Jump to content

Recommended Posts

Posted

Having come across a flagged issue with ping castle yesterday I was looking at the different authentication method I currently have on my Smoothwall box.

 

I have

Active Directory

Idex

Radius

Azure

 

For in premise stuff - I’m assuming I can now bin the Active Directory method as I’m now using idex??

 

Would people concur?

 

Cheers

Posted

Azure is used for the cloud filter extension to map Azure users so that's needed.

iDent is used to login users based on their AD Account logins processed on the DCs.

Active Directory is used for any auth method that involves NTLM/Kerberos, used for SSL VPN and for RADIUS authentication in the BYOD section.

 

Not certain what the RADIUS entry you have is used for - could you elaborate on that?

Posted
Azure is used for the cloud filter extension to map Azure users so that's needed.

iDent is used to login users based on their AD Account logins processed on the DCs.

Active Directory is used for any auth method that involves NTLM/Kerberos, used for SSL VPN and for RADIUS authentication in the BYOD section.

 

Not certain what the RADIUS entry you have is used for - could you elaborate on that?

 

Sorry, should have said Radius Accounting - which used for Wifi access,- using a Windows NPS to authenticate uses as I have Dynamic VLAN assignment which Smoothwall doesn't handle and then sending Radius Accounting info to Smoothwall.

 

We originally used Active Directory before moving to Idex and kept it in place as a belt and braces approach.

 

Since we don't use Smoothwall for SSL VPN and for RADIUS authentication in the BYOD section, and we now use Idex for authentication, I'm assuming I can remove the Active Directory auth method.

 

Am i Correct in thinking that?

 

Cheers

Mark

Posted

Hi Mark

 

Yes - if there is no authentication going on for the AD connection, it can be removed. Make certain you have the correct group mappings under the iDex directory before you disable the AD connection.

 

Is the RADIUS entry you mentioned initially in the directories section or did you mean the BYOD feature?

  • Thanks 1
Posted
Hi Mark

 

Is the RADIUS entry you mentioned initially in the directories section or did you mean the BYOD feature?

 

In the Directories section - showing as Radius Accounting.

Posted
And what is that used for? The RADIUS accounting for the BYOD section does not require the Smoothwall itself to send RADIUS accounting anywhere so if you are only sending accounting messages to the Smoothwall, you do not need any entry in the directories section.
Posted
And what is that used for? The RADIUS accounting for the BYOD section does not require the Smoothwall itself to send RADIUS accounting anywhere so if you are only sending accounting messages to the Smoothwall, you do not need any entry in the directories section.

 

Not using Smoothwall for BYOD or radius authentication.

 

I am using a Windows NPS server to authenticate users for WiFi access.

 

NPS then passes the Radius Accounting info across to Smoothwall to filter the users correctly according to their AD groups.

 

I’m using NPS as I have 1 SSID for users and then use NPS to dynamically assign them to the different VLAN according to their AD group - so staff users connect to staff VLAN and student to students VLAN etc.

 

Hope that makes more sense.

Posted
That is what I assumed, so my question was if there was any specific reason why there's a RADIUS accounting entry in the directories section - that is not needed for the BYOD functions to work. Smoothwall is a RADIUS accounting service - it does not need to talk to one. What the RADIUS accounting entry pointing to?
Posted
Not using Smoothwall for BYOD or radius authentication.

 

I am using a Windows NPS server to authenticate users for WiFi access.

 

NPS then passes the Radius Accounting info across to Smoothwall to filter the users correctly according to their AD groups.

 

I’m using NPS as I have 1 SSID for users and then use NPS to dynamically assign them to the different VLAN according to their AD group - so staff users connect to staff VLAN and student to students VLAN etc.

 

Hope that makes more sense.

 

Hi @MRDabble - I hate to intrude on a vaguely unrelated post, but could you walk me through vaguely how this is setup for you please? Trying to get accounting requests over to our Smoothie for the same purpose. Already have a BYOD ssid set up via windows NPS and getting a bit stuck there!

Posted
Hi @MRDabble - I hate to intrude on a vaguely unrelated post, but could you walk me through vaguely how this is setup for you please? Trying to get accounting requests over to our Smoothie for the same purpose. Already have a BYOD ssid set up via windows NPS and getting a bit stuck there!

 

I’m not in until Thursday, so will drop you a PM with setup details when I’m back in if that ok.

  • 2 months later...
Posted
Any chance you could send the details to me too? I’ve been meaning to look at this for ages but haven’t got around to it - could do with the jump start!

@Driftingashore yea, well send a PM on Monday with details.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...