Jump to content

Recommended Posts

Posted

Hi all.

 

Our school uses a Sonicwall UTM and its wireless AP's with a captive portal login but it's 50/50 whether a user can login and quite often it will disconnect when they need it the most.

We've tried all sorts to resolve the issue even with the support of Sonicwall themselves but never really made any progress with it.

 

With that in mind I've been testing the authentication via RADIUS but the Sonicwall which seems to be much easier for the end user but it only logs the IP address of the client connecting and not the user. We generate daily reports that are sent to our pastoral team but they need to know the person to investigate and not an IP address.

 

I've even tried to pick out information from the RADIUS accounting logs but this only logs the IP address of the AP and not the client. Not helpful to the pastoral team but I was hoping it would at least have the information in it.

 

Is anyone aware of a method to successfully log the user id and feed that back into the Sonicwall for reporting? An agent of some sort?

I realise it's a long shot but any help appreciated.

Thanks

Posted (edited)
What are you using for RADIUS (Windows NPS, freeradius, etc) , and is this backed to Active Directory authentication?? Edited by Davit2005
Posted (edited)

On firewalls normally you would use some form of way to map username to IP address. This could be done via some form of agent that the SonicWall can talk back to. I have seen in the past this sort of agent installed on fileservers, windows servers domain joined, but also some able to interrogate active directory directly for login events.

 

If users are authenticating against a Captive Portal that is tied to Radius for authentication I'm surprised you are not able to see the user names in the NPS accounting logs when they log into the captive portal.

 

I've not experienced Captive Portal authentication by radius however.

Edited by Davit2005
Posted

Thanks for that. I forgot to explain that I've turned off the captive portal as it is this that is causing issues. I've setup RADIUS authentication directly on the VLAN'd SSID which works okay but only logs the IP.

With captive portal enabled it does log the user fine though.

Posted
Thanks for that. I forgot to explain that I've turned off the captive portal as it is this that is causing issues. I've setup RADIUS authentication directly on the VLAN'd SSID which works okay but only logs the IP.

With captive portal enabled it does log the user fine though.

 

You could have a look in the security events on your domain controllers for login events then see if you can see any extra info. Are the APs individually added to the NPS server or is just the SonicWall added?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...