Jump to content

Recommended Posts

Posted
In the meantime could you perhaps run a RADIUS account server on a DC for instance, point your WiFi to that so it prompts for login credentials and push traffic through a local proxy such as squid for the time being to achieve what you need? It's far from ideal, as radius via the firewall/filter and wireless systems is almost a turnkey solution but you should be able to achieve something workable with no cost and relatively little effort. Have unauthenticated wifi clients go to a separate DHCP range maybe so they pick up the squid proxy as gateway. (thinking out loud, so could be rubbish!)

 

Firstly, thanks for your suggestion. This is similar to the setup we had before we went to SBB and was one of the reasons we switched (to simplify our WiFi solution) as with Lightspeed it just worked and we didn't need extra servers and configuration etc. Due to this we are waiting to see if we can get what we want in the next version of NetSweeper.

 

As our WiFi has its own port on the Mikrotik we are currently exploring the possibility of having that one port switched back to Lightspeed so our internal network is on NewSweeper and our WiFi is back fully working under Lightspeed. We still have access to Lightspeed and our rules are still there and ironically we have had a message that our Lightspeed has been updated. We are hoping we can do this for a short while in order to get the WiFi back up and running whilst we look at a longer term solution and give SBB time to come up with and document ways to configure the system to achieve what we want.

Posted

Hi All,

 

We're migrating in the easter break and we have a more complex setup than any ive seen on here so i hope @SchoolsBroadband / @RobMason could quickly answer this.

 

We have 4 Windows Domains that we are currently migrating in to one. We have 4 schools hence 4 domains. But we only want to run one IIS server to serve all of the requests in the cloud. Now we have all of that set up including our WPAD and PROXY.PAC and when installing the Netsweeper auth portal i didnt specify a override domain as we have multiple but when we test the authportal/whoami it doesnt bring up the username nor domain name.

 

Have i done something wrong or is this normal until we have a portal id etc?

 

Responce from anyone would be appreciated.

 

Thanks

Posted
Hi All,

 

We're migrating in the easter break and we have a more complex setup than any ive seen on here so i hope @SchoolsBroadband / @RobMason could quickly answer this.

 

We have 4 Windows Domains that we are currently migrating in to one. We have 4 schools hence 4 domains. But we only want to run one IIS server to serve all of the requests in the cloud. Now we have all of that set up including our WPAD and PROXY.PAC and when installing the Netsweeper auth portal i didnt specify a override domain as we have multiple but when we test the authportal/whoami it doesnt bring up the username nor domain name.

 

Have i done something wrong or is this normal until we have a portal id etc?

 

Responce from anyone would be appreciated.

 

Thanks

 

Good Morning,

 

It sounds like something isn't 100% correct as even with none of the configuration tick boxes selected the whoami.asp page should report the correct user logged into the machine. This of course assumes you are testing from a client machine rather than the server itself. Microsoft implement security so the server cannot test against itself.

 

If you are testing from a client my guess would be you have anonymous authentication enabled within IIS. You can check this by going to the website you are using (probably authportal) and then selecting the authportal application opening Authentication within the feature view. It should look like this (click to expand);

 

auth.JPG

 

I will follow this up with a PM,

 

Thanks,

  • Thanks 1
Posted
Hi All,

 

We're migrating in the easter break and we have a more complex setup than any ive seen on here so i hope @SchoolsBroadband / @RobMason could quickly answer this.

 

We have 4 Windows Domains that we are currently migrating in to one. We have 4 schools hence 4 domains. But we only want to run one IIS server to serve all of the requests in the cloud. Now we have all of that set up including our WPAD and PROXY.PAC and when installing the Netsweeper auth portal i didnt specify a override domain as we have multiple but when we test the authportal/whoami it doesnt bring up the username nor domain name.

 

Have i done something wrong or is this normal until we have a portal id etc?

 

Responce from anyone would be appreciated.

 

Thanks

Can you post a screenshot of the following pages: http://authportal/authportal/whoami.asp and http://authportal/authportal/install.asp (scrub out the identifying stuff)

Posted
Has anyone else who's migrated had an issue with iOS clients taking an age to recognise connectivity, even once proxy/certificate/trust settings are configured? Regularly takes anything from 30 seconds to a couple of minutes from joining the SSID and getting an IP, to the wifi icon showing top left and users being able to browse and hit authportal to authenticate. Very strange behaviour and I can't seem to get to the bottom of what's going on.
Posted
Has anyone else who's migrated had an issue with iOS clients taking an age to recognise connectivity, even once proxy/certificate/trust settings are configured? Regularly takes anything from 30 seconds to a couple of minutes from joining the SSID and getting an IP, to the wifi icon showing top left and users being able to browse and hit authportal to authenticate. Very strange behaviour and I can't seem to get to the bottom of what's going on.

Our's don't even get that far... we can log in to our wifi, but the authportal constantly asks for auth and gets no further (yes we have got everything set up etc)

Posted
Has anyone else who's migrated had an issue with iOS clients taking an age to recognise connectivity, even once proxy/certificate/trust settings are configured? Regularly takes anything from 30 seconds to a couple of minutes from joining the SSID and getting an IP, to the wifi icon showing top left and users being able to browse and hit authportal to authenticate. Very strange behaviour and I can't seem to get to the bottom of what's going on.

 

Is DNS taking a long time to respond?

