Jump to content

Recommended Posts

Posted

We have an Alcatel Mobility Switch based WLAN with Captive Portal BYOD authentication via LDAP, and RADIUS AAA to our NPS server. Users logged on to domain-joined PCs and through the captive portal on the BYOD network are identified correctly (Username associated with IP address of device). This information is not passed to our Smoothwall filter (Username is IP address of client), which is causing problems with filtering and monitoring. The NPS server is a RADIUS client of the Smoothwall, and also authenticates users via LDAP to the same DC as on the Wireless network.

 

Do I need to put a direct link (RADIUS client / supplicant) between the WLAN controller and the Smoothwall for the Accounting information to be recognised on the Smoothwall? If so, which is the supplicant? If not, where else could this configuration be incorrect?

Posted
I don't have the same WiFi system, but similar setup in terms of Radius (although we don't have captive portal, just WiFi with domain credentials). You need to set the Radius accounting on the WiFi to smoothwall IP address, with Authentication going to NPS (you can forward on the Accounting back to NPS in smoothwall if you require) and add a radius accounting directory service (place above AD directory and it should pull all groups from the AD). I also added each access point to the Radius clients on smoothwall.
  • Thanks 1
Posted
I also added each access point to the Radius clients on smoothwall.

 

*Each* access point?! I have over 80! That can't be necessary...

 

If you don't have captive portal, how do your users use domain credentials for guest wifi?

Posted

Yes, each access point was added, a real pain with Smoothwall, I had 50 to add wasn't a lot of fun.

We don't use domain credentials for guest WiFi, we spit out different VLANS for school laptops, staff and pupils if they're allowed access to the WiFi based on a security group in AD.

You could always just add the IP of your nearest AP to smoothwall so you can test before plugging them all into the UI

  • 4 weeks later...
Posted

Hi,

 

This is a very good resource by SmoothwallTV explaining how to setup RADIUS accounting on Smoothwall:

We have it setup so our wireless controller forwards accounting messages to the Smoothwall. It is very successful for guardian filtering policies and safeguarding reports.

  • Thanks 1
Posted
*Each* access point?! I have over 80! That can't be necessary...

 

If you don't have captive portal, how do your users use domain credentials for guest wifi?

 

Alcatel APs are the same as HPE Aruba ones I think! So you would have a Controller (central wifi switch) or a Virtual Controller on one of the APs if they are the controller-less Instant range (IAPs). There also are the newer cloud controller variants. Anyway my point being that will be a controller based setup from the info you gave. All you need to put into the Smoothwall is the central controller for all of your access points. The only reason you would need to put individual APs onto the Smoothwall radius configuration is if they are not centrally managed. All the radius is terminated individually at each access point! And this definitely isn't true of an Aruba set up. Alcatel wi-Fi kit just being rebadged Aruba!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...