Jump to content

Recommended Posts

Posted

We have a (part) MERU wireless system and smoothwall.

 

I'd like to be able to offer access without giving out a key. So the user will connect to the access point, they will then be prompted for their network credentials and authenticate with the domain. No authentication, no access. Authenticate OK and it doesn't matter what device it is, you are in.

 

Is this possible?

Posted
You will require a Radius server. The Meru Wireless controller can be configured to act as a Radius server which would allow access via AD authentication (Or so Im led to believe).
  • Thanks 1
Posted (edited)

Yes

 

You will need radius server configured on your DC,

 

You will need a radius entry in the meru "Configuration > Security > Radius"

You will need a security Profile "configuration > security >profile"to use the radius server

You will want an ESS " configuration > wireless > ess " to use the security profile

 

 

HOWEVER...

 

are you going to be restricting what they can do once connected to your network?

 

are you vlanning, port ACLing?

 

Rob

Edited by twin--turbo
  • Thanks 1
Posted
I thought smoothwall could do the authentication with AD accounts - that's what I am planning here but not got round to setting it up yet.
Posted
I thought smoothwall could do the authentication with AD accounts - that's what I am planning here but not got round to setting it up yet.
It can, but I'm guessing they're talking about authentication for the Wireless prior to Smoothwall authentication.

 

We leave our BYOD network as an open wireless network, when a user connects and then tries browsing the web they get the Smoothwall SSL login prompt at which point they enter their username & password and can then start browsing the internet on their device with their normal filter policy. I've created a Smoothwall policy towards the top policy of the web filter policy to block everything for Year7-11 students on the BYOD subnet (added as a location) as we only allow Sixth Form and Staff on the BYOD network,

Posted
It can, but I'm guessing they're talking about authentication for the Wireless prior to Smoothwall authentication.

 

We leave our BYOD network as an open wireless network, when a user connects and then tries browsing the web they get the Smoothwall SSL login prompt at which point they enter their username & password and can then start browsing the internet on their device with their normal filter policy. I've created a Smoothwall policy towards the top policy of the web filter policy to block everything for Year7-11 students on the BYOD subnet (added as a location) as we only allow Sixth Form and Staff on the BYOD network,

 

 

do you have encryption? if not then the UN/PW is being fired over the air with no encryption.

 

we have an easy SSID passphrase and encrypted traffic.

 

Rob

Posted
do you have encryption? if not then the UN/PW is being fired over the air with no encryption.

 

we have an easy SSID passphrase and encrypted traffic.

 

Rob

BYOD network is VLAN'd off with no access to main network, smoothwall is the gateway/dns/dhcp. UN/PW is going via the Smoothwall SSL login. Also client isolation is set up on this wireless network.
  • Thanks 1
Posted
are you going to be restricting what they can do once connected to your network?

 

are you vlanning, port ACLing?

 

Many thanks.

 

We do VLan traffic. Our current set up requires that they have a wireless key and they then authenticate with smoothwall and only get filtered http or https traffic.

 

I'd like to be able to open up the protocols a little more so staff (and possibly students) can connect IMAP/POP3, SIP etc.

Posted

Ours is nice and simple as we just let the pupils access one server on :443 ( our VDI ) and that is all. This is via a Captive portal on pFsense, the meru just vlans the Student BYOD ESS to that machine.

 

We are not implementing AD intergration as yet, we are starting small with 6FM users that have to register for the service acceptint the AUP. We will add them to the users on the Portal.

 

Once evlauated we will look at the need for Directoy intergration.

 

Rob

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...