Ernie Posted June 8, 2021 Posted June 8, 2021 Having a real problem trying to connect Chrome books to our Radius Wireless. I think I've tried all the authentication and cert settings possible. Any Help would be much appreciated One of the settings which seemed the most obvious, though with no luck:- EAP method: PEAP Phase 2 authentication: MSCHAP-V2 CA certificate: Do not validate Identity: domain\username Password: password Thanks for any possible help. Ern
ibpalle Posted June 9, 2021 Posted June 9, 2021 There is a new dynamic MAC address setting in Android , not certain about Chromebooks - try disabling that and see if it makes any difference. I am assuming other devices can login to the same Wifi?
Ernie Posted June 9, 2021 Author Posted June 9, 2021 Thanks The setup is Smoothwall - AD Will give this a try its only the Pixel and Chromebooks where the problem lies. Ern
ibpalle Posted June 9, 2021 Posted June 9, 2021 I assume it makes no difference if it's just username entered, without the domain part?
Ernie Posted June 9, 2021 Author Posted June 9, 2021 Tried the different permutations of username. Do you think this is linked to looking for the smoothwall root certificate? Ern
ibpalle Posted June 9, 2021 Posted June 9, 2021 No - the root CA is used when users browse. If they are not on the wifi they are not browsing.
BGlanders Posted June 9, 2021 Posted June 9, 2021 Hi, we've had this exact problem all week. Were looking into it, if you find anything out please share! I'll let you know if I make any progress. Thanks!
kernelmart Posted June 9, 2021 Posted June 9, 2021 Hi, I had this bought to my attention yesterday. I asked user to show me her Android version, which is 11. From a quick google I found this: Why can’t I add my enterprise WiFi network in Android 11? The problem that many users will come across after they update to Android 11* is that the “Do Not Validate” option under the “CA certificate” dropdown has been removed. This option previously appeared when adding a new WiFi network with WPA2-Enterprise security. from: https://www.xda-developers.com/android-11-break-enterprise-wifi-connection/ I think I will have to work out how to do the certificate bit on the Ruckus controller now.
The_Oracle Posted June 9, 2021 Posted June 9, 2021 Had a similar issue connecting my chromebook at our new (rented) offices. In desperation, as all the IP's etc looked correct, I changed the Name Server to 'Google name servers' rather that use the 'Automatic name servers' option and it connected! (Thats under the 'network' settings for the wifi connection.) All the other settings are as the OP. Might be worth a try?
ibpalle Posted June 10, 2021 Posted June 10, 2021 The option to not validate is still there on Android 11. Used this myself after updating to 11 last year. The CA that created the certificate the Smoothwall RADIUS service is using can be downloaded from the services - authentication - BYOD page. You could try to import that on an android, use it for Wifi and see if that changes behavior. I'd recommend turning the dynamic MAC address feature off for the School Wifi connection first as a test.
RobFuller Posted June 10, 2021 Posted June 10, 2021 Feel time is coming to setup Lets Encrypt on the NPS servers. 1
simpsonj Posted June 28, 2021 Posted June 28, 2021 Just ran into this problem today connecting my new Pixel 4a to our 802.1x WiFi network. So far it's only Google's pixel devices that require the domain field to be entered, but it's due to be released on all Android devices going forward. Anyone got a good guide to setup Lets Encrypt on NPS servers? Or a similar (free!) solution that isn't going to be difficult for end users (and Network Managers for that matter!) to implement?
APMerry Posted September 21, 2021 Posted September 21, 2021 Just ran into this problem today connecting my new Pixel 4a to our 802.1x WiFi network. So far it's only Google's pixel devices that require the domain field to be entered, but it's due to be released on all Android devices going forward. Anyone got a good guide to setup Lets Encrypt on NPS servers? Or a similar (free!) solution that isn't going to be difficult for end users (and Network Managers for that matter!) to implement? I'm starting to run into this issue, again, it's only pixel devices that are affected. If anyone does have a good how to guide I'm sure a lot of people would appreciate it. 1
ibpalle Posted September 22, 2021 Posted September 22, 2021 I took a look at the code yesterday for the BYOD section in Smoothwall. I was hoping I could find an easy way to replace the certificates with ones created in the certificates for services section. Unfortunately the certificate code in the BYOD section is not as modular as I would have liked which makes it tricky to find a way to modify the backend with minimum risk. Hoping to get some feedback from a dev - will let you know how I get on. 3
ibpalle Posted May 10, 2022 Posted May 10, 2022 Not yet, currently still, the best way forward is to use Windows NPS with supported certificate setup for auth and Smoothwall for accounting. 1
woodham Posted February 15, 2023 Posted February 15, 2023 i know this is a very old thread but any update on this ?
ibpalle Posted February 15, 2023 Posted February 15, 2023 No new developments on the RADIUS side from us so far. Best option is still to send Smoothwall RADIUS accounting while using another solution, like MS NPS to provide RADIUS with a valid certificate setup.
Primus Posted February 16, 2023 Posted February 16, 2023 No new developments on the RADIUS side from us so far. Best option is still to send Smoothwall RADIUS accounting while using another solution, like MS NPS to provide RADIUS with a valid certificate setup. For lots of us though that's not really an option as we isolate guest networks completely from the server infrastructure so that all they can hit is the Smoothwall unfortunately.
ibpalle Posted February 16, 2023 Posted February 16, 2023 For lots of us though that's not really an option as we isolate guest networks completely from the server infrastructure so that all they can hit is the Smoothwall unfortunately. Perfectly possible to do. The RADIUS info is flowing between Wifi controller/APs and the Smoothwall so clients can still be isolated.
Primus Posted February 16, 2023 Posted February 16, 2023 Perfectly possible to do. The RADIUS info is flowing between Wifi controller/APs and the Smoothwall so clients can still be isolated. You're totally correct but it involves re-architecting networks and putting in place ACLs etc. As it stands guest networks cannot touch anything other than the Smoothwall. To move to using NPS for this we would have to allow limited traffic to flow - opening any routing or holes from the guest network is potentially problematic and even more so with Cyber Essentials and scoping of devices etc. Far simpler to just have the vLAN the guest traffic sits on not route and only hit the Smoothwall.
slugshead Posted February 16, 2023 Posted February 16, 2023 The last two schools I've worked at have had guest on a different vlan - Ruckus Wi-Fi though, which has a pretty decent guest pass system built in. Radius for BYOD - PITA with the certs, especially on pixels and some motorolas that dont have the option to not validate.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now