Manny-Tech Posted September 23, 2015 Posted September 23, 2015 Hi, We have a Ruckus Controller in school that performs 802.1x authentication to a Windows Server 2008 R2 running NPS for wireless devices. We also have a Lightspeed web filter. If the Lightspeed filter doesn't know who you are it presents a captive portal page for you to login with your AD credentials before you can get out to the Internet. With this in mind, we created a WLAN for 802.1x authentication to our RADIUS server which works great. The problem we had was to then get out to the Internet you had to enter your password in on the captive portal page of Lightspeed. To bypass this we set the accountancy server on the Ruckus controller to point to the Lightspeed filter. In theory this should pass on the user identification and let the user straight out to the Internet rather than being presented with a login page. This isn't the case. I've logged it with both Ruckus and Lightspeed and we're at a junction point where neither are able to commit to changes. The main problem seems to be as a user moves from AP to AP they retain connection, but it seems to send a 'stop' message to the Lightspeed filter when they disassociate with the old AP which then proceeds to log the user out therefore presenting the captive portal login page. Ruckus say that is usual behaviour and Lightspeed said if they receive a 'stop' message then they will log the user out. Is anyone else in the same scenario as us, maybe not with Ruckus but with using Lightspeed as the 'accounting' server? Does anyone have any recommendations on how to bypass this captive portal once users have authentication with the RADIUS server? Please let me know if you require more details. Thanks
Jamman960 Posted September 23, 2015 Posted September 23, 2015 I've just setup a similar configuration except I'm using a Cyberoam firewall, so far I've not seen the captive portal since getting the radius accounting working although I've generally gone from one building to another and may not have gone directly from one ap to another. It may be worth looking at sending the accounting info to the NPS server and getting the NPS to send accounting info to the lightspeed box. https://technet.microsoft.com/en-us/library/cc771347(v=ws.10).aspx
Manny-Tech Posted September 24, 2015 Author Posted September 24, 2015 Would it not be easier to just send accounting info from the RADIUS server straight to the Lightspeed box rather than setting the Ruckus controller to send the accounting info back to the RADIUS? The only other option Lightspeed said was to somehow stop the RADIUS server sending 'stop' messages to them, not sure how plausible that is.
Jamman960 Posted September 30, 2015 Posted September 30, 2015 Looks like I'm running into the same issues, radius clients are being presented with the captive portal fairly randomly. Have you had any luck so far?
MagicMalc Posted September 30, 2015 Posted September 30, 2015 I am having similar issues but with Smoothwall not Lightspeed. I have spoken to Ruckus and again similar outcome standard behaviour. It has been recommended to me to use a transparent proxy which would remove the captive portal issue but this won't indentify individual users so is no good. Any advice if anyone has got it working would be great.
Bob_the_Goon Posted October 1, 2015 Posted October 1, 2015 Don't Lightspeed offer a client app that runs at login and passes your AD credentials to the Lightspeed box?
Manny-Tech Posted October 12, 2015 Author Posted October 12, 2015 I'm not sure about that, if they do they haven't mentioned it. I've recently been away on holiday so I'm going to get back onto this again this week. It's a massive problem for us, especially as it used to work previously. I'm due to get a packet capture setup with Ruckus and Lightspeed so they can have a look what's going on. I'll come back to you all when I have anything else.
matthewc Posted November 30, 2015 Posted November 30, 2015 (edited) Hi, We've been using Ruckus in conjunction with Lightspeed for some time now. To get the authentication from Ruckus to pass through (and persist whilst roaming across access points) you need to do the following: Add Lightspeed as a RADIUS Accounting server in Ruckus (under AAA servers) Then set the Accounting server to Lightspeed in the advanced options section on the WLAN you are using with interim updates set to 15 minutes. Now you need to SSH on to your ZoneDirector and do the following: ruckus>enable ruckus# config ruckus(config)# wlan ruckus(config-wlan)# show Roaming Acct-Interim-Update= Enabled More details are in the Ruckus knowledgebase https://support.ruckuswireless.com/answers/000002813 After that it should all work Edited November 30, 2015 by matthewc 1
JordanT91 Posted November 30, 2015 Posted November 30, 2015 Don't Lightspeed offer a client app that runs at login and passes your AD credentials to the Lightspeed box? They do, and it works relatively well. We got our MSI from our LA, it then gets pushed out by group policy. Does the job. The only time anyone has to enter their credentials now is on the iPads or their mobile phones.
Manny-Tech Posted November 30, 2015 Author Posted November 30, 2015 Hi, We've been using Ruckus in conjunction with Lightspeed for some time now. To get the authentication from Ruckus to pass through (and persist whilst roaming across access points) you need to do the following: Add Lightspeed as a RADIUS Accounting server in Ruckus (under AAA servers) Then set the Accounting server to Lightspeed in the advanced options section on the WLAN you are using with interim updates set to 15 minutes. Now you need to SSH on to your ZoneDirector and do the following: ruckus>enable ruckus# config ruckus(config)# wlan ruckus(config-wlan)# show Roaming Acct-Interim-Update= Enabled More details are in the Ruckus knowledgebase https://support.ruckuswireless.com/answers/000002813 After that it should all work I probably should have updated this. We had this resolution from Ruckus about 4 weeks ago. Back to roaming ways again now without disconnects
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now