Jump to content

Recommended Posts

Posted

At present we have ~10 production SSIDs across the MAT (but no more than 3 at each site).

 

This is.....problematic for non-technical users who unexpectedly visit a location where IT never expected them to roam.

 

I want to consolidate that down to 3 SSID:

 

MAT-owned devices (domain/Jamf/InTune joined)

Student BYOD (owned by individual students, radius auth)

Guest (randos - WPA2/3 personal that's rotated and/or a captive portal token that's valid for X hours)

 

None of the schools care about having their school initials in their SSIDs.

 

Anyone done this recently? Any unexpected pitfalls (beyond making sure the SSID info is pushed out to devices well in advance of changeovers and that any certs presented to clients are publicly trusted)?

 

Pete

Posted

Not recently but have been involved in implementing this for my current employer, so about 15k/20k people globally. This is all about having a single central management console for your wireless network and then each access point in each site is just one more access point in the same network whether you're in Newcastle or New Zealand. Easy. We follow the three SSID model you describe above.

 

When I was in education, I implemented eduroam for my college which was an example of distributed roaming access from users whose authentication was managed by their "home" site but there was only one SSID and people could connect to it wherever they went. This was considerably more work than the first option (though it wasn't a huge amount of work tbh) but stealing Eduroam's model (or just joining them!) may be your best option if you have lots of disparate systems across the schools in the MAT and no ability to consolidate them.

Posted
At present we have ~10 production SSIDs across the MAT (but no more than 3 at each site).

 

This is.....problematic for non-technical users who unexpectedly visit a location where IT never expected them to roam.

 

I want to consolidate that down to 3 SSID:

 

MAT-owned devices (domain/Jamf/InTune joined)

Student BYOD (owned by individual students, radius auth)

Guest (randos - WPA2/3 personal that's rotated and/or a captive portal token that's valid for X hours)

 

None of the schools care about having their school initials in their SSIDs.

 

Anyone done this recently? Any unexpected pitfalls (beyond making sure the SSID info is pushed out to devices well in advance of changeovers and that any certs presented to clients are publicly trusted)?

 

Pete

 

We do similar at my sites, except we also have a 2.4ghz only IOT SSID which lives on the IOT Vlan which is not routed to any other vlan. You could probably deploy that on a site by site basis.

Posted
At present we have ~10 production SSIDs across the MAT (but no more than 3 at each site).

 

This is.....problematic for non-technical users who unexpectedly visit a location where IT never expected them to roam.

 

I want to consolidate that down to 3 SSID:

 

MAT-owned devices (domain/Jamf/InTune joined)

Student BYOD (owned by individual students, radius auth)

Guest (randos - WPA2/3 personal that's rotated and/or a captive portal token that's valid for X hours)

 

None of the schools care about having their school initials in their SSIDs.

 

Anyone done this recently? Any unexpected pitfalls (beyond making sure the SSID info is pushed out to devices well in advance of changeovers and that any certs presented to clients are publicly trusted)?

 

Pete

 

Seems fine if they're all using the same wifi settings.

 

Remember that case matters in an SSID

 

If you're doing this consider certs for the MAT SSID not a password.

Posted
At present we have ~10 production SSIDs across the MAT (but no more than 3 at each site).

 

This is.....problematic for non-technical users who unexpectedly visit a location where IT never expected them to roam.

 

I want to consolidate that down to 3 SSID:

 

MAT-owned devices (domain/Jamf/InTune joined)

Student BYOD (owned by individual students, radius auth)

Guest (randos - WPA2/3 personal that's rotated and/or a captive portal token that's valid for X hours)

 

None of the schools care about having their school initials in their SSIDs.

 

Anyone done this recently? Any unexpected pitfalls (beyond making sure the SSID info is pushed out to devices well in advance of changeovers and that any certs presented to clients are publicly trusted)?

 

Pete

 

Our config is very similar to your proposal across all our schools:

1. MAT-owned devices (WPA3, MAC Address filter, VLAN)

2. Pupils Chromebooks and classroom tablets (WPA2/3, VLAN)

3. Guest (WPA2, VLAN, separate broadband) We just had to push the new WiFi names in advance (2 -3 months) and then removed the old WiFi SSIDs. There were few devices like reception label printers and other small bits that had to be manually added to new SSIDs.

Posted
What solutions are people using for authenticating pure Azure/Intune managed devices on SSIDs with 802.1x?
Posted
What solutions are people using for authenticating pure Azure/Intune managed devices on SSIDs with 802.1x?

 

We’re not. Interested to see if there is a viable solution as when we first looked there wasn’t.

Posted (edited)

Looking to do someting similar and have 4 out of 5 sites setup with a Unifi solution with a SSID setup for use for Trust staff.. How do other get around the issue of having the need to use a certificate?

Do you provide guides (which we already do)? Is there a way around it, without the need of a guest having to install a certificate which they struggle to do?

Edited by gpjt
Posted
We’re not. Interested to see if there is a viable solution as when we first looked there wasn’t.

 

Is pushing internal CA certs via NDES/SCEP not an option? We use that for pushing VPN certificates to users on Intuned devices for auth against NPS.

Posted

For guests? Either you only filter/log based on ip address, or they install a cert.

 

In theory you could proxy and then pretend you don't know about any encryption since 2015, but that'll fail more

Posted
We’re not. Interested to see if there is a viable solution as when we first looked there wasn’t.

 

Still isn't - Despite years of asking, Microsoft refuse to add something as basic as 802.11 computer authentication to NPS for intune devices. Best you can do is user level certs.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...