Jump to content

Recommended Posts

Posted

We're looking at implementing BYOD shortly but we're struggling to come to a consensus on the best approach.

 

We have a few options are our disposal but can't decide which is the best option for the smoothest end user experience.

 

  1. LDAP Captive Portal on our Palo Alto Firewall with URL filtering polices on the Palo Alto appliance setup for the required user groups
  2. LDAP Captive Portal on via CensorNet USS Gateway. Our Domain Trust client machines use this as their proxy currently, but we're considering moving away from CensorNet and consolidating on just Palo Alto.
  3. Captive Portal on AeroHive with SSL Certs and instructions which redirects to Palo Alto Captive Portal for Authentication.

 

Our ultimate goal is to have exactly the same visibility on BYOD Untrust clients as we do with our Domain Trust clients but in such a way where it's minimal effort for the user.

 

Every route I've tried so far is fine for me, as a techy, but a complete minefield for Students and Staff.

I've currently got LDAP Captive Portal (redirect, not transparent) semi-working in Palo, but the user experience isn't seemless.

 

How have others dealt with this?

  • 4 weeks later...
Posted

Well - we use enterprise WPA with Radius/LDAP for BYOD devices to connect to the wireless, and as the Radius server is our Smoothwall box - which also hands out DCHP addresses to BYOD devices there is no need for further authentication.

 

The problem with captive portals is that devices often need to use wireless traffic for email, and apps (including the google search app) without even starting up a browser or visiting a web page....and that makes it really annoying if your emails and notifications are not even getting to your device.

 

And requiring users to set a proxy (even if its only to tick a box to allow automatic configuration via a proxy pac file) is little better - because - again - there may be no authentication information passed as far as "apps" are concerned - and most apps don't even know how to use a proxy even if they use http

 

With Radius - once a user has entered his details in their device ... it just works...and ...in our case smoothwall logs all their useage against those credentials.

 

Yes - you need users to install a certificate to inspect their https traffic - but that is going to be necessary for whatever method you use. We have an internal portal that everyone uses - with a link to the certificate to make this really easy. Having said that...some android devices seem to install certificates in a very round about way, failing to do it directly through the browser.

  • 2 weeks later...
Posted

Thanks for the reply. Our end goal is for 802.1x and Radius, we're just not there yet.

I think with what we've got to work with there are going to be some compromises.

 

I'm currently looking at using the CensorNet Gateway Captive Portal to see if that's more user friendly than the Palo Alto CWP.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...