Arcolite Posted November 28, 2016 Posted November 28, 2016 We're looking at implementing BYOD shortly but we're struggling to come to a consensus on the best approach. We have a few options are our disposal but can't decide which is the best option for the smoothest end user experience. LDAP Captive Portal on our Palo Alto Firewall with URL filtering polices on the Palo Alto appliance setup for the required user groups LDAP Captive Portal on via CensorNet USS Gateway. Our Domain Trust client machines use this as their proxy currently, but we're considering moving away from CensorNet and consolidating on just Palo Alto. Captive Portal on AeroHive with SSL Certs and instructions which redirects to Palo Alto Captive Portal for Authentication. Our ultimate goal is to have exactly the same visibility on BYOD Untrust clients as we do with our Domain Trust clients but in such a way where it's minimal effort for the user. Every route I've tried so far is fine for me, as a techy, but a complete minefield for Students and Staff. I've currently got LDAP Captive Portal (redirect, not transparent) semi-working in Palo, but the user experience isn't seemless. How have others dealt with this?
AlanD Posted December 26, 2016 Posted December 26, 2016 Well - we use enterprise WPA with Radius/LDAP for BYOD devices to connect to the wireless, and as the Radius server is our Smoothwall box - which also hands out DCHP addresses to BYOD devices there is no need for further authentication. The problem with captive portals is that devices often need to use wireless traffic for email, and apps (including the google search app) without even starting up a browser or visiting a web page....and that makes it really annoying if your emails and notifications are not even getting to your device. And requiring users to set a proxy (even if its only to tick a box to allow automatic configuration via a proxy pac file) is little better - because - again - there may be no authentication information passed as far as "apps" are concerned - and most apps don't even know how to use a proxy even if they use http With Radius - once a user has entered his details in their device ... it just works...and ...in our case smoothwall logs all their useage against those credentials. Yes - you need users to install a certificate to inspect their https traffic - but that is going to be necessary for whatever method you use. We have an internal portal that everyone uses - with a link to the certificate to make this really easy. Having said that...some android devices seem to install certificates in a very round about way, failing to do it directly through the browser.
Arcolite Posted January 3, 2017 Author Posted January 3, 2017 Thanks for the reply. Our end goal is for 802.1x and Radius, we're just not there yet. I think with what we've got to work with there are going to be some compromises. I'm currently looking at using the CensorNet Gateway Captive Portal to see if that's more user friendly than the Palo Alto CWP.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now