timbo343 Posted October 8, 2015 Posted October 8, 2015 Is there a way to redirect users to a webpage once they have authenticated? I know its possible via guest access but the trouble is there isnt any authentication via AD with guest access. I have 2 SSIDs which i want to happen on. Once authenticated they are redirected to an internal page with the smoothwall MITM certificate which can be downloaded along with a few links to Home Access Plus and Papercut web print along with a few others. Surely Ruckus would have thought of this?
markwilfan Posted October 8, 2015 Posted October 8, 2015 We do this a different way. We direct them to a page that has the cert on first allowed in ruckus without auth. Then there is a link at the bottom to the ruckus login. Someone else on edugeek gave me idea so can't take credit
timbo343 Posted October 8, 2015 Author Posted October 8, 2015 Would be interest how you do this if you are able to post your setup.
markwilfan Posted October 8, 2015 Posted October 8, 2015 Here you go @timbo343 The hotspot service as you can see takes the user to http://192.168.31.253/byod/index.html as their login page which has info on what to do, then the link down the bottom takes them to the ruckus login page. It only works because of the entry in the walled garden to allow unathenticated users to 192.168.31.253 . Does that make sense? 1
timbo343 Posted October 8, 2015 Author Posted October 8, 2015 Ah yeah i think so, i see you are using the hotspot service. I tried to get that to work earlier today at work but failed, may have to review it. Are you running a ZD firmware better than 9.8.0.0?? I think ive just borked one of my ZDs trying to update it to 9.8.3 and then going up to 9.10 as i only have 2x 1100 controllers. My night my be a reconfigure of the second box as i tried to take a backup of it but it downloaded a .jsp file :S
timbo343 Posted October 8, 2015 Author Posted October 8, 2015 (edited) What about mobile devices such as Android and IOS, do these need the certs installing too? Do you provide instructions on what to do with the certs on windows machines? I found when i installl the cert i have to select Local User and place it in the correct store as placing it in the auto-location i found doesnt work as it puts it in the intermediate Certificate store. Edited October 8, 2015 by timbo343
markwilfan Posted October 8, 2015 Posted October 8, 2015 we have 2x ruckus 3050 controllers running 9.9.0.0 build216 and 32 x zf7363 APs
timbo343 Posted October 8, 2015 Author Posted October 8, 2015 (edited) The trouble with the HotSpot service i had was, i couldnt get the hotspot to work with AD. Sorry, it was the guest access i couldnt get to work. The Hotspot service didnt work on some of my devices, god, ive changed that many settings today in Ruckus. Edited October 8, 2015 by timbo343
timbo343 Posted October 8, 2015 Author Posted October 8, 2015 I found the original post in another thread ... D'oh, dont i feel thick now lol.
markwilfan Posted October 8, 2015 Posted October 8, 2015 lol so say again what doesn't work, you've confuzzled me now
timbo343 Posted October 8, 2015 Author Posted October 8, 2015 LOL, i was running 9.8.0.0 and some of the devices i was testing would not load the authentication page with the hotspot service attached to the WLAN. Ill give it another go tomorrow but first job tomorrow is to move all APs over to the secondary ZD as the Primary one isnt responding, well, it is but its taking forever to do owt. Ill post back on what i find, what works and what doesn't.
markwilfan Posted October 8, 2015 Posted October 8, 2015 cool, happy to help matey. ours works fine so can compare config if needed. To answer a previous question we currently don't give detailed instructions for installing certs. Thinking I might need to
timbo343 Posted October 9, 2015 Author Posted October 9, 2015 Ive just set this up on my ruckus box under a test SSID and I cannot get a windows 7 laptop to redirect me to the unauthenticated web page however my phone Android 5.0.1 works fine 0 it comes up and say need to "Sign in" and when I do it takes me to my internal landing page. Do you have this problem?
markwilfan Posted October 9, 2015 Posted October 9, 2015 Have you got the "isolate wireless client traffic" on with whitelist?
timbo343 Posted October 9, 2015 Author Posted October 9, 2015 Nope these were my settings under Hotspot
timbo343 Posted October 9, 2015 Author Posted October 9, 2015 Found what was up... VLAN1 (main domain) doesn't push out a default gateway... now ive added a default gateway into the windows 7 laptop I go straight to the landing page . Simples!!
timbo343 Posted October 9, 2015 Author Posted October 9, 2015 but now im wanting to add something else to this. Once the user has authenticated I would like to push them to a site internally where they can access print / HAP shortcuts. Ive tried to add "After the user has authenticated redirect to: {the schools web page}" however all I get is null in the address bar. Have you got anything that pushes them to another page once authenticated.
timbo343 Posted October 9, 2015 Author Posted October 9, 2015 Carp!!!! looks like someone else is having the same problem and it looks like it might be a problem with the SW rather than ruckus https://forums.ruckuswireless.com/ruckuswireless/topics/url_redirection_problem_after_successful_authentication
markwilfan Posted October 9, 2015 Posted October 9, 2015 CArp indeed. That was the initial problem I had which is why we did it this way round. I never solved that and just put it down to a ruckus bug
timbo343 Posted October 9, 2015 Author Posted October 9, 2015 Interesting.. even if i dont set a URL redirect i get null.. however if i give my phone, Android 5.0.1, an ip address i dont get a ruckus login screen or directed to the authenticated page.
timbo343 Posted October 9, 2015 Author Posted October 9, 2015 Not made much progress with this today. I have managed to get the Post16 wireless to use the unauthenticated page - a bit like yours but trying to apply this to the staff one and it doesn't work... I get a smoothwall login box instead of the page even though ruckus is using the same hotspot policy and has all the same zone bridging entries as the post16 vlan and the authentication is the same under web proxy. I don't understand why I'm getting the login page for smoothwall.
markwilfan Posted October 9, 2015 Posted October 9, 2015 Check in user activity in sw mate. Are there radius entries for staff. Sounds like the groups being sent by radius accounting aren't matching
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now