Jump to content

Recommended Posts

Posted

hi

 

newbie to posting....

 

I've been digging around for the solution on how to sort transparent proxy for BYOD on wireless, and info using cisco kit is - to say the least - sparse :-(

 

have got guest wireless, using separate vlan/dhcp/port on LEA switch, using 5508 WLC, and ASA 5520 (DHCP, option for pac file which works for IE, but nothing else!) and want zero touch on as many devices as possible, just for internet access... I must be missing something obvious, at least I hope I am as I can't believe with this kit I can't configure this !

 

tell me I'm not alone !!!

 

cheers

Anne :-)

Posted

You appear to have missed the "set the default gateway for BYOD devices to the proxy server's IP". Though this may/will break certain things, depending on your proxy rules.

 

Most clients should be picking up the .pac file if it's constructed correctly (they may need to be set to something like "automatically detect proxy" (i.e if there's a .pac, use it, otherwise proceed as normal).

 

We just handle it via the gateway flipping.

Posted

hi

the default gateway is the local ASA device (which is the DHCP server for that scope).

 

The proxy I am using is at the LEA, so using URL for that, not IP address, I do have a local pac file on the rest of the college VLAN, but that isn't accessible from this guest WLAN VLAN. It is picked up fine by IE with 'automatically detect settings', but other devices (RIM/Andriod/iPhone) need the info to be put in manually, which is what I want to avoid...

 

Excuse my ignorance, but what do you mean by gateway flipping ?

 

thanks...

Posted
hi

the default gateway is the local ASA device (which is the DHCP server for that scope).

 

The proxy I am using is at the LEA, so using URL for that, not IP address, I do have a local pac file on the rest of the college VLAN, but that isn't accessible from this guest WLAN VLAN. It is picked up fine by IE with 'automatically detect settings', but other devices (RIM/Andriod/iPhone) need the info to be put in manually, which is what I want to avoid...

 

Excuse my ignorance, but what do you mean by gateway flipping ?

 

thanks...

 

Sorry, I meant "rather than using the standard gateway (our usual edge router), we set the gateway to our (internal) proxy". We then handle validation / filtering policies based on the incoming device.

Posted

so am I right in thinking then that I need something like TMG to handle that - the ASA (afaik) doesn't have that functionality, there's probably another cisco box that does :-(

thanks :-)

Posted (edited)
We have a ubuntu box with 2 nic's, FireHol On it and squid and we set it to the Gateway in DHCP and set firehol to forward ports to squid wich throws them onto the correct proxy it is on its own network thats only used for wireless but it works great we dont have to do any fideling with setting proxys. and the data can get filterd as well if you put dans guardian on between the firehol and squid(this is what we have done). if you want any of the basic config ill be happy to help. Edited by januttall

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...