psynegy Posted May 20, 2024 Posted May 20, 2024 What's everyone using for wireless BYOD authentication these days? We're still on MSCHAPv2 with RADIUS accounting to Smoothwall. Obviously MSCHAPv2 has had it's day, and needs to be replaced. We've been looking at Ruckus CloudPath as an option, but we aren't crazy about having to ask staff/students/visitors to download apps/executables/profiles that install root certificate authorities on BYOD devices. There's the option of some sort of DPSK/MPSK assignment, but we've been led to believe that can't work with RADIUS accounting for Smoothwall(?) and that's obviously more management for IT to handle. Any ideas or thoughts appreciated!
TechMonkey Posted May 20, 2024 Posted May 20, 2024 We use CloudPath and don't get users to download or install anything and use DPSK with Smoothwall. The only thing needed to be installed is if you have want MitM certificate on the device, but this will be needed no matter what system is used. The only thing I can think of is something along the lines that you can't use Smoothwall as the auth server but you can account against it, to get Smoothwall authentication. Currently set up that users connect to a setting up SSID, authenticate against AzureAD, get given a code, then copy that and then paste it in to the general SSID. You can have it setup for visitors to get given a code, or email a nominated person to authorise. CloudPath can do a hell of a lot more than we are doing with it and I need to find time to play with it. Yell if you have any questions.
psynegy Posted May 20, 2024 Author Posted May 20, 2024 We use CloudPath and don't get users to download or install anything and use DPSK with Smoothwall. The only thing needed to be installed is if you have want MitM certificate on the device, but this will be needed no matter what system is used. The only thing I can think of is something along the lines that you can't use Smoothwall as the auth server but you can account against it, to get Smoothwall authentication. Currently set up that users connect to a setting up SSID, authenticate against AzureAD, get given a code, then copy that and then paste it in to the general SSID. You can have it setup for visitors to get given a code, or email a nominated person to authorise. CloudPath can do a hell of a lot more than we are doing with it and I need to find time to play with it. Yell if you have any questions. That sounds exactly like what we want! We'll persevere through them telling us it's not possible then! Yeah, we'll give you a shout if we get stuck! Thanks
TechMonkey Posted May 20, 2024 Posted May 20, 2024 Depending on who "they" are, @Net-Ctrl do awesome work with CloudPath. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now