fiza Posted October 15, 2015 Posted October 15, 2015 We have started down the road of BYOD with our 6th form and its working well. They authenticate with their AD credentials and are then allowed to connect. We use the Ruckus client isolation to keep them away from the network and they just get internet access. What we are finding though is that students in the lower years are attempting to connect. Obviously they get refused as they are not in the right AD group for BYOD but it allows them to pick up an IP address. Whats the best way to stop this from happening?
fiza Posted October 15, 2015 Author Posted October 15, 2015 Are you using Radius authentication? We are using the built in AD authentication on the Zone Director.
CyberNerd Posted October 15, 2015 Posted October 15, 2015 Set a low lease time for BYOD? We did this too (but allow all devices). I'm suprised the controller allows them to get a lease, is it a login page re-direct? perhaps you can change your auth methods. Also check the DHCP fail-over as there is a 80:20 split of addresses so it is worth adjusting your scopes.
fiza Posted October 15, 2015 Author Posted October 15, 2015 The BYOD SSID is visible to all so the students just click it on the their devices and it gives them an IP address and redirects them to the login page where they would input their AD credentials. when they try to input their credentials they get rejected but the phone still keeps the IP address until the lease expires.
timbo343 Posted October 15, 2015 Posted October 15, 2015 We have dropped the Inactivity Timeout down to 10 minutes. I'm sure this is the option that you configure to kick users off the WLAN if they haven't authenticated. 1
CyberNerd Posted October 15, 2015 Posted October 15, 2015 We have dropped the Inactivity Timeout down to 10 minutes. I'm sure this is the option that you configure to kick users off the WLAN if they haven't authenticated. You would have to combine that with a low lease time, even if the Wifi kicks them the DHCP server won't 1
fiza Posted October 15, 2015 Author Posted October 15, 2015 We have dropped the Inactivity Timeout down to 10 minutes. I'm sure this is the option that you configure to kick users off the WLAN if they haven't authenticated. Is this a per WLAN setting? I don't want it do disconnect school owned devices that connect to another WLAN.
CyberNerd Posted October 15, 2015 Posted October 15, 2015 To be honest I'm not sure this would work well anyway. We have a guest wifi that re-directs to an SSL page. Every day we have 30-40 connections on it ; and all kids can connect to the main school network. Even if you kick them the operating systems will just re-connect, and issue another DHCP lease - it may make the problem worse. 1
timbo343 Posted October 15, 2015 Posted October 15, 2015 My SW is doing the DHCP, the lease time is set to 60 mins, might have to change that to 10 mins but the scope i have is fairly large.
CyberNerd Posted October 15, 2015 Posted October 15, 2015 My SW is doing the DHCP, the lease time is set to 60 mins, might have to change that to 10 mins but the scope i have is fairly large. That might be a bit too short - a DHCP client will attempt to get a new lease after half the time of the lease. 1
fiza Posted October 15, 2015 Author Posted October 15, 2015 Currently my DHCP servers shows ; Total Addresses : 1771 In Use : 1631 Available : 140 We do not have 1631 school owned devices so the majority of these are student devices attempting to connect.
timbo343 Posted October 15, 2015 Posted October 15, 2015 Currently my DHCP servers shows ; Total Addresses : 1771 In Use : 1631 Available : 140 We do not have 1631 school owned devices so the majority of these are student devices attempting to connect. Just out of interest, have you got your BYOD stuff on a VLAN?
Davit2005 Posted October 15, 2015 Posted October 15, 2015 Same issue here, they get a lease as soon as they have WiFi on. We have set DHCP to 4 hours for BOYD devices.
timbo343 Posted October 15, 2015 Posted October 15, 2015 I think the only other way for users not to get an IP is to enforce 802.11x but ive tried for months to get it to work with SW and failed.
CyberNerd Posted October 15, 2015 Posted October 15, 2015 I think the only other way for users not to get an IP is to enforce 802.11x but ive tried for months to get it to work with SW and failed. That, or increasing the scope are the best options. The others are workarounds.
fiza Posted October 15, 2015 Author Posted October 15, 2015 Just out of interest, have you got your BYOD stuff on a VLAN? No VLANs here.
CyberNerd Posted October 15, 2015 Posted October 15, 2015 No VLANs here. a good opportunity to do both increase the scopes and segregate groups using 802.1x !
timbo343 Posted October 15, 2015 Posted October 15, 2015 No VLANs here. Have you thought about implementing it? Do you have a smoothwall at your place? And what switches do you have?
NewFormz Posted October 15, 2015 Posted October 15, 2015 We were having this issue last year. We setup VLANs and expanded our scope over the summer. Although it was a bit of a headache to setup We now have plenty of addresses and it is much easier to manage.
fiza Posted October 15, 2015 Author Posted October 15, 2015 Have you thought about implementing it? Do you have a smoothwall at your place? And what switches do you have? We don't have smoothwall. Switches are all Procurves.
FN-GM Posted October 15, 2015 Posted October 15, 2015 If you switch to radius you shouldn't have this issue. It will only hand out an IP after authentication has occurred. 1
truebluesteve Posted October 15, 2015 Posted October 15, 2015 Oddly I am having the same issue here with my SW/Ruckus - but with our guest network (which is on a VLAN). The DHCP lease time is pretty short so reducing it further isn't likely to help so I have increased the scope which was originally quite small (255 subnet mask).
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now