Jump to content

Recommended Posts

Posted

At present, we use RM SafetyNet inline filtering (with transparent proxy enabled) and are in the process of migrating to Smoothwall. We have a Ruckus ZD1200 managing our WLANs, which includes a WLAN for BYOD with Captive Portal enabled. Smoothwall have configured a non-inline VM implementation of their filtering, which was recommended by their proposal as being the best option.

 

However, once our users have authenticated onto BYOD, they do not have to put any proxy details on their devices, as transparent proxy works and forces them through RM's filtering. We'd prefer this sort of approach for Smoothwall filtering too, but as it isn't in-line, the traffic will not automatically go there. We could use PAC/WPAD, but from my understanding, Android doesn't play well with this sort of approach. I also cannot find anywhere to force a specific WLAN (or anywhere in Zone Director at all) to go through a specific proxy.

 

Anyone have any ideas?

Posted
...well I wouldn't use (and don't use) captive portals for BYOD (...but yes probably necessary for shared devices/tablets). I would use radius/enterprise wireless authentication - using smoothwall as radius server (which in turn talks to Active Directory). I use Smoothwall to provide DHCP for BYOD (which of course are isolated from the rest of the network). Smoothwall is the gateway for BYOD traffic - so no proxy configuration - and most BYOD devices are happy to remember their clients details. Captive portals are a pain with devices/tablets - because users might not actually go to a browser (and the session may time out without them realising it). And they might for example have a "google APP" - which fails to work because they have not been on a browser (and don't understand the difference between using a browser and using the google app). And its a pain if they are using an APP like word - and the captive portal session times out. But you do need a certificate installed of course...
  • 2 weeks later...
Posted

Smoothwall uses a really obscure method of handling their NTLM which breaks most modern applications, so I would never switch to that option.

 

I can’t think of a way you can enforce this without control of the BYOD devices. If they’re iPads or Chromebooks can you do MDM on them?

Posted
As long as the gateway on your devices is set to the up of the smoothwall,transparent filtering will still work without the need for the smoothwall to be in line [emoji4]
Posted (edited)
...well I wouldn't use (and don't use) captive portals for BYOD (...but yes probably necessary for shared devices/tablets). I would use radius/enterprise wireless authentication - using smoothwall as radius server (which in turn talks to Active Directory). I use Smoothwall to provide DHCP for BYOD (which of course are isolated from the rest of the network). Smoothwall is the gateway for BYOD traffic - so no proxy configuration - and most BYOD devices are happy to remember their clients details. Captive portals are a pain with devices/tablets - because users might not actually go to a browser (and the session may time out without them realising it). And they might for example have a "google APP" - which fails to work because they have not been on a browser (and don't understand the difference between using a browser and using the google app). And its a pain if they are using an APP like word - and the captive portal session times out. But you do need a certificate installed of course...

We have a RADIUS server for our school owned devices, however these devices are not school owned. They are the personal smartphones of the students.

 

Smoothwall uses a really obscure method of handling their NTLM which breaks most modern applications, so I would never switch to that option.

 

I can’t think of a way you can enforce this without control of the BYOD devices. If they’re iPads or Chromebooks can you do MDM on them?

If not Captive Portal, then how to we audit the access students have on their phones? The idea is that students use their own phones periodically for revision, but we want to be able to pinpoint a student if they access something inappropriate. Obviously being their own personal phones, we have no control of their management.

Edited by CHiLL
Posted

Smoothwall can use radius to identify the user. So instead of a single WiFi code - you set the access points to use Enterprise authentication and users put their username and password into their BYOD device/phone. You radius server (which can be smoothwall itself - in fact I would do this) then passes the information to smoothwall. And provided DHCP is setting smootwall to be be gateway - and you have smoothwall set to be a transparent proxy for the traffic on that wireless VLAN - there is no proxy configuration. And they probably never need to re-enter their name and password - so everytime they use their own device it automatically knows who they are....

 

Captive portals are - sadly - necessary for shared devices...but such devices were never intended for sharing...and don't expect to be subjugated to a captive portal...and are a pain when working with apps....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...