Jump to content

Recommended Posts

Posted
For a long time now we have had a Ruckus Zone Director and Smoothwall set up where Ruckus does the authentication against AD and we have the Smoothwall doing the accounting. In the Smoothwall we have an authorised radius client pointing to the IP of the Ruckus Zone Director. This all works fine but now I am experimenting with Ruckus unleashed but I am trying to replicate the current setup. I have no idea what to point the authorised radius client to in Smoothwall as we won't have a Zone Director. Does anyone have any guidance on how to approach this?
Posted

Hi @fiza - if you login to the Unleashed platform under 'Network Settings' I think is it there is a management address box, enter an extra IP address for Ruckus, and then there is a tickbox that says something like 'Radius requests to come from this IP address, which you then tick.

 

This means you only need to set one client in the Smoothwall with the IP address you added.

  • Thanks 1
Posted
Hi @fiza - if you login to the Unleashed platform under 'Network Settings' I think is it there is a management address box, enter an extra IP address for Ruckus, and then there is a tickbox that says something like 'Radius requests to come from this IP address, which you then tick.

 

This means you only need to set one client in the Smoothwall with the IP address you added.

I am not sure where that setting is found.

 

Unleashed Dashboard.jpg

Posted
Go to 'System' and then 'Network Settings' should be in that sub menu

Under system there is IP Settings but no Network Settings. Do you mean in there?

 

Unleashed Dashboard2.jpg

Posted

Apologies - all the menu descriptions are similar across the portfolio and I didn't have an Unleashed GUI to hand so was doing it from memory.

 

Yes, you're in the right place.

 

Tick - 'Enable IPv4 Management Interface'

Enter IP Address and subject mask

Tick - 'Use for RADIUS services'

Enter the IP specified in the Smoothwall

  • Thanks 1
Posted
Apologies - all the menu descriptions are similar across the portfolio and I didn't have an Unleashed GUI to hand so was doing it from memory.

 

Yes, you're in the right place.

 

Tick - 'Enable IPv4 Management Interface'

Enter IP Address and subject mask

Tick - 'Use for RADIUS services'

Enter the IP specified in the Smoothwall

 

That's great, thanks!

Then in the Ruckus under 'Authorised Radius Clients' do I put the IP address of this AP?

If so what happens when this AP is no longer the master or is no longer online for any reason?

Posted

Sorry for any confusion.

 

On the Ruckus Unleashed solution, in the 'IP Address' box you enter a new IP address in the same VLAN as the Ruckus currently appears.

 

This is shared between all Ruckus Unleashed APs on your network, regardless of which is the Master.

 

Then go to the Smoothwall and enter the new IP Address stated in the Ruckus Unleashed IP Address box as the Radius client.

 

Remember to tick the 'Use for Radius Services' tick box on the Unleashed as well.

Posted
Not sure if it’s related but once I put the radius client in the smoothwall I have now lost access to the smoothwall console and access to the internet! Currently have a ticket open with smoothwall to get access back.
Posted

Sorry to hear about the issues. I hope Smoothwall are able to resolve them quickly for you.

 

I can't think of any reason why this change would have caused any issues on the box so can only think it must be something unrelated.

Posted
Not sure if it’s related but once I put the radius client in the smoothwall I have now lost access to the smoothwall console and access to the internet! Currently have a ticket open with smoothwall to get access back.

 

Try running this command on the console:

 

# iptables -F mac1x

 

And see if you get connectivity back. There is an underlying security rule that matches MAC addresses with IPs for RADIUS and this can create issues in certain cases. If this command returns access for you, mention that to the support team.

  • Thanks 1
Posted
Try running this command on the console:

 

# iptables -F mac1x

 

And see if you get connectivity back. There is an underlying security rule that matches MAC addresses with IPs for RADIUS and this can create issues in certain cases. If this command returns access for you, mention that to the support team.

I didnt see this reply before I managed to get access by connecting via the Ruckus unleashed AP I had set up with a laptop and navigating to the Smoothwall console. I removed the authorised radius client and rebooted the smoothwall. Access to the console and internet are now restored. I am guessing the new authorised radius client took precendence over the existing one that had pointed to the Zone Director even though the Zone Director IP was first in the list in Smoothwall.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...