timbo343 Posted October 15, 2015 Posted October 15, 2015 If you switch to radius you shouldn't have this issue. It will only hand out an IP after authentication has occurred. Is that radius authentication over AD authentication? Ruckus and smoothwall radius authentication dont work (ive not got it to work, and spent time with SW on this) however AD authentication and Smoothwall Radius Accounting works. Also, a certificate is needed for windows 7 devices with radis authentication.
FN-GM Posted October 15, 2015 Posted October 15, 2015 Is that radius authentication over AD authentication? Ruckus and smoothwall radius authentication dont work (ive not got it to work, and spent time with SW on this) however AD authentication and Smoothwall Radius Accounting works. Also, a certificate is needed for windows 7 devices with radis authentication. Smoothwall Radius and accounting works with our Ruckus in our schools. And in 2 others schools I setup. The Windows 7 thing I am aware of so we don't support it with the BYOD, not really caused us an issue anyway, most people are on 8 and above. Soon it won't be supported on the production network.
DarrenShan Posted October 15, 2015 Posted October 15, 2015 You could try blocking known unauthorised devices? (long winded I know but maybe worth a try and might stop other students from connecting if their peers can't connect.) Export the list of MAC addresses (Monitor -> Wireless Clients) sort by STATUS so that UNAUTHORISED are at the top, click EXPORT CSV. Pop the CSV into Excel and filter it so it just shows the UNAUTHORISED MAC addresses and then save that. Configuration -> Access Control -> L2 Access Control -> Create New. Give it a name and IMPORT CSV (you can download an example CSV file from here as well - nice touch) Configuration -> WLANS and select your BYOD/Guest Wlan Expand ADVANCED OPTIONS and then next to L2 Access Control, you should see the L2 Access Control list you created in the previous step. This will prevent any device in the list from even connecting onto your WLAN, so it won't be able to get a DHCP lease. I believe that there is a limit to the number of MAC addresses within an L2 ACL but I don't know what it is. Obviously, if you get an issue with an approved client not being able to connect, check the L2 ACL list for their MAC address.
timbo343 Posted October 15, 2015 Posted October 15, 2015 Smoothwall Radius and accounting works with our Ruckus in our schools. And in 2 others schools I setup. The Windows 7 thing I am aware of so we don't support it with the BYOD, not really caused us an issue anyway, most people are on 8 and above. Soon it won't be supported on the production network. Oh! Hang on have you got it set to that roles are configured as i would want different SSIDs and certain users to access these SSIDs. Thats the problem i was having, everyone had to be in the default role group wih access the to wlan.
CyberNerd Posted October 15, 2015 Posted October 15, 2015 Oh! Hang on have you got it set to that roles are configured as i would want different SSIDs and certain users to access these SSIDs. Thats the problem i was having, everyone had to be in the default role group wih access the to wlan. If you can you want to keep them all on the same SSID and then segregate them by vlan: your radius will do this.
timbo343 Posted October 15, 2015 Posted October 15, 2015 Ive got different SSIDs with their own VLANs. I guess that is where the enable dynamic vlan comes into play on ruckus.
CyberNerd Posted October 15, 2015 Posted October 15, 2015 Ive got different SSIDs with their own VLANs. I guess that is where the enable dynamic vlan comes into play on ruckus. Sure, I guess they must be using different auth methods? We have one SSID that serves 6 vlans and another SSID for a different auth method.
FN-GM Posted October 15, 2015 Posted October 15, 2015 Oh! Hang on have you got it set to that roles are configured as i would want different SSIDs and certain users to access these SSIDs. Thats the problem i was having, everyone had to be in the default role group wih access the to wlan. We have 1 SSID for all users. This covers 3 - 18 year olds and staff. Can't see any reason to have anymore to be honest. Plus multiple SSID's will have an impact on WIFI performance.
truebluesteve Posted October 15, 2015 Posted October 15, 2015 Is that radius authentication over AD authentication? Ruckus and smoothwall radius authentication dont work (ive not got it to work, and spent time with SW on this) however AD authentication and Smoothwall Radius Accounting works. Also, a certificate is needed for windows 7 devices with radis authentication. We have it working here, albeit only on 1 WLAN on its own VLAN. We have 2 more WLAN's - also on their own VLAN's but they have different authentication methods. There is a bug in the Smoothwall software that causes us a particular issue using this setup but it works fine in the main
timbo343 Posted October 15, 2015 Posted October 15, 2015 Ahh thats why it dont work. They keep shugging me off with it getting me to try different ways to get what i want. Has it been reported to them? Do they know what is causing it?
Jose Posted October 20, 2015 Posted October 20, 2015 so many different successful ways of doing this but this how we do ours 5 ssids but only 4 deployed on each ap group and 3 of the ssid are non broadcasting. ssid = sta-teacher is a 5ghz ac device ssid, with qos limiting each laptop to max speed of 5MB, this used for 6thform laptops and BYOD devices that IT have allowed on this ssid. ssid = sta-apple is 5ghz ac apple only devices, qos limiting 2mb, with a acl restriction to prevent access to school resources other than internet. this ssid only allows approved mac address. ssid = KS2 or KS1 or HS, these are 5ghz ac only and are on a ap group depending on the area of the school, qos is max speed of 25MB ssid = byod is a 2.4ghz using a captive portal with qos limiting it to 1mb we use around 300 curriculum laptops and 140 6thform laptops and 130 Ipads and very rarely have issues but we are strict about the quality of devices we allow onto the 5GHZ radios.
Duke5A Posted October 28, 2015 Posted October 28, 2015 No VLANs here. I cannot begin to tell you how bad of an idea this is. By standing imperial decree there isn't a single device that is allowed to touch the internal network if it isn't being managed by me. You need a separate SSID and VLAN that is completely segregated from the internal network for BYOD. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now