me what do I need to do so that students and staff can connect their devices to the school network. If I use certificates for authentication, should I be creating multiple certificates for different groups of users and computers.

 

Have you tagged the VLANs that are used for the WLANs on the ports going to the APs? Also, why do you have the management VLAN handing out IP addresses? I would set the management network up as a static VLAN?

 

We have another problem that students will plug their devices into the Ethernet ports so is there a way to prevent them from doing so by not giving them access via wired network.

 

 

Yes, you could use MAC filtering so that your DHCP server doesn't hand out IP addresses. There are ways to defeat this though, so if you want to do it really properly, you'll need to use NAP.

Edited by seawolf
Posted
the devices do not get assigned to the VLAN I have specified in NPS.

 

You can only use the NPS to allow/deny access to a SSID with it's associated VLAN on Unifi, it does not currently support radius assigned vlans because it is not really enterprise wireless. I assume you have all the APs as radius clients on NPS? (because it doesn't run any auth centrally through the controller, it's a glorified central config for each AP, with bugs).

 

 

We have another problem that students will plug their devices into the Ethernet ports so is there a way to prevent them from doing so by not giving them access via wired network.

 

Wired 802.1x is what I implemented on procurves to stop most of this, allowing only machines with a domain account (for the windows ones). MAC auth for the non windows machines, printers etc.

Posted

Thanks for the reply.

All the VLANs are tagged on the port AP is connected to except VLAN 2.

Actually, management VLAN is set to static but I turned on DHCP to test as the devices were not getting the IP addresses.

So do I need to install the certificates on all of our devices and set up a policy in NPS to authenticate only those with the certificate via wired connection.

Posted

For wireless byod you could still use 802.1x for wireless authentication, but prompt for the users AD credentials instead of a certificate, either will work, the VLAN you want them to join needs to be set for the SSID on the unifi and tagged on all the ports with a unifi AP.

 

Wired authentication needs quite a lot of planning, however you can do computer/user based authentication, unauthenticated vlans, radius assigned vlans etc.

 

If you are just wanting all BYOD devices on a separate vlan then you just need to create another ssid on the unifi controller with a different vlan assigned to it and tag the APs.

Posted

Hi DMcCoy

I have setup authentication with AD credentials for BYOD and it is working fine. At the moment, I have Unifi set to assign the clients to the VLANs based on SSIDs but I will have too many SSIDs this way. To avoid this I am actually trying to get NPS to assign the clients to the desired VLANs dynamically as I can have only 3-4 SSIDs for everyone. See Screenshot. I am thinking it's either the configuration in NPS or the switch is not able to handle it correctly. Can anyone confirm?

NPS Dynamic VLAN assignment.jpg

Posted
Hi DMcCoy

I have setup authentication with AD credentials for BYOD and it is working fine. At the moment, I have Unifi set to assign the clients to the VLANs based on SSIDs but I will have too many SSIDs this way. To avoid this I am actually trying to get NPS to assign the clients to the desired VLANs dynamically as I can have only 3-4 SSIDs for everyone. See Screenshot. I am thinking it's either the configuration in NPS or the switch is not able to handle it correctly. Can anyone confirm?

[ATTACH=CONFIG]23178[/ATTACH]

 

The switch can do dynamic vlans, so can nps.

 

Unifi can't.

 

You cannot yet assign the vlan for a wireless client with Unifi and radius

 

Which you should know, having posted in the unifi thread asking for this feature (although available on many other managed wireless products).

 

https://community.ubnt.com/t5/ideas/v2/ideapage/blog-id/UniFi_Ideas/article-id/2/page/2

  • Thanks 1
Posted
The switch can do dynamic vlans, so can nps.

 

Unifi can't.

 

You cannot yet assign the vlan for a wireless client with Unifi and radius

 

Which you should know, having posted in the unifi thread asking for this feature (although available on many other managed wireless products).

 

https://community.ubnt.com/t5/ideas/v2/ideapage/blog-id/UniFi_Ideas/article-id/2/page/2

 

Thanks for pointing me to the link. I did search Ubiquiti forums but must have missed it. Will wait for the option to be available.

 

Are you able to point me to a good guide to setup certificates for Domain and BYOD computers. I have created a new certificate from template in ADCS but it is not appearing in Group Policy or NPS. I am not sure what I am missing. This is the first time I am using certificates so do not much about it.

Posted

@ DMcCoy

I read your your post above again and am feeling stupid now.

Actually I didn't know at the time that any such thing is even possible so I wondered what the feature request is for. I had completely forgotten about it after that. And now I understand when I need it myself.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...