Stormborn15 Posted October 2, 2017 Posted October 2, 2017 Hi All, I was wondering how / if any of you have set up an SSID that doesn't require a guest device to have the proxy settings added manually to their device? or the protex ssl? We use MERAKI for wifi and have E2BN for broadband.
atcoates Posted October 2, 2017 Posted October 2, 2017 (edited) Hi, We have Meraki Wi-Fi and have set up a staff wi-fi that uses meraki dhcp and google authentication to sign them in specifying our domain as the only allowed domain. You can also use facebook sign in etc as well. https://meraki.cisco.com/blog/2013/09/secure-guest-access-in-3-steps/ Edited October 2, 2017 by atcoates
jthompson Posted October 2, 2017 Posted October 2, 2017 (edited) We use UniFi and have a separate VLAN set up for the guest SSID. The WAPs authenticate clients using RADIUS (set up using NPS) on our main VLAN, but clients on the guest SSID only ever get to see the separate VLAN. We've then got a pfSense box on that VLAN which acts as a DHCP server and DNS forwarder, with the Protex proxy configured using WPAD. Apple and Windows devices can therefore be set for proxy autodiscovery, but Android does require the user to manually set the proxy (we have posters up with instructions for the different device types). If they want to use Google search, they have to install the Protex certificate, but it's not required for general web access. We've simplified the process there as far as possible by linking to it with a tinyurl. That's all set up without using any of the specific 'guest access' features of UniFi or a captive portal: it's just a regular SSID as far as it's concerned. In NPS, you can set up a policy for a particular SSID (i.e. your guest SSID) by having a condition against "Called Station ID". You can then set it up as you need it. For instance, we have a security group that will grant members the ability to connect to the guest WiFi, so we can take away that right if someone is naughty. It also means that we can hand out guest login details for particular events, disabling the account of changing the password once they're finished, etc. Edited October 2, 2017 by jthompson
Stormborn15 Posted October 2, 2017 Author Posted October 2, 2017 Hi, We have Meraki Wi-Fi and have set up a staff wi-fi that uses meraki dhcp and google authentication to sign them in specifying our domain as the only allowed domain. You can also use facebook sign in etc as well. https://meraki.cisco.com/blog/2013/09/secure-guest-access-in-3-steps/ Hi @atcoates, So does this then mean that if a new device comes into your school , you don't put in a proxy setting into their browser?
atcoates Posted October 2, 2017 Posted October 2, 2017 (edited) I can only comment on my schools set up and our ISP may do something but when using meraki dhcp they don't need to use a proxy. Every other machine in the school does use a proxy. It maybe you need to pass on some info to your ISP to achieve this. Try it yourself and see if it works, I was surprised it did, but it does! Edited October 2, 2017 by atcoates
Stormborn15 Posted October 2, 2017 Author Posted October 2, 2017 I can only comment on my schools set up and our ISP may do something but when using meraki dhcp they don't need to use a proxy. Every other machine in the school does use a proxy. It maybe you need to pass on some info to your ISP to achieve this. Try it yourself and see if it works, I was surprised it did, but it does! Thanks - will do :-)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now