_techie_ Posted October 26, 2020 Posted October 26, 2020 I have been given the task of setting up the wifi for a 1:1 chromebook scheme, for use for students in and out of school. We have an existing Windows network of PC's. We have Unifi and NPS Server setup, with WPA2 enterprise setup (currently using MSChap with a single AD account for shared chromebooks, used as Citrix Thin Clients in Kiosk mode). We also have to use ADFS as the windows computers will still be in place (I don't want to use the Google domain password sync, and install that tool on my domain controllers). SSO is in effect on our windows domain PC's by enforcing auto sign in to our ADFS URL. SLT have requested that we have safeguarding/tracking in place on the chromebooks, so I will need to put the HTTPS certificate and a proxy settings onto the chromebooks (I know you can do this through the g-suite admin console). I can add the HTTPS cert, and proxy settings, and connect for chromebooks extension from g-suite, but my question is: So how do I connect the students usingto the internal wifi network WITHOUT MSChap? If I use EAP-TLS and a certificate, how do I get the user certificate onto the device without an internet connection first using Wifi? Any help would be good with this, as I don't have anything in place for this issue. Cheers Mark
BCraigs Posted November 16, 2020 Posted November 16, 2020 We use a "provisioning" wifi limited only to google IPs in Smoothwall, which means users can login using their google credentials. The wifi has a preshared key but is otherwise unauthenticated. Once they've logged on, you can provide the certificate and details for another wifi SSID with the proper security. Hope this helps! Ben
BCraigs Posted November 16, 2020 Posted November 16, 2020 Forgot to add, Google admin lets you shunt users over to other SSIDs once they've logged on.
_techie_ Posted November 16, 2020 Author Posted November 16, 2020 Hi Ben. Yes I'm already there on the provisioning network/SSID and have already set one up for us to use on one AP, with a basic PSK. Its how I setup the remaining items that is causing the issue, particularly the requirement to use ADFS (so a startup network connection is required to access the ADFS connection, or am I overthinking this?). Is it possible to push RADIUS auth to ident on Smoothwall, or do I just need to use connect for chromebooks? I can easily push out the required certificates for SSL inspection etc via Google Admin console. Regards
BCraigs Posted November 16, 2020 Posted November 16, 2020 Hi Mark, We originally used the Connect for Chromebook app, but that stopped working for us last year. We rang up Smoothwall and they sorted it, now we aren't using the app at all. I think it's something in Services > Authentication > Google. If you do ring up smoothwall try and get to Eric Coetzee, he's the font of all knowledge when it comes to SW. Many thanks, Ben
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now