synaesthesia Posted July 5, 2024 Posted July 5, 2024 How do you do yours? We're Smoothwall and UniFi, and looking to find a simple as possible, additional cost-free solution for guests whilst mitigating the additional risks presented by not inspecting SSL traffic. Best way of achieving that would be just being able to identify who's using the guest network at any one time - in the past there have been setups like reception creating accounts for them when needed. In the absence of this as an option, and unifi being rather limited in that respect, is there another way of achieving this? My preference would be daily rotating passwords on preset accounts, given to users upon request via captive portal which prompts them for a name or email address. UniFi is close with facebook (not achievable) and just about every firewall solution out there can do it, including everything Smoothwall is based upon.
Steve21 Posted July 5, 2024 Posted July 5, 2024 I thought Unifi had the guest "vouchers" it can print out with one-use login/auto expiry etc? "Vouchers: Provide guests with vouchers that can be used to authenticate. Customize vouchers to support various expiration times, bandwidth limits, or data consumption quotas." When you say limited, was that in regards to that? Steve
synaesthesia Posted July 5, 2024 Author Posted July 5, 2024 Yeah, I did look at that but it relies on IT staff setting them up as and when required, not something we could hand off to reception
Steve21 Posted July 5, 2024 Posted July 5, 2024 From my understanding (at least last time I looked at it) you can just bulk create them with the set "time allowed" for each voucher, and then off-load the sheets to Reception Then just re-print a new lot every few months etc. Or did you really want it created one account at a time based on each user? Steve 1
synaesthesia Posted July 5, 2024 Author Posted July 5, 2024 From my understanding (at least last time I looked at it) you can just bulk create them with the set "time allowed" for each voucher, and then off-load the sheets to Reception Then just re-print a new lot every few months etc. Or did you really want it created one account at a time based on each user? Steve Ah, I think I get you now. That may be worth a look, I didn't think of it like that! One for next week though, got friday brain fog Cheers!
StephenPink Posted July 5, 2024 Posted July 5, 2024 We have the same (Smoothwall and Unifi) at one site, and have created Reception a login to just the Hotspot Portal so that they can create the codes themselves, when required. Creating a Hotspot Manager Account UniFi Network Portal > Sites > Select "****" Settings > System > Administration > Add New Admin: Role: Hotspot Manager Username: Set the username according to the accounts table Password: Set appropriate password (user cannot change) Hotspot Portal(external - only if they have a Unifi Account): https://unifi.ui.com/manage/hotspot-manager/account/login/default Hotspot Portal(internal - local account only): https://unifi:8443/manage/hotspot-manager/account/login/default 2
AndrewPowell Posted July 8, 2024 Posted July 8, 2024 As discussed above, there's two options. We've tried both. We created reception a hotspot only account - Useless, but that was due to our staff. Now, we have a form that is submitted, giving us name, email, guest company etc, and then automatically spits them a code from the 100 or so we added to the database. Have to add more codes every so often, and it did involve one of our staff coding it, but he wrote our entire helpdesk! The other option as mentioned above is to just print out 100 codes at a time and give them to reception to use. We wanted a little more detail, as unifi only links the token to mac address - no way to track that down if something happens.
tom_newton Posted July 9, 2024 Posted July 9, 2024 You could probably get the unifi to spit a radius accounting packet to the smoothie to track the usage on a token by token basis too
synaesthesia Posted July 9, 2024 Author Posted July 9, 2024 Aye indeed cheers. We're keeping it simple for now just for the sake of mitigating risk - noting who has been given access and when, and changing the password regularly. Too many variables otherwise including the joy that is mac randomisation as default on modern devices. Trust lead has spoken to Smoothwall with a view to have this as a feature, but despite this being something built into just about everything available including pfsense, it's not likely to become viable unless just about their entire userbase requests it.
tom_newton Posted July 9, 2024 Posted July 9, 2024 I'd usually suggest your wifi controller is the place to do the visitor management, as that mediates at the network level, so they dont even get on the network without (agreeing to AUP, having a token, etc)
synaesthesia Posted July 9, 2024 Author Posted July 9, 2024 I do sort of agree - makes managing multiple sites with different vendors difficult though. I'd quite happily just turn it off if it wasn't for our building having the worst 4G connectivity I've ever seen! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now