Jump to content

Recommended Posts

Posted

Bit of back end info.

 

8 VLans (1: old swgfl. 2: Servers (no DHCP) 3: MB1 4:MB2 5: ITRooms 6:Outside Buildings and Macs. 7: Not used 8: Wireless

 

Just after some information about Unifi APs. (ac-pros?)

 

Currently have Netgears Wireless and i feel its underpowered (its only A/B/G) and its all setup on the wireless VLAN and loose 32 ips due to the Access points

 

Can i set up the AP's to be on VLAN2? and do i need to have the VLANs that i want added, tagged set to each AP?

Also can i have SSID to match VLAN 6 so we can use the macbooks with the mac server that is on VLAN6

 

Also best reseller or site to get them? (I know comms-express has them)

 

Sorry kinda new area to myself and NM and would like to know the basics before we commit to them

 

Thank you :)

Posted

First and foremost, never ever use VLAN 1 especially if it is the native vlan. It is is a massive security risk and attackers can use it to VLAN hop and get access to other parts of the network.

 

You can have the AP and the SSID in separate VLANS. I am not sure what switches you have but in the Cisco world you will set them up as trunk ports.

 

Can't help on the reseller. I have a few at home I got off Amazon and that is about it.

  • Thanks 1
Posted
First and foremost, never ever use VLAN 1 especially if it is the native vlan. It is is a massive security risk and attackers can use it to VLAN hop and get access to other parts of the network.

 

You can have the AP and the SSID in separate VLANS. I am not sure what switches you have but in the Cisco world you will set them up as trunk ports.

 

Can't help on the reseller. I have a few at home I got off Amazon and that is about it.

 

It was never setup by us. (we dont use and i know there is nothing on it)

 

Mostly HP switches, Netgear smart POE switches (which wont be used as they are only POE and not POE+. Would have to have a look at that.

 

Thank you :)

Posted

Ours we have the APs themselves sat on VLAN1 but all of the SSIDs are on other VLANs, on the switch ports for the APs we have vlan 1 untagged, and vlans 20-23 (the wireless vlans) tagged.

 

We got ours off Complete IT (Home | Complete IT Systems Ltd) and they were quite a bit cheaper than Comms Express. Think we got four 5-packs and one single AC Pro.

  • Thanks 1
Posted
Ours we have the APs themselves sat on VLAN1 but all of the SSIDs are on other VLANs, on the switch ports for the APs we have vlan 1 untagged, and vlans 20-23 (the wireless vlans) tagged.

 

We got ours off Complete IT (Home | Complete IT Systems Ltd) and they were quite a bit cheaper than Comms Express. Think we got four 5-packs and one single AC Pro.

 

Bingo. Trunk port to the AP, untag whatever VLAN you want the AP to communicate on, tag the VLANs for SSIDs. We've bought ours through Millgate, 4Gon, and VeryPC before.

 

UniFi only allow 4 SSIDs though - not a bad thing necessarily due to performance degradation with multiple SSIDs.

  • Thanks 1
Posted (edited)

We’re just in the process of putting in a unifi wireless network.

We’ve basically set the ports as such...

 

Untagged in a Unifi Vlan (for AP comms)

Tagged in each vlan which is assigned to a SSID (or in our case dynamic vlan).

 

So I expect you’d set your AP switch ports to untagged 2 and tagged 6 & 8.

 

Then you can create your SSIDs and tag the appropriate vlan in the wireless network settings.

 

All our unifi kit came from linitx because they had the stock we needed, but you have to pay up front. Did buy some test equipment from MSDist and they’ll happily send an invoice.

Edited by IrritableTech
  • Thanks 1
Posted

I have a couple of AC-Pros at home plugged into a HP PoE+ switch.

 

On HP you tagg what vlans you need on the APs. The management is untagged, which is much the same as the HP MSM APs I think.

 

I have a few SSIDs at home, one is 802.1x where the same SSID gives different vlan depending on NPS Radius settings i.e. Security Groups which may be a good idea if you want staff/students/BOYD on different IP Ranges and cuts down the amount of SSIDs you need broadcast.

  • Thanks 1
Posted (edited)
I have a couple of AC-Pros at home plugged into a HP PoE+ switch.

 

On HP you tagg what vlans you need on the APs. The management is untagged, which is much the same as the HP MSM APs I think.

 

I have a few SSIDs at home, one is 802.1x where the same SSID gives different vlan depending on NPS Radius settings i.e. Security Groups which may be a good idea if you want staff/students/BOYD on different IP Ranges and cuts down the amount of SSIDs you need broadcast.

 

Do you mind me asking, what RADIUS server are you using to assign the VLANs (it sounds like Windows)? I'm looking at doing something similar to try and get rid of our 'mobile' SSID that we stick all our iPads onto so I'm looking at doing something like this either via MAC address or maybe looking for a specific iPad AD user. At the moment we're feeding our main data SSID from Windows NPS but it looks as if something like FreeRADIUS might be more flexible so I'm interested in what others are using!

Edited by Blue_Cookeh
Posted
Do you mind me asking, what RADIUS server are you using to assign the VLANs? I'm looking at doing something similar to try and get rid of our 'mobile' SSID that we stick all our iPads onto so I'm looking at doing something like this either via MAC address or maybe looking for a specific iPad AD user. At the moment we're feeding our main data SSID from Windows NPS but it looks as if something like FreeRADIUS might be more flexible so I'm interested in what others are using!

