am_may Posted February 29, 2012 Posted February 29, 2012 hi newbie to posting.... I've been digging around for the solution on how to sort transparent proxy for BYOD on wireless, and info using cisco kit is - to say the least - sparse :-( have got guest wireless, using separate vlan/dhcp/port on LEA switch, using 5508 WLC, and ASA 5520 (DHCP, option for pac file which works for IE, but nothing else!) and want zero touch on as many devices as possible, just for internet access... I must be missing something obvious, at least I hope I am as I can't believe with this kit I can't configure this ! tell me I'm not alone !!! cheers Anne :-)
pete Posted February 29, 2012 Posted February 29, 2012 You appear to have missed the "set the default gateway for BYOD devices to the proxy server's IP". Though this may/will break certain things, depending on your proxy rules. Most clients should be picking up the .pac file if it's constructed correctly (they may need to be set to something like "automatically detect proxy" (i.e if there's a .pac, use it, otherwise proceed as normal). We just handle it via the gateway flipping.
am_may Posted March 1, 2012 Author Posted March 1, 2012 hi the default gateway is the local ASA device (which is the DHCP server for that scope). The proxy I am using is at the LEA, so using URL for that, not IP address, I do have a local pac file on the rest of the college VLAN, but that isn't accessible from this guest WLAN VLAN. It is picked up fine by IE with 'automatically detect settings', but other devices (RIM/Andriod/iPhone) need the info to be put in manually, which is what I want to avoid... Excuse my ignorance, but what do you mean by gateway flipping ? thanks...
pete Posted March 1, 2012 Posted March 1, 2012 hi the default gateway is the local ASA device (which is the DHCP server for that scope). The proxy I am using is at the LEA, so using URL for that, not IP address, I do have a local pac file on the rest of the college VLAN, but that isn't accessible from this guest WLAN VLAN. It is picked up fine by IE with 'automatically detect settings', but other devices (RIM/Andriod/iPhone) need the info to be put in manually, which is what I want to avoid... Excuse my ignorance, but what do you mean by gateway flipping ? thanks... Sorry, I meant "rather than using the standard gateway (our usual edge router), we set the gateway to our (internal) proxy". We then handle validation / filtering policies based on the incoming device.
am_may Posted March 1, 2012 Author Posted March 1, 2012 so am I right in thinking then that I need something like TMG to handle that - the ASA (afaik) doesn't have that functionality, there's probably another cisco box that does :-( thanks :-)
januttall Posted March 1, 2012 Posted March 1, 2012 (edited) We have a ubuntu box with 2 nic's, FireHol On it and squid and we set it to the Gateway in DHCP and set firehol to forward ports to squid wich throws them onto the correct proxy it is on its own network thats only used for wireless but it works great we dont have to do any fideling with setting proxys. and the data can get filterd as well if you put dans guardian on between the firehol and squid(this is what we have done). if you want any of the basic config ill be happy to help. Edited March 1, 2012 by januttall
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now