Simcfc73 Posted August 19, 2015 Posted August 19, 2015 Morning, I've read lots of articles on here about this subject but there seems to have been alot of updates recently so I am struggling. Can someone check i am doing this right. Ruckus - I have setup a WLAN with authentication as open > Captive portal as Radius - Smoothwall and in advanced smoothwall accounting. In the AAA a radius pointing to the Smoothwall with a simple shared key > PAP as the auth and everything else set to default and a Radius accounting doing the same Smoothwall - In the BYOD section I added the ruckus controllers IP address in the Authorized RADIUS clients bit and the same for the Forward RADIUS accounting to. I am testing this with a simple shared secret. In the authentication polieic I added a simple transparent proxy rule for everywhere Core authentication as the top rule.I get the Ruckus logon page when I connect to the WIFI I setup but it doesn't authenticate. I look in the Smoothwall log and I can see it says RADIUS authentication failed; username: stafftest, access point: 192.168.100.180 I am missing something very obvious so please can someone point me in the right direction. I want to set this basic one up then start playing with the VLAN stuff. Much appreciated.
Simcfc73 Posted August 27, 2015 Author Posted August 27, 2015 I have got this working but are roles supposed to work with the SW radius facility? If I take the WLAN for my radius out of the default group it stops working altogether. The groups are set ok as they work when I just use the portal page and it fills the users groups in properly.
timbo343 Posted August 27, 2015 Posted August 27, 2015 I see you and @Paid_Peanuts have been trying to get this to work along with me and a few others. I've always had the problem with groups and Radius with smoothwall so its on the back burner at the moment, i can get everything to work but when i add an AD group in Ruckus to say who can access the SSID smoothwall throws an error, not seen the error. The only way i can i this to work is to have everyone in the default ruckus group.
Simcfc73 Posted August 27, 2015 Author Posted August 27, 2015 Shane really, I have a decision to make now whether to switch over. It does seem a nicer way to log on but I like the ruckus logon page. Had a couple of issues when testing with my windows phone too where it wouldn't connect so I had to reboot. Suppose we have to just rely on staff and students to not use the wrong one.... Might as well just have one SSID.
timbo343 Posted October 8, 2015 Posted October 8, 2015 @Simcfc73 just revisiting this, i might have got it working (not the 802.11x) but having linking ruckus to smoothwall via radius. Ive got it so that users dont need to login to the smoothwall but yet their username displays in the smoothwall realtime logs.
Simcfc73 Posted October 8, 2015 Author Posted October 8, 2015 I've got this up and running too but there is issues so I might dump it. Its a bit hit and miss and one thing that seems to pop up is sometimes the logs show the radius logon as a string of numbers (or the mac address).. and the faff of getting windows 7 to play nicely is a pain too.
timbo343 Posted October 8, 2015 Posted October 8, 2015 Really?? Oh! I spent all morning trying to get it to work and trying different solutions. Ruckus does the authentication via AD and smoothwall does the accounting over port 1813.
Simcfc73 Posted October 8, 2015 Author Posted October 8, 2015 Just looking at my logs and there are loads of Radius logons so its working, I think there was a couple of issues with keychains too. There is a article on the SW site about having to manually create a connection to radius if your using windows 7 which I couldn't get working, if I manually connected to the BYOD and tried logging in that's when I got a log on the SW with the string of characters instead of the username. I think it sais they are working on a better log viewer so its easier to work out what's wrong.
