Jump to content

Recommended Posts

Posted

We are looking at setting up a BYOD network.

 

We have successfully setup the SSID to authenticate users via the RADIUS server.

 

However, also need our proxy/filter to know who the user is (for filtering and logging).

 

We don't want the users to have to authenticate twice, how would this normally be achieved?

 

Any advise is appreciated.

 

WiFi: MoJo

Proxy: Smoothwall (operating in bridged transparent mode).

 

Many Thanks,

 

Bruce.

Posted

Who's implementation of RADIUS are you using?

 

The way that we've achieved this is to have a Microsoft NPS server do the authentication then have pass accounting off to Smoothwall. Smoothwall then knows who is on the IP address that the device has got and applies the appropriate browsing policy. This should be vendor neutral but FWIW we have it working on our Aerohive system. From what I can see, the Mojo and Aerohive systems are very similar.

  • Thanks 1
Posted
Who's implementation of RADIUS are you using?

 

The way that we've achieved this is to have a Microsoft NPS server do the authentication then have pass accounting off to Smoothwall. Smoothwall then knows who is on the IP address that the device has got and applies the appropriate browsing policy. This should be vendor neutral but FWIW we have it working on our Aerohive system. From what I can see, the Mojo and Aerohive systems are very similar.

 

Windows 2012 R2 NPS. That's that I wondered, but where would you configure the accounting server IP (i.e. Smoothwall's IP), on the WiFi Controller or on the RADIUS server?

 

Thanks,

 

Bruce.

Posted
We are looking at setting up a BYOD network.

 

We have successfully setup the SSID to authenticate users via the RADIUS server.

 

However, also need our proxy/filter to know who the user is (for filtering and logging).

 

We don't want the users to have to authenticate twice, how would this normally be achieved?

 

 

 

So, I would be using your smoothwall as the radius server...actually I'd be using it for DHCP on the wireless network too (I assume you have a the BYOD on a separate VLAN). Smoothwall then knows who is logged on at that IP address. (In turn Smoothwall of course - is linked to your Active Directory). In my experience - this works really well....just like magic,

 

 

If you use a separate radius server (...and I can't see any advantage of doing this) you would need to forward accounting information to smoothwall. I believe this can be done - but I've not done it.

 

Note: you will need to have a shared key between smoothwall and your access points.

Posted (edited)
If you use a separate radius server (...and I can't see any advantage of doing this) you would need to forward accounting information to smoothwall. I believe this can be done - but I've not done it.

 

For me, the Smoothwall RADIUS server isn't flexible enough or, more accurately, Smoothwall's frontend to FreeRADIUS isn't flexible enough. With NPS, I can have one RADIUS server give different different policies for different SSIDs. For example, with NPS I can have the RADIUS server only let on people with a certificate assigned to their device on one SSID but with another, let them on with a username and password. I can't do that with Smoothwall so I have NPS passing accounting information to it users get the correct browsing policies no matter which SSID they're connected to.

 

I also have my main DHCP Server host the BYOD and guest SSIDs DHCP ranges as I find having DHCP in multiple places to be a major pain in the posterior and at least if Windows serves IP addresses, it can register those IPs in the reverse DNS zones. That way, we can see who's being naughty on which devices a little more easily.

Edited by Norphy
Posted
OK...point taken..and I don't disagree...I'd like to have DHCP in one place...but decided it was sacrifice I'd make to keep smoothwall happy. I used to use NPS (pre-smoothwall) and decided it was an extra thing I could live without.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...