 

Dave

Posted

How are you expecting the iOS clients to authenticate to the authportal, out of interest? It was my understanding that the authportal would only work with clients that supported Windows SSO.

 

We just stuck all our iPads on their own subnet which is then forced onto a pupil-level filter with no authentication, connectivity is instant.

Posted
How are you expecting the iOS clients to authenticate to the authportal, out of interest? It was my understanding that the authportal would only work with clients that supported Windows SSO.

 

We just stuck all our iPads on their own subnet which is then forced onto a pupil-level filter with no authentication, connectivity is instant.

 

This is not what we were led to believe. From what I gather the username/password box should pop up if there is no NTLM source. The http://authportal/authportal/whoami.asp works, just no other website on the actual internet

 

The problem with putting them all on their own, non-authenticated filter is that there is no ability to audit the traffic. This in itself is a safeguarding/prevent issue.

Posted
Is DNS taking a long time to respond?

 

Dave

 

Maybe, but apparently only on iOS devices.

 

Our BYOD config now consists of a new DC on the BYOD network, with a firewall rule allowing it to sync with a DC and authportal on the main network. Clients are then able to authenticate with AD credentials whilst on the other IP range. I don't like it but it does work once devices are configured correctly. Unfortunately it looks like we won't be able to get the Meraki splash page functioning correctly with the new config so I'm going to have to produce an internally-hosted splash page to clue users in to the first-time configuration. It will be a fun Easter writing documentation and testing all of this.

 

Here's hoping future Netsweeper updates will allow a return to a simpler BYOD solution.

Posted

The problem with putting them all on their own, non-authenticated filter is that there is no ability to audit the traffic. This in itself is a safeguarding/prevent issue.

 

Not entirely. If you can identify what IP was being used by whom at any one time the results may not be instant, but they are still available.

 

If you had either radius or your Wifi network tracking users to IPs you can quickly cross reference.

 

There is an issue with school owned iPads which get hands about though - not sure of the best solution here.

Posted
Not entirely. If you can identify what IP was being used by whom at any one time the results may not be instant, but they are still available.

 

If you had either radius or your Wifi network tracking users to IPs you can quickly cross reference.

 

There is an issue with school owned iPads which get hands about though - not sure of the best solution here.

 

The SBB logs only track the public facing IP of our site so no way of tracking IP - Basically as soon as the request leaves site (based on the config mentioned above) there is absolutely no way of finding out who sent the request (or at least not to my knowledge from the logs anyway)

  • Thanks 1
Posted
Good Morning,

 

It sounds like something isn't 100% correct as even with none of the configuration tick boxes selected the whoami.asp page should report the correct user logged into the machine. This of course assumes you are testing from a client machine rather than the server itself. Microsoft implement security so the server cannot test against itself.

 

If you are testing from a client my guess would be you have anonymous authentication enabled within IIS. You can check this by going to the website you are using (probably authportal) and then selecting the authportal application opening Authentication within the feature view. It should look like this (click to expand);

 

[ATTACH=CONFIG]48317[/ATTACH]

 

I will follow this up with a PM,

 

Thanks,

 

Hi Rob,

 

Spot on. I had anonymous authentication enabled.

 

Thanks

 

Ash

Posted

To all you BYODers out there i found so rather interesting stuff...

 

In a webinar back in december the presenter said that certain networks can be configured to disable https decryption and there for not have to install the cert on every device.

 

Ive though of a simple solution to this, create new vlan, new dhcp scope and push proxy pac through dhcp, set netsweeper to disable https decryption on the new ip address range.

 

I havent migrated yet but i am on tuesday but if anyone can confirm if this would work/does work that would be grand. @RobMason do you know the answer?

 

Thanks

 

Ash

  • Thanks 1
Posted
Wouldn't this work if you just pushed byod traffic out a different proxy port? This is how we have it set up as advised by Rob Mason. No certificate to install for our guests.
Posted
Wouldn't this work if you just pushed byod traffic out a different proxy port? This is how we have it set up as advised by Rob Mason. No certificate to install for our guests.

 

Can you do without certificate as well?

 

We currently push through different port using wpad but they still need to install a certificate.

Posted
I've only just set it up on Monday but it's working with only proxy settings and no certificate on an android phone. Will be testing with iPhone next week.
Posted
Is that with a blanket filter policy set for the whole range, or are users able to authenticate against their AD credentials?

No this is purely for visitors so no authentication against AD. Seperate BYOD policy set in Netsweeper.

Posted

Morning All,

 

Just to confirm, we can choose to not decrypt SSL for custom proxy ports if that is what you prefer. As people have mentioned it is better suited for visitor networks where you are not as bothered about keyword control and don't want to ask users to install a certificate.

 

Thanks,

 

Rob

Posted

anyone have any issues with WSUS connecting after switching? Can't see where to configure a proxy in it and SB are saying they have setup an allow all policy on it.

 

Cheers

Posted
anyone have any issues with WSUS connecting after switching? Can't see where to configure a proxy in it and SB are saying they have setup an allow all policy on it.

 

Cheers

 

Assuming your WSUS is hosted on a server I would say not to bother proxying it, if this is the case then it should just be whitelisted on the FortiGate. Internal connections should also not be proxied.

 

Thanks,

Posted

We just stuck all our iPads on their own subnet which is then forced onto a pupil-level filter with no authentication, connectivity is instant.

 

How are you complying with prevent strategy without any user authentication? Do you keep logs of who uses which I pad?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...