Jump to content

Recommended Posts

Posted

How do you do yours? :)

 

We're Smoothwall and UniFi, and looking to find a simple as possible, additional cost-free solution for guests whilst mitigating the additional risks presented by not inspecting SSL traffic.

Best way of achieving that would be just being able to identify who's using the guest network at any one time - in the past there have been setups like reception creating accounts for them when needed. In the absence of this as an option, and unifi being rather limited in that respect, is there another way of achieving this?

My preference would be daily rotating passwords on preset accounts, given to users upon request via captive portal which prompts them for a name or email address. UniFi is close with facebook (not achievable) and just about every firewall solution out there can do it, including everything Smoothwall is based upon.

Posted

I thought Unifi had the guest "vouchers" it can print out with one-use login/auto expiry etc?

 

"Vouchers: Provide guests with vouchers that can be used to authenticate. Customize vouchers to support various expiration times, bandwidth limits, or data consumption quotas."

 

When you say limited, was that in regards to that?

 

Steve

Posted

From my understanding (at least last time I looked at it) you can just bulk create them with the set "time allowed" for each voucher, and then off-load the sheets to Reception :p Then just re-print a new lot every few months etc.

 

Or did you really want it created one account at a time based on each user?

 

Steve

  • Thanks 1
Posted
From my understanding (at least last time I looked at it) you can just bulk create them with the set "time allowed" for each voucher, and then off-load the sheets to Reception :p Then just re-print a new lot every few months etc.

 

Or did you really want it created one account at a time based on each user?

 

Steve

 

Ah, I think I get you now. That may be worth a look, I didn't think of it like that!

One for next week though, got friday brain fog ;)

 

Cheers!

Posted

We have the same (Smoothwall and Unifi) at one site, and have created Reception a login to just the Hotspot Portal so that they can create the codes themselves, when required.

 

Creating a Hotspot Manager Account

 


  • UniFi Network Portal > Sites > Select "****"
  • Settings > System > Administration > Add New Admin:

    • Role: Hotspot Manager
    • Username: Set the username according to the accounts table
    • Password: Set appropriate password (user cannot change)

Hotspot Portal(external - only if they have a Unifi Account): https://unifi.ui.com/manage/hotspot-manager/account/login/default

Hotspot Portal(internal - local account only): https://unifi:8443/manage/hotspot-manager/account/login/default

  • Thanks 2
Posted

As discussed above, there's two options. We've tried both. We created reception a hotspot only account - Useless, but that was due to our staff.

Now, we have a form that is submitted, giving us name, email, guest company etc, and then automatically spits them a code from the 100 or so we added to the database. Have to add more codes every so often, and it did involve one of our staff coding it, but he wrote our entire helpdesk!

The other option as mentioned above is to just print out 100 codes at a time and give them to reception to use. We wanted a little more detail, as unifi only links the token to mac address - no way to track that down if something happens.

Posted

Aye indeed cheers. We're keeping it simple for now just for the sake of mitigating risk - noting who has been given access and when, and changing the password regularly. Too many variables otherwise including the joy that is mac randomisation as default on modern devices.

Trust lead has spoken to Smoothwall with a view to have this as a feature, but despite this being something built into just about everything available including pfsense, it's not likely to become viable unless just about their entire userbase requests it.

Posted
I'd usually suggest your wifi controller is the place to do the visitor management, as that mediates at the network level, so they dont even get on the network without (agreeing to AUP, having a token, etc)
Posted
I do sort of agree - makes managing multiple sites with different vendors difficult though. I'd quite happily just turn it off if it wasn't for our building having the worst 4G connectivity I've ever seen! ;)
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...