Jump to content

Recommended Posts

Posted

Morning!

 

I've been asked to look into setting up a new guest WIFI network, as the current one is just an additional SSID for the internal network with no segregation at all, (setup before i started). I've established that i need to create a dedicated VLAN so that it cannot access the internal network, However im getting stuck on how to push our LA proxy settings & certificate (Smoothwall) to our to guest users. Internally i have pushed the proxy setting out via W-PAD and installed the certificate via group policy, but unsure how i will go about this for guest users.

 

We are running UniFi AP-AC-Pro's & have 2 UniFi Switch 48

Posted

This is always a problem on BYOD/Guest networks that require SSL interception. If you havent got big bucks to spend on something like Aruba or Ruckus' onboarding systems then you're pretty much stuck with offering the users the ability to install the certificate on the captive portal page.

 

IMO your best option is to look into a method of providing Guest WiFi that does not have SSL inspection, removing the need for a certificate. We have a secondary FTTC connection coming into our school for this purpose and only do content filtering based on URL.

 

Just an FYI - if you're in a school that uses laptops etc make sure you deny access to the Guest network on those devices somehow. There's a group policy setting to block devices from connecting to specific SSIDs.

Posted

I thought this may be the case, unfortunately alot of the people we get in wouldn't aren't exactly IT savvy so offering the certificate from the captive portal wouldn't work. My first suggestion was to install something like ruckus but they shot that down as they only installed the UniFi kit in September.

 

Sounds like a separate FTTC is the easiest way, i could then use a DNS based content filtering service aswell to make it even easier.

 

Thanks for the heads up. The guest network is currently secured and the key phrase (which is manually changed, every week) is only given out to guests. before i got here it was unsecured, don't know who thought that was a good idea :confused2:

Posted (edited)

Surely you have transparent proxy and filtering on your Smoothwall that doesn't require a certificate?

 

Can you not set up the second SSID to use another VLAN, DHCP etc and pass that traffic through the transparent proxy ?

 

 

Or is your Smoothy provided by the LA where you can't tweak it ?

 

 

 

EDIT: In fact you shouldn't need a VLAN just another DHCP scope.

Edited by mikkydoos
Posted
I thought this may be the case, unfortunately alot of the people we get in wouldn't aren't exactly IT savvy so offering the certificate from the captive portal wouldn't work. My first suggestion was to install something like ruckus but they shot that down as they only installed the UniFi kit in September.

 

Sounds like a separate FTTC is the easiest way, i could then use a DNS based content filtering service aswell to make it even easier.

 

Thanks for the heads up. The guest network is currently secured and the key phrase (which is manually changed, every week) is only given out to guests. before i got here it was unsecured, don't know who thought that was a good idea :confused2:

 

I'd argue the value for money out of UniFi is far greater than anything Ruckus can provide nowadays so I'd agree with them :p

 

DNS filtering on a "clean" Internet connection sounds ideal.

 

@mikkydoos they need a VLAN, the Guest network shouldn't ever be able to talk to your internal network.

Posted (edited)

 

Or is your Smoothy provided by the LA where you can't tweak it ?

 

 

Unfortunately our smoothy is provided by the LA and we only have delegated access to manage the filter list, we cant even edit policies.

 

I'd argue the value for money out of UniFi is far greater than anything Ruckus can provide nowadays so I'd agree with them :p

 

I completely agree, UniFi kit is great and is massive value for money, heck i even use it at home. but unfortunately it doesn't work for the current setup we have here.

Edited by mgs1990
Posted
Surely you have transparent proxy and filtering on your Smoothwall that doesn't require a certificate?

 

Can you not set up the second SSID to use another VLAN, DHCP etc and pass that traffic through the transparent proxy ?

 

EDIT: In fact you shouldn't need a VLAN just another DHCP scope.

 

Another DHCP scope would not provide traffic isolation between the Guest and existing wireless. Users..could for example just change their IP address...

 

you are ALWAYS going to require a certificate to inspect and filter https. You can decide not to inspect...but then they can practically go anywhere, without visibility or monitoring or filtering.

  • 3 months later...
Posted

any update on this? I'm in the same boat, to some extent but just looking at the captive portal and accounting side of things.

 

I have SSIDs on separate VLANs that "exit" on dedicated PVID ports on the switch to dedicated ports on the smoothwall. unlike our previous setups the smoothwall is unable to provide DHCP to the guest network so i'm currently using an old router to do so.

 

Does anyone use any hotspot services to sign in with email/phone number/facebook via a captive portal such as wifidog ect?

Posted
Another DHCP scope would not provide traffic isolation between the Guest and existing wireless. Users..could for example just change their IP address...

 

you are ALWAYS going to require a certificate to inspect and filter https. You can decide not to inspect...but then they can practically go anywhere, without visibility or monitoring or filtering.

 

We've been using a separate DHCP scope for over 10 years on our guest network, no complicated VLANS and never had any issue. Its been totally secure in all that time. I'm rather pleased we did it that way as it was very easy to configure and gives us the security we need.

Posted
We've been using a separate DHCP scope for over 10 years on our guest network, no complicated VLANS and never had any issue. Its been totally secure in all that time. I'm rather pleased we did it that way as it was very easy to configure and gives us the security we need.
Have you tested to see if changing your IP to one on your production network gives you the ability to reach your servers or clients?
Posted

Sounds like "its definitely secure because I haven't seen any evidence to the contrary" rather than "its definitely secure because I tested it". :)

 

If it isn't segregated onto a separate VLAN, it isn't going to be secure, sorry.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...