Jump to content

Recommended Posts

Posted

Just wanted to check this was correct.

 

Currently anyone with an AD account can join our INTERNET wireless network (MERU) - primarily it's for staff/students to BYOD.

 

We've decided we want to restrict this now to staff and 6th formers only!

 

Filtering is done via a smoothwall.

 

The original MERU install was done by a third party and I've been looking in to how to restrict the lower school from connecting.

 

It looks simple enough to do - see screenshot - just add another rule "must be a member of one of these security groups".....

 

Is there any more to it than this?

 

Cheers

Posted
It looks simple enough to do - see screenshot - just add another rule "must be a member of one of these security groups".....Cheers

 

Am I missing something?

 

We've achieved this using RADIUS based on Security Group Membership in AD.

  • Thanks 1
Posted
Are you using smoothwalls BYOD feature? If so you can use that to restrict security groups.

 

I'm not ....

 

I have two radius profile names set up on the MERU controller:

 

Profile 1 is for the school owned devices - network policy allows domain computers and is on one 2012 Server.

 

Profile 2 is for BYOD - network policy allows domain users and this is on another 2012 Server.

 

 

I think I need a Profile 3 - network policy allows staff and 6th for groups - but this needs to go on the same 2012 Server that runs radius for profile 2.

 

I can see how in MERU to create a new profile and I can see on the 2012 server how to create a new radius client (with matching secret key!)

 

But how do I create differing network profiles matched to them?

 

Hope that makes sense....

Posted

I've configured our Meru controller's Captive Portal to look for authentication, using RADIUS, from one of our Domain Controllers and then the radius accounting is past to our Lightspeed Rocket for web filtering.

 

We have three SSIDs each working on a separate VLAN and with a different domain name (this allows us to query the 'Station ID') and limit the user based on group membership.

 

Screen Shot 2015-02-05 at 13.45.03.png

 

From your screenshot it looks like your connecting domain connected machines but I may be worth looking at adjusting the 'Called-Station-ID Type' setting in Configuration > Security > RADIUS to see if you can achieve the same thing.

 

Are you using smoothwalls BYOD feature? If so you can use that to restrict security groups.

 

In our situation we didn't want to do this on our web filter as our staff iPads connect to their own SSID and SLT didn't want them having to login to use the internet at which point we base their access to the internet on the IP range they are currently working on.

  • Thanks 1
Posted

In short yes.

 

You need some way of differentiating between the different wireless networks.

 

We've done this by setting the "Called Station ID" which is looking for the clients DNS Domain name ".SJBStudents" which is set on the DHCP server.

 

We have three SSID's all configured in this way.

 

Screen Shot 2015-02-05 at 14.08.14.png

Screen Shot 2015-02-05 at 13.45.03.png

  • Thanks 1
Posted
In short yes.

 

You need some way of differentiating between the different wireless networks.

 

We've done this by setting the "Called Station ID" which is looking for the clients DNS Domain name ".SJBStudents" which is set on the DHCP server.

 

We have three SSID's all configured in this way.

 

[ATTACH=CONFIG]29019[/ATTACH]

 

If you expand your Radios Client and Servers - do you then see your three SSIDs under the Radius Client section?

Posted

I've found how to set the Called-Station-ID Type on the MERU controller :)

 

At the moment for each radius profile name it's set to "default"

 

But can be changed to MacAddress or MacAddress:SSID

Posted
I've found how to set the Called-Station-ID Type on the MERU controller :)

 

At the moment for each radius profile name it's set to "default"

 

But can be changed to MacAddress or MacAddress:SSID

 

Change "Called-Station-ID Type" to MacAddress:SSID

  • Thanks 1
Posted
Change "Called-Station-ID Type" to MacAddress:SSID

 

I think I get it - keep one Radius Client on the 2012 Server and differentiate the groups which can connect based on the calledstation id which will equal the MacAddress of the MERU controller + SSID name ?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...