Jump to content

Recommended Posts

Posted

Tearing my hair out with BYOD on Smoothwall. It's working well for iDrones and older Androids, but Android 13 devices are just having none of it. You can't "not validate" the certificate on these, and even trying to import the CA certificate directly, there's no attempt at connection. I don't even know what to put in the "domain" field on the Android, as there isn't a domain in the CA.

Fairly standard RADIUS setup with Smoothwall, PEAP and MSCHAP auth.

Smoothwalls documentation only says anything about the now defunct "Do not validate" option :(

Any hints/gotchas on this ?

Posted
Only thing I can tell you is that when you try and connect, take the word anonymous out of the anonymous field. Apparently its a bug. If I do that, I can connect.
  • Thanks 1
Posted
Tearing my hair out with BYOD on Smoothwall. It's working well for iDrones and older Androids, but Android 13 devices are just having none of it. You can't "not validate" the certificate on these, and even trying to import the CA certificate directly, there's no attempt at connection. I don't even know what to put in the "domain" field on the Android, as there isn't a domain in the CA.

Fairly standard RADIUS setup with Smoothwall, PEAP and MSCHAP auth.

Smoothwalls documentation only says anything about the now defunct "Do not validate" option :(

Any hints/gotchas on this ?

 

Haven't got any advice for you I'm afraid, but we see the same problem here. Thankfully we don't have too many staff with newer Androids and those that have for now we have given them a captive portal password on our visitor SSID. It's only my list of things to investigate.

 

This is the one thing that Apple have right IMHO - our apple users simply enter a username and password, hit 'trust' on the cert and job done. No messing around with setting do not validate and making sure username is in the identity field etc. I still hate Apple though 🤣

  • Thanks 1
Posted
We have a similar setup (Ruckus, Smoothwall and freeradius) Android 13 devices can be very difficult. We import the CA certificate for the CA that signs the radius cert before attempting to join. For domain when joining on an Android device we use the CN attribute of the CA cert. This does seem important if we don't fill in the domain field correctly the join fails.
  • Thanks 2
Posted
we use a public/signed cert from comodo on our radius servers due to this, we just enter the cert domain in domain field and it just works.
Posted (edited)
Tearing my hair out with BYOD on Smoothwall. It's working well for iDrones and older Androids, but Android 13 devices are just having none of it. You can't "not validate" the certificate on these, and even trying to import the CA certificate directly, there's no attempt at connection. I don't even know what to put in the "domain" field on the Android, as there isn't a domain in the CA.

Fairly standard RADIUS setup with Smoothwall, PEAP and MSCHAP auth.

Smoothwalls documentation only says anything about the now defunct "Do not validate" option :(

Any hints/gotchas on this ?

BYOD MitM on Android devices is no more or you have to accept the "no internet connection" issue.

 

The issue is Android 13 and 14 need to connect to google.com or *.google.com which then breaks search term filtering so BYOD should only be DNS filtering now and list it on a risk register.

 

At the end of the day, users could just tether their own devices to their phones or use data on their phones.

Edited by timbo343
Posted

At the end of the day, users could just tether their own devices to their phones or use data on their phones.

 

Aware, although irritated as it works fine for crapple users.

And that last bit - true for most places, however here is the Bermuda Triangle of Phone Signal :D

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...