Jump to content

Recommended Posts

Posted

Hi guys

 

Trying to setup a guest only wlan on my Ruckus kit so that guest clients can access the Internet but not the internal network.

 

I have the guest lan setup ok and clients can connect fine. The problem comes when they try to go on the Internet.

 

Our internet comes through a proxy, now because Ruckus doesnt allow the guest network access to the internal network the guest clients cannot see the proxy and therefore cannot get onto the Internet.

 

Is there anyway around this?

Can I add an exception to allow the guest wlan access to just the proxy server?

 

Currently have net-ctrl looking into it for me, but i thought i'd post here to see if anyone had got round this somehow

 

ta . . .

Posted

UPDATE:

 

Sorted within the hour by Net-Ctrl

Just needed a firmware flash after which i could set the layer 3,4 ACL's better

 

Nice one guys!

  • Thanks 2
  • 3 months later...
Posted

Hi,

 

I've just had installed a Ruckus Wireless network and wish to setup the exact same thing, I have an SSID which has encryption setup for which the staff will connect to to access the school network etc, I also wish to have a "Guest/Student" style SSID which will allow only access to the Internet which goes out thr a proxy server, ideally for students, instead of having to enter a "Guess Pass" could they enter there AD Username and Password to get onto the internet, this will mainly be 6th Form Students bringing in their own personal laptops to access the Internet when in the 6th Form Study Room/Common Room.

 

How would I go about setting this up, we are running the very latest Firmware Version, 8.0.1.0.15 (I think) Do you have any step by step guides you used please?

 

Thanks

 

Matt

Posted (edited)
Hi,

 

I also wish to have a "Guest/Student" style SSID which will allow only access to the Internet which goes out through a proxy server, ideally for students, instead of having to enter a "Guess Pass" could they enter there AD Username and Password to get onto the internet, this will mainly be 6th Form Students bringing in their own personal laptops to access the Internet when in the 6th Form Study Room/Common Room.

 

 

You can do this, but I've not found a way that you can do it and also have it as a secure network, other than making the user enter a WPA key as well *before* entering their AD username and password into the captive portal. That gets a bit painful when they need to enter:

 

WPA Key

AD Username (for captive portal)

AD Password (for captive portal)

Proxy settings in IE

AD Username (to auth to the proxy)

AD Password (to auth to the proxy)

 

I think in the short term I'm going to cut out the captive portal bit, because someone stealing access to the wireless - which will require the WPA key anyway - will also need an AD account to do anything... the L3/L4/IP ACL means they can only do DHCP, DNS and proxy.

 

I think it's possible to use the zero-it config stuff to redirect users from the captive portal to a WPA2-encrypted WLAN with a PSK unique to their MAC, but I've not tackled that just yet.

Edited by sahmeepee
Posted

Ok,

 

Say I just setup a "Guest" WLAN for Students (and Visitors) where we generate pass codes out for them, is there away in which the RUCKUS ZoneDirector can automatically push out the proxy settings forr Internet Access to the students/visitors laptop? Also, how do we make sure they only get Internet access and not access to our school network/file servers etc, can they be given a totally different IP Address/Range?

 

I can't find any info on setting this sceniro up in any support documents etc.

 

Thanks

 

Matt

Posted
Ok,

Is there away in which the RUCKUS ZoneDirector can automatically push out the proxy settings forr Internet Access to the students/visitors laptop?

 

I'm pretty sure there's not, but I have made a feature request to Ruckus. Possibly you can make them redirect to a page with instructions or a batch file/script to download. Not tried it yet. Alternatively you could distribute the batch file via some other means and they could copy it on using a pen drive (not a very sexy solution though)

 

Also, how do we make sure they only get Internet access and not access to our school network/file servers etc, can they be given a totally different IP Address/Range?

 

First off you will need to make sure you are on the latest firmware. I suspect most ZDs are shipped with out of date firmware on them. Version 7.x doesn't have the L3/L4/IP filter options at all.

 

Then you can set up L3/L4/IP filters to only allow access to specific ports on specific servers. You can achieve the config above by only allowing access to specific ports on your DHCP, DNS and proxy servers.

  • 1 month later...
Posted
UPDATE:

 

Sorted within the hour by Net-Ctrl

Just needed a firmware flash after which i could set the layer 3,4 ACL's better

 

Nice one guys!

 

Hi "Jamin100" or anybody else that can help!!!

 

How did you manage to do this, do you have a "Step By Step" guide? Do you have to get your clients to manually enter the Proxy server into their web browser when they connect to your Guest Access WLAN or does the internet just work going thr the Proxy once connected to the Guest VLAN without any config changes.

 

I'm trying to get this setup for our 6th Form Students when they bring their laptops in, but Ideally without having to manually enter any settings.

 

Thanks

 

Matt

 

PS> I am running the latest firmware which allows you to enter the ACLS etc

Posted

No, not yet i thought that Edugeek may hold the answer to the question first as it seems the majority of users are running the Ruckus system,

 

I've tried the Ruckus support forums but seem to be less users on there then there are on here!

