GoldenWonder Posted November 3, 2010 Posted November 3, 2010 Has anyone out here successfully got their Ruckus system set up to allow student access from their own devices (laptops,iphones etc) so they authenticate using their own AD credentials? Currently we have WPA2/TKIP authentication using RADIUS for domain PCs and laptops and this is working fine. But I want to allow student the ability to use the internet from their own devices, but authenticating as themselves and only having access to the web proxy. I've tried a few ways and it doesn't seem to work as expected. I've also tried setting up guest access (with a pass) and this works, but theres no way of setting the web proxy address (apart from telling the user to configure it manually)
apeo Posted November 3, 2010 Posted November 3, 2010 You could configure WPA2/AES and RADIUS to do what you want. There is a guide on here somewhere. With regards to proxy, maybe wpad? Automatic Discovery for Firewall and Web Proxy Clients This may not work with all devices tho. Dont grant access to kid here to save bandwidth.
localzuk Posted November 3, 2010 Posted November 3, 2010 Personally, I'd do all the authentication stuff on the proxy myself. Set up a VLAN for the wireless network, create a wireless network in ruckus that uses that vlan. Have the DHCP server for that VLAN set the gateway as the proxy server and then using the proxy server, have it handle the authentication via some form of web form. I know Forefront can handle this, and I'd guess Smoothwall can too.
GoldenWonder Posted November 3, 2010 Author Posted November 3, 2010 Cheers for the ideas - Its Forefront I'd be using and I was wanting to limit it to specific user groups (ie Sixth Form initially). What I was trying to avoid is DHCP filling up with all sorts of devices, therefore authentication at the wireless side would limit that to those who are going to use it. If authentication is only at the proxy side, the vlan's dhcp will be full of entries for everyones phone/ipad/coffee machine! I was trying to avoid vlans due to the mixture of kit we have - everything is split into subnets at the core switch but I've avoided vlans as the various switches around the place have varying capabilities.
localzuk Posted November 3, 2010 Posted November 3, 2010 Cheers for the ideas - Its Forefront I'd be using and I was wanting to limit it to specific user groups (ie Sixth Form initially). What I was trying to avoid is DHCP filling up with all sorts of devices, therefore authentication at the wireless side would limit that to those who are going to use it. If authentication is only at the proxy side, the vlan's dhcp will be full of entries for everyones phone/ipad/coffee machine! I was trying to avoid vlans due to the mixture of kit we have - everything is split into subnets at the core switch but I've avoided vlans as the various switches around the place have varying capabilities. You're not going to have much luck trying to do any form of segregation without VLANS, as there would be no way to stop those clients accessing the servers. Also, regarding IPs in DHCP, why would this be an issue? Have a short enough lease time, and those which don't use their address will be released quickly anyway. You'd be able to limit to specific groups via active directory group memberships in Forefront.
GoldenWonder Posted November 3, 2010 Author Posted November 3, 2010 Yeah I guess I'll have to bite the bullet and start looking at replacing switches as well!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now