Jump to content

Recommended Posts

Posted
The strange thing is on site they have Smoothwall, Ruckus, HP ProCurve switches yet no VLAN's.

 

Thankfully with smoothwall you can quickly setup a location and filter this accordingly against a new set of filtering policies, literally thats 20 minutes work. That definitely isnt where the issue is. Similarly with Ruckus you can do a guest portal quickly and easily and hand on the responsibility for key generation to someone else without too much time or effort.

 

The only downfall you have is your network infrastructure in that it isnt VLAN'd........so unless someone comes up with something that might be what you have to tell them. That opens up a whole set of other issues though as typically you'd have someone come in, spec your network and hardware, make recommendations, then find the time and money to have the work done. Potentially not cheap.

 

Won't people have 3G?? :p

 

I can see a network that's just grown to meet its needs being configured like this.

 

This can all be configured out of current hardware, with maybe a bit of fun and games and a few upgrades, but doing so without disrupting the continuing use of that stuff for curriculum won't be quite so easy.

Posted
so unless someone comes up with something that might be what you have to tell them

 

It's why I mentione the second port (if it has one) on the Rukus and connect it straight to the Smoothwall.

 

Rob

Posted
We're not using a separate VLAN on our setup. Our SmoothWall has both non-transparent and transparent (redirect to SSL login page with session cookie) authentication policies on the main network. Our UniFi wireless network has an open Guest SSID with subnet restrictions so the only device that can be accessed is the SmoothWall box (which also works well for effective client isolation). On their first web request it directs them to log into the filter so we still know who's who and it ticks all the boxes for filtering and logging, just like on the main network.
Posted
We're not using a separate VLAN on our setup. Our SmoothWall has both non-transparent and transparent (redirect to SSL login page with session cookie) authentication policies on the main network. Our UniFi wireless network has an open Guest SSID with subnet restrictions so the only device that can be accessed is the SmoothWall box (which also works well for effective client isolation). On their first web request it directs them to log into the filter so we still know who's who and it ticks all the boxes for filtering and logging, just like on the main network.

 

So if you changed the auth method from SSL login to location you could do similar. You couldnt use SSL login as Guest users wouldnt have AD credentials to authenticate with.

Posted
It's why I mentione the second port (if it has one) on the Rukus and connect it straight to the Smoothwall.

 

Rob

 

We have a ZD3000 and it has a spare interface from the looks of it :)

Posted

I'd keep it the same but create an internal SmoothWall account rather than AD and give everyone that - then you know it's them and not some random kid who's worked out they can get on the WiFi now (and therefore to Facebook if it's not filtered!).

 

Username: teachmeet

Password: awesomenetwork

 

Or similar... :p

Posted
I'd keep it the same but create an internal SmoothWall account rather than AD and give everyone that - then you know it's them and not some random kid who's worked out they can get on the WiFi now (and therefore to Facebook if it's not filtered!).

 

Username: teachmeet

Password: awesomenetwork

 

Or similar... :p

 

Could do, though i'd personally save them the step of logging in and just do it by location but thats just me.

 

You could alter the group the location is filtered by afterwards to something more strict, or disable the interface so no one else gets onto it.... :)

Posted

What about during? If it's a day the kids are in and somebody gets on the wireless and starts accessing Facebook/Twitter because the external people can... and then there's an incident of cyberbullying... it's on your head.

 

In light of the above, if you're going with the auth by location option I'd definitely make sure your SLT link knows about it too.

Posted
We have a ZD3000 and it has a spare interface from the looks of it :)

 

So you should be ableto configure an SSID to use that interface.

Put the interface on a spare port on Smooth.

Set Smooth to handle DHCP for that interface.

Apply a filtering policy.

 

And that should do it, more or less.....

 

Rob

Posted
What about during? If it's a day the kids are in and somebody gets on the wireless and starts accessing Facebook/Twitter because the external people can... and then there's an incident of cyberbullying... it's on your head.

 

In light of the above, if you're going with the auth by location option I'd definitely make sure your SLT link knows about it too.

 

Even with a password, a kid can find it out and most likely will as how is this going to be filtered around all the external people coming into school? Word of mouth......a poster in reception?

 

I know what your saying though but then the vast majority of kids have phones with 3G anyway and access facebook and twitter whenever they want regardless.

 

Maybe i'm just being a sceptic as I know how some people are within our school but I dont see the kids not getting hold of the username and password throughout the day.

Posted

Ok.....

 

So what would you say to upgrading the core switch chassis to a HP Procurve 5406VL and usng our existing modules? Which are x 2 j8768a and x 2 J9033a. Then getting someone to come onsite and help me config it?

 

I think there will be money available for that.

Posted

I would say it needs to be planned as part of a review of your infrastructure and done in a considred and managed way and not a rush job. Half term is your window and that's rolling in fast.

