Jump to content

Recommended Posts

Posted

I have just got round to testing the wireless and the google HTTPS problem which needs the smoothwall certificate to be installed on Windows devices so users with own devices dont get the HTTPS unsafe/certificate warning when browsing to sites.

 

Has anyone got a way to import the certificate on the machine when the machine joins the wireless or when a user logs in to the wireless. We have a ruckus system which a user logs into and if they are a staff member they get the smoothwall SSL login too.

 

Thanks

Posted

The latest update from Smoothwall allows for non-SSL login pages.

 

What I am doing is setting up redirection on our wireless to forward users to an internal page (could be external as long as it isn't HTTPS & using transparent proxy) which has the certificate and a few install guides for the different OS's. Still very much a work in progress and it only automatically redirects the first time a user joins the network. There will be no way to automatically install the certificate.

Posted
I looked at the non-ssl login page but didnt quite understand what it might and might not break.

 

It won't break anything it's just that the information sent from the login page is not encrypted, otherwise it is exactly the same as using the SSL methods. It does get around the need for the certificate before browsing anywhere though.

Posted (edited)
It won't break anything it's just that the information sent from the login page is not encrypted, otherwise it is exactly the same as using the SSL methods. It does get around the need for the certificate before browsing anywhere though.

 

Its only good for authentication though (the OP means ssl inspection certificate). Using the Radius facility option would be a much better option anyway. You only authenticate once and thats when the device joins the network.

Edited by FN-GM
Posted
Its only good for authentication though (the OP means ssl inspection certificate). Using the Radius facility option would be a much better option anyway. You only authenticate once and thats when the device joins the network.

 

I was saying that in regards to getting the users to my non SSL instruction page.

Posted

Similar issue here,

 

See my post here :- http://www.edugeek.net/forums/smoothwall-direct-support/157884-byod-mitm.html

@foofighterjim how do you do the redirect ?

 

I was planning on an internal webpage with instructions and links (also the MDM profiles) and asking users to visit it

 

I found radius on Smoothwall to be problematic on apple devices, seems a bit hit and miss when joining, it may be easier for the end user to just use the SSL / NON SSL sign in

Posted
Wonder if this is possible with unifi, I know I can create a captive portal with it but I'm going to use that for guest access with a ticket system.
Posted
I was saying that in regards to getting the users to my non SSL instruction page.

 

What is SSL instruction? There is SSL login and SSL inspection.

 

If the issue with with SSL inspection setup your wireless with Radius, it works really well.

Posted
What is SSL instruction? There is SSL login and SSL inspection.

 

If the issue with with SSL inspection setup your wireless with Radius, it works really well.

 

For BYOD he has setup up a non ssl page that contains his ssl decryption certificate and some instructions to the user on how to install it depending on which device they have.

 

Ben

  • 2 months later...
Posted

Ive ended up having a page which unauthenticated users hit first which contains the certificate and a couple of how to guides. One the same page i have link to continue to login.

 

This takes the user to a simple web page which is a form and the user authenticates here. I wish i could use https here and the ruckus page but if i use the ruckus page, the redirect doesnt work after the user has authenticated. Ruckus support have told me to do it this way.

 

Once the user has authenticated, they then hit a BYOD landing page which has links to BYOD printing, remote file access via HAP and a few other links too.

 

I honestly cannot find any other way to do it.

Posted
Ive ended up having a page which unauthenticated users hit first which contains the certificate and a couple of how to guides. One the same page i have link to continue to login.

 

This takes the user to a simple web page which is a form and the user authenticates here. I wish i could use https here and the ruckus page but if i use the ruckus page, the redirect doesnt work after the user has authenticated. Ruckus support have told me to do it this way.

 

Once the user has authenticated, they then hit a BYOD landing page which has links to BYOD printing, remote file access via HAP and a few other links too.

 

I honestly cannot find any other way to do it.

 

Done the same here with PaloAlto, It is a bit of a PITA. I find the IOS experience is better than Windows when it comes to the users installing certificates, no suprise there ???

  • 2 years later...
Posted
My wireless (Aerohive) supports redirection when the initial connection is made. The only problem is that it is a one shot deal, if people ignore it the only way back to it is to browse to the URL.

 

Sorry for the necro thread raising, but I can't find a way to redirect to a URL on Aerohive other than using the Captive Web Portal, which forces users to login every day, which is a bit of a pita...

Posted
.... We have a ruckus system which a user logs into and if they are a staff member they get the smoothwall SSL login too.

 

Sounds as if you are using a captive portal with Ruckus...better to use radius authentication either by using Smoothwall's radius server - or passing the information to smoothwall to avoid a second login...

 

The certificate hassle is a pain...and very soon it may well be that no filter will be able to use this method of interception...and then essentially everyone will be invisible (...well maybe DNS filtering will still work...) Android 8 devices for example won't let you use a certificate for MITM interception ....or at least not unless you use a golocal certificate - and that would be strictly against the usage permissions for such certificates.

 

In any case - APPs increasingly use certificate pining and you have to create exceptions for them to work - including the google search app - so we won't be able to monitor this.

Posted
Sorry for the necro thread raising, but I can't find a way to redirect to a URL on Aerohive other than using the Captive Web Portal, which forces users to login every day, which is a bit of a pita...

 

That's correct, the only way to redirect is with a CWP. We now only use this method on the guest SSID.

  • Thanks 1
Posted
So maybe a general solution might be to provide a guest SSID - with redirect or CWP which is able to get to smoothwall certificate page (which doesn't have the correct instructions for the current iOS by the way!). Explain that it needs to be installed...following various guildes and instructing user to join a different RADIUS network using the AD credentials after which it should just work.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...