Blue_Cookeh Posted May 20, 2016 Posted May 20, 2016 (edited) Hi All, I'm trying to go for a BYOD style plan and was wondering how you guys did it? We have some users (governors for example) that need Internet access whilst on site, but not network access. How would you go about this? I don't want to give them access straight onto the Internet, we'd still rather be logging traffic against specific users. I thought about 802.1x authentication on our WAPs but I'm not entirely sure what to do about the certificate, since their devices wont trust our CA. Ideally, I'd like a captive portal type scenario which will authenticate users against AD and pass this on to Lightspeed somehow since this seems like the most unobtrusive way of doing things. I know Lightspeed has a captive portal, but this doesn't seem to have any sort of granular control (so I can disable it on our curriculum LAN). Any ideas? Edited May 20, 2016 by Blue_Cookeh
pcstru Posted May 20, 2016 Posted May 20, 2016 (edited) We use pfsense's Capitive Portal with a Meru system for customers of our leisure facilities. From a users POV, they collect a voucher from reception, connect to a guest SID, any browser request will then be sent to the login page where they accept an AUP, type in their voucher number and are then redirected to the page they requested. Technically, we operate a dedicated VLAN for the guest SID with the pfsense LAN interface set as the gateway. We point the WAN interface at our smoothwall and smoothwall treats the whole VLAN as not requiring any authentication but student level filtering is applied. ETA - we also do BYOD for students where we register their MAC address and they authenticate via RADIUS. Edited May 20, 2016 by pcstru
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now