Jump to content

Recommended Posts

Posted

what do you use with guest wireless?

 

We had transparent proxy but it didn't work with SSL. So i've spent ALL day making wpad/proxy.pac work only to discover whilst it works great with windows laptops if you tick autodiscover box, it's not as useful with mobiles. Iphones need to put in the pac url, not sure about android or blackberry.

 

Transparent proxy worked better but no SSL was a problem..... /sigh

Posted

Aye I'm stuck with the same issue for our public network. You can't transparently proxy SSL URL's as it would defeat the point if anyone could sit in the middle of an SSL connection.

 

They suggest that you allow SSL urls to go straight out to the web, but that kinda defeats the point in setting up a captive portal & is impossible anyway for us as you have to go out via the main proxy anyway, so your back to the problems of having a .pac file

>.< It's annoying!

Posted
Aye I'm stuck with the same issue for our public network. You can't transparently proxy SSL URL's as it would defeat the point if anyone could sit in the middle of an SSL connection.

 

They suggest that you allow SSL urls to go straight out to the web, but that kinda defeats the point in setting up a captive portal & is impossible anyway for us as you have to go out via the main proxy anyway, so your back to the problems of having a .pac file

>.< It's annoying!

 

I've read you can get SSL through transparency to work by using a man-in-the-middle procedure but I'm wary of that idea.

How do public wi-fi hotspots work...do they give you an actual internet ip address?

Posted
We use Smoothwall for our Guest Wifi which does HTTPS filtering using transparent proxy. The only requirement is that the client is running Windows Vista and above , XP using Firefox/Chrome, newer iOS versions for iPhones/iPads etc. If the client isn't running that they can still access HTTP sites but not HTTPS sites.
  • Thanks 1
Posted (edited)

Aye, I was afraid of that :p, having read that on an older post on this forum. I wouldn't mind smoothwall to replace my own custom Dansguardian/Squid system but it's a question of £££. I'd be interested as to how it gets around the man in the middle restriction tho.

From what I remember, it's something to do with SNI? (server name indication) I wonder how hard it would be to recreate that on other systems (i.e I use pfsense for the captive portal at the moment)

Edited by DrCheese
Posted

I'm gonna stick with pac. You can get around transparency with ssl_bump, ie SQUID transparent SSL interception « Dvas0004's Blog

but recompiling squid is getting too crazy for my liking. pac is fairly flexible~

 

Works with XP/win7 if "Automatically detect settings" tickbox in IE is ticked

Works with i-devices setting autodiscover WITH the url http://servername/proxy.pac

Most likely to work with android + Opera mobile app + proxy settings

Only Blackberry won't work. only works with transparent proxy. Doesn't support any other kind

Posted

Aye :p I've arranged a trial of Smoothwall today to test this.

I've been wanting to replace our proxy solution with smoothwall for a while, we've just not had the money to do so until recently. Being able to scrap our custom solution that has it's own issues and gaining the ability to do this will be a big bonus for us.

  • 4 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...