Jump to content

Recommended Posts

Posted (edited)

Hi all,

 

I have been set a task.... make BYOD work for a Teachmeet we are having on the 20th March.

 

So here is the problem....

 

I have one DHCP server this is running server 2008 r2 datacentre. We have been allocated our IP Address range this is 10.171.52.1 - 10.171.55.254. We also run a Ruckus wireless network. I have a separate SSID setup already.

 

What I am looking to do is setup the DHCP server to allocate addresses to BYOD devices in the 10.171.54.* range. Based on the face I have my DHCP scope set up as above how would I go about this? As we are identifying devices by location in Smoothwall.

 

I know I will need a WPAD.dat and a VLAN or two...

 

Can someone give me some advice where to start? oh and I need this working for 20th March.....! Not much to do eh? :(

Edited by denon101
Posted

Assuming your guests are on a separate SSID, and separate VLAN (which they may or may not be), then you could make Smoothwall give out IPs on the guest SSID int he correct range, and make your DHCP not hand otu those addresses.

 

You could then do some messing on the Smoothwall box to redirect any internal things, well internally, and also use ident by IP on just that range. No need to use a WPAD.dat I don't think.

 

We have a similar setup here, (except our Smoothwall uses an entirely separate range for our "Guests"), but internally hosted sites are still all handled internally, such as the VLE etc. It is done int he Zone Bridging section.

Posted (edited)

You don't need WPAD. You can filter transparently by location in Smoothwall and save yourself that problem straight away (your location will be 10.171.54.x - 10.171.54.254 I guess).

 

We have our Guest SSID on its own VLAN, our DHCP server issues the IP's as normal (each VLAN has its own scope), we use the guest access in Ruckus for users to login with and then we filter this as a location in smoothwall transparently.......

Edited by RTFM
Posted
What actual equipment do you have?

Is this for a permenant fixture?

 

Rob

 

Righty then,

 

At the networks core we have a HP Procurve 4208VL with 4 modules installed. Mostly 1gb but there are some SFP ports to connect fibre up. A couple of trunks have been setup for bonding the fibre connections. A the edge of the network we have a number of 2810-48 HP Procurve's. We have a vmware install and hp storage works san. At the moment the entire network is flat, we have no vlans at all. We are fairly small school.

 

So from the suggestions I would be looking to setup a wireless VLAN and setup DHCP to hand out specific addresses to the VLAN.

 

Is that correct? Forgive my ignorance, I have only worked on small flat networks to date.

 

Thanks

 

Anthony

Posted

Is the connection between the Ruckus and the Core a Trunk?

 

Our Meru is trunked to the Cisco core which then has the vlans on it.

 

Our BYOD is tagged by the Meru for the BYOD VLAN on the cisco.

 

 

I imagin Rukus can do similar.

 

Rob

Posted (edited)
Is the connection between the Ruckus and the Core a Trunk?

 

Our Meru is trunked to the Cisco core which then has the vlans on it.

 

Our BYOD is tagged by the Meru for the BYOD VLAN on the cisco.

 

 

I imagin Rukus can do similar.

 

Rob

 

He doesnt have any VLAN's though, its a flat network. To add VLAN's will need config of his core and edge switches and work on his DHCP scopes doing so it isnt a 2 minute job.....

 

I havent looked but is the HP Procurve 4208VL at your core layer 3?

Edited by RTFM
Posted

With VLANs you need to configure the ip helper address on the switch which is the DHCP server.

 

The basic idea is that between switches you use trunk ports so that all vlans are carried.

e1-12 are access ports so they are untagged in vlan 2

e13-24 are access ports for server so they are in vlan 3

e25-28 are uplink ports so the are untagged in vlan1 and tagged in all other vlans.

You need to put all vlan's in each switch.

At some point all the subnets need to talk to each other so you need some routing going on this is easiest to do on the smoothwall box as you can create the intervlan firewall rules.

 

In your situation you can leave all devices on the default vlan and move the management interfaces of the HP on to a new vlan.

So I would create to vlan 1 and vlan 2.

Vlan 1 is for management of the switches.

Vlan 2 is for the guest traffic.

Posted
With VLANs you need to configure the ip helper address on the switch which is the DHCP server.

 

The basic idea is that between switches you use trunk ports so that all vlans are carried.

e1-12 are access ports so they are untagged in vlan 2

e13-24 are access ports for server so they are in vlan 3

e25-28 are uplink ports so the are untagged in vlan1 and tagged in all other vlans.

You need to put all vlan's in each switch.

At some point all the subnets need to talk to each other so you need some routing going on this is easiest to do on the smoothwall box as you can create the intervlan firewall rules.

 

In your situation you can leave all devices on the default vlan and move the management interfaces of the HP on to a new vlan.

So I would create to vlan 1 and vlan 2.

Vlan 1 is for management of the switches.

Vlan 2 is for the guest traffic.

 

Unless your confident about doing this though I wouldn't be trying it yourself, especially not on a live environment.....

Posted
Unless your confident about doing this though I wouldn't be trying it yourself, especially not on a live environment.....

Good point I meant to say that. If you have a spare switch you could play around with it.

Posted
Is there no way to setup an exclusion on his DHCP scope for the IP's he wants to be used for wireless, then do another scope only to be used for those IP's he previously excluded? I guess it's making sure that that scope is only assigning IP's to devices connecting to the Guest SSID.....
Posted
Hi all,

 

I have been set a task.... make BYOD work for a Teachmeet we are having on the 20th March.

 

So here is the problem....

