Jump to content

Recommended Posts

Posted (edited)

Hi All,

 

I'm trying to go for a BYOD style plan and was wondering how you guys did it?

 

We have some users (governors for example) that need Internet access whilst on site, but not network access. How would you go about this? I don't want to give them access straight onto the Internet, we'd still rather be logging traffic against specific users.

 

I thought about 802.1x authentication on our WAPs but I'm not entirely sure what to do about the certificate, since their devices wont trust our CA. Ideally, I'd like a captive portal type scenario which will authenticate users against AD and pass this on to Lightspeed somehow since this seems like the most unobtrusive way of doing things.

 

I know Lightspeed has a captive portal, but this doesn't seem to have any sort of granular control (so I can disable it on our curriculum LAN).

 

Any ideas?

Edited by Blue_Cookeh
Posted (edited)

We use pfsense's Capitive Portal with a Meru system for customers of our leisure facilities. From a users POV, they collect a voucher from reception, connect to a guest SID, any browser request will then be sent to the login page where they accept an AUP, type in their voucher number and are then redirected to the page they requested. Technically, we operate a dedicated VLAN for the guest SID with the pfsense LAN interface set as the gateway. We point the WAN interface at our smoothwall and smoothwall treats the whole VLAN as not requiring any authentication but student level filtering is applied.

 

ETA - we also do BYOD for students where we register their MAC address and they authenticate via RADIUS.

Edited by pcstru

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...