Jump to content

Recommended Posts

Posted

We need to change the password on our staff SSID, as some students have found it out and are "having fun" with AirPlay. How do you go about doing this without knocking all the devices off?

 

Here's what I did, but I'm wondering if there is a better way...

 

I set up a second SSID and pushed this out via our Meraki MDM, waited until all devices had updated and I then removed the old one from Meraki, and changed its password. At some point, I will push the original SSID and its new password back out over Meraki, but I might hold off on that until I next want to change it again. Is this the best way to do it?

 

The main problem I encountered with this is how long it takes, which is mostly down to Meraki - it took over two weeks for all iPads to pick up the new profile settings and new SSID/password. I don't want to just change the password from under people and have lots of devices fail to connect, nor do I want to tell staff what the password is (as that is how students found out about it in the first place!).

 

3 weeks to change a wireless password seems wrong to me. Is this a problem of process, Meraki or not actually a problem, just something I need to put up with?

Posted
It shouldn't be something you have to put up with - this is an argument in favour of implementing something like 802.11x/Radius authentication so that device connections can be authenticated by their user where appropriate, and passwords can certainly be centrally controlled and managed to lessen the blow of a change, and prevent passwords from "getting out there" where they can not.
Posted
Radius has always struck me as too "big and expensive" for our needs, but now we're doing student 1:1 with personal devices, I might rethink this. Was it much (time, effort and money) to implement?
Posted (edited)

Time? Hardly any. Cost? Cheaper than most managed wireless systems.

 

EDIT: Derp. Totally misread that. Radius can be free. NPS is a feature on Windows Server, or you can use a linux based radius server instead.

Edited by localzuk
Posted

Radius is actually reasonably straightforward to setup and does not actually cost anything as the NPS feature is part of Windows 2008/2012 anyway.

Depending on your wireless system it could be as simple as a 5-10 minute task (or at least it was for our Ruckus config)

Posted (edited)

RADIUS was a piece of cake for us but then we've been using it for various things on and off for years and have a good understanding of how to implement it. There's no reason it has to be complex, certainly, and as for cost, if you're running a Windows network then its part of the server licence you've already paid for, assuming you have servers with capacity to run it, it's essentially free, aside from your time.

 

If you wish to use *nix based systems then open source/free is the way to go, and again have the capacity already then its essentially free.

Edited by Roberto

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...