Jump to content

Proxy.pac / Wpad, different for different wifi networks?


Recommended Posts

Posted

We have Ruckus and Smoothwall. Smoothwall has a proxy.pac file which gives out a proxy that requires Windows Authentication.

We also have another proxy option without authentication that we use for iPads etc.

 

I am trying to set up a guest wifi network, and can point the Guest Network to the Proxy.pac file automatically - that is sort of working - but it's picking up Windows Authentication proxy.

 

I've tried uploaded a WPAD file directly to ruckus which just returns the other Proxy, but it seems the original proxy.pac file is over-ruling the wpad file.

 

Is it possible to put an 'if' into the proxy.pac file to say, if there is no Windows Authentication to use the other proxy? Or can it detect which wlan we are connected to and use a different proxy depending on that?

I can see how to do it by IP Range but not either of the two things that I need.

 

thanks

Bev

Posted (edited)
Does it all run off the same DHCP range (it probably shouldn't)? If it doesn't you can create different option 252 for each DHCP range to download different WPAD. Edited by Oaktech
Posted
I would look into changing that first TBH, if they're all on the same network and you're about to think about a guest network you are creating a GDPR and safeguarding issue because people on your guest will be able to browse your main network with ease. - you could probably use the DHCP in the controllers for the various WIFI to create DHCP for their individual networks.
Posted
... Are you saying you allow any device.. With any possible infection... To connect to same network as domain devices as a guest? If so, I'd rather not offer any advice just incase I was held responsible for aiding construct a configuration that could easily compromise privacy and security.
Posted

Currently, if the head teacher has a visitor into school, or the governors visit school, I am asked to 'put them on the wifi', this involves entering both the password and a proxy.

 

I have been asked by the head to investigate a guest password so that visitors can be given easier access to the wifi. It wouldn't be open, the password would be distributed from the office to specific visitors. However, it is true that their devices could have an infection, but that's the case currently.

 

I am just trying to find the best way to do this.

Posted
Currently, if the head teacher has a visitor into school, or the governors visit school, I am asked to 'put them on the wifi', this involves entering both the password and a proxy.

 

I have been asked by the head to investigate a guest password so that visitors can be given easier access to the wifi. It wouldn't be open, the password would be distributed from the office to specific visitors. However, it is true that their devices could have an infection, but that's the case currently.

 

I am just trying to find the best way to do this.

 

You need to watch the film "A few good Men". It it does not make it OK to do a job because you are directed by your line manager or Headmaster - and you can - and definitely should decline. But you should raise this issue first - and explain that you are changing what perhaps has become as seen to be common practice. I'd also put the importance of backups into this category. If backups are not working - you need to get them working as a priority - regardless of what else SLT demand of you.

 

Putting a visitors machine on your network is a risk....a potentially serious risk you have no way to quantify or evaluate. You could mention GDPR because its in everyone's headlights- but in fact it was the case with the previous Data Protection Act. In fact if I arrived as a governor and asked for WiFi access - I'd be alarmed if I was anything but restricted internet access. You might be shocked to discover how many schools are completely locked out of the network every week because of ransomware that spreads from infected computer to infected computer. It is your job to make them understand the risks...and that those risks cannot be taken. And while SLT might say they are prepared to take responsibility...they don't have that responsibility and can't assume it - which is why you are doing that job.

 

Why would anyone want such access your network? If its just "free" access to the internet - I'd be inclined to tell them to use 4G. If SLT really want to offer free internet access to guests - then you need to set up a VLAN back to your router/firewall via a separate SSID on the access points assigned to that VLAN. Nobody should be able to connect their own device, phone tablet or laptop to your network...not yourself...or technicians.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...