Jump to content

Recommended Posts

Posted
If you switch to radius you shouldn't have this issue. It will only hand out an IP after authentication has occurred.

 

Is that radius authentication over AD authentication? Ruckus and smoothwall radius authentication dont work (ive not got it to work, and spent time with SW on this) however AD authentication and Smoothwall Radius Accounting works. Also, a certificate is needed for windows 7 devices with radis authentication.

Posted
Is that radius authentication over AD authentication? Ruckus and smoothwall radius authentication dont work (ive not got it to work, and spent time with SW on this) however AD authentication and Smoothwall Radius Accounting works. Also, a certificate is needed for windows 7 devices with radis authentication.

 

Smoothwall Radius and accounting works with our Ruckus in our schools. And in 2 others schools I setup.

 

The Windows 7 thing I am aware of so we don't support it with the BYOD, not really caused us an issue anyway, most people are on 8 and above. Soon it won't be supported on the production network.

Posted

You could try blocking known unauthorised devices? (long winded I know but maybe worth a try and might stop other students from connecting if their peers can't connect.)

 

Export the list of MAC addresses (Monitor -> Wireless Clients) sort by STATUS so that UNAUTHORISED are at the top, click EXPORT CSV.

 

Pop the CSV into Excel and filter it so it just shows the UNAUTHORISED MAC addresses and then save that.

 

Configuration -> Access Control -> L2 Access Control -> Create New. Give it a name and IMPORT CSV (you can download an example CSV file from here as well - nice touch)

 

Configuration -> WLANS and select your BYOD/Guest Wlan

 

Expand ADVANCED OPTIONS and then next to L2 Access Control, you should see the L2 Access Control list you created in the previous step.

 

This will prevent any device in the list from even connecting onto your WLAN, so it won't be able to get a DHCP lease.

 

I believe that there is a limit to the number of MAC addresses within an L2 ACL but I don't know what it is.

 

Obviously, if you get an issue with an approved client not being able to connect, check the L2 ACL list for their MAC address.

Posted
Smoothwall Radius and accounting works with our Ruckus in our schools. And in 2 others schools I setup.

 

The Windows 7 thing I am aware of so we don't support it with the BYOD, not really caused us an issue anyway, most people are on 8 and above. Soon it won't be supported on the production network.

 

Oh! Hang on have you got it set to that roles are configured as i would want different SSIDs and certain users to access these SSIDs. Thats the problem i was having, everyone had to be in the default role group wih access the to wlan.

Posted
Oh! Hang on have you got it set to that roles are configured as i would want different SSIDs and certain users to access these SSIDs. Thats the problem i was having, everyone had to be in the default role group wih access the to wlan.

 

If you can you want to keep them all on the same SSID and then segregate them by vlan: your radius will do this.

Posted
Ive got different SSIDs with their own VLANs. I guess that is where the enable dynamic vlan comes into play on ruckus.

 

Sure, I guess they must be using different auth methods? We have one SSID that serves 6 vlans and another SSID for a different auth method.

Posted
Oh! Hang on have you got it set to that roles are configured as i would want different SSIDs and certain users to access these SSIDs. Thats the problem i was having, everyone had to be in the default role group wih access the to wlan.

 

We have 1 SSID for all users. This covers 3 - 18 year olds and staff. Can't see any reason to have anymore to be honest. Plus multiple SSID's will have an impact on WIFI performance.

Posted
Is that radius authentication over AD authentication? Ruckus and smoothwall radius authentication dont work (ive not got it to work, and spent time with SW on this) however AD authentication and Smoothwall Radius Accounting works. Also, a certificate is needed for windows 7 devices with radis authentication.

 

We have it working here, albeit only on 1 WLAN on its own VLAN. We have 2 more WLAN's - also on their own VLAN's but they have different authentication methods. There is a bug in the Smoothwall software that causes us a particular issue using this setup but it works fine in the main

Posted

Ahh thats why it dont work. They keep shugging me off with it getting me to try different ways to get what i want.

 

Has it been reported to them? Do they know what is causing it?

Posted

so many different successful ways of doing this but this how we do ours

 

5 ssids but only 4 deployed on each ap group and 3 of the ssid are non broadcasting.

 

ssid = sta-teacher is a 5ghz ac device ssid, with qos limiting each laptop to max speed of 5MB, this used for 6thform laptops and BYOD devices that IT have allowed on this ssid.

ssid = sta-apple is 5ghz ac apple only devices, qos limiting 2mb, with a acl restriction to prevent access to school resources other than internet. this ssid only allows approved mac address.

ssid = KS2 or KS1 or HS, these are 5ghz ac only and are on a ap group depending on the area of the school, qos is max speed of 25MB

 

ssid = byod is a 2.4ghz using a captive portal with qos limiting it to 1mb

 

we use around 300 curriculum laptops and 140 6thform laptops and 130 Ipads and very rarely have issues but we are strict about the quality of devices we allow onto the 5GHZ radios.

Posted
No VLANs here.

 

I cannot begin to tell you how bad of an idea this is. By standing imperial decree there isn't a single device that is allowed to touch the internal network if it isn't being managed by me. You need a separate SSID and VLAN that is completely segregated from the internal network for BYOD.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...