timbo343 Posted October 8, 2015 Posted October 8, 2015 ahh ok, well this is what I did to get mine working: Ok. I have managed to get the usernames in smoothwall to display in the realtime filter so it doesn't show the IP address under the username. I might be a bit behind but here how it goes: Ruckus will do the authentication and the smoothwall with do the Radius Accounting. In ruckus: Setup the AAA servers: Create new >> Call it SMOOTHWALL_RADIUS_ACCT >> IP Address = Smoothwall IP Address >> Port = 1813 >> Enter a shared secret and confirm >> Click OK. Create new >> Call it {Domain-AD} >> Type = Active Directory >> IP Address = DC Ip address >> Port 389 >> Domain - Your domain name WLANS: If WLANS are already setup and using AD, edit the WLAN >> Expand Advanced >> Under Accounting Server - change this to SMOOTHWALL_RADIUS_ACCT. This is set on my Post16 SSID and my STAFF SSID. Unfortunately there isn't any encryption on the WLAN as I have tried to get the Zero-IT to work but as stated above, things didn't go according to plan . If you are setting up a WLAN from scratch, these are the settings I used: WLAN Usages - Type - Standard Authentication - Method - Open Encryption options - Method - NONE Options - Web Authentication - Tick Enable captive portal Options - Authentication Server - {Domain-AD} The rest of the options are optional. ROLES: Set the roles up so that specific AD groups can only access specific WLANS IN SMOOTHWALL I originally had the following set in Smoothwall >> Web Proxy >> Authentication >> Manage Policies Interface > The IP range where the device/user is coming from HTTPS > On Where > The BYOD Location Unauthenticated Requests > BLANK Staff were and still are set to be redirected to NON-SSL login page (with background tab) Students were set as Ident by Location meaning that they didn't have to log in to the smoothwall once the authenticated against the smoothwall. I have now changed this so they are no Redirected to NON-SSL login page (with background tab) Now both staff and students have this set, once they have authenticated against Ruckus, they do not need to log in to the smoothwall, as Radius automatically does this for them. I know its only a small thing but it means that we can now see what is happening by who on the BYOD networks via the RealTime logs in smoothwall. Now I need to find a way to push the MITM certificate out to BYOD windows clients.
Simcfc73 Posted October 8, 2015 Author Posted October 8, 2015 Might have a play with this then, mine is setup so when they attach to the WIFI they are prompted for a username and password in the WIFI connection, they don't see a SW login box or a Ruckus box. I wanted to change this as my idea was that the MITM cert could be displayed on the SW login page for them to download. SW told me how to do it but I haven't got round to it yet.
timbo343 Posted October 8, 2015 Posted October 8, 2015 (edited) Interesting how SW have told you how to do this. We have regular meets with smoothwall at our Network Manager meetings and they haven't said anything about this even though there are a good few of us who are struggling with getting the certificate to BYOD devices. I have asked the question about redirecting users from the Ruckus authentication page to an internal landing page where the certificate would be and a few other links. Maybe i could have a go at scripting in once the site loads the certificate downloads depending on device?? In terms of the whole 802.11x with getting the users to login to the wifi before any pages are made, i think ive counted my losses on this one and accepting that users will have to authenticate against Ruckus and AD and then be passed over to smoothwall transparently. Someone on here though has a setup where they issue the certificate first before authenticating so i have asked to see how they have it all setup. If i can get this MITM certificate out to devices, i will be more than happy. I think this is the final hurdle now, unless Ruckus have made major changes in their firmware as im on 9.8.0.0.369 and planning on upgrading to 9.12.1 and turn off IPv6 and NTP as im running the 7363 APs. EDIT: i can't upgrade to 9.12 as i have a 1100. I can only upgrade to 9.10. Edited October 8, 2015 by timbo343
timbo343 Posted October 8, 2015 Posted October 8, 2015 Talking to another Ruckus/smoothwall user about the redirection i found the original post: Ok, so we have had a bit of eureka moment which, when you look at it is really simple. It was staring us in the face the whole time. Leave all the settings as they are... except one. In Ruckus edit you Hotspot Service to redirect unauthenticated users to a custom webpage. This webpage will have instructions on how to install the Gaurdian CA Cert and give users a download button. (the crt will need to be hosted on an https site, we're going to use our schools webpage). We then give them a login button which redirects them to https://zonedirector/user/user_login_auth.jsp for authentication. You just need some html knowledge to create the webpage but I can help you out with some code if needed. from http://www.edugeek.net/forums/wireless-networks/155813-ruckus-redirect-following-url-not-working-hotspot-services.html#post1340239.
timbo343 Posted October 9, 2015 Posted October 9, 2015 Update: Ive changed the following: Staff were and still are set to be redirected to NON-SSL login page (with background tab) to - Core Authentication
timbo343 Posted October 12, 2015 Posted October 12, 2015 Ive not got a document on how to set this up from start to finish - see attached. The only thing i cannot get to work is the redirect once an authenticated user as logged in.Setting up BYOD with Smoothwall & Ruckus 11.10.15.pdf
Simcfc73 Posted October 14, 2015 Author Posted October 14, 2015 My biggest issue is I've never got my head round VLAN routing. So currently no VLANS talk to each other. My main VLAN is 1 I have a junior/Chromebook VLAN 15 BYOD and Staff on VLAN 30 30 and 15 get their IPs from SW DHCP So the config falls down because they cant get to the ruckus controller page on the VLANS.. its been on my to do list for years now. Did try and budget to get a PRO in to help setup and show me how but haven't had the time.
