Jump to content

Recommended Posts

Posted

Has anyone out here successfully got their Ruckus system set up to allow student access from their own devices (laptops,iphones etc) so they authenticate using their own AD credentials?

 

Currently we have WPA2/TKIP authentication using RADIUS for domain PCs and laptops and this is working fine. But I want to allow student the ability to use the internet from their own devices, but authenticating as themselves and only having access to the web proxy.

 

I've tried a few ways and it doesn't seem to work as expected. I've also tried setting up guest access (with a pass) and this works, but theres no way of setting the web proxy address (apart from telling the user to configure it manually)

Posted
Personally, I'd do all the authentication stuff on the proxy myself. Set up a VLAN for the wireless network, create a wireless network in ruckus that uses that vlan. Have the DHCP server for that VLAN set the gateway as the proxy server and then using the proxy server, have it handle the authentication via some form of web form. I know Forefront can handle this, and I'd guess Smoothwall can too.
Posted

Cheers for the ideas - Its Forefront I'd be using and I was wanting to limit it to specific user groups (ie Sixth Form initially). What I was trying to avoid is DHCP filling up with all sorts of devices, therefore authentication at the wireless side would limit that to those who are going to use it. If authentication is only at the proxy side, the vlan's dhcp will be full of entries for everyones phone/ipad/coffee machine!

 

I was trying to avoid vlans due to the mixture of kit we have - everything is split into subnets at the core switch but I've avoided vlans as the various switches around the place have varying capabilities.

Posted
Cheers for the ideas - Its Forefront I'd be using and I was wanting to limit it to specific user groups (ie Sixth Form initially). What I was trying to avoid is DHCP filling up with all sorts of devices, therefore authentication at the wireless side would limit that to those who are going to use it. If authentication is only at the proxy side, the vlan's dhcp will be full of entries for everyones phone/ipad/coffee machine!

 

I was trying to avoid vlans due to the mixture of kit we have - everything is split into subnets at the core switch but I've avoided vlans as the various switches around the place have varying capabilities.

 

You're not going to have much luck trying to do any form of segregation without VLANS, as there would be no way to stop those clients accessing the servers.

 

Also, regarding IPs in DHCP, why would this be an issue? Have a short enough lease time, and those which don't use their address will be released quickly anyway.

 

You'd be able to limit to specific groups via active directory group memberships in Forefront.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...