_techie_ Posted April 15, 2014 Posted April 15, 2014 Hi Today with support from MERU, I finally got our captive portal working with our SSL cert! Long overdue task! We have a VLAN for BYOD associated to a SSID with which the captive portal works. This uses RADIUS authentication and AD credentials so that users in our boarding houses can be tracked for safeguarding reasons. This is currently for both students and staff, however I would like to provide slightly more elevated access for Staff to certain web services on our LAN. I was intending on setting up a new DHCP scope, mapped to another VLAN on the Meru along with a new SSID for the staff to use. Our Sonicwall could then allow access to certain servers. We also have our content filter, the Lightspeed rocket. Users currently have to authenticate twice on the BYOD SSID. Once to the captive portal and again to the Lightspeed Rocket, as they do not have the Lightspeed user agent installed on their own device. Is it possible to pass credentials from the Meru captive portal to the lightspeed rocket via the RADIUS? Or Is it possible to specify the captive portal to only allow certain AD groups for a certain SSID? (So that when staff connect to their SSID it will only allow them through if they are in the AD All Staff Group?) Any help would be great!! Cheers _techie_
njc235 Posted April 16, 2014 Posted April 16, 2014 I have run this past one of our engineers. It seems that there is a single sign-on method. Meru & Lightspeed have an integration to achieve single-sign-on. If you speak to Meru again, they should be able to help. HTH Nick
RobD Posted April 16, 2014 Posted April 16, 2014 You should just be able to add the lightspeed server as Radius Account server on Meru (with key) so once its authenticated the meru will pass the details to lightspeed and auth the user again without the need to logon then appear in the lightspeed reports as a radius logon. Out of interest your not in S.Wales are you as your setup is very similar to mine!
_techie_ Posted April 16, 2014 Author Posted April 16, 2014 Hi Rob, yes its Mark the Network Eng from the girls school! Perhaps you could send me some screenshots of your setup on the NPS/Meru on how to do this? You have my work email? Cheers Mark
MrGAWilson Posted December 9, 2014 Posted December 9, 2014 Hello there! Just resurrecting this thread a bit :S I have a similar setup here with Meru WiFi and the LightSpeed Rocket Web Filter. We have been working on an issue lately where the RADIUS single sign on between the two systems isn’t working. The Rocket is suggesting that the RADIUS packets from the Meru Controller are adding the @domain suffix to a username instead of leaving it as domain\username format. Meru of course say that the controller isn’t doing that. Have you guys managed to accomplish the single sign on capabilities?
psydii Posted December 9, 2014 Posted December 9, 2014 It should be easy enough to prove one way or another. Just configure a mirror port and wireshark to sniff the radius traffic between lightspeed and Meru. If the @domain is there then you have a smoking gun.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now