supportman Posted March 11, 2025 Posted March 11, 2025 (edited) I've just submitted this to smoothwall support, but wondered if anyone else has done this here? I'm trying to show usernames on our smoothwall safegaurding reports. Currently domain users show fine on reports but our BYOD users just show as an IP address. I've setup both Radius authentication and accounting our the Unify BYOD Wi-Fi side as so: so .10 is our radius server and .6 is our smoothwall server. But I don't know what to do on the Smoothwall side. Anyone done this before? Edited March 11, 2025 by supportman
PotNoodleTech Posted March 11, 2025 Posted March 11, 2025 Aren't you supposed ot install an app/browser extension on the client side for that to work?
Netwacky87 Posted March 11, 2025 Posted March 11, 2025 Have you set up your authentication policies for BYOD network?
DrCheese Posted March 11, 2025 Posted March 11, 2025 Have you set up your authentication policies for BYOD network? Yeah this is what you need to be looking at - You need to enable 802.11x & then have core auth active on your BYOD network in Smoothwall as that's how it pulls the username, not RADIUS accounting. 2
CrootUK Posted March 11, 2025 Posted March 11, 2025 (edited) We push our accounting to central radius servers, radius servers then to relevant smoothwall, very simple to setup and works well. (you do have to add nps servers in as authorised clients on the BYOD page on smoothwall) Like others say web proxy should be on core auth. I had UniFi previously working for this but just removed our last controller so don’t have config to compare sadly. The custom browser or browser extension isn’t needed for this, neither would be very feasible on a BYOD device tbh. Happy to have a team’s call if we can help! PM me. Edited March 11, 2025 by CrootUK
PaddyNewman Posted March 11, 2025 Posted March 11, 2025 Sorry if being a sausage, but do you not want 1813 for accounting. 2
Netwacky87 Posted March 11, 2025 Posted March 11, 2025 (edited) Sorry if being a sausage, but do you not want 1813 for accounting. That's a very good point lol and probably why its not working! Don't forget to setup core authentication for your BYOD network. Should work fine then. Also, make sure you have RADIUS Accounting (1813) and Authentication (1812) enabled on the correct port under 'Network' > 'Smoothwall Access' Edited March 11, 2025 by Netwacky87
supportman Posted March 12, 2025 Author Posted March 12, 2025 Have you set up your authentication policies for BYOD network? Yeh sorry for being slow here, but our BYOD network is all setup and working great using a windows NPS radius server for authentication. All I want to do is show the usernames in the smoothwall reports instead of the the IP addresses and I was told that radius accounting was the way to go with this. Is that not the case?
Rob_D Posted March 12, 2025 Posted March 12, 2025 Are your BYOD users filtered based on their AD account they logged into the wifi with (assuming this is how your BYOD is set up)?
supportman Posted March 12, 2025 Author Posted March 12, 2025 Are your BYOD users filtered based on their AD account they logged into the wifi with (assuming this is how your BYOD is set up)? Yeh they authenticate with the NPS server and we set a rule that only certain AD groups (6th form and staff in this case) can connect to our BYOD Wi-Fi. Problem is when the BYOD users show up in smoothwall reports, its just an IP address which is pretty useless for safeguarding stuff.
Rob_D Posted March 12, 2025 Posted March 12, 2025 Yeh they authenticate with the NPS server and we set a rule that only certain AD groups (6th form and staff in this case) can connect to our BYOD Wi-Fi. Problem is when the BYOD users show up in smoothwall reports, its just an IP address which is pretty useless for safeguarding stuff. But is Smoothwall then wbefiltering users based on their AD account? Or does it filtered by location (so everyone on the BYOD gets the same filtering)? I only ask because if you have got filtering based on username working but the usernames don't appear in the reports then somethings gone pretty weird and your probably stuck waiting for support to get back to you. But if you're using ident by location rather than by username, then the answer (as DrCheese suggested) to change to core authentication so the smoothwall pulls the username from your NTFS to identify the users should fix it. Although, hopefully smoothwall have gotten back to you by now and this is a moot point.
supportman Posted March 12, 2025 Author Posted March 12, 2025 But is Smoothwall then wbefiltering users based on their AD account? Or does it filtered by location (so everyone on the BYOD gets the same filtering)? I only ask because if you have got filtering based on username working but the usernames don't appear in the reports then somethings gone pretty weird and your probably stuck waiting for support to get back to you. But if you're using ident by location rather than by username, then the answer (as DrCheese suggested) to change to core authentication so the smoothwall pulls the username from your NTFS to identify the users should fix it. Although, hopefully smoothwall have gotten back to you by now and this is a moot point. The BYOD users are using the transparent proxy currently. Looks like I need to change our entire radius setup then! ouch
CrootUK Posted March 12, 2025 Posted March 12, 2025 (edited) The BYOD users are using the transparent proxy currently. Looks like I need to change our entire radius setup then! ouch Transparent proxy is correct for BYOD, could you share some screenshots? as I am not convinced you need to change much at all. Like I mentioned before happy to do a team’s call if your a school worker not an MSP lol… if its of help, i’m not from smoothwall or an MSP myself but we do use smoothwall in our schools so familiar with them. Edited March 12, 2025 by CrootUK 1
PaddyNewman Posted March 12, 2025 Posted March 12, 2025 All that happens is an accounting packet gets sent, I would assume they read the username and framed IP, and tie the two up. Going back to my other post, are you sure, 100%, SW is accepting accounting on 1812 and not the standard 1813. Transparent works, at least in Netsweeper which I imagine has a less refined (although functionally sound) RADIUS setup. Its a super basic concept.
DrCheese Posted March 12, 2025 Posted March 12, 2025 The BYOD users are using the transparent proxy currently. Looks like I need to change our entire radius setup then! ouch As @CrootUK says, Transparent proxy is right for BYOD. But what do you have auth set to currently? Needs to be core auth & then you point your Unifi controller at your smoothwall for Radius.
supportman Posted March 13, 2025 Author Posted March 13, 2025 (edited) [ATTACH=CONFIG]73274[/ATTACH] Big thanks for all your help with this one guys. It was actually staring at me right in the face after smoothwall 2nd line support noticed the packets were arriving on port 1812 rather than 1813. Its literally in the screenshot I posted although I think I was thrown off because Unify shows 1813 in the entry form but it was set to 1812. I simply changed the radius accounting port to 1813 in our unify setup and its all working perfectly now. Simple as that! We can now finally report safeguarding concerns for our BYOD network. A huge leap forward! Edited March 13, 2025 by supportman 1
supportman Posted March 13, 2025 Author Posted March 13, 2025 Got it working finally using the correct port for radius accounting and adding to the Smoothwall firewall. You can check in Smoothwall by going to Security >> User Activity The IP's should now match a username if its working.
CrootUK Posted March 13, 2025 Posted March 13, 2025 PaddyNewman mentioned that, glad its working, nice work.
supportman Posted March 13, 2025 Author Posted March 13, 2025 Sorry if being a sausage, but do you not want 1813 for accounting. Now if only I had read this properly. Congrats on spotting the issue, you were right!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now