mgs1990 Posted June 27, 2018 Posted June 27, 2018 Morning! I've been asked to look into setting up a new guest WIFI network, as the current one is just an additional SSID for the internal network with no segregation at all, (setup before i started). I've established that i need to create a dedicated VLAN so that it cannot access the internal network, However im getting stuck on how to push our LA proxy settings & certificate (Smoothwall) to our to guest users. Internally i have pushed the proxy setting out via W-PAD and installed the certificate via group policy, but unsure how i will go about this for guest users. We are running UniFi AP-AC-Pro's & have 2 UniFi Switch 48
Blue_Cookeh Posted June 27, 2018 Posted June 27, 2018 This is always a problem on BYOD/Guest networks that require SSL interception. If you havent got big bucks to spend on something like Aruba or Ruckus' onboarding systems then you're pretty much stuck with offering the users the ability to install the certificate on the captive portal page. IMO your best option is to look into a method of providing Guest WiFi that does not have SSL inspection, removing the need for a certificate. We have a secondary FTTC connection coming into our school for this purpose and only do content filtering based on URL. Just an FYI - if you're in a school that uses laptops etc make sure you deny access to the Guest network on those devices somehow. There's a group policy setting to block devices from connecting to specific SSIDs.
mgs1990 Posted June 27, 2018 Author Posted June 27, 2018 I thought this may be the case, unfortunately alot of the people we get in wouldn't aren't exactly IT savvy so offering the certificate from the captive portal wouldn't work. My first suggestion was to install something like ruckus but they shot that down as they only installed the UniFi kit in September. Sounds like a separate FTTC is the easiest way, i could then use a DNS based content filtering service aswell to make it even easier. Thanks for the heads up. The guest network is currently secured and the key phrase (which is manually changed, every week) is only given out to guests. before i got here it was unsecured, don't know who thought that was a good idea
mikkydoos Posted June 27, 2018 Posted June 27, 2018 (edited) Surely you have transparent proxy and filtering on your Smoothwall that doesn't require a certificate? Can you not set up the second SSID to use another VLAN, DHCP etc and pass that traffic through the transparent proxy ? Or is your Smoothy provided by the LA where you can't tweak it ? EDIT: In fact you shouldn't need a VLAN just another DHCP scope. Edited June 27, 2018 by mikkydoos
Blue_Cookeh Posted June 27, 2018 Posted June 27, 2018 I thought this may be the case, unfortunately alot of the people we get in wouldn't aren't exactly IT savvy so offering the certificate from the captive portal wouldn't work. My first suggestion was to install something like ruckus but they shot that down as they only installed the UniFi kit in September. Sounds like a separate FTTC is the easiest way, i could then use a DNS based content filtering service aswell to make it even easier. Thanks for the heads up. The guest network is currently secured and the key phrase (which is manually changed, every week) is only given out to guests. before i got here it was unsecured, don't know who thought that was a good idea I'd argue the value for money out of UniFi is far greater than anything Ruckus can provide nowadays so I'd agree with them DNS filtering on a "clean" Internet connection sounds ideal. @mikkydoos they need a VLAN, the Guest network shouldn't ever be able to talk to your internal network.
mikkydoos Posted June 27, 2018 Posted June 27, 2018 @mikkydoos they need a VLAN, the Guest network shouldn't ever be able to talk to your internal network. Yeah..... I'd go with that.
mgs1990 Posted June 27, 2018 Author Posted June 27, 2018 (edited) Or is your Smoothy provided by the LA where you can't tweak it ? Unfortunately our smoothy is provided by the LA and we only have delegated access to manage the filter list, we cant even edit policies. I'd argue the value for money out of UniFi is far greater than anything Ruckus can provide nowadays so I'd agree with them I completely agree, UniFi kit is great and is massive value for money, heck i even use it at home. but unfortunately it doesn't work for the current setup we have here. Edited June 27, 2018 by mgs1990
AlanD Posted June 27, 2018 Posted June 27, 2018 Surely you have transparent proxy and filtering on your Smoothwall that doesn't require a certificate? Can you not set up the second SSID to use another VLAN, DHCP etc and pass that traffic through the transparent proxy ? EDIT: In fact you shouldn't need a VLAN just another DHCP scope. Another DHCP scope would not provide traffic isolation between the Guest and existing wireless. Users..could for example just change their IP address... you are ALWAYS going to require a certificate to inspect and filter https. You can decide not to inspect...but then they can practically go anywhere, without visibility or monitoring or filtering.
chrisakak9 Posted October 12, 2018 Posted October 12, 2018 any update on this? I'm in the same boat, to some extent but just looking at the captive portal and accounting side of things. I have SSIDs on separate VLANs that "exit" on dedicated PVID ports on the switch to dedicated ports on the smoothwall. unlike our previous setups the smoothwall is unable to provide DHCP to the guest network so i'm currently using an old router to do so. Does anyone use any hotspot services to sign in with email/phone number/facebook via a captive portal such as wifidog ect?
supportman Posted October 18, 2018 Posted October 18, 2018 Another DHCP scope would not provide traffic isolation between the Guest and existing wireless. Users..could for example just change their IP address... you are ALWAYS going to require a certificate to inspect and filter https. You can decide not to inspect...but then they can practically go anywhere, without visibility or monitoring or filtering. We've been using a separate DHCP scope for over 10 years on our guest network, no complicated VLANS and never had any issue. Its been totally secure in all that time. I'm rather pleased we did it that way as it was very easy to configure and gives us the security we need.
ITGuyWestMidlands Posted October 18, 2018 Posted October 18, 2018 We've been using a separate DHCP scope for over 10 years on our guest network, no complicated VLANS and never had any issue. Its been totally secure in all that time. I'm rather pleased we did it that way as it was very easy to configure and gives us the security we need.Have you tested to see if changing your IP to one on your production network gives you the ability to reach your servers or clients?
Opendium_Steve Posted October 22, 2018 Posted October 22, 2018 Sounds like "its definitely secure because I haven't seen any evidence to the contrary" rather than "its definitely secure because I tested it". If it isn't segregated onto a separate VLAN, it isn't going to be secure, sorry. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now