timbo343 Posted October 14, 2015 Posted October 14, 2015 (edited) Do the devices get an ip address? If so you're half way there. The document i uploaded should talk you through the whole process. It should be just a case of allowing the connection through to the smoothwall be it configured on the SW or the ZD. Edited October 14, 2015 by timbo343
Simcfc73 Posted October 14, 2015 Author Posted October 14, 2015 Sort of getting there. I wanted to make it simpler with my existing VLANs so opened up more than I should on my test site. It seems to ignore the redirect and take me to http://myruckuscontroller/user/index.jsp@url=connectivitycheck.android.com/generate_204 If I tick the 'tunnel vlan to controller' in the WLAN it gets there but its painfully slow. (slightly quicker on my W8 phone) the tablet is taking over a minute. I need to do some more fiddling, it flies to the Ruckus logon page when it eventually loads up and allows me to logon... I can see the authentication in the SW logs but I cant get to any pages... think its a DNS issue.
Simcfc73 Posted October 14, 2015 Author Posted October 14, 2015 Actually my windows phone flies after it logs on... must be a android thing.
timbo343 Posted October 14, 2015 Posted October 14, 2015 If its a DNS issue make sure you have them right on the SW: Networking >> Configuration >> DNS System DNS Resolver = System Internal DNS Server DNS Forwarders = Google (8.8.4.4 & 8.8.8.8) TalkTalk (my ISP DNSs) Conditional DNS Forwarders = Internal DNS Servers Static DNS Hosts = Hostnames which i want my BYOD networks to use, so my ZD is known on the BYOD networks as byodlogin.localdomainname Also have a look at Zone Bridging if not configured; Networking >> Filtering >> Zone Bridging In here you need to configure rules so that VLANs can talk to the main domain network. Source interface = VLAN network Destination interface = Main network Bidirectional = Ticked Protocol = All Source IP = Leave Blank Destination IP = ZD IP address Service (dont touch this) Port (dont touch this) 1
Simcfc73 Posted October 28, 2015 Author Posted October 28, 2015 Thanks for all this, got 3 vlans setup and working now.. only issue I found is I needed to add the DNS proxy to the external access rules to get it to work nicely. The logon to my intranet site is still taking a minute to show up too... need to tweak it somehow. Now to do the taggin for my switches.. might take a while
timbo343 Posted October 28, 2015 Posted October 28, 2015 Thanks for all this, got 3 vlans setup and working now.. only issue I found is I needed to add the DNS proxy to the external access rules to get it to work nicely. yeah thats right, ive got the DNS proxy in my external access too. Glad things are slowly coming together for you. The logon to my intranet site is still taking a minute to show up too... need to tweak it somehow. I wonder if this is a DNS issue somewhere? What happens if you just use the IP address? Now to do the taggin for my switches.. might take a while haha, so starts the tagging of Ports, i managed to get lost with all of mine and even the documentation i have regarding setup and switch ports still confuses me, i need about 5 - 10 mins to sit and work it all out.
Simcfc73 Posted October 28, 2015 Author Posted October 28, 2015 And now the Ruckus controller decided to die FFS.... and I just got to a cabinet and water was seeping out... and the switch had lost all its config. Its come back up but have an issue with windows 7, its not coming up with a log onto the wifi option and I cannot browse to anything.. its a bit frustrating.
Simcfc73 Posted October 28, 2015 Author Posted October 28, 2015 So the additional logon is working with W7 now... its still slow when I first logon to get to the AUP page, after I have logged on I can instantly get to it so its something going funny pre authentication. The webserver runs on a QNAP box and I haven't done any VLANNING on that bit of the network so its still on VLAN 1....but it does eventually get to it so the routing is working
timbo343 Posted October 28, 2015 Posted October 28, 2015 Glad to hear things are slowly coming together. My unauthenticated user page, custom login page and BYOD landing page are all on an internal server which are on VLAN1 too. Have you added the DNS routes on the smoothwall?? Its under DNS > Static route and obviously you have the zone bridging set right too.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now