mdrabble Posted November 30, 2021 Posted November 30, 2021 Having come across a flagged issue with ping castle yesterday I was looking at the different authentication method I currently have on my Smoothwall box. I have Active Directory Idex Radius Azure For in premise stuff - I’m assuming I can now bin the Active Directory method as I’m now using idex?? Would people concur? Cheers
robyholmes Posted November 30, 2021 Posted November 30, 2021 How are you assigning groups on the Smoothwall?
mdrabble Posted November 30, 2021 Author Posted November 30, 2021 Groups assigned by AD Groups - which are picked up by both idex and AD......
ibpalle Posted November 30, 2021 Posted November 30, 2021 Azure is used for the cloud filter extension to map Azure users so that's needed. iDent is used to login users based on their AD Account logins processed on the DCs. Active Directory is used for any auth method that involves NTLM/Kerberos, used for SSL VPN and for RADIUS authentication in the BYOD section. Not certain what the RADIUS entry you have is used for - could you elaborate on that?
mdrabble Posted November 30, 2021 Author Posted November 30, 2021 Azure is used for the cloud filter extension to map Azure users so that's needed. iDent is used to login users based on their AD Account logins processed on the DCs. Active Directory is used for any auth method that involves NTLM/Kerberos, used for SSL VPN and for RADIUS authentication in the BYOD section. Not certain what the RADIUS entry you have is used for - could you elaborate on that? Sorry, should have said Radius Accounting - which used for Wifi access,- using a Windows NPS to authenticate uses as I have Dynamic VLAN assignment which Smoothwall doesn't handle and then sending Radius Accounting info to Smoothwall. We originally used Active Directory before moving to Idex and kept it in place as a belt and braces approach. Since we don't use Smoothwall for SSL VPN and for RADIUS authentication in the BYOD section, and we now use Idex for authentication, I'm assuming I can remove the Active Directory auth method. Am i Correct in thinking that? Cheers Mark
ibpalle Posted November 30, 2021 Posted November 30, 2021 Hi Mark Yes - if there is no authentication going on for the AD connection, it can be removed. Make certain you have the correct group mappings under the iDex directory before you disable the AD connection. Is the RADIUS entry you mentioned initially in the directories section or did you mean the BYOD feature? 1
mdrabble Posted November 30, 2021 Author Posted November 30, 2021 Hi Mark Is the RADIUS entry you mentioned initially in the directories section or did you mean the BYOD feature? In the Directories section - showing as Radius Accounting.
ibpalle Posted December 1, 2021 Posted December 1, 2021 And what is that used for? The RADIUS accounting for the BYOD section does not require the Smoothwall itself to send RADIUS accounting anywhere so if you are only sending accounting messages to the Smoothwall, you do not need any entry in the directories section.
mdrabble Posted December 1, 2021 Author Posted December 1, 2021 And what is that used for? The RADIUS accounting for the BYOD section does not require the Smoothwall itself to send RADIUS accounting anywhere so if you are only sending accounting messages to the Smoothwall, you do not need any entry in the directories section. Not using Smoothwall for BYOD or radius authentication. I am using a Windows NPS server to authenticate users for WiFi access. NPS then passes the Radius Accounting info across to Smoothwall to filter the users correctly according to their AD groups. I’m using NPS as I have 1 SSID for users and then use NPS to dynamically assign them to the different VLAN according to their AD group - so staff users connect to staff VLAN and student to students VLAN etc. Hope that makes more sense.
ibpalle Posted December 2, 2021 Posted December 2, 2021 That is what I assumed, so my question was if there was any specific reason why there's a RADIUS accounting entry in the directories section - that is not needed for the BYOD functions to work. Smoothwall is a RADIUS accounting service - it does not need to talk to one. What the RADIUS accounting entry pointing to?
synaesthesia Posted December 6, 2021 Posted December 6, 2021 Not using Smoothwall for BYOD or radius authentication. I am using a Windows NPS server to authenticate users for WiFi access. NPS then passes the Radius Accounting info across to Smoothwall to filter the users correctly according to their AD groups. I’m using NPS as I have 1 SSID for users and then use NPS to dynamically assign them to the different VLAN according to their AD group - so staff users connect to staff VLAN and student to students VLAN etc. Hope that makes more sense. Hi @MRDabble - I hate to intrude on a vaguely unrelated post, but could you walk me through vaguely how this is setup for you please? Trying to get accounting requests over to our Smoothie for the same purpose. Already have a BYOD ssid set up via windows NPS and getting a bit stuck there!
mdrabble Posted December 6, 2021 Author Posted December 6, 2021 Hi @MRDabble - I hate to intrude on a vaguely unrelated post, but could you walk me through vaguely how this is setup for you please? Trying to get accounting requests over to our Smoothie for the same purpose. Already have a BYOD ssid set up via windows NPS and getting a bit stuck there! I’m not in until Thursday, so will drop you a PM with setup details when I’m back in if that ok.
Driftingashore Posted March 5, 2022 Posted March 5, 2022 Any chance you could send the details to me too? I’ve been meaning to look at this for ages but haven’t got around to it - could do with the jump start!
mdrabble Posted March 5, 2022 Author Posted March 5, 2022 Any chance you could send the details to me too? I’ve been meaning to look at this for ages but haven’t got around to it - could do with the jump start! @Driftingashore yea, well send a PM on Monday with details.
mdrabble Posted March 7, 2022 Author Posted March 7, 2022 @Driftingashore just sent you a PM with link for PDF config guide. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now