Jump to content

Recommended Posts

Posted

Hi,

 

We have a Ruckus Controller in school that performs 802.1x authentication to a Windows Server 2008 R2 running NPS for wireless devices. We also have a Lightspeed web filter.

 

If the Lightspeed filter doesn't know who you are it presents a captive portal page for you to login with your AD credentials before you can get out to the Internet.

 

With this in mind, we created a WLAN for 802.1x authentication to our RADIUS server which works great. The problem we had was to then get out to the Internet you had to enter your password in on the captive portal page of Lightspeed. To bypass this we set the accountancy server on the Ruckus controller to point to the Lightspeed filter. In theory this should pass on the user identification and let the user straight out to the Internet rather than being presented with a login page. This isn't the case.

 

I've logged it with both Ruckus and Lightspeed and we're at a junction point where neither are able to commit to changes. The main problem seems to be as a user moves from AP to AP they retain connection, but it seems to send a 'stop' message to the Lightspeed filter when they disassociate with the old AP which then proceeds to log the user out therefore presenting the captive portal login page. Ruckus say that is usual behaviour and Lightspeed said if they receive a 'stop' message then they will log the user out.

 

Is anyone else in the same scenario as us, maybe not with Ruckus but with using Lightspeed as the 'accounting' server? Does anyone have any recommendations on how to bypass this captive portal once users have authentication with the RADIUS server?

 

Please let me know if you require more details.

 

Thanks

Posted

I've just setup a similar configuration except I'm using a Cyberoam firewall, so far I've not seen the captive portal since getting the radius accounting working although I've generally gone from one building to another and may not have gone directly from one ap to another.

 

It may be worth looking at sending the accounting info to the NPS server and getting the NPS to send accounting info to the lightspeed box.

 

https://technet.microsoft.com/en-us/library/cc771347(v=ws.10).aspx

Posted

Would it not be easier to just send accounting info from the RADIUS server straight to the Lightspeed box rather than setting the Ruckus controller to send the accounting info back to the RADIUS?

 

The only other option Lightspeed said was to somehow stop the RADIUS server sending 'stop' messages to them, not sure how plausible that is.

Posted
I am having similar issues but with Smoothwall not Lightspeed. I have spoken to Ruckus and again similar outcome standard behaviour. It has been recommended to me to use a transparent proxy which would remove the captive portal issue but this won't indentify individual users so is no good. Any advice if anyone has got it working would be great.
  • 2 weeks later...
Posted

I'm not sure about that, if they do they haven't mentioned it.

 

I've recently been away on holiday so I'm going to get back onto this again this week. It's a massive problem for us, especially as it used to work previously. I'm due to get a packet capture setup with Ruckus and Lightspeed so they can have a look what's going on. I'll come back to you all when I have anything else.

  • 1 month later...
Posted (edited)

Hi,

 

We've been using Ruckus in conjunction with Lightspeed for some time now. To get the authentication from Ruckus to pass through (and persist whilst roaming across access points) you need to do the following:

 

Add Lightspeed as a RADIUS Accounting server in Ruckus (under AAA servers)

Then set the Accounting server to Lightspeed in the advanced options section on the WLAN you are using with interim updates set to 15 minutes.

 

Now you need to SSH on to your ZoneDirector and do the following:

 

ruckus>enable

ruckus# config

ruckus(config)# wlan

ruckus(config-wlan)# show

Roaming Acct-Interim-Update= Enabled

 

More details are in the Ruckus knowledgebase https://support.ruckuswireless.com/answers/000002813

 

After that it should all work :)

Edited by matthewc
  • Thanks 1
Posted
Don't Lightspeed offer a client app that runs at login and passes your AD credentials to the Lightspeed box?

 

They do, and it works relatively well. We got our MSI from our LA, it then gets pushed out by group policy. Does the job. The only time anyone has to enter their credentials now is on the iPads or their mobile phones.

Posted
Hi,

 

We've been using Ruckus in conjunction with Lightspeed for some time now. To get the authentication from Ruckus to pass through (and persist whilst roaming across access points) you need to do the following:

 

Add Lightspeed as a RADIUS Accounting server in Ruckus (under AAA servers)

Then set the Accounting server to Lightspeed in the advanced options section on the WLAN you are using with interim updates set to 15 minutes.

 

Now you need to SSH on to your ZoneDirector and do the following:

 

ruckus>enable

ruckus# config

ruckus(config)# wlan

ruckus(config-wlan)# show

Roaming Acct-Interim-Update= Enabled

 

More details are in the Ruckus knowledgebase https://support.ruckuswireless.com/answers/000002813

 

After that it should all work :)

 

I probably should have updated this. We had this resolution from Ruckus about 4 weeks ago. Back to roaming ways again now without disconnects :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...