Jump to content

Recommended Posts

Posted

Good Morning All,

 

We have a Lightspeed Rocket appliance which has real issues with RADIUS and Unifi. The Lightspeed appliance is receiving the Radius logon requests then almost immediately a logoff request. We've followed the process with Lightspeed support, but they cannot track down where these logoff request are appearing from?

 

Has anyone else had these issues with these appliances and Unifi? As I'm thinking now of changing my Filtering Vendor as our license renewal with Lightspeed is due soon

 

Thanks for any feedback!

Posted
Good Morning All,

 

We have a Lightspeed Rocket appliance which has real issues with RADIUS and Unifi. The Lightspeed appliance is receiving the Radius logon requests then almost immediately a logoff request. We've followed the process with Lightspeed support, but they cannot track down where these logoff request are appearing from?

 

Has anyone else had these issues with these appliances and Unifi? As I'm thinking now of changing my Filtering Vendor as our license renewal with Lightspeed is due soon

 

 

Thanks for any feedback!

Which lightspeed have you got - the bottle rocket on site? I wanted to set it up on a guest vlan for BYOD but it doesn't support it, so currently i have a security group i add users to, clients connect to the SSID which then authenticates the user through RADIUS , they get an IP and then get the captive portal login page.

 

Set this up without lightspeed support and not seen that issue.

Posted

Good Morning, thanks for the reply..

 

Spot on - bottle rocket on site. Lightspeed gets the RADIUS logon requests - then the log off - It then defaults to the Captive Portal Page that then allows the user to authenticate. Trouble is on any Android device on PIE 9 the OS will not show the captive portal page as its HTTP and not HTTPS thus no authentication with Lightspeed. The original call to lightspeed was for a workaround for this. There answer 'use RADIUS' ! So stuck in a loop.

Posted
Good Morning, thanks for the reply..

 

Spot on - bottle rocket on site. Lightspeed gets the RADIUS logon requests - then the log off - It then defaults to the Captive Portal Page that then allows the user to authenticate. Trouble is on any Android device on PIE 9 the OS will not show the captive portal page as its HTTP and not HTTPS thus no authentication with Lightspeed. The original call to lightspeed was for a workaround for this. There answer 'use RADIUS' ! So stuck in a loop.

 

the only issue we do have is once the use has authenticated they don't always get the captive portal page because they have to go to a non https site for it to then come up so going to google.com won't always redirect them

 

I'm trying to get Relay setup to see if this is an alternative solution and works better for BYOD on a separate VLAN as the bottlerocket doesnt support this (or at least the model we have)

Posted

This all sounds very similar to our issues..

 

Everyone knows http://lsaccess.me/login in our organisation.

 

Our restricted Guest network is VLAN'd bypasses Lightspeed and works like a dream. I'd be interested in how you get on with Relay as I feel my Rocket Appliance was very good six years ago when it was installed, but I feel its now rather long in the tooth and not fit for our needs.

 

Thus I have a call setup with Smoothwall in 10mins to see what they have to offer (we moved away from them six years ago for similar reasons as I'm finding lightspeed) I hope they have improved!

Posted
This all sounds very similar to our issues..

 

Everyone knows http://lsaccess.me/login in our organisation.

 

Our restricted Guest network is VLAN'd bypasses Lightspeed and works like a dream. I'd be interested in how you get on with Relay as I feel my Rocket Appliance was very good six years ago when it was installed, but I feel its now rather long in the tooth and not fit for our needs.

 

Thus I have a call setup with Smoothwall in 10mins to see what they have to offer (we moved away from them six years ago for similar reasons as I'm finding lightspeed) I hope they have improved!

Do you get them to type that in when they want to access with BYOD? do you give them a leaflet/guide on connecting?

 

I inherited the site with lightspeed so don't know how old their system is.

 

Is your rocket not inline between LAN and router but in proxy mode?

Posted
We do. We train key members of staff to assist them - but normally its a queue in outside my door for the stragglers. Used to use the BBC until that became more secure. I find its just a bit more consistent. Lightspeed sits between my school LAN and my Firewall and only intercepts the traffic on the School LAN not the restricted Guest LAN. We are multi function building so our events team and our lets use the Guest LAN. Just easier not to involve Lightspeed with any out of school events. Does mean constant password changes and monitoring of the Guest traffic through our UniFi controller, just in case any student gain access to it.
  • 1 month later...
Posted
Good Morning All,

 

We have a Lightspeed Rocket appliance which has real issues with RADIUS and Unifi. The Lightspeed appliance is receiving the Radius logon requests then almost immediately a logoff request. We've followed the process with Lightspeed support, but they cannot track down where these logoff request are appearing from?

 

Has anyone else had these issues with these appliances and Unifi? As I'm thinking now of changing my Filtering Vendor as our license renewal with Lightspeed is due soon

 

Thanks for any feedback!

 

Hi doombadger, did you make any progress with this issue? We have the exact same thing happening with Rocket, RADIUS and AeroHive APs. We have logged a ticket with Lightspeed but have been met by stony silence so far...

Posted
I think the Unify controller is the one to look at here - if a logoff is sent from the controller, lightspeed or any other radius service would honour that. I have seen a similar case where the user, even though stationary, was swapping between APs causing a general mess with the users auth as the IPs were swapped for a brief second too. Apologies for not being more specific.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...