 

Also interested in the "getting everyone on one SSID with RADIUS vlans" thing - I can see how to do it for domain computers and users on their own device but we've got two ipad SSIDs currently (ipads and ipads-staff) - there must be an easier way to dish out the vlan to ipads via radius besides a huge list of MAC addresses. Is it possible to embed a user/pass in the wifi connection settings pushed via the MDM, then I could just look for that ipad/ipadstaff user?

 

(And also, does anybody have vlans assigned by radius using HP MSM765zl controller? I can see how to do it on the Unifi in the junior school, but the HP for the rest of the site is a nightmare)

Posted (edited)
Also interested in the "getting everyone on one SSID with RADIUS vlans" thing - I can see how to do it for domain computers and users on their own device but we've got two ipad SSIDs currently (ipads and ipads-staff) - there must be an easier way to dish out the vlan to ipads via radius besides a huge list of MAC addresses. Is it possible to embed a user/pass in the wifi connection settings pushed via the MDM, then I could just look for that ipad/ipadstaff user?

 

(And also, does anybody have vlans assigned by radius using HP MSM765zl controller? I can see how to do it on the Unifi in the junior school, but the HP for the rest of the site is a nightmare)

 

This is what I'm thinking of doing - I created an AD user called ipads-student and then created a new WiFi profile in Meraki MDM that included the username/pass and details for our RADIUS SSID - my test iPad seemed to pick it up and automatically connect OK. I just haven't gotten around to implementing the VLAN bit yet!

 

I haven't got an Android device to try out yet though, and I'm a bit conscious of the password for the iPad user account getting out, expiring, or being changed. If the password ever expires then all the iPads are going to lose connectivity and it's going to be a manual job to go around fixing them all. On our computers they authenticate using user details or fall back to machine authentication.

Edited by Blue_Cookeh
Posted
First and foremost, never ever use VLAN 1 especially if it is the native vlan. It is is a massive security risk and attackers can use it to VLAN hop and get access to other parts of the network.

 

You can have the AP and the SSID in separate VLANS. I am not sure what switches you have but in the Cisco world you will set them up as trunk ports.

 

Can't help on the reseller. I have a few at home I got off Amazon and that is about it.

Is this really an issue on non Cisco switches (i.e no DTP support)? It only really leaves you with double tagging which cant route their way back to the source.

Posted
Is this really an issue on non Cisco switches (i.e no DTP support)? It only really leaves you with double tagging which cant route their way back to the source.

 

Its not an issue with DTP. DTP has its own security issues!

 

The problem is having client devices share the same VLAN as the native VLAN used on the 802.1Q trunk. 802.1Q is vendor natural and not a Cisco proprietary technology. If you change the native VLAN on your trunks it will mitigate the problem.

Posted (edited)

DTP will allow an end device to form a trunk and connect to any VLAN it wants. An attackers dream!

 

When a 802.1Q connection is formed between 2 network devices such as switches it uses a native VLAN to send un-tagged frames. These are used to establish and monitor the trunk. By default every 802.1Q device will use VLAN 1 for the native VLAN. If the client ports also use VLAN 1 the traffic is sent down the 802.1Q trunk un-tagged because the native VLAN is also VLAN 1. So an attacker who connects to the client ports can add a VLAN tag and send the traffic into another VLAN.

 

Thats the simple explanation.

Edited by FN-GM
Posted (edited)

The attacker can be connected to an access port (doesn't have to be a trunk) to VLAN hop providing the client port is VLAN 1 and the trunk port native VLAN is also VLAN 1.

 

Changing the VLAN ID on the client port or changing the 802.1Q native VLAN will fix this issue. Don't change both to the same ID or you will have the same problem.

Edited by FN-GM
Posted
But don't access ports drop tagged frames unless configured to accept them?

 

No it won't drop them. You can have an IP phone connected to a switch port and then a PC connected to the phone. The phone is in 1 VLAN and the PC is in another. These are access ports and not trunk ports. If access ports dropped tagged frames this wouldn't work. A bit like the below.

 

It was something that came up in my Cisco R&S certifications. It didn't go into huge amounts of detail as I guess that would be for the security certification. But it was stressed how important it was to sort this out. There might be other resources on the internet to explain it better.

 

b1b46ab77977094456526a9bc4a83ca62b550b7f.png

Posted (edited)
Another issue with the client / server ports and the native VLAN sharing the same ID is DHCP. In certain circumstances you can run into issues where the clients pick up IP addresses from the wrong DHCP scope. Again its down to the frames being un-tagged and going into the wrong VLAN. DHCP just makes it more noticable. Edited by FN-GM
Posted (edited)

I am pretty sure in that instance the port would be a trunk with a native 10 and a tagged 20. It shouldnt work with an access port unless access port is defined as a voice port with the appropriate vlans id and the phone supports cdp. Ill try it in Cisco packet tracer. If cdp isn't supported the port will need to be set as a trunk port with a native 10 and a tagged 20.

 

I can't see how apart from double tagging it would be an issue. Though I'm more than happy to learn otherwise. Can't get my head around it.

Edited by ITGuyWestMidlands
Posted

It wouldn't be double tagged. It will be signed tagged because there is no tag when the native VLAN is used.

 

I'm sorry that I can't explain it better. I can see it in my head very clear!

Posted
It won't be a trunk it will be an access port.

 

Anyways we need to stop hijacking the thread :)

 

Its all kind of related...

 

5 APs ordered though VeryPC

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...