Jump to content

Recommended Posts

Posted

Hi

 

We currently use EXA as our ISP with a Stormshield (Netasq) firewall and Meru wifi .

 

Stormshield can report on internet access for users, and ip addresses for all domain devices but only ip address for lan wifi devices.

 

We have a LAN ssid on our wifi which authenticates via radius and all of this works fine apart from the reporting.

 

There is a Netasq SSO agent installed on the server that picks off the logon events and obtains the username. This gets the domain devices but not those that have been authenticated via Radius.

 

EXA are unable to help any further but they say we can use the captive portal on the Stormshield box to enter the network details, and if we do this it does report correctly. However it is a really naff portal and it would mean everyone would have to log back into their wifi every day. Is this something that you all do anyway? With our normal wifi Lan logon once you are in you are in and you do not need to log back in every day.

 

Does anyone know how we can get those logon events reported on the DC?

 

Any advice would be appreciated.

 

Thanks

Posted

If you're using user auth for RADIUS on the wireless, you'll have a log of accounts associated with each device (AD account + MAC is logged by default). Look at event id 6278 and 6272, for example with source "Network Policy Server" (assumes Windows Server providing RADIUS).

 

If you can tie that to DHCP leases at that time of interest, you know who* was accessing what on which device.

 

or rather, whose account is tied to the device.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...