Jump to content

Recommended Posts

Posted (edited)

Going to sort out the mess of the wifi and authentication once and for all this summer I hope.

 

We use Smoothwall and Unifi to provide wifi to a mix of class sets, staff iPads and BYOD and also some students are supplied with one.

 

We have two SSID's one is open wifi for guests which I plan to replace with Unifi's ticketing system if it works and the other is radius.

 

I need to get the MITM certificate and a profile on all devices so usage can be filtered / monitored

I'm aware we can push the cert out using MDM but we would need a profile on there first so it's a bit chicken and egg.

 

What is the best way of going about this ? I really need to get it sorted out properly

 

Radius on Smoothwall doesn't seem to work too well on ios8 - iPads struggle to connect, so is SSL login the way to go ? Or set up a windows radius server and forward the radius accounting ?

 

Or just SSL login page on smoothwall ? (Can I provide links to cert + profiles on this page?)

 

I'm thinking if possible some kind of hosted page that has the links to the cert and profiles so the end users can manually install themselves but there would be no way of making sure they actually did it...

Edited by caffrey
Posted

I use the HTTPS SSL logon page, it cant provide links to the cert for MITM or profiles, but it looks like they will be "investigating potential solutions" for making the MITM self installation easier

 

The Carisbrooke update provides a NON-SSL Login Page "The option should remove alerts warning end users about security certificates —and removes the need to roll out a certificate— but it should be noted that this will also transmit unencrypted login information."

  • Thanks 1
Posted
Im unsure which way to do this as there seems to be many ways, I'll just use the excuse of it's coming soon then until Smoothwall do something about it (I would've thought this would be a huge priority to be fair). I was considering setting up an internal webpage with the links on and tell end users to go there and install (with basic instructions on the page) but that would mean me relying on them to do it - bit of a pants situation really :(

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...