badders Posted November 20, 2009 Posted November 20, 2009 Is anybody using Smoothwall and Ruckus and managed to get a guest WLAN working. We have no problem setting up a school WLAN for domain attached devices, but would like to enable students to use their own laptops to access the internet by authenticating against thier AD account. We've got as far as setting up another WLAN for students that asks for authentication using the Ruckus portal to authorize the device but then when we try to browse the internet Smoothwall blocks access due to the local user of the laptop being an unauthorised user. Would we have to use VLans with a separate DHCP server?
tom_newton Posted November 20, 2009 Posted November 20, 2009 I wonder how the traffic is hitting Smoothie... if you want authentication, non-domain users *should* get a popup if they are presented with an ntlm handshake. Is ruckus proxying the traffic first? You could potentially give "unauthenticated IPs" some very limited web access? You'd lose a bit of visibility though.
badders Posted November 20, 2009 Author Posted November 20, 2009 We.ve manually set smoothwall as the proxy in the non-domain client, but we don't seem to get a pop-up asking for username/password. Would this be related to the SSL login settings in smoothwall?
badders Posted November 20, 2009 Author Posted November 20, 2009 (edited) Smoothwall is set to use NTLM identification. Edited November 20, 2009 by badders Wrong info
pantscat Posted November 20, 2009 Posted November 20, 2009 (edited) Change it to NTLM authentication and hey-presto! I bet it will work... Actually... scrap that. NTLM identification should work too... Edited November 20, 2009 by pantscat Bad advice!
badders Posted December 1, 2009 Author Posted December 1, 2009 Tried both NTLM authentication and NTLM identifcation, a guest trying to access the internet still gets the unauthenticated ip/ username not allowed. I was expecting a popup box from smoothwall asking for a username password if the logged on account is not located in AD. Is this possible?
tom_newton Posted December 1, 2009 Posted December 1, 2009 OOh... guest.. hmm. If they are not authed, the smoothie would probably pass the "who are ye request" back to the Ruckus box, and it may get filtered there. A tough one. Maybe we can set this situation up at BETT if we can find an AD. Or perhaps we can borrow a ruckus for 5.
DMcCoy Posted December 1, 2009 Posted December 1, 2009 Windows will helpfully return the details of the current user. You will need to use basic authentication to get IE to prompt. We had to run an additional instance of smoothwall due to only being able to use one auth method.
tom_newton Posted December 1, 2009 Posted December 1, 2009 ..which we promise to fix ASAP (we're working on it, honest )
Edu-IT Posted December 1, 2009 Posted December 1, 2009 OOh... guest.. hmm. If they are not authed, the smoothie would probably pass the "who are ye request" back to the Ruckus box, and it may get filtered there. A tough one. Maybe we can set this situation up at BETT if we can find an AD. Or perhaps we can borrow a ruckus for 5. You could use the one on the EG stand?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now