The_IT_Guy Posted February 26, 2016 Posted February 26, 2016 Right i need some help with this as my head is getting battered. Trying to setup BYOD on our ruckus wireless (ZD3000) with Lightspeed filtering from schools broadband. Firstly ACL's and subnets. I have set up a deny rule for 10.0.0.0/32 to stop them connecting to any of our computers, servers or printers which are all in 10.24.80.1-10.24.95.255. But i need them to be able to access our moodle server and HAP server which are in this range. How would i do this? Secondly i tried setting up radius authentication on my ruckus controlled and linking it to my lightspeed filter. It works in that you login to the ruckus controller and it passes the credentials to the filter and authenticates but it is not doing the final authentication so it is falling back to the default student level even when logging in as a teacher. Any advice would be great thanks.
pantscat Posted February 26, 2016 Posted February 26, 2016 In terms of ACLs, you'll need to create allow rules for your HAP and Moodle servers and order them so that they are above the deny rule. Are your DNS servers on that subnet, too? You'll want allow rules for those. Not sure about your radius issue - is lightspeed recognising them as properly authenticated?
The_IT_Guy Posted March 2, 2016 Author Posted March 2, 2016 First things first this is the ACL's i have configured. I wiped them and i have started adding them in one by one to get it working. With this setup the devices get an IP address and can access external sites. But they cannot access any internal sites because of my Deny rule (Which is basically what i want.) But how do i now add individual IP addresses for the Moodle Server and HAP? When i try add just the IP address it comes back saying it is not a valid subnet as i don't have a /20 for example after it but that is where my knowledge gets really sketchy. Any advice how you add an individual IP address would be greatly appreciated. Cheers
pantscat Posted March 2, 2016 Posted March 2, 2016 (edited) Can you not add the IP address with the correct subnet after it? e.g. 10.10.10.10/24? EDIT... Scrap that - add the ip address wth a /32 after it. Try that. Edited March 2, 2016 by pantscat Being dim 1
The_IT_Guy Posted March 2, 2016 Author Posted March 2, 2016 (edited) Can you not add the IP address with the correct subnet after it? e.g. 10.10.10.10/24? EDIT... Scrap that - add the ip address wth a /32 after it. Try that. Thanks for the reply. That looks to have done the trick! Edited March 2, 2016 by The_IT_Guy Being dim / Set it to deny instead of allow :P
The_IT_Guy Posted March 2, 2016 Author Posted March 2, 2016 Secondly the radius authentication. It doesn't seem to identify the user correctly. It lets them log in and get on the wireless but then doesn't match them up to any assignments so gives them the default of sixth form. So it appears to check the credentials against our AD fine its when it trys to then match their AD group to the assignments in lightspeed that it fails.
pantscat Posted March 2, 2016 Posted March 2, 2016 That sounds like lightspeed isn't matching AD groups properly. I'm not really familiar with Lightspeed stuff though, so can't help. Soz! Good luck.
_techie_ Posted April 28, 2016 Posted April 28, 2016 You need to get your Radius server to forward authentication to Lightspeed from Ruckus. If your using NPS it's fairly easy to do, just add in Lightspeed as a RADIUS client and you should be good to go.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now