Jump to content

Recommended Posts

Posted

Hi,

 

Apologies in advance if this causes anyone to pull out their hair.

 

Last year we had an AeroHive wiFi system installed. Traffic is pushed through to our RM router which has a transparent proxy. Everything works.

 

Now we need to set up our SmoothWall box but we don't know where to start. Smoothwall will be set up inline, internet traffic gets pushed to Smoothwall which pushes it through to the RM router.

 

Adding SmoothWall means (for client PC's) changing the proxy address. We've tested this with PC's and it works fine. Where do we make this change in the AeroHive config manager? Is it as simple as that or are we missing something?

 

The company who put the AeroHive in didn't exactly leave much in the way of documentation & I was away during the install ...

Posted

At a guess, here's what is happening. Traffic is pushed from the WAPs to a switch based on VLAN ID and the Switch pushes the traffic on to the gateway address for the VLAN.

 

Because the proxy is transparent , no proxy info needs adding in the AeroHive management console. If we want to push the traffic through to Smoothwall, the change needs to be made on the switch (changing the gateway address to the Smoothwall IP)

 

I'm just guessing here so please correct me!

 

Once we figure this bit out the next thing will be HOW users connect. On the wired network, when a user logs in, their machine registers a token with Smoothwall which identifies them and ensures they get the correct filter settings. How will this work with the AeroHive? Does it need binding to AD? Currently it does not, users & their email addresses have been imported from a spreadsheet & are enabled for wifi use manually.

  • 2 weeks later...
Posted
This may not be helpful ...but I wouldn't be doing it this way. Exporting and importing user details - YUK! I would use smoothwall's radius server - and get smoothwall to authenticate against your AD. Then I would configure Aerohive to use smoothwall's radius for authentication - rather than Aerohive's PPSK system (which I assume you are using)....or at least I would do that for BYOD. For school devices (but not domain PCs) I would use smoothwall's captive portal (again using its integration with AD) with a timeout equal to the length of a teaching period. FOR domain PC's - yes I'd probably use smoothwall as a proxy. I would segregate the various traffic from domain/BYOD/staff/etc onto different VLANs and different physical networks on smoothwall - and add rules to allow any necessary communication - such as allowing mobile devices access to print servers, or staff devices access to airservers. Setting this up - is clearly not trivial...and you will need to think about DNS as internal addresses will need to resolve correctly etc. Can't help thinking that you need Aerohive installer and Smoothwall installer - to spend a day together to make it work.
  • Thanks 1
  • 1 month later...
Posted

Sorry for dragging this old thread back to life... To answer AlanD more fully, yes we are using PPSK on the Aerohive. It's not an issue now because no one (almost!) is using the wifi. This is OK for limited use but not ideal for BYOD.

 

I'm a bit further down the track than I was, at least in understanding the concepts

 

I've created a test BYOD policy in the Aerohive

This contains a BYOD SSID

I'm going to push that down to a single WAP for testing purposes

 

Binding the Aerohive to a RADIUS server seems easy enough (**!!!**)

Setting the Smoothwall up as a RADIUS server doesn't seem that hard either...

 

But I'm a bit confused about setting up the NPS role on a windows server

 

Can I set it up on a DC?

Posted

We have smoothwall and unifi here. We treat the BYOD is a seperate network, it is vlaned off from everything except the smoothwall box, which then acts as a router using group bridgeing to the main network.

 

We have the ap`s radius authentication+accounting pointed to smoothwall. We use smoothwalls built in dhcp server to serve addresses to the BYOD network (Can be important for some ap`s that dont send framed-ip headers). Smoothwall is set to core authentication for the BYOD vlan, this picks up the radius login user for the device and uses that as the user in smoothwall, so doesnt require the user to login seperately to smoothwall. We then use group briding rules to allow access to internal servers from the BYOD network. In this setup there is no need for nps.

Posted
Same here. We don't use NPS either (..we used to when we had a TMG box ...but never actually applied any meaningful policies with it as far as I remember). And we keep BYOD separated in the same way - using smoothwall's DHCP and Radius server the the BYOD network. And while we have routing/bridging we have some tight restrctions on which servers and protocols are allowed to access anything in our DMZ zone (basically the same as is allowed from an exterrnal access...except for access to bonjour/airplay/print for staff).
Posted
You can use one of the aerohive WAPS as a radius server as it has built in functionality to act as a radius server. However, it isn't that reliable so NPS is a better route, i installed it on a DC.
Posted
No - If you are using smoothwall - you need to have smoothwall as your radius server and DHCP server for the wireless network. This is because it then knows who it has handed which IP address to as part of the authentication when they connect a device to the wireless. Yes - in theory you can use a different Radius server ...but things then sstart to get a bit more complicated if you want smoothwall to know who that user is - and which AD group they belong to etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...