Jump to content

Recommended Posts

Posted

Morning,

 

I have got a new Fortinet wireless system setup. It is working really well but I need some help with getting some RADIUS authentication setup to authenticate with a Schools Broadband hosted Lightspeed system.

 

So I have a RADIUS server on our domain to authenticate users against our AD which is setup and working fine with the controller. I have a hosted Lightspeed which supports RADIUS authentication. I have added these details onto both the wireless controller and our internal NPS server but Lightspeed is not authenticating or picking up the RADIUS authentication.

 

If anyone has a solution to get this working that would be great.

 

Thanks,

Posted (edited)

When someone stops on the road and asks you the way to X it's always tempting to offer the reply "well, I wouldn't start from here...".

 

Ideally you need to design access points, controller, radius and filtering all as one solution. Putting together a random combination, regardless of how good and well designed each product might be does not guarantee that they are going to work together. You need to get each supplier to explain how they are going to integrate their component with the rest your network components.

 

I am pretty certain, assuming fortinet/Meru controller is on site, that you can integrate that with any standard radius controller. Get that working first so that wpa enterprise connections authenticate using ad credentials via your radius server. Not sure if it's sufficient to have a shared key on every access point or whether it's sufficient just to have it for the controller.

 

Then you need radius accounting to pass details of the logo and is addess to light speed. Not sure whether light speed supports an on site relay to pass this on or whether you will need to write firewal rules to do it directly....or maybe light speed doesn't support using radius accounting....you will need to talk to light speed.

 

Don't let each supplier make you decide to repeat the logon process via a second captive portal...that would be plainly annoying, especially for apps that don't even open a browser.

.

Edited by AlanD

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...