 

Rob

Posted
Would be no rush job.... Would be planned properly. That's one of the benefits of being actually consulted. I have a company in mind that can help me.
Posted
Would be no rush job.... Would be planned properly. That's one of the benefits of being actually consulted. I have a company in mind that can help me.

 

I had dropped your a PM for the people who did our VLAN work. Ignore it or not, upto you :)

Posted (edited)
Ok.....

 

So what would you say to upgrading the core switch chassis to a HP Procurve 5406VL and usng our existing modules? Which are x 2 j8768a and x 2 J9033a. Then getting someone to come onsite and help me config it?

 

I think there will be money available for that.

 

I'd say that's a worthwhile upgrade in its own right. This will get you some big improvements over the 4208 series. We use 5406/5412zl switches as edge switches here and I've been impressed with them.

 

There's a company we use that are good at sorting this kinda thing out in a rush if you want to PM me for their details, though it sounds like you have that covered either way.

Edited by Roberto
Posted

I doubt you'd need to upgrade you're current hardware for setting up a basic guest vlan. You don't even need the switches to be able to do layer 3 routing. As long as they support 802.1Q VLAN tagging you should be fine. If you use the Smoothwall box as the gateway device for the guest VLAN/Network then that will do all the routing for you.

 

You could initially set up a guest VLAN on the switch your smoothwall server and Zonedirector are connected to and also the switch that the AP is connected to that is closest to where the event will be taking place. You'd then set up the switch ports that the Zonedirector & smoothwall are connected to with untagged (main network probably default VLAN1) and tagged for the guest vlan (eg VLAN100). Same with the port the AP is connected to and also the ports that connect the two switches together.

 

Then it's a case of using the "Virtual LAN Adaptors" option in Smoothwall to create a new tagged interface (VLAN100) for the guest VLAN. I would set up Smoothwall to act as the DHCP server for the guest network and then create a new transparent proxy policy with no authentication for the VLAN100 guest interface. You can create a custom filter policy/group that allows Facebook and twitter like you mentioned and add this for unauthenticated requests. Then set up a new SSID on the Zonedirector using the Guest Access mode that is set to put clients on VLAN100 and only apply to the AP being used (think you would need to create a WLAN Group for this).

 

That's the main gist of it anyway, the clients will pick up their IPs from Smoothwall with the gateway and dns being the Smoothwall IP specified in the VLAN100 guest network interface. You could then generate a single shareable guest pass for the day for the visitors to use on their devices or you could generate individual non shareable ones for each of the visitors if you're worried about students finding out the code etc.

Posted
Even with a password, a kid can find it out and most likely will as how is this going to be filtered around all the external people coming into school? Word of mouth......a poster in reception?

 

I know what your saying though but then the vast majority of kids have phones with 3G anyway and access facebook and twitter whenever they want regardless.

 

Maybe i'm just being a sceptic as I know how some people are within our school but I dont see the kids not getting hold of the username and password throughout the day.

 

True, but there's the legal side too: it's good to be able to show you tried, or more specifically that you "took all reasonable technical measures". It doesn't always work, but showing willing in that regard closes off one avenue for Negligence: that of not even thinking of the hazard. You could still be Negligent in other ways, but at least if something did happen and it was traced to some kid "hacking" (obviously a slight exaggeration) then that would factor into the equation. But if you were shown not to have even tried because you thought it would be pointless, you wouldn't be able to use the defence of having at least attempted to reduce the risk to As Low As Reasonably Possible.

Posted

/shrug

 

I let our kids access Twitter on our main computers. On the guest wireless I allow pretty much everything, with the exception of porn.

 

My logic is that if the kids have 3g access, they'll access it anyway. If they access it via our wifi, we can at least track it.

Posted (edited)

Guys,

 

What about following on from Ashm post. Could I VLAN tag the ports on the 4208 that the smoothwall vm and zonedirector and the connecting trunk together. Then vlan the ap port and uplinks on the edge switch. Exclude the bank of addresses from my 2k8 r2 DHCP server and setup the Zonedirector to act as a DHCP. Then use a WPAD.dat held on the zonedirector to point at the smoothwall, setup to identify by location (groups of IP). We already ident by ip for our Android tablet deployment.

 

Would that work?

Edited by denon101
Posted

Why not use the Smoothwall server to do DHCP + DNS on the guest VLAN, it would probably keep things simpler. There would be no need for WPAD.dat if you use set up transparent proxy on the guest VLAN interface on the smoothwall server. This would be best for visitors as it's more likely to work without any extra configuration on the different types of devices they may bring in.

 

There would be no need to exclude any addresses from the 2k8 r2 SHCP server in this case as everything is kept separate which is cleaner in my opinion. You can use whatever IP range you like for the guest VLAN.

Posted
/shrug

 

I let our kids access Twitter on our main computers. On the guest wireless I allow pretty much everything, with the exception of porn.

 

My logic is that if the kids have 3g access, they'll access it anyway. If they access it via our wifi, we can at least track it.

 

How can you track it on the guest network without auth?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...