White_Fi Posted November 23, 2010 Posted November 23, 2010 You'd think by now you'd worked out my tech speak level Off to see if I can find anything like that! Si For webportal authentication you will need to check "Web Authentication" on the WLAN under Configure - WLANS , then select an Authentication Server. If you use local you will need to create local users on the ZD under "Configure - Users" or tie it in with AD. To add AD as an Authentication Server go to "Configure - AAA" Servers and click create new. Web portal authentication: - The user will be redirected to a web portal page for authorization once they have authenticated to the AP. There is a 30minute grace period. After this grace period if the client disconnects from the AP and reconnects they will be asked for authorization again. RADIUS is much easier to integrate into AD but can be tricky if you do not have a RADIUS server to work with at hand. I recommend getting IAS on one of your windows server along with windows certificate authority. Integration into Ruckus is as simple as changing the authentication method under "Configure - WLANs" to 802.1X and changing the authentication server to the RADIUS server. (again to add the RADIUS server into the ZoneDirector - "Configure - AAA Servers" Thanks Stuart
pantscat Posted November 23, 2010 Posted November 23, 2010 Yes - that's it... But... you also need a RADIUS server on your network to authenticate the clients. This can be, for example, IAS on Windows Server 2003, NPS on Windows Server 2008 or FreeRadius. Personally I'm running NPS - I have it configured so that only machines that are members of "Domain Computers" security group are allowed to authenticate and access the network. (I chose this because I didn't want pupils or staff connecting their own machines and authenticating with their AD credentials - they'd be able to do this if I'd chosen user authentication). In a nutshell you need to: 1. Install IAS/NPS on a windows server (it's a Windows feature - so add/remove control panel). 2. Get a certificate issued to that server. (I used my in-house certificate authority). 3. Setup the NPS box as an AAA server on the ZoneDirector 4. Set NPS to use the ZoneDirector as a RADIUS client. 5. Set an access policy. 6. Set a Group Policy Object to automatically configure the wireless settings for mobile clients. I'm happy to offer advice, as I've only just recently done this and it's still (relatively) fresh in my mind! Ant
White_Fi Posted November 23, 2010 Posted November 23, 2010 [ATTACH=CONFIG]8672[/ATTACH] Are we talking the 801.x option on this page and what will happen with the clients if I select it? regards Simon The client will be unable to authenticate as no further setup as taken place
SimpleSi Posted November 23, 2010 Author Posted November 23, 2010 Well - thats my brain frazzled But going back a bit Hi Guys, you can have the logs dashboard etc display a descriptive name of the AP instead of it's MAC address by giving the AP a descriptive name under Configure -> Access Points. I had entered the class names for all the APs in Descriptive name but it doesn't show up in the dashboard at all if I could get the APs to show my name that would at least be a little help regards Simon
White_Fi Posted November 23, 2010 Posted November 23, 2010 Cold you take a screenshot of the dashboard and of one of the AP's when in edit mode.
White_Fi Posted November 23, 2010 Posted November 23, 2010 Simon, the logs will not update themselves from MAC address to Device name. Any New logs however will use the descriptive name of the AP if available. Restart an AP and you should see the name instead of its MAC
SimpleSi Posted November 23, 2010 Author Posted November 23, 2010 Restart an AP and you should see the name instead of its MAC No diff - all screens still show [xx.yy.zz.aa.bb.cc] MAC addresses Does anyone running V8.x (without authorisation) see AP names instead of MAC Addresses in the dashboard? regards Simon
White_Fi Posted November 23, 2010 Posted November 23, 2010 Simon can i see screenshot of the requested please. I recommend you update to V9 for quite a few fixes and new features
SimpleSi Posted November 23, 2010 Author Posted November 23, 2010 Can't upgrade to 9 because I can't get the school to fork out for the support! Get Aggy to email me a copy of the invoice and I'll try again
Aggy Posted November 23, 2010 Posted November 23, 2010 Can't upgrade to 9 because I can't get the school to fork out for the support! Get Aggy to email me a copy of the invoice and I'll try again [ATTACH=CONFIG]8674[/ATTACH] Hi Si, Leave this with me and with a great pleasure I will look into this for you. Aggy 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now