steveg Posted July 9, 2020 Posted July 9, 2020 Looking to upgrade our wifi this summer, and spec wise the Unifi AP AC HD Wave 2 points look great, but I want to be sure the virtual controller is up to the job too. At the moment about the most advanced thing we do is authenticate our staff wireless devices using Radius, which also links in to our smoothwall appliance for filtering. Is anyone doing this or similar with Unifi access points at the moment? Any problems?
chrisjako Posted July 9, 2020 Posted July 9, 2020 This is the same setup we have, unifi is installed on a DC where DHCP dishes out VLAN 10 BYOD traffic with radius set to tunnel the traffic to VLAN 10 It doesn't take much to run the controller so any machine will do My only gripe with SW is dishing out the SSL certificate for the first time via radius, looking for a way to auto push it out as soon as you authenticate but not having any joy with that so far
steveg Posted July 9, 2020 Author Posted July 9, 2020 That's good to hear that it works! I can get all 4x4 AC wave 2 points for about 3k less than the 2x2 ruckus solution by going with unifi
supportman Posted July 10, 2020 Posted July 10, 2020 We do this also on Radius with Unify AC pro AP's. Works well with the NPS server I installed on a 2019 server machine. I havent worked out how to integrate the smoothwall yet though.
steveg Posted July 10, 2020 Author Posted July 10, 2020 We do this also on Radius with Unify AC pro AP's. Works well with the NPS server I installed on a 2019 server machine. I havent worked out how to integrate the smoothwall yet though. Is that because you haven't had a chance to look at it properly, or that it doesn't work nicely?
supportman Posted July 10, 2020 Posted July 10, 2020 Is that because you haven't had a chance to look at it properly, or that it doesn't work nicely? Just no idea really where to start! Feels so complicated. Currently we just run a transparent proxy for all BYOD users without authentication. Does the job!
ThomL Posted July 10, 2020 Posted July 10, 2020 Just no idea really where to start! Feels so complicated. Currently we just run a transparent proxy for all BYOD users without authentication. Does the job! not complicated from what I remember - you just have to forward the Radius accounting to the smoothwall from the unift controller so it can identify the users with their radius creds (again.... from what I remember - It's been a while.) Smoothwall: You need to add the unifi controller as an Authorized RADIUS Client: Services > BYOD & see the Authorized RADIUS Clients section I think this is where you add the details of the Unifi controller to the smoothwall so it will accept the radius accounting - I believe you will need a shared secret that will be configure here in the smoothwall and again later on the Unifi controller to enable trust. Unifi: Settings > Configuration Profiles > Radius Here you should be able to configure the controller to forward accounting to the smoothwall. We forward accounting and authentication to an NPS server and then the NPS server forwards the accounting to the smoothwall - so not as described above - but i think the above would still work? 1
meakjoe Posted July 10, 2020 Posted July 10, 2020 I've just been working on something similar too and used the instructions found here, namely post #5... http://www.edugeek.net/forums/internet-related-filtering-firewall/182658-smoothwall-radius-accounting.html Basically have to add the APs as a RADIUS client within Smoothwall, and foward RADIUS accounting requests onto to Smoothwall from the AP. This is set up on the Unifi controller. Add an authentication policy to the port the traffic arrives on for that IP range, and set it to 'Core Authentication'. All should work quite smoothly. On the above post, they say to set it to Negotiate NTLM/Kerberos, although I haven't tried that. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now