Jump to content

Recommended Posts

Posted

Hi,

 

I'm currently looking at our BYOD WiFi config as we currently use a captive portal (from firewall) to get students to enter AD credentials and then gain access(filtered) to the internet.

 

I want to move away from the captive portal, as we are getting quite a few issues with it not popping up, or getting SSL errors as although i have a public certificate on the page, it is not google.com's one, the other problem is that i don't have the visibility of the user in my wifi system, so if i see a device that is behaving in an unwanted manner, or not experiencing a good connection, i have to go look up the user elsewhere. So i want to move to some form of radius authentication where the student/staff member put's their username/password in as part of the connection instead.

 

My AD is 2012, WiFi is Aerohive and Firewalls are Fortinet (I also have Smoothwall Proxy's)

 

Where do i do the radius/authentication?

 

The AP has to be involved somewhere to secure the connection... but i also need the firewall to know who the user is. AD Exists... i also have 2 NPS server's doing the authentication for Domain Computers

 

Very confused.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...