 

Cheers

 

Matt

Posted

Hi Matt,

 

Sorry, didnt notice this thread again.

 

ok,

 

I have setup 2 wlans. One the main school network and then a second "guest" network which just provides access to the internet.

 

In the Configure > Guest access tab about half way down there is a section called Restricted Subnet Access.

 

Here you can block and allow access to different IP's.

 

So i've added an entry and entered the IP and subnet mask of my proxy server and set that to allow.

 

I've also entered the IP's of my servers and set those to deny.

 

I did however have to configure the guest clients to access the proxy settings in Internet Explorer.

 

Hope this helps

 

Ben

Posted
We are in the same position... I need a guest network set with proxy settings set automatically if thats possible? I can set an alternative proxy with no AD authentication to avoid that problem.
Posted

Hi Ben,

 

Thanks for the reply, ahh I too can setup the system to access the proxy server using the guest access as you have mentioned, but I really don't want to have to configure the Proxy Settings manually, just all seems a bit messy, I know other rivals to Ruckus do have a feature which pushes out the Proxy settings when connected to the Guest Access system.

 

I have spoken to Ruckus and they have said "We have an open feature request to auto-configure client’s browser proxy settings, but this is not yet committed for release. I will add your use case to the feature request."

 

Hopefully one day soon we will see this feature.

 

Cheers

 

Matt

Posted

 

I have spoken to Ruckus and they have said "We have an open feature request to auto-configure client’s browser proxy settings, but this is not yet committed for release. I will add your use case to the feature request."

 

 

Ha! I made that feature request on one of their blog postings! It was only about a month ago, so they've not had much time to act on it yet. Fingers crossed!

  • Thanks 1
Posted

Nice one,

 

Thanks, hopefully we will see it featured in the not so distant future! It would also be nice to see it assigning Guest PCs with a totally different IP Range, whilst still allowing access to the proxy, I know with the ACLs in place it can be setup so not to see any other devices on the network, but I like the idea of not having the same IP Address Range.

 

Cheers

 

Matt

  • Thanks 1
Posted
Nice one,

 

Thanks, hopefully we will see it featured in the not so distant future! It would also be nice to see it assigning Guest PCs with a totally different IP Range, whilst still allowing access to the proxy, I know with the ACLs in place it can be setup so not to see any other devices on the network, but I like the idea of not having the same IP Address Range.

 

I couldn't agree more! I don't like having my DHCP scope cluttered up with unmanaged laptops, especially as I currently get an alert when any new leases are given out and it's going to be difficult to tell the difference between PCs plugged into a wall socket and PCs getting a lease through DHCP.

 

Presumably it could be done with a separate router, but it would be neater if it was handled by the ZoneDirector/APs

Posted

Yeah, would be much better, again, I have seen a demo of a rival managed wireless system that does offer the facility of a seperate IP Range straight from the controller on Guest Networks.

 

Hopefully Ruckus have picked up on this and will include it. I have seen somewhere on the Ruckus Forums a mention of somebody requesting the facilty to set DHCP options based on the Wireless SSID they connect to, so that should do the trick.

 

Matt

  • 5 months later...
Posted

We have this solved for Windows+IE guests, in that we set some DHCP options so that the clients get a wpad.dat from the ISA server. We then used GPOs/login scripts to stop our non-guest (managed) PCs from using "automatically detect settings" and manually specified the address of our proxy server as you are probably doing already.

 

Non-windows+IE guests don't seem to pick up the autodetect settings stuff reliably, so we have to tell them to enter the location of the wpad.dat file. This works fine for iphones/ipod touches. Android phones are currently sadly still too dumb to allow access via authenticating proxies.

Posted

we did something similar, we created a ruckus vlan called guest, it uses active directory to authorise the user, the person then has to close internet explorer and reopen it and the smoothwall then asks for a username and password.

 

It works but having to login twice is a pain as the smoothwall login page requires the domain name to be in front of the username but the ruckus login page does not.

Posted

Yeah, I've also got it running for Guests using the WPAD.DAT file which is dished out from DHCP. Seems to be working well, Guest users can't access anything they shouldn't, but I would be happier if the ZoneDirector could manage a seperate DHCP scope for guest users based on the SSID name so it was all seperate.

 

Maybe in the furture an update will allow this.

 

Matt

  • 1 year later...
  • 3 months later...
Posted

Has anyone managed to get the new auto detect proxy feature working on Ruckus? If so, any chance you could copy and paste the info from your WPAD.dat file here.

 

Thanks very much in advance.

  • 1 month later...
Posted

Hi Randle,

 

Managed to get this working. The wpad.dat is built into Smoothwall so we just used that.

 

If you need a copy of mine to help, let me know.

Posted

Hi ronnoco. Great to hear. I managed to find an example PAC file which I'm attempting to use deploy using Ruckus as don't have Smoothwall here. Just need to configure DHCP and DNS now.

 

Thanks anyway.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...