pcstru Posted December 4, 2012 Posted December 4, 2012 We have a (part) MERU wireless system and smoothwall. I'd like to be able to offer access without giving out a key. So the user will connect to the access point, they will then be prompted for their network credentials and authenticate with the domain. No authentication, no access. Authenticate OK and it doesn't matter what device it is, you are in. Is this possible?
JonThompson Posted December 4, 2012 Posted December 4, 2012 You will require a Radius server. The Meru Wireless controller can be configured to act as a Radius server which would allow access via AD authentication (Or so Im led to believe). 1
twin--turbo Posted December 4, 2012 Posted December 4, 2012 (edited) Yes You will need radius server configured on your DC, You will need a radius entry in the meru "Configuration > Security > Radius" You will need a security Profile "configuration > security >profile"to use the radius server You will want an ESS " configuration > wireless > ess " to use the security profile HOWEVER... are you going to be restricting what they can do once connected to your network? are you vlanning, port ACLing? Rob Edited December 4, 2012 by twin--turbo 1
maark Posted December 4, 2012 Posted December 4, 2012 I thought smoothwall could do the authentication with AD accounts - that's what I am planning here but not got round to setting it up yet.
Ashm Posted December 4, 2012 Posted December 4, 2012 I thought smoothwall could do the authentication with AD accounts - that's what I am planning here but not got round to setting it up yet.It can, but I'm guessing they're talking about authentication for the Wireless prior to Smoothwall authentication. We leave our BYOD network as an open wireless network, when a user connects and then tries browsing the web they get the Smoothwall SSL login prompt at which point they enter their username & password and can then start browsing the internet on their device with their normal filter policy. I've created a Smoothwall policy towards the top policy of the web filter policy to block everything for Year7-11 students on the BYOD subnet (added as a location) as we only allow Sixth Form and Staff on the BYOD network,
Geoff Posted December 4, 2012 Posted December 4, 2012 You want to VLAN off BYOD stuff as you have no idea what they are using and have no control over it. Ideally you want to check these devices before you let them on your network too. I do this with Packetfence myself. PacketFence: Open Source NAC (Network Access Control) 1
twin--turbo Posted December 4, 2012 Posted December 4, 2012 It can, but I'm guessing they're talking about authentication for the Wireless prior to Smoothwall authentication. We leave our BYOD network as an open wireless network, when a user connects and then tries browsing the web they get the Smoothwall SSL login prompt at which point they enter their username & password and can then start browsing the internet on their device with their normal filter policy. I've created a Smoothwall policy towards the top policy of the web filter policy to block everything for Year7-11 students on the BYOD subnet (added as a location) as we only allow Sixth Form and Staff on the BYOD network, do you have encryption? if not then the UN/PW is being fired over the air with no encryption. we have an easy SSID passphrase and encrypted traffic. Rob
Ashm Posted December 4, 2012 Posted December 4, 2012 do you have encryption? if not then the UN/PW is being fired over the air with no encryption. we have an easy SSID passphrase and encrypted traffic. RobBYOD network is VLAN'd off with no access to main network, smoothwall is the gateway/dns/dhcp. UN/PW is going via the Smoothwall SSL login. Also client isolation is set up on this wireless network. 1
pcstru Posted December 4, 2012 Author Posted December 4, 2012 are you going to be restricting what they can do once connected to your network? are you vlanning, port ACLing? Many thanks. We do VLan traffic. Our current set up requires that they have a wireless key and they then authenticate with smoothwall and only get filtered http or https traffic. I'd like to be able to open up the protocols a little more so staff (and possibly students) can connect IMAP/POP3, SIP etc.
twin--turbo Posted December 4, 2012 Posted December 4, 2012 Ours is nice and simple as we just let the pupils access one server on :443 ( our VDI ) and that is all. This is via a Captive portal on pFsense, the meru just vlans the Student BYOD ESS to that machine. We are not implementing AD intergration as yet, we are starting small with 6FM users that have to register for the service acceptint the AUP. We will add them to the users on the Portal. Once evlauated we will look at the need for Directoy intergration. Rob
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now