Jump to content

Recommended Posts

Posted

Hello everyone,

 

We have a Smoothwall UTM which is bound to Active Directory so can automatically identify users what are logged into the school domain. However, we are slowly rolling out BYOD for both students and staff and I would like to make use of RADIUS for the user authentication and have Smoothwall automatically log the user in without them getting another login page.

 

Currently our school managed laptops are authenticated onto our managed SSID using RADIUS machine authentication. This is done using a 2012 R2 NPS VM and has been working for almost a year without any issues.

 

I would like to, therefore, continue making use of the NPS for the user authentication for BYOD. I understand that I need to somehow forward RADIUS accounting onto the Smoothwall box so that I can make use of the SSO funtionality.

 

My question is: how do I go about doing this and getting it setup? I have contacted Smoothwall and they sent me a response but I am still not fully understanding what I need to do. Thought I'd ask on here as I'm sure someone has done it and got it working well :)

 

Many thanks in advance and hope the above makes sense.

Posted
What Wi-Fi system are you using?

Many thanks for your response. We are using Aerohive.

 

After having a further look into this I have managed to get it working, by forwarding only Accounting information to Smoothwall whcih then in turns forwards it onto the NPS server. It seems to all be working as expected from a high level. However, when running the "Functionality Tests" tools it displays the following error:

 

RADIUSError.png

 

I am currently stuck on resolving this, but am slowly making some progress with it! :)

 

Many thanks.

Posted
Many thanks for your response. We are using Aerohive.

 

After having a further look into this I have managed to get it working, by forwarding only Accounting information to Smoothwall whcih then in turns forwards it onto the NPS server. It seems to all be working as expected from a high level. However, when running the "Functionality Tests" tools it displays the following error:

 

[ATTACH=CONFIG]42715[/ATTACH]

 

I am currently stuck on resolving this, but am slowly making some progress with it! :)

 

Many thanks.

 

I am also looking to do this exact setup. Please do report back on how you get on and what you had to do to achieve it. Sorry I cant be any help as I'm yet to do it myself.

Posted
I am also looking to do this exact setup. Please do report back on how you get on and what you had to do to achieve it. Sorry I cant be any help as I'm yet to do it myself.

 

I got it working (apart from the issue above) by doing:

 

1. Set your Wireless Access Points/Controller to forward RADIUS accounting to Smoothwall (I created a new shared key between the APs and Smoothwall) ensuring that RADIUS authentication is still going to your NPS.

2. Add your Access Points/Controller to the "Authorised RADIUS Clients" part of "Services -> BYOD". If you have controller-less APs you can specify a CIDR mask so you don't have to enter each and every AP to the list.

3. Under "Forward RADIUS accounting to" enter your NPS Server information and the appropriate shared key.

4. In NPS, you will need to add the Smoothwall appliance as a RADIUS Client.

 

Once done, you just need to ensure the Transparent Proxy authentication method is set to "Negotiate NTLM/Kerberos (with redirect).

 

Once this was done, it started working as expected. I.e. Connect to BYOD SSID with AD credentials and then authentication to Smoothwall was seamless.

 

Hope this helps.

 

(Doesn't resolve the error I keep getting - have emailed SmoothWall regarding it but as mentioned, at a high level it appears to be working as expected).

  • Thanks 3
Posted
I have set this up in a number of schools. I always use core authentication for the BYOD authentication policy. Also make sure you go into services / settings and turn off the bottom tick box. Can't remember what it's called at the moment but it causes excessive CPU with BYOD
  • Thanks 1
  • 7 years later...
Posted

Check user activity in services - authentication or take a look at reports - realtime - system and select authentiocation from the section dropdown. You should see RADIUS logins in both places ideally.

 

Smoothall only use accounting for logins - it does not need to do authentication. On NPS or WIFI controller, you can forward or send accounting directly to Smoothwall. Authentication only works for AD connections but lookup does work for Google and Azure so if you can find a way to get RADIUS authentication working for those accounts, accounting sent to Smoothwall should give the correct user/group lookup result.

  • 5 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...