ccadit Posted December 5, 2016 Posted December 5, 2016 We currently use Meraki for our wireless network which does work very well, however due to cost we are trying to evaluate UNIFI. Currently we use Microsoft NPS to authenticate BYOD users using radius. Meraki then puts all the clients in a private 10.0.0.0 range. The SSID is using a splash screen that interrogates Radius. With our own assets we create an AD object with username as the Mac Address and the password as the Mac Address these are then able to connect to an open SSID without requiring any credentials. This uses an SSID that has MAC-based access control. How can we achieve something similar in UNIFI with ensuring our BYOD devices bar internet access are not able to do anything else and our own assets have full access without having to populate any credentials. Any guidance or advice would be very much appreciated
AlanD Posted December 27, 2016 Posted December 27, 2016 I'd certainly add my name to those who think that all these "managed" wireless systems are difficult to justify the cost of. I'm not suggesting that they are not good - indeed the Meraki web interface is fantastic - but once you have finished playing with all the knobs and switches and being nosy into what everyone is doing you soon find that you don't look at it for weeks - months - possibly for whole year - because it just sits there and works. You care still doing to need some kind of web filter/monitor - so there is little point in paying for duplicating those firewall type features in wireless management systems. Yes - some of the cloud managed APs work better with large number of clients - but when you start installing 1 AP per classroom - and you probably can't avoid this with 5GHz as it barely goes through thin walls - its no big ask to support up to 30 devices with Ubiquiti devices. I use Enterprise WPA with a radius server for BYOD- although we do expect users to enter their AD logon details to connect - which are cached in most devices and rarely require re-entering. The radius/DHCP data is used by web filter/firewall to identify the user. Our own devices connect via a different VLAN with a WPA "key" - with a GPO that prevents the key being read. You can limit and/or force DHCP addresses to known MAC addresses regardless of which wireless system is in use. Ubiquiti APs are so cheap - best plan would probably be to get one and try it...although you might need some external support to set up VLANS, DHCP, RADIUS etc, if its not your area of expertise.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now