Jump to content

Recommended Posts

Posted

Is anyone currently using Smoothwall for filtering with Windows NPS for RADIUS authentication?

 

I have a Ruckus wireless network and there seems to be a fair amount on the forum about using the Smoothwall as a RADIUS server, however, from the documentation I have read, the Smoothwall RADIUS does not allow for restricting certain users from joining wireless networks (i.e. if I only wanted the sixth form to access the BYOD network). I can see it would be possible to deny Internet access once a user is connected to a BYOD SSID however, this would mean an unnecessary traffic overhead from client devices joined to the wireless network that can't do anything. At the moment, my network denies access based on NPS policy/AD group membership. If the client doesn't meet a policy within a set time period the Ruckus drops the connection.

 

Please let me know if I have completely misinterpreted this and am talking nonsense.

 

Is it possible, but not many people are doing it, or is it a case of using NPS as a RADIUS accounting server and forwarding the info from there or from the Ruckus to Smoothwall?

  • 9 months later...
Posted
Are you looking to deny the user from the network by failing their login? (i.e. User auths with network and the return is login disabled and no network access) Or are you looking to stop them from browsing the web but still retain access on the LAN?
Posted
I want to control who connects to which wlan and on which devices which I can with NPS, just need to work out how to pass that information onto Smoothwall for seamless authentication.
Posted
I want to control who connects to which wlan and on which devices which I can with NPS, just need to work out how to pass that information onto Smoothwall for seamless authentication.

This is exactly what I want to do too. Currently, I have NPS which allows staff and 6th form onto the BYOD SSID but then they have to log in again on the smoothwall authentication page.

Posted

They are use to a seamless experience so that wouldn't go down to well, and surely SW can work out the user from the accounting information?

 

Another reason to switch is we've been having roaming issues with UniFi and Smoothwall radius, I think it something to do with lack of fast reconnect support but I cannot get to the bottom of it to be certain.

Posted

From my understanding in setting Smoothwall RADIUS setup:

 

1) Wireless Controller

- use the RADIUS auth against your RADIUS server(ususally domain controller)

- set the Smoothwall as your RADIUS accounting

2) On your Smoothwall

- wireless controller set as a client and pre-shared keys are installed to the wireless controllers

- RADIUS accounting should be set to NPS

 

If I'm not mistaken this should let you achieve what you're looking for.

  • 4 weeks later...
Posted
Thanks @SW_DavidNewton, I need to check if UBNT Unifi forward the Framed-IP-Address attribute in the accounting packet as apparently that is a show stopper..

Hi,

 

Did you get this working? I'm trying this now and cant seem to figure it out. Like you, we are running UniFi. I dont think it forwards the Framed-IP-Address attribute as it doesn't have an IP until it is connected anyway. Is there another way?

 

Thanks

Posted

This is what stumped me as far as UBNT where concerned UniFi "won't" pass the framed ip address packet to accounting servers, from various forms I read it was "too difficult"!

However I have had success in getting it working but I'm not entirely sure how! (I've tried a couple of different approaches) but at present I've set Smoothwall as the accounting server and the NPS servers for auth.

 

I need to investigate more over the next two days so will keep you posted.

Posted

Cool, thank you that would be great! I had tried it as you suggested with the UniFi's set to NPS for Auth and Smoothwall for Accounting, but didn't get the desired result; Perhaps I had something set wrong.

I also tried having both Auth and Acc on the UniFi pointing at the NPS server, and then on the "Connection Request Policies" have it forwarding any Accounting data coming from the BYOD SSID to the Smoothwall... this didn't seem to work either.

  • 2 years later...
Posted

Hi

 

Did you get this to work in the end? It seems UniFi isn’t sending the Framed-IP-Address attribute to our firewall (WatchGuard) var nps

Posted

We have had multiple cases of framed-ip not being sent when using Unify - it may have been addressed in their updates as we have sent this information to them multiple times.

 

When using NPS often setup Wifi to send auth to NPS and accounting to SW - if NPS need accounting as well, we forward accounting to NPS from SW as setting up NPS to forward accounting is tricky to configure - or at least, I could not figure out how to do it the few times I had to deal with an NPS server.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...