 

I have one DHCP server this is running server 2008 r2 datacentre. We have been allocated our IP Address range this is 10.171.52.1 - 10.171.55.254. We also run a Ruckus wireless network. I have a separate SSID setup already.

 

What I am looking to do is setup the DHCP server to allocate addresses to BYOD devices in the 10.171.54.* range. Based on the face I have my DHCP scope set up as above how would I go about this? As we are identifying devices by location in Smoothwall.

 

I know I will need a WPAD.dat and a VLAN or two...

 

Can someone give me some advice where to start? oh and I need this working for 20th March.....! Not much to do eh? :(

 

What exactly do you have to implement. And don't say "BYOD" - that's just marketing mumbo-jumbo. What exactly do they expect you to provide?

A wireless connection? - What about the one you have now. If this is just something your bosses want to show off at a meeting (what's a 'teachmeet'?) when can't you fake it via your normal wireless provision for that?

Posted

What they want it for teachers, outside people to come along and present ideas to a group of teachers. But what they really want is for people to be able to turn up with their own, smartphone, tablet etc and be able to access the wireless to use twitter and facebook to comment on the event whilst is happening... It's something they have seen done elsewhere. So they want to do it here. More trouble than it's worth potentially!

 

Hope that helps

Posted
What they want it for teachers, outside people to come along and present ideas to a group of teachers. But what they really want is for people to be able to turn up with their own, smartphone, tablet etc and be able to access the wireless to use twitter and facebook to comment on the event whilst is happening... It's something they have seen done elsewhere. So they want to do it here. More trouble than it's worth potentially!

 

Hope that helps

 

It's all well and good people wanting these things, but you need the infrastructure to provide it and do it correctly / safely / reliably.

Posted
It's all well and good people wanting these things, but you need the infrastructure to provide it and do it correctly / safely / reliably.

 

I know, but it was all decided without consulting me..... JOY!

Posted
I know, but it was all decided without consulting me..... JOY!

 

Then they might have to put their hands in their pockets for some additional work to be done to provide it. The most advisable way to achieve what you are after is to VLAN you network off and then you can securely run guest wireless, or at least, from what everyone has said that is the conclusion I would come to.

 

It's how we do it, though that doesnt mean its the only way.

 

I'm sure if it can be done another way someome here will know how, unfortunately I don't though :(

  • Thanks 1
Posted

without either a seperate LAN or a VLAN you have the potential for any of the BYOD devices to have unrestricted access to your entire network ( servers, printers, clients, etc )

 

Does your Rukus have 2 interfaces? one could go directly to your smoothwall and be firewalled purely for the BYOD internet.

 

Rob

Posted (edited)
without either a seperate LAN or a VLAN you have the potential for any of the BYOD devices to have unrestricted access to your entire network ( servers, printers, clients, etc )

 

Does your Rukus have 2 interfaces? one could go directly to your smoothwall and be firewalled purely for the BYOD internet.

 

Rob

 

Just thinking out loud, if all your network clients are Windows machines and pick up their proxy from group policy and you forward to a specific port to do some sort of NTLM authentication, couldn't you transparently filter the whole range on port 80 as a location? If a client doesnt have proxy settings, it's going to be hit by that filtering not the NTLM auth (theoretically all your 'BYOD' clients wouldnt have proxy settings in).

 

If all your clients though pick up from group policy and you lock down changing of proxy settings from GP then theoretically you could run both at the same time???

 

Does that make sense? I know it isnt in any way ideal but it would work.....i think?

 

EDIT: I wouldnt want to put my name to the above in terms of security of either what people can or cant access on the web or the security of the network, but just saying the above should work.

Edited by RTFM
Posted (edited)
I know, but it was all decided without consulting me..... JOY!

 

Well this is where you return and tell them it's no problem to give them what they want but you require the following resources:

{whatever you decide, enough to provide a separate 'guest' wireless VLAN at the very least, though if they want the event twittered and facebooked and you don't normally allow access to those on site then you'll need to provide alternative filtering policies, etc. and you'll need a 'guest' device to test all this with}.

 

If they don't want to go for that then they can't have their magical "BYOD" guest wireless network. Simple as.

 

When you posted about a 'teachmeet' I wasn't sure if that was this week's term for a baker day or whatever, but yeah if this is external people coming on site then you need to maintain a gap between the guest wireless network and your main network (we do this) and I'd say this was an absolute requirement both for safeguarding and the security and integrity of the business functions of the school.

Edited by Roberto
Posted
Well this is where you return and tell them it's no problem to give them what they want but you require the following resources:

{whatever you decide, enough to provide a separate 'guest' wireless VLAN at the very least, though if they want the event twittered and facebooked and you don't normally allow access to those on site then you'll need to provide alternative filtering policies, etc. and you'll need a 'guest' device to test all this with}.

 

The strange thing is on site they have Smoothwall, Ruckus, HP ProCurve switches yet no VLAN's.

 

Thankfully with smoothwall you can quickly setup a location and filter this accordingly against a new set of filtering policies, literally thats 20 minutes work. That definitely isnt where the issue is. Similarly with Ruckus you can do a guest portal quickly and easily and hand on the responsibility for key generation to someone else without too much time or effort.

 

The only downfall you have is your network infrastructure in that it isnt VLAN'd........so unless someone comes up with something that might be what you have to tell them. That opens up a whole set of other issues though as typically you'd have someone come in, spec your network and hardware, make recommendations, then find the time and money to have the work done. Potentially not cheap.

 

Won't people have 3G?? :p

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...