burgemaster Posted November 2, 2016 Posted November 2, 2016 Hi, We are testing out 5 x Ubiquiti AC access points. These have been setup with a cloud management system. They are all registered in the management system but currently they are showing as Offline. I believe that this is due to the school they are installed requires a proxy and port to access the internet. I'm guessing that the APs are trying to connect to the web to update their details but cant as they have no way out without a proxy. There is always the option of a local cloud key or setting up local management software on the server. But if possible we would like to use the cloud management. We have SSH access to the APs. They have all pulled a lease from DHCP. They appear to be a flavour of Linux. List of available commands: https://community.ubnt.com/t5/UniFi-Wireless/Unifi-CLI-SSH-commands-list/td-p/944081 Does anyone please know how to attempt to add proxy details to these APs? We just require proxy address and port 3128. https://www.ubnt.com/unifi/unifi-ap-ac-pro/ Thanks in advance
Blue_Cookeh Posted November 2, 2016 Posted November 2, 2016 (edited) You'd be better off not screwing with the underlying OS on those APs and just creating a firewall exemption to allow whatever the management port is out to whichever IP your cloud management console is using. EDIT: Port information is here: https://help.ubnt.com/hc/en-us/articles/204910084-UniFi-Change-Default-Ports-for-Controller-and-UAPs Edited November 2, 2016 by Blue_Cookeh
burgemaster Posted November 2, 2016 Author Posted November 2, 2016 You'd be better off not screwing with the underlying OS on those APs and just creating a firewall exemption to allow whatever the management port is out to whichever IP your cloud management console is using. EDIT: Port information is here: https://help.ubnt.com/hc/en-us/articles/204910084-UniFi-Change-Default-Ports-for-Controller-and-UAPs Thanks for the reply. There isn't a firewall issue, its just that all devices require proxy details entered to be able to access the web. For example in IE you are required to add proxy details, on an iPad you need to enter them under wireless settings. Or are you suggesting that they setup a transparent proxy for these APs? that would be great but I don't believe that would be an option from Worcestershire Council.
burgemaster Posted November 2, 2016 Author Posted November 2, 2016 Does Linux maybe support WPAD to automatically enter the proxy authentication details???
Blue_Cookeh Posted November 2, 2016 Posted November 2, 2016 I believe you should be completely ignoring the proxy, Worcester CC should have a way to give you access to a 'clean' Internet connection for these specific devices, the proxy is only going to cause you headaches in the long run. Back to the actual problem, there's about twenty different ways to set proxies in Linux and even then it is completely up to the software (in this case Ubiquiti's management software on the AP) as to wether it uses the proxy or not.
burgemaster Posted November 2, 2016 Author Posted November 2, 2016 I believe you should be completely ignoring the proxy, Worcester CC should have a way to give you access to a 'clean' Internet connection for these specific devices, the proxy is only going to cause you headaches in the long run. Back to the actual problem, there's about twenty different ways to set proxies in Linux and even then it is completely up to the software (in this case Ubiquiti's management software on the AP) as to wether it uses the proxy or not. Thanks again. Ive asked many years ago, but then they give different levels of internet access by giving 2 different proxy addresses. We were considering putting a pSense install between their supply and the core switch. We might just have to install the local management software on the server but wanted to give the cloud management a good try beforehand.
localzuk Posted November 2, 2016 Posted November 2, 2016 This is a firewall issue - you should be able to request that the APs have direct access out to the ports they require from your ISP. With SWGfL, we would fill out a change request form with the IP addresses of the devices, and the ports they need to be able to access. That way, proxies are ignored entirely.
burgemaster Posted November 2, 2016 Author Posted November 2, 2016 Thanks, They are both internet provider and firewall. We fill out change request for firewall changes that get passed though their firewall when their proxy is used, but have never been able to request that an IP be able to access the web without a proxy being used. Just to confirm, do all devices require proxy settings for all web access (E.g. Google) under SWGfl and you can request that certain devices do not require the proxy details be entered to gain web accesss? That would be ideal!!!! Thanks
localzuk Posted November 3, 2016 Posted November 3, 2016 No, not all devices require proxy details. An example, our Franking machine is able to go direct to several addresses on port 80 and port 443.
ReBoot Posted November 7, 2016 Posted November 7, 2016 We have Ubiquiti ac-lites throughout my primary school. In general Ubiquiti kit doesn't seem to support an internet proxy which is a bit of an omission for enterprise kit. I have a local cloud key installed for management which I think is a brilliant bit of kit for the money (under £100 for a wifi controller !). I think this is the way to go, as its a small price, and you have full local control over your wifi network (with the option of Cloud management as well). So far my experience with unifi has been very positive with staff even complementing the wifi quality and performance. As others have commented you should be able to bypass the proxy for specific IP addresses by configuring your firewall settings.
ITGuyWestMidlands Posted November 7, 2016 Posted November 7, 2016 I think the acess points require internet access for firmware updates alao
Michael Posted November 7, 2016 Posted November 7, 2016 I agree with previous statements - implement a transparent proxy, or request your provider to bypass the proxy for a group of IPs. Only problem with this is they'll need to be static (for ease), unless you start specifying reservations. Easier to bypass a block of IPs in sequential order rather than 10 random IPs.
mikeprice Posted November 7, 2016 Posted November 7, 2016 I think the acess points require internet access for firmware updates alao doesn't seem to be a problem with ours
Blue_Cookeh Posted November 8, 2016 Posted November 8, 2016 doesn't seem to be a problem with ours The APs pull their firmware from wherever the controller is based, either on-prem or in cloud.
mikeprice Posted November 8, 2016 Posted November 8, 2016 Good point - we have the controller on a server - it takes almost no resources so I don't see the point in using a 'cloud' version I like everything under MY control (rings hands in a scary way and strokes white cat) then when I cock it all up I know who to blame
Michael Posted November 8, 2016 Posted November 8, 2016 Good point - we have the controller on a server - it takes almost no resources so I don't see the point in using a 'cloud' version I like everything under MY control (rings hands in a scary way and strokes white cat) then when I cock it all up I know who to blame Will the localised server version work over multiple subnets out of curiosity?
mikeprice Posted November 8, 2016 Posted November 8, 2016 Will the localised server version work over multiple subnets out of curiosity? As far as I am aware - Yes - but I have never had to actually do it when we got the things I was told that the local version can do everything that the cloud version can - except - presumably - for access from home etc 1
Michael Posted November 8, 2016 Posted November 8, 2016 Do you access it from a browser? I mean the management of it all.
mikeprice Posted November 8, 2016 Posted November 8, 2016 Do you access it from a browser? I mean the management of it all. Yes - you start the controller and it comes up with a window - inside the windows is a button - click that and it launches a browser window which has full access ot the controller alternatively you can easily see the port it connects to on the server and then access it from anywhere on the network I think they have problems with IE but firefox and Chrome seem to work fine It is so reliable that I use it as a basic network check in the mornings it also allows me to identify where teacher/TAs are as they all have phones that connect - it's a bit like Harry Potter's scroll - I love it!!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now