supportman Posted October 14, 2019 Posted October 14, 2019 Morning all, I am just at the start of a project to re-do our WIFI BYOD system and want to get it right. How is everyone else doing it terms of Registration, Security, Hardware and Configuration? At the moment we get students to fill out a survey then approve their MAC address but its very resource intensive. There must be a better way?
BKGarry Posted October 14, 2019 Posted October 14, 2019 We have a RADIUS Rule for a BYOD SSID that is set to authenticate against certain AD Groups. As long as the user is in one of those groups they can connect. This is done on the Microsoft NPS server 1
supportman Posted October 14, 2019 Author Posted October 14, 2019 We have a RADIUS Rule for a BYOD SSID that is set to authenticate against certain AD Groups. As long as the user is in one of those groups they can connect. This is done on the Microsoft NPS server [ATTACH=CONFIG]55331[/ATTACH] Looks very nice, so how does the user initially connect. what process do they go through? Do you have any ideas what devices they are using? Do you allow phones?
KevinB Posted October 14, 2019 Posted October 14, 2019 We've done it the same as @BKGarry, it works really well.
BKGarry Posted October 14, 2019 Posted October 14, 2019 We allow any device for Sixth Form and staff, the student connects to the BYOD and then puts in their AD username and password. On Android they have to tell it to ignore the self published certificate. Our wireless authentication is then setup to pass the details through to our Web Filter (Lightspeed) for the accounting details, so that is reported as it should be as well. As we use Unifi for our wireless we can see the name of the device there, and if it is causing issues, we can set it on the Unifi Software controller to be blocked 1
chazzy2501 Posted October 14, 2019 Posted October 14, 2019 (edited) I have a couple of Meraki APs that use the Facebook login. This is only for Internet access though. EDIT: as most users have already logged into Facebook prior to a visit, the splash page jumps straight to approval and they 'check in'. The device mac address and name is recorded but not much else. Edited October 14, 2019 by chazzy2501 1
ticktock Posted October 19, 2019 Posted October 19, 2019 I'm looking into the same thing at the minute. Do you have BYOD wireless on a separate subnet to keep traffic isolated from the rest of your network in case of infection or malicious attacks.
chris11256 Posted October 19, 2019 Posted October 19, 2019 We do. Our BYOD network only has access to a server runing Papercut mobility print & a our BYOD DNS server. All other traffic other internal subnets is blocked & ut only